import * as outputs from "../types/output"; export interface GetAvailabilityZoneFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeAvailabilityZones API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAvailabilityZones.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } export interface GetAvailabilityZonesFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeAvailabilityZones API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAvailabilityZones.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } export interface GetRegionsFilter { /** * Name of the filter field. Valid values can be found in the [describe-regions AWS CLI Reference](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } export declare namespace accessanalyzer { interface AnalyzerConfiguration { /** * Specifies the configuration of an internal access analyzer for an AWS organization or account. This configuration determines how the analyzer evaluates access within your AWS environment. See `internalAccess` Block for details. */ internalAccess?: outputs.accessanalyzer.AnalyzerConfigurationInternalAccess; /** * Specifies the configuration of an unused access analyzer for an AWS organization or account. See `unusedAccess` Block for details. */ unusedAccess?: outputs.accessanalyzer.AnalyzerConfigurationUnusedAccess; } interface AnalyzerConfigurationInternalAccess { /** * Information about analysis rules for the internal access analyzer. These rules determine which resources and access patterns will be analyzed. See `analysisRule` Block for Internal Access Analyzer for details. */ analysisRule?: outputs.accessanalyzer.AnalyzerConfigurationInternalAccessAnalysisRule; } interface AnalyzerConfigurationInternalAccessAnalysisRule { /** * List of rules for the internal access analyzer containing criteria to include in analysis. Only resources that meet the rule criteria will generate findings. See `inclusion` Block for details. */ inclusions?: outputs.accessanalyzer.AnalyzerConfigurationInternalAccessAnalysisRuleInclusion[]; } interface AnalyzerConfigurationInternalAccessAnalysisRuleInclusion { /** * List of AWS account IDs to apply to the internal access analysis rule criteria. Account IDs can only be applied to the analysis rule criteria for organization-level analyzers. */ accountIds?: string[]; /** * List of resource ARNs to apply to the internal access analysis rule criteria. The analyzer will only generate findings for resources that match these ARNs. */ resourceArns?: string[]; /** * List of resource types to apply to the internal access analysis rule criteria. The analyzer will only generate findings for resources of these types. Refer to [InternalAccessAnalysisRuleCriteria](https://docs.aws.amazon.com/access-analyzer/latest/APIReference/API_InternalAccessAnalysisRuleCriteria.html) in the AWS IAM Access Analyzer API Reference for valid values. */ resourceTypes?: string[]; } interface AnalyzerConfigurationUnusedAccess { /** * Information about analysis rules for the analyzer. Analysis rules determine which entities will generate findings based on the criteria you define when you create the rule. See `analysisRule` Block for Unused Access Analyzer for details. */ analysisRule?: outputs.accessanalyzer.AnalyzerConfigurationUnusedAccessAnalysisRule; /** * Specified access age in days for which to generate findings for unused access. */ unusedAccessAge?: number; } interface AnalyzerConfigurationUnusedAccessAnalysisRule { /** * List of rules for the analyzer containing criteria to exclude from analysis. Entities that meet the rule criteria will not generate findings. See `exclusion` Block for details. */ exclusions?: outputs.accessanalyzer.AnalyzerConfigurationUnusedAccessAnalysisRuleExclusion[]; } interface AnalyzerConfigurationUnusedAccessAnalysisRuleExclusion { /** * List of AWS account IDs to apply to the analysis rule criteria. The accounts cannot include the organization analyzer owner account. Account IDs can only be applied to the analysis rule criteria for organization-level analyzers. */ accountIds?: string[]; /** * List of key-value pairs for resource tags to exclude from the analysis. */ resourceTags?: { [key: string]: string; }[]; } interface ArchiveRuleFilter { /** * Contains comparator. */ contains: string[]; /** * Filter criteria. */ criteria: string; /** * Equals comparator. */ eqs: string[]; /** * Boolean comparator. */ exists: string; /** * Not Equals comparator. */ neqs: string[]; } } export declare namespace account { interface GetRegionsRegion { /** * The Region code of a given Region */ regionName: string; /** * The opt-in status of the region. Possible values are `ENABLED`, `ENABLING`, `DISABLING`, `DISABLED`, and `ENABLED_BY_DEFAULT`. */ regionOptStatus: string; } } export declare namespace accountaccess { interface ApplicationIdentitySource { /** * IAM Identity Center instance to use as the identity source. See `identityCenter` Block below. */ identityCenter?: outputs.accountaccess.ApplicationIdentitySourceIdentityCenter; } interface ApplicationIdentitySourceIdentityCenter { /** * ARN of the IAM Identity Center application created for this account access manager application. */ applicationArn: string; /** * ARN of the IAM Identity Center instance. */ instanceArn: string; } interface ApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface EntitlementEntitlement { /** * Principal role entitlement configuration. See `entitlement.principal_role` Block below. */ principalRole?: outputs.accountaccess.EntitlementEntitlementPrincipalRole; } interface EntitlementEntitlementPrincipalRole { /** * Target AWS account ID. */ accountId: string; /** * Target AWS account name. */ accountName: string; /** * Principal configuration. See `entitlement.principal_role.principal` Block below. */ principal: outputs.accountaccess.EntitlementEntitlementPrincipalRolePrincipal; /** * ARN of the IAM role in the target AWS account that the principal is granted access to. */ roleArn: string; } interface EntitlementEntitlementPrincipalRolePrincipal { /** * IAM Identity Center principal configuration. See `entitlement.principal_role.principal.identity_center` Block below. */ identityCenter?: outputs.accountaccess.EntitlementEntitlementPrincipalRolePrincipalIdentityCenter; } interface EntitlementEntitlementPrincipalRolePrincipalIdentityCenter { /** * IAM Identity Center group ID. */ groupId?: string; /** * IAM Identity Center user ID. */ userId?: string; } interface GetApplicationIdentitySource { /** * IAM Identity Center instance used as the identity source. See `identityCenter` Block below. */ identityCenters: outputs.accountaccess.GetApplicationIdentitySourceIdentityCenter[]; } interface GetApplicationIdentitySourceIdentityCenter { /** * ARN of the IAM Identity Center application for this account access manager application. */ applicationArn: string; /** * ARN of the IAM Identity Center instance. */ instanceArn: string; } interface GetEntitlementsEntitlement { /** * Date and time when the Entitlement was created in RFC 3339 format. */ createdAt: string; /** * Service-assigned unique identifier for the Entitlement. */ entitlementId: string; /** * Principal-role entitlement configuration. See `entitlements.entitlement` Block below. */ entitlements: outputs.accountaccess.GetEntitlementsEntitlementEntitlement[]; } interface GetEntitlementsEntitlementEntitlement { /** * Principal-role entitlement configuration. See `entitlements.entitlement.principal_role` Block below. */ principalRoles: outputs.accountaccess.GetEntitlementsEntitlementEntitlementPrincipalRole[]; } interface GetEntitlementsEntitlementEntitlementPrincipalRole { /** * 12-digit AWS account ID for the target role. */ accountId: string; /** * Human-readable name of the target account. */ accountName: string; /** * IAM Identity Center principal granted access. See `entitlements.entitlement.principal_role.principal` Block below. */ principals: outputs.accountaccess.GetEntitlementsEntitlementEntitlementPrincipalRolePrincipal[]; /** * Target IAM role ARN. */ roleArn: string; } interface GetEntitlementsEntitlementEntitlementPrincipalRolePrincipal { /** * IAM Identity Center principal. See `entitlements.entitlement.principal_role.principal.identity_center` Block below. */ identityCenters: outputs.accountaccess.GetEntitlementsEntitlementEntitlementPrincipalRolePrincipalIdentityCenter[]; } interface GetEntitlementsEntitlementEntitlementPrincipalRolePrincipalIdentityCenter { /** * IAM Identity Center group ID. */ groupId: string; /** * IAM Identity Center user ID. */ userId: string; } interface GetEntitlementsFilter { /** * principal-to-role filter criteria for narrowing entitlement results. See `filter.principal_role` Block below. */ principalRole?: outputs.accountaccess.GetEntitlementsFilterPrincipalRole; } interface GetEntitlementsFilterPrincipalRole { /** * AWS account ID to filter entitlements by. */ accountId?: string; /** * principal to filter entitlements by. See `filter.principal_role.principal` Block below. */ principal?: outputs.accountaccess.GetEntitlementsFilterPrincipalRolePrincipal; /** * IAM role ARN to filter entitlements by. */ roleArn?: string; } interface GetEntitlementsFilterPrincipalRolePrincipal { /** * IAM Identity Center principal filter criteria. See `filter.principal_role.principal.identity_center` Block below. */ identityCenter?: outputs.accountaccess.GetEntitlementsFilterPrincipalRolePrincipalIdentityCenter; } interface GetEntitlementsFilterPrincipalRolePrincipalIdentityCenter { /** * IAM Identity Center group ID. */ groupId?: string; /** * IAM Identity Center user ID. */ userId?: string; } } export declare namespace acm { interface CertificateDomainValidationOption { /** * Domain to be validated */ domainName: string; /** * The name of the DNS record to create to validate the certificate */ resourceRecordName: string; /** * The type of DNS record to create */ resourceRecordType: string; /** * The value the DNS record needs to have */ resourceRecordValue: string; } interface CertificateOptions { /** * Whether certificate details should be added to a certificate transparency log. Valid values are `ENABLED` or `DISABLED`. See https://docs.aws.amazon.com/acm/latest/userguide/acm-concepts.html#concept-transparency for more details. */ certificateTransparencyLoggingPreference?: string; /** * Whether the certificate can be exported. Valid values are `ENABLED` or `DISABLED` (default). **Note** Issuing an exportable certificate is subject to additional charges. See [AWS Certificate Manager pricing](https://aws.amazon.com/certificate-manager/pricing/) for more details. */ export: string; } interface CertificateRenewalSummary { /** * The status of ACM's managed renewal of the certificate */ renewalStatus: string; /** * The reason that a renewal request was unsuccessful or is pending */ renewalStatusReason: string; updatedAt: string; } interface CertificateValidationOption { /** * Fully qualified domain name (FQDN) in the certificate. */ domainName: string; /** * Domain name that you want ACM to use to send you validation emails. This domain name is the suffix of the email addresses that you want ACM to use. This must be the same as the `domainName` value or a superdomain of the `domainName` value. For example, if you request a certificate for `"testing.example.com"`, you can specify `"example.com"` for this value. */ validationDomain: string; } } export declare namespace acmpca { interface CertificateAuthorityCertificateAuthorityConfiguration { /** * Type of the public key algorithm and size, in bits, of the key pair that your key pair creates when it issues a certificate. Valid values can be found in the [ACM PCA Documentation](https://docs.aws.amazon.com/privateca/latest/APIReference/API_CertificateAuthorityConfiguration.html). */ keyAlgorithm: string; /** * Name of the algorithm your private CA uses to sign certificate requests. Valid values can be found in the [ACM PCA Documentation](https://docs.aws.amazon.com/privateca/latest/APIReference/API_CertificateAuthorityConfiguration.html). */ signingAlgorithm: string; /** * Nested argument that contains X.500 distinguished name information. At least one nested attribute must be specified. */ subject: outputs.acmpca.CertificateAuthorityCertificateAuthorityConfigurationSubject; } interface CertificateAuthorityCertificateAuthorityConfigurationSubject { /** * Fully qualified domain name (FQDN) associated with the certificate subject. Must be less than or equal to 64 characters in length. */ commonName?: string; /** * Two digit code that specifies the country in which the certificate subject located. Must be less than or equal to 2 characters in length. */ country?: string; /** * Disambiguating information for the certificate subject. Must be less than or equal to 64 characters in length. */ distinguishedNameQualifier?: string; /** * Typically a qualifier appended to the name of an individual. Examples include Jr. for junior, Sr. for senior, and III for third. Must be less than or equal to 3 characters in length. */ generationQualifier?: string; /** * First name. Must be less than or equal to 16 characters in length. */ givenName?: string; /** * Concatenation that typically contains the first letter of the `givenName`, the first letter of the middle name if one exists, and the first letter of the `surname`. Must be less than or equal to 5 characters in length. */ initials?: string; /** * Locality (such as a city or town) in which the certificate subject is located. Must be less than or equal to 128 characters in length. */ locality?: string; /** * Legal name of the organization with which the certificate subject is affiliated. Must be less than or equal to 64 characters in length. */ organization?: string; /** * Subdivision or unit of the organization (such as sales or finance) with which the certificate subject is affiliated. Must be less than or equal to 64 characters in length. */ organizationalUnit?: string; /** * Typically a shortened version of a longer `givenName`. For example, Jonathan is often shortened to John. Elizabeth is often shortened to Beth, Liz, or Eliza. Must be less than or equal to 128 characters in length. */ pseudonym?: string; /** * State in which the subject of the certificate is located. Must be less than or equal to 128 characters in length. */ state?: string; /** * Family name. In the US and the UK for example, the surname of an individual is ordered last. In Asian cultures the surname is typically ordered first. Must be less than or equal to 40 characters in length. */ surname?: string; /** * Title such as Mr. or Ms. which is pre-pended to the name to refer formally to the certificate subject. Must be less than or equal to 64 characters in length. */ title?: string; } interface CertificateAuthorityRevocationConfiguration { /** * Nested argument containing configuration of the certificate revocation list (CRL), if any, maintained by the certificate authority. Defined below. */ crlConfiguration?: outputs.acmpca.CertificateAuthorityRevocationConfigurationCrlConfiguration; /** * Nested argument containing configuration of * the custom OCSP responder endpoint. Defined below. */ ocspConfiguration?: outputs.acmpca.CertificateAuthorityRevocationConfigurationOcspConfiguration; } interface CertificateAuthorityRevocationConfigurationCrlConfiguration { /** * Name inserted into the certificate CRL Distribution Points extension that enables the use of an alias for the CRL distribution point. Use this value if you don't want the name of your S3 bucket to be public. Must be less than or equal to 253 characters in length. */ customCname?: string; /** * Configures a custom path for the CRL in S3. If specified, the CRL will be written to `s3:////`. Must conform to the pattern `[-a-zA-Z0-9;?:@&=+$,%_.!~*()']+(/[-a-zA-Z0-9;?:@&=+$,%_.!~*()']+)*` and be between 0 and 253 characters in length. */ customPath?: string; /** * Boolean value that specifies whether certificate revocation lists (CRLs) are enabled. Defaults to `false`. */ enabled?: boolean; /** * Number of days until a certificate expires. Must be between 1 and 5000. */ expirationInDays?: number; /** * Name of the S3 bucket that contains the CRL. If you do not provide a value for the `customCname` argument, the name of your S3 bucket is placed into the CRL Distribution Points extension of the issued certificate. You must specify a bucket policy that allows ACM PCA to write the CRL to your bucket. Must be between 3 and 255 characters in length. */ s3BucketName?: string; /** * Determines whether the CRL will be publicly readable or privately held in the CRL Amazon S3 bucket. Defaults to `PUBLIC_READ`. */ s3ObjectAcl: string; } interface CertificateAuthorityRevocationConfigurationOcspConfiguration { /** * Boolean value that specifies whether a custom OCSP responder is enabled. */ enabled: boolean; /** * CNAME specifying a customized OCSP domain. Note: The value of the CNAME must not include a protocol prefix such as "http://" or "https://". */ ocspCustomCname?: string; } interface CertificateValidity { /** * Determines how `value` is interpreted. Valid values: `DAYS`, `MONTHS`, `YEARS`, `ABSOLUTE`, `END_DATE`. */ type: string; /** * If `type` is `DAYS`, `MONTHS`, or `YEARS`, the relative time until the certificate expires. If `type` is `ABSOLUTE`, the date in seconds since the Unix epoch. If `type` is `END_DATE`, the date in RFC 3339 format. */ value: string; } interface GetCertificateAuthorityRevocationConfiguration { /** * Nested attribute containing configuration of the certificate revocation list (CRL). See `crlConfiguration` below. */ crlConfigurations: outputs.acmpca.GetCertificateAuthorityRevocationConfigurationCrlConfiguration[]; /** * Nested attribute containing configuration of the Online Certificate Status Protocol (OCSP). See `ocspConfiguration` below. */ ocspConfigurations: outputs.acmpca.GetCertificateAuthorityRevocationConfigurationOcspConfiguration[]; } interface GetCertificateAuthorityRevocationConfigurationCrlConfiguration { /** * Name inserted into the certificate CRL Distribution Points extension that enables the use of an alias for the CRL distribution point. */ customCname: string; /** * Custom path for the CRL in S3. */ customPath: string; /** * Boolean value that specifies whether a custom OCSP responder is enabled. */ enabled: boolean; /** * Number of days until a certificate expires. */ expirationInDays: number; /** * Name of the S3 bucket that contains the CRL. */ s3BucketName: string; /** * Whether the CRL is publicly readable or privately held in the CRL Amazon S3 bucket. */ s3ObjectAcl: string; } interface GetCertificateAuthorityRevocationConfigurationOcspConfiguration { /** * Boolean value that specifies whether a custom OCSP responder is enabled. */ enabled: boolean; /** * A CNAME specifying a customized OCSP domain. */ ocspCustomCname: string; } } export declare namespace agentregistry { interface GetRegistryApprovalConfiguration { /** * Set of rules that determine which registry records are automatically approved on submission. When empty, submitted records require manual review. */ autoApprovalRules: string[]; } interface GetRegistryDiscoveryConfiguration { /** * Authorizer configuration for the registry. Present when `authorizerType` is `CUSTOM_JWT`. See below. */ authorizerConfigurations: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfiguration[]; /** * Type of authorizer that controls how consumers access the registry's search and MCP invoke operations. Valid values: `AWS_IAM`, `CUSTOM_JWT`. */ authorizerType: string; } interface GetRegistryDiscoveryConfigurationAuthorizerConfiguration { /** * Configuration for a custom JWT authorizer. See below. */ customJwtAuthorizers: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizer[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizer { /** * Audience values accepted during JWT validation. */ allowedAudiences: string[]; /** * Client identifiers accepted during JWT validation. */ allowedClients: string[]; /** * Scopes accepted during JWT validation. */ allowedScopes: string[]; /** * Custom claims for additional JWT validation beyond standard OIDC claims. See below. */ customClaims: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaim[]; /** * OpenID Connect discovery URL used to retrieve the identity provider's metadata and signing keys. */ discoveryUrl: string; /** * Per-domain private endpoint overrides that route specific identity provider domains through distinct private endpoints. See below. */ privateEndpointOverrides: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride[]; /** * Private endpoint used to reach the specified domain. See above. */ privateEndpoints: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaim { /** * Claim match criteria. See below. */ authorizingClaimMatchValues: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue[]; /** * Name of the claim validated in the inbound JWT token. */ inboundTokenClaimName: string; /** * Type of the claim value. Valid values: `STRING`, `STRING_ARRAY`. */ inboundTokenClaimValueType: string; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue { /** * Operator used to match claim values. Valid values: `EQUALS`, `CONTAINS`, `CONTAINS_ANY`. */ claimMatchOperator: string; /** * Value matched against. See below. */ claimMatchValues: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue { /** * Single string value to match. */ matchValueString: string; /** * Set of string values to match. */ matchValueStringLists: string[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint { /** * Private endpoint backed by a service-managed VPC resource. See below. */ managedVpcResources: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource[]; /** * Private endpoint backed by a self-managed VPC Lattice resource configuration. See below. */ selfManagedLatticeResources: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource { /** * IP address type used by the private endpoint, either `IPV4` or `IPV6`. */ endpointIpAddressType: string; /** * Routing domain used to resolve traffic through the private endpoint. */ routingDomain: string; /** * IDs of the security groups associated with the private endpoint network interfaces. */ securityGroupIds: string[]; /** * IDs of the subnets in which the private endpoint network interfaces are placed. */ subnetIds: string[]; /** * Tags applied to the service-managed VPC resource. */ tags: { [key: string]: string; }; /** * ID of the VPC in which the private endpoint is provisioned. */ vpcIdentifier: string; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride { /** * Domain name to which this private endpoint override applies. */ domain: string; /** * Private endpoint used to reach the specified domain. See above. */ privateEndpoints: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint { /** * Private endpoint backed by a service-managed VPC resource. See below. */ managedVpcResources: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource[]; /** * Private endpoint backed by a self-managed VPC Lattice resource configuration. See below. */ selfManagedLatticeResources: outputs.agentregistry.GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource[]; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type used by the private endpoint, either `IPV4` or `IPV6`. */ endpointIpAddressType: string; /** * Routing domain used to resolve traffic through the private endpoint. */ routingDomain: string; /** * IDs of the security groups associated with the private endpoint network interfaces. */ securityGroupIds: string[]; /** * IDs of the subnets in which the private endpoint network interfaces are placed. */ subnetIds: string[]; /** * Tags applied to the service-managed VPC resource. */ tags: { [key: string]: string; }; /** * ID of the VPC in which the private endpoint is provisioned. */ vpcIdentifier: string; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration, specified as a resource configuration ID or ARN. */ resourceConfigurationIdentifier: string; } interface GetRegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration, specified as a resource configuration ID or ARN. */ resourceConfigurationIdentifier: string; } interface GetRegistryEncryptionConfiguration { /** * ARN of the customer-managed AWS KMS key used to encrypt the registry's content. */ kmsKeyArn: string; } interface RegistryApprovalConfiguration { /** * Set of rules that determine which registry records are automatically approved on submission. Valid values: `APPROVE_ALL`. When omitted or empty, submitted records require manual review. */ autoApprovalRules?: string[]; } interface RegistryAutoDetectionConfiguration { /** * Whether auto-detection is requested for the registry. */ enabled: boolean; /** * Source from which resources are detected. Valid values: `ORGANIZATION`. */ scope: string; } interface RegistryDiscoveryConfiguration { /** * Authorizer configuration for the registry. Required when `authorizerType` is `CUSTOM_JWT`. See below. */ authorizerConfiguration?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfiguration; /** * Type of authorizer that controls how consumers access the registry's search and MCP invoke operations. Valid values: `AWS_IAM`, `CUSTOM_JWT`. */ authorizerType: string; } interface RegistryDiscoveryConfigurationAuthorizerConfiguration { /** * Configuration for a custom JWT authorizer. */ customJwtAuthorizer?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizer; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizer { /** * Audience values accepted during JWT validation. A token is rejected if none of its audience claims match. */ allowedAudiences?: string[]; /** * Client identifiers accepted during JWT validation. A token is rejected if it was not issued to one of these clients. */ allowedClients?: string[]; /** * Scopes accepted during JWT validation. A token is rejected if it does not carry one of these scopes. */ allowedScopes?: string[]; /** * Custom claims for additional JWT validation beyond standard OIDC claims. See below. */ customClaims?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaim[]; /** * OpenID Connect discovery URL used to retrieve the identity provider's metadata and signing keys. */ discoveryUrl: string; /** * Private endpoint used to reach the identity provider's discovery URL over a private network path. See below. */ privateEndpoint?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint; /** * Per-domain private endpoint overrides that route specific identity provider domains through distinct private endpoints. See below. */ privateEndpointOverrides?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride[]; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaim { /** * Claim match criteria. See below. */ authorizingClaimMatchValue: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue; /** * Name of the claim to validate in the inbound JWT token. Must contain only letters, numbers, and the characters `_`, `.`, `-`, `:`. */ inboundTokenClaimName: string; /** * Type of the claim value. Valid values: `STRING`, `STRING_ARRAY`. */ inboundTokenClaimValueType: string; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue { /** * Operator used to match claim values. Valid values: `EQUALS`, `CONTAINS`, `CONTAINS_ANY`. */ claimMatchOperator: string; /** * Value to match against. See below. */ claimMatchValue: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue { /** * Single string value to match. Must contain only letters, numbers, and the characters `_`, `.`, `-`, `:`. */ matchValueString?: string; /** * Set of string values to match. Each value must contain only letters, numbers, and the characters `_`, `.`, `-`, `:`. */ matchValueStringLists?: string[]; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint { /** * Private endpoint backed by a service-managed VPC resource. See below. */ managedVpcResource?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource; /** * Private endpoint backed by a self-managed VPC Lattice resource configuration. See below. */ selfManagedLatticeResource?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource { /** * IP address type used by the private endpoint, either `IPV4` or `IPV6`. */ endpointIpAddressType: string; /** * Routing domain used to resolve traffic through the private endpoint. */ routingDomain?: string; /** * IDs of the security groups associated with the private endpoint network interfaces. */ securityGroupIds?: string[]; /** * IDs of the subnets in which the private endpoint network interfaces are placed. */ subnetIds: string[]; /** * Tags applied to the service-managed VPC resource. */ tags?: { [key: string]: string; }; /** * ID of the VPC in which the private endpoint is provisioned. */ vpcIdentifier: string; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride { /** * Domain name to which this private endpoint override applies. */ domain: string; /** * Private endpoint used to reach the specified domain. See above. */ privateEndpoint: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint { /** * Private endpoint backed by a service-managed VPC resource. See below. */ managedVpcResource?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource; /** * Private endpoint backed by a self-managed VPC Lattice resource configuration. See below. */ selfManagedLatticeResource?: outputs.agentregistry.RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type used by the private endpoint, either `IPV4` or `IPV6`. */ endpointIpAddressType: string; /** * Routing domain used to resolve traffic through the private endpoint. */ routingDomain?: string; /** * IDs of the security groups associated with the private endpoint network interfaces. */ securityGroupIds?: string[]; /** * IDs of the subnets in which the private endpoint network interfaces are placed. */ subnetIds: string[]; /** * Tags applied to the service-managed VPC resource. */ tags?: { [key: string]: string; }; /** * ID of the VPC in which the private endpoint is provisioned. */ vpcIdentifier: string; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration, specified as a resource configuration ID or ARN. */ resourceConfigurationIdentifier?: string; } interface RegistryDiscoveryConfigurationAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration, specified as a resource configuration ID or ARN. */ resourceConfigurationIdentifier?: string; } interface RegistryEncryptionConfiguration { /** * ARN of the customer-managed AWS KMS key used to encrypt the registry's content. */ kmsKeyArn: string; } interface RegistryTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace alb { interface GetListenerDefaultAction { authenticateCognitos: outputs.alb.GetListenerDefaultActionAuthenticateCognito[]; authenticateOidcs: outputs.alb.GetListenerDefaultActionAuthenticateOidc[]; fixedResponses: outputs.alb.GetListenerDefaultActionFixedResponse[]; forwards: outputs.alb.GetListenerDefaultActionForward[]; jwtValidations: outputs.alb.GetListenerDefaultActionJwtValidation[]; order: number; redirects: outputs.alb.GetListenerDefaultActionRedirect[]; targetGroupArn: string; type: string; } interface GetListenerDefaultActionAuthenticateCognito { authenticationRequestExtraParams: { [key: string]: string; }; onUnauthenticatedRequest: string; scope: string; sessionCookieName: string; sessionTimeout: number; userPoolArn: string; userPoolClientId: string; userPoolDomain: string; } interface GetListenerDefaultActionAuthenticateOidc { authenticationRequestExtraParams: { [key: string]: string; }; authorizationEndpoint: string; clientId: string; clientSecret: string; issuer: string; onUnauthenticatedRequest: string; scope: string; sessionCookieName: string; sessionTimeout: number; tokenEndpoint: string; userInfoEndpoint: string; } interface GetListenerDefaultActionFixedResponse { contentType: string; messageBody: string; statusCode: string; } interface GetListenerDefaultActionForward { stickinesses: outputs.alb.GetListenerDefaultActionForwardStickiness[]; targetGroups: outputs.alb.GetListenerDefaultActionForwardTargetGroup[]; } interface GetListenerDefaultActionForwardStickiness { duration: number; enabled: boolean; } interface GetListenerDefaultActionForwardTargetGroup { /** * ARN of the listener. Required if `loadBalancerArn` and `port` is not set. */ arn: string; weight: number; } interface GetListenerDefaultActionJwtValidation { additionalClaims: outputs.alb.GetListenerDefaultActionJwtValidationAdditionalClaim[]; issuer: string; jwksEndpoint: string; } interface GetListenerDefaultActionJwtValidationAdditionalClaim { format: string; name: string; values: string[]; } interface GetListenerDefaultActionRedirect { host: string; path: string; /** * Port of the listener. Required if `arn` is not set. */ port: string; protocol: string; query: string; statusCode: string; } interface GetListenerMutualAuthentication { advertiseTrustStoreCaNames: string; ignoreClientCertificateExpiry: boolean; mode: string; trustStoreArn: string; } interface GetLoadBalancerAccessLogs { bucket: string; enabled: boolean; prefix: string; } interface GetLoadBalancerConnectionLog { bucket: string; enabled: boolean; prefix: string; } interface GetLoadBalancerHealthCheckLog { bucket: string; enabled: boolean; prefix: string; } interface GetLoadBalancerIpamPool { ipv4IpamPoolId: string; } interface GetLoadBalancerSubnetMapping { allocationId: string; ipv6Address: string; outpostId: string; privateIpv4Address: string; subnetId: string; } interface GetTargetGroupHealthCheck { enabled: boolean; healthyThreshold: number; interval: number; matcher: string; path: string; port: string; protocol: string; timeout: number; unhealthyThreshold: number; } interface GetTargetGroupStickiness { cookieDuration: number; cookieName: string; enabled: boolean; type: string; } interface ListenerDefaultAction { /** * Configuration block for using Amazon Cognito to authenticate users. Specify only when `type` is `authenticate-cognito`. See below. */ authenticateCognito?: outputs.alb.ListenerDefaultActionAuthenticateCognito; /** * Configuration block for an identity provider that is compliant with OpenID Connect (OIDC). Specify only when `type` is `authenticate-oidc`. See below. */ authenticateOidc?: outputs.alb.ListenerDefaultActionAuthenticateOidc; /** * Information for creating an action that returns a custom HTTP response. Required if `type` is `fixed-response`. */ fixedResponse?: outputs.alb.ListenerDefaultActionFixedResponse; /** * Configuration block for creating an action that distributes requests among one or more target groups. Specify only if `type` is `forward`. See below. */ forward?: outputs.alb.ListenerDefaultActionForward; /** * Configuration block for creating a JWT validation action. Required if `type` is `jwt-validation`. */ jwtValidation?: outputs.alb.ListenerDefaultActionJwtValidation; /** * Order for the action. The action with the lowest value for order is performed first. Valid values are between `1` and `50000`. Defaults to the position in the list of actions. */ order: number; /** * Configuration block for creating a redirect action. Required if `type` is `redirect`. See below. */ redirect?: outputs.alb.ListenerDefaultActionRedirect; /** * ARN of the Target Group to which to route traffic. Specify only if `type` is `forward` and you want to route to a single target group. To route to one or more target groups, use a `forward` block instead. Can be specified with `forward` but ARNs must match. */ targetGroupArn?: string; /** * Type of routing action. Valid values are `forward`, `redirect`, `fixed-response`, `authenticate-cognito`, `authenticate-oidc` and `jwt-validation`. * * The following arguments are optional: */ type: string; } interface ListenerDefaultActionAuthenticateCognito { /** * Query parameters to include in the redirect request to the authorization endpoint. Max: 10. See below. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * Behavior if the user is not authenticated. Valid values are `deny`, `allow` and `authenticate`. */ onUnauthenticatedRequest: string; /** * Set of user claims to be requested from the IdP. */ scope: string; /** * Name of the cookie used to maintain session information. */ sessionCookieName: string; /** * Maximum duration of the authentication session, in seconds. */ sessionTimeout: number; /** * ARN of the Cognito user pool. */ userPoolArn: string; /** * ID of the Cognito user pool client. */ userPoolClientId: string; /** * Domain prefix or fully-qualified domain name of the Cognito user pool. * * The following arguments are optional: */ userPoolDomain: string; } interface ListenerDefaultActionAuthenticateOidc { /** * Query parameters to include in the redirect request to the authorization endpoint. Max: 10. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * Authorization endpoint of the IdP. */ authorizationEndpoint: string; /** * OAuth 2.0 client identifier. */ clientId: string; /** * OAuth 2.0 client secret. */ clientSecret: string; /** * OIDC issuer identifier of the IdP. */ issuer: string; /** * Behavior if the user is not authenticated. Valid values: `deny`, `allow` and `authenticate` */ onUnauthenticatedRequest: string; /** * Set of user claims to be requested from the IdP. */ scope: string; /** * Name of the cookie used to maintain session information. */ sessionCookieName: string; /** * Maximum duration of the authentication session, in seconds. */ sessionTimeout: number; /** * Token endpoint of the IdP. */ tokenEndpoint: string; /** * User info endpoint of the IdP. * * The following arguments are optional: */ userInfoEndpoint: string; } interface ListenerDefaultActionFixedResponse { /** * Content type. Valid values are `text/plain`, `text/css`, `text/html`, `application/javascript` and `application/json`. * * The following arguments are optional: */ contentType: string; /** * Message body. */ messageBody?: string; /** * HTTP response code. Valid values are `2XX`, `4XX`, or `5XX`. */ statusCode: string; } interface ListenerDefaultActionForward { /** * Configuration block for target group stickiness for the rule. See below. */ stickiness?: outputs.alb.ListenerDefaultActionForwardStickiness; /** * Set of 1-5 target group blocks. See below. * * The following arguments are optional: */ targetGroups: outputs.alb.ListenerDefaultActionForwardTargetGroup[]; } interface ListenerDefaultActionForwardStickiness { /** * Time period, in seconds, during which requests from a client should be routed to the same target group. The range is 1-604800 seconds (7 days). * * The following arguments are optional: */ duration: number; /** * Whether target group stickiness is enabled. Default is `false`. */ enabled?: boolean; } interface ListenerDefaultActionForwardTargetGroup { /** * ARN of the target group. * * The following arguments are optional: */ arn: string; /** * Weight. The range is 0 to 999. */ weight?: number; } interface ListenerDefaultActionJwtValidation { /** * Repeatable configuration block for additional claims to validate. */ additionalClaims?: outputs.alb.ListenerDefaultActionJwtValidationAdditionalClaim[]; /** * Issuer of the JWT. */ issuer: string; /** * JSON Web Key Set (JWKS) endpoint. This endpoint contains JSON Web Keys (JWK) that are used to validate signatures from the provider. This must be a full URL, including the HTTPS protocol, the domain, and the path. * * The following arguments are optional: */ jwksEndpoint: string; } interface ListenerDefaultActionJwtValidationAdditionalClaim { /** * Format of the claim value. Valid values are `single-string`, `string-array` and `space-separated-values`. */ format: string; /** * Name of the claim to validate. `exp`, `iss`, `nbf`, or `iat` cannot be specified because they are validated by default. */ name: string; /** * List of expected values of the claim. */ values: string[]; } interface ListenerDefaultActionRedirect { /** * Hostname. This component is not percent-encoded. The hostname can contain `#{host}`. Defaults to `#{host}`. */ host?: string; /** * Absolute path, starting with the leading "/". This component is not percent-encoded. The path can contain #{host}, #{path}, and #{port}. Defaults to `/#{path}`. */ path?: string; /** * Port. Specify a value from `1` to `65535` or `#{port}`. Defaults to `#{port}`. */ port?: string; /** * Protocol. Valid values are `HTTP`, `HTTPS`, or `#{protocol}`. Defaults to `#{protocol}`. */ protocol?: string; /** * Query parameters, URL-encoded when necessary, but not percent-encoded. Do not include the leading "?". Defaults to `#{query}`. */ query?: string; /** * HTTP redirect code. The redirect is either permanent (`HTTP_301`) or temporary (`HTTP_302`). * * The following arguments are optional: */ statusCode: string; } interface ListenerMutualAuthentication { /** * Valid values are `off` and `on`. */ advertiseTrustStoreCaNames: string; /** * Whether client certificate expiry is ignored. * Default is `false`. */ ignoreClientCertificateExpiry?: boolean; /** * Valid values are `off`, `passthrough`, and `verify`. */ mode: string; /** * ARN of the elbv2 Trust Store. */ trustStoreArn?: string; } interface ListenerRuleAction { /** * Information for creating an authenticate action using Cognito. Required if `type` is `authenticate-cognito`. */ authenticateCognito?: outputs.alb.ListenerRuleActionAuthenticateCognito; /** * Information for creating an authenticate action using OIDC. Required if `type` is `authenticate-oidc`. */ authenticateOidc?: outputs.alb.ListenerRuleActionAuthenticateOidc; /** * Information for creating an action that returns a custom HTTP response. Required if `type` is `fixed-response`. */ fixedResponse?: outputs.alb.ListenerRuleActionFixedResponse; /** * Configuration block for creating an action that distributes requests among one or more target groups. * Specify only if `type` is `forward`. * Cannot be specified with `targetGroupArn`. */ forward?: outputs.alb.ListenerRuleActionForward; /** * Information for creating a JWT validation action. Required if `type` is `jwt-validation`. */ jwtValidation?: outputs.alb.ListenerRuleActionJwtValidation; /** * Order for the action. * The action with the lowest value for order is performed first. * Valid values are between `1` and `50000`. * Defaults to the position in the list of actions. */ order: number; /** * Information for creating a redirect action. Required if `type` is `redirect`. */ redirect?: outputs.alb.ListenerRuleActionRedirect; /** * ARN of the Target Group to which to route traffic. * Specify only if `type` is `forward` and you want to route to a single target group. * To route to one or more target groups, use a `forward` block instead. * Cannot be specified with `forward`. */ targetGroupArn?: string; /** * The type of routing action. Valid values are `forward`, `redirect`, `fixed-response`, `authenticate-cognito`, `authenticate-oidc` and `jwt-validation`. */ type: string; } interface ListenerRuleActionAuthenticateCognito { /** * The query parameters to include in the redirect request to the authorization endpoint. Max: 10. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * The behavior if the user is not authenticated. Valid values: `deny`, `allow` and `authenticate` */ onUnauthenticatedRequest: string; /** * The set of user claims to be requested from the IdP. */ scope?: string; /** * The name of the cookie used to maintain session information. */ sessionCookieName?: string; /** * The maximum duration of the authentication session, in seconds. */ sessionTimeout?: number; /** * The ARN of the Cognito user pool. */ userPoolArn: string; /** * The ID of the Cognito user pool client. */ userPoolClientId: string; /** * The domain prefix or fully-qualified domain name of the Cognito user pool. */ userPoolDomain: string; } interface ListenerRuleActionAuthenticateOidc { /** * The query parameters to include in the redirect request to the authorization endpoint. Max: 10. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * The authorization endpoint of the IdP. */ authorizationEndpoint: string; /** * The OAuth 2.0 client identifier. */ clientId: string; /** * The OAuth 2.0 client secret. */ clientSecret: string; /** * The OIDC issuer identifier of the IdP. */ issuer: string; /** * The behavior if the user is not authenticated. Valid values: `deny`, `allow` and `authenticate` */ onUnauthenticatedRequest: string; /** * The set of user claims to be requested from the IdP. */ scope?: string; /** * The name of the cookie used to maintain session information. */ sessionCookieName?: string; /** * The maximum duration of the authentication session, in seconds. */ sessionTimeout?: number; /** * The token endpoint of the IdP. */ tokenEndpoint: string; /** * The user info endpoint of the IdP. */ userInfoEndpoint: string; } interface ListenerRuleActionFixedResponse { /** * The content type. Valid values are `text/plain`, `text/css`, `text/html`, `application/javascript` and `application/json`. */ contentType: string; /** * The message body. */ messageBody?: string; /** * The HTTP response code. Valid values are `2XX`, `4XX`, or `5XX`. */ statusCode: string; } interface ListenerRuleActionForward { /** * The target group stickiness for the rule. */ stickiness?: outputs.alb.ListenerRuleActionForwardStickiness; /** * One or more target group blocks. */ targetGroups: outputs.alb.ListenerRuleActionForwardTargetGroup[]; } interface ListenerRuleActionForwardStickiness { /** * The time period, in seconds, during which requests from a client should be routed to the same target group. The range is 1-604800 seconds (7 days). */ duration: number; /** * Indicates whether target group stickiness is enabled. */ enabled?: boolean; } interface ListenerRuleActionForwardTargetGroup { /** * ARN of the target group. */ arn: string; /** * The weight. The range is 0 to 999. */ weight?: number; } interface ListenerRuleActionJwtValidation { /** * Repeatable configuration block for additional claims to validate. */ additionalClaims?: outputs.alb.ListenerRuleActionJwtValidationAdditionalClaim[]; /** * Issuer of the JWT. */ issuer: string; /** * JSON Web Key Set (JWKS) endpoint. This endpoint contains JSON Web Keys (JWK) that are used to validate signatures from the provider. This must be a full URL, including the HTTPS protocol, the domain, and the path. */ jwksEndpoint: string; } interface ListenerRuleActionJwtValidationAdditionalClaim { /** * Format of the claim value. Valid values are `single-string`, `string-array` and `space-separated-values`. */ format: string; /** * Name of the claim to validate. `exp`, `iss`, `nbf`, or `iat` cannot be specified because they are validated by default. */ name: string; /** * List of expected values of the claim. */ values: string[]; } interface ListenerRuleActionRedirect { /** * The hostname. This component is not percent-encoded. The hostname can contain `#{host}`. Defaults to `#{host}`. */ host?: string; /** * The absolute path, starting with the leading "/". This component is not percent-encoded. The path can contain #{host}, #{path}, and #{port}. Defaults to `/#{path}`. */ path?: string; /** * The port. Specify a value from `1` to `65535` or `#{port}`. Defaults to `#{port}`. */ port?: string; /** * The protocol. Valid values are `HTTP`, `HTTPS`, or `#{protocol}`. Defaults to `#{protocol}`. */ protocol?: string; /** * The query parameters, URL-encoded when necessary, but not percent-encoded. Do not include the leading "?". Defaults to `#{query}`. */ query?: string; /** * The HTTP redirect code. The redirect is either permanent (`HTTP_301`) or temporary (`HTTP_302`). */ statusCode: string; } interface ListenerRuleCondition { /** * Host header patterns to match. Host Header block fields documented below. */ hostHeader?: outputs.alb.ListenerRuleConditionHostHeader; /** * HTTP headers to match. HTTP Header block fields documented below. */ httpHeader?: outputs.alb.ListenerRuleConditionHttpHeader; /** * Contains a single `values` item which is a list of HTTP request methods or verbs to match. Maximum size is 40 characters. Only allowed characters are A-Z, hyphen (-) and underscore (\_). Comparison is case sensitive. Wildcards are not supported. Only one needs to match for the condition to be satisfied. AWS recommends that GET and HEAD requests are routed in the same way because the response to a HEAD request may be cached. */ httpRequestMethod?: outputs.alb.ListenerRuleConditionHttpRequestMethod; /** * Path patterns to match against the request URL. Path Pattern block fields documented below. */ pathPattern?: outputs.alb.ListenerRuleConditionPathPattern; /** * Query strings to match. Query String block fields documented below. */ queryStrings?: outputs.alb.ListenerRuleConditionQueryString[]; /** * Source IP address to match. For ALB, use `values` to specify CIDR ranges. For NLB, use `ipAddressType` to match the IP address type (`ipv4` or `ipv6`). Source IP block fields documented below. * * > **NOTE::** Exactly one of `hostHeader`, `httpHeader`, `httpRequestMethod`, `pathPattern`, `queryString` or `sourceIp` must be set per condition. */ sourceIp?: outputs.alb.ListenerRuleConditionSourceIp; } interface ListenerRuleConditionHostHeader { /** * List of regular expressions to compare against the host header. The maximum length of each string is 128 characters. Conflicts with `values`. */ regexValues?: string[]; /** * List of host header value patterns to match. Maximum size of each pattern is 128 characters. Comparison is case-insensitive. Wildcard characters supported: * (matches 0 or more characters) and ? (matches exactly 1 character). Only one pattern needs to match for the condition to be satisfied. To match host headers containing a non-standard port (for example, `example.com:8443`), use `regexValues`. Conflicts with `regexValues`. */ values?: string[]; } interface ListenerRuleConditionHttpHeader { /** * Name of HTTP header to search. The maximum size is 40 characters. Comparison is case-insensitive. Only RFC7240 characters are supported. Wildcards are not supported. You cannot use HTTP header condition to specify the host header, use a `host-header` condition instead. */ httpHeaderName: string; /** * List of regular expression to compare against the HTTP header. The maximum length of each string is 128 characters. Conflicts with `values`. */ regexValues?: string[]; /** * List of header value patterns to match. Maximum size of each pattern is 128 characters. Comparison is case-insensitive. Wildcard characters supported: * (matches 0 or more characters) and ? (matches exactly 1 character). If the same header appears multiple times in the request they will be searched in order until a match is found. Only one pattern needs to match for the condition to be satisfied. To require that all of the strings are a match, create one condition block per string. Conflicts with `regexValues`. */ values?: string[]; } interface ListenerRuleConditionHttpRequestMethod { values: string[]; } interface ListenerRuleConditionPathPattern { /** * List of regular expressions to compare against the request URL. The maximum length of each string is 128 characters. Conflicts with `values`. */ regexValues?: string[]; /** * List of path patterns to compare against the request URL. Maximum size of each pattern is 128 characters. Comparison is case-sensitive. Wildcard characters supported: * (matches 0 or more characters) and ? (matches exactly 1 character). Only one pattern needs to match for the condition to be satisfied. Path pattern is compared only to the path of the URL, not to its query string. To compare against the query string, use a `queryString` condition. Conflicts with `regexValues`. */ values?: string[]; } interface ListenerRuleConditionQueryString { /** * Query string key pattern to match. */ key?: string; /** * Query string value pattern to match. */ value: string; } interface ListenerRuleConditionSourceIp { /** * IP address type for Network Load Balancers. Valid values are `ipv4` and `ipv6`. */ ipAddressType?: string; /** * List of source IP addresses in CIDR format for Application Load Balancers. Both IPv4 and IPv6 addresses can be used. Wildcards are not supported. Condition is satisfied if the source IP address of the request matches one of the CIDR blocks. Condition is not satisfied by the addresses in the `X-Forwarded-For` header, use `httpHeader` condition instead. */ values?: string[]; } interface ListenerRuleTransform { /** * Configuration block for host header rewrite. Required if `type` is `host-header-rewrite`. See Host Header Rewrite Config Blocks below. */ hostHeaderRewriteConfig?: outputs.alb.ListenerRuleTransformHostHeaderRewriteConfig; /** * Type of transform. Valid values are `host-header-rewrite` and `url-rewrite`. */ type: string; /** * Configuration block for URL rewrite. Required if `type` is `url-rewrite`. See URL Rewrite Config Blocks below. */ urlRewriteConfig?: outputs.alb.ListenerRuleTransformUrlRewriteConfig; } interface ListenerRuleTransformHostHeaderRewriteConfig { /** * Block for host header rewrite configuration. Only one block is accepted. See Rewrite Blocks below. */ rewrite?: outputs.alb.ListenerRuleTransformHostHeaderRewriteConfigRewrite; } interface ListenerRuleTransformHostHeaderRewriteConfigRewrite { /** * Regular expression to match in the input string. Length constraints: Between 1 and 1024 characters. */ regex: string; /** * Replacement string to use when rewriting the matched input. Capture groups in the regular expression (for example, `$1` and `$2`) can be specified. Length constraints: Between 0 and 1024 characters. */ replace: string; } interface ListenerRuleTransformUrlRewriteConfig { /** * Block for URL rewrite configuration. Only one block is accepted. See Rewrite Blocks below. */ rewrite?: outputs.alb.ListenerRuleTransformUrlRewriteConfigRewrite; } interface ListenerRuleTransformUrlRewriteConfigRewrite { /** * Regular expression to match in the input string. Length constraints: Between 1 and 1024 characters. */ regex: string; /** * Replacement string to use when rewriting the matched input. Capture groups in the regular expression (for example, `$1` and `$2`) can be specified. Length constraints: Between 0 and 1024 characters. */ replace: string; } interface LoadBalancerAccessLogs { /** * S3 bucket name to store the logs in. */ bucket: string; /** * Boolean to enable / disable `accessLogs`. Defaults to `false`, even when `bucket` is specified. */ enabled?: boolean; /** * S3 bucket prefix. Logs are stored in the root if not configured. */ prefix?: string; } interface LoadBalancerConnectionLogs { /** * S3 bucket name to store the logs in. */ bucket: string; /** * Boolean to enable / disable `connectionLogs`. Defaults to `false`, even when `bucket` is specified. */ enabled?: boolean; /** * S3 bucket prefix. Logs are stored in the root if not configured. */ prefix?: string; } interface LoadBalancerHealthCheckLogs { /** * S3 bucket name to store the logs in. */ bucket: string; /** * Boolean to enable / disable `healthCheckLogs`. Defaults to `false`, even when `bucket` is specified. */ enabled?: boolean; /** * S3 bucket prefix. Logs are stored in the root if not configured. */ prefix?: string; } interface LoadBalancerIpamPools { /** * The ID of the IPv4 IPAM pool. */ ipv4IpamPoolId: string; } interface LoadBalancerMinimumLoadBalancerCapacity { /** * The number of capacity units. */ capacityUnits: number; } interface LoadBalancerSubnetMapping { /** * Allocation ID of the Elastic IP address for an internet-facing load balancer. */ allocationId?: string; /** * IPv6 address. You associate IPv6 CIDR blocks with your VPC and choose the subnets where you launch both internet-facing and internal Application Load Balancers or Network Load Balancers. */ ipv6Address?: string; outpostId: string; /** * Private IPv4 address for an internal load balancer. */ privateIpv4Address?: string; /** * ID of the subnet of which to attach to the load balancer. You can specify only one subnet per Availability Zone. */ subnetId: string; } interface TargetGroupHealthCheck { /** * Whether health checks are enabled. Defaults to `true`. */ enabled?: boolean; /** * Number of consecutive health check successes required before considering a target healthy. The range is 2-10. Defaults to 3. */ healthyThreshold?: number; /** * Approximate amount of time, in seconds, between health checks of an individual target. The range is 5-300. For `lambda` target groups, it needs to be greater than the timeout of the underlying `lambda`. Defaults to 30. */ interval?: number; /** * The HTTP or gRPC codes to use when checking for a successful response from a target. * The `health_check.protocol` must be one of `HTTP` or `HTTPS` or the `targetType` must be `lambda`. * Values can be comma-separated individual values (e.g., "200,202") or a range of values (e.g., "200-299"). * Once the value has been set, removing it has no effect. To unset it, set it to an empty string `""`. * * For gRPC-based target groups (i.e., the `protocol` is one of `HTTP` or `HTTPS` and the `protocolVersion` is `GRPC`), values can be between `0` and `99`. The default is `12`. * * When used with an Application Load Balancer (i.e., the `protocol` is one of `HTTP` or `HTTPS` and the `protocolVersion` is not `GRPC`), values can be between `200` and `499`. The default is `200`. * * When used with a Network Load Balancer (i.e., the `protocol` is one of `TCP`, `TCP_UDP`, `UDP`, or `TLS`), values can be between `200` and `599`. The default is `200-399`. * * When the `targetType` is `lambda`, values can be between `200` and `499`. The default is `200`. */ matcher: string; /** * Destination for the health check request. Required for HTTP/HTTPS ALB and HTTP NLB. Only applies to HTTP/HTTPS. * Once the value has been set, removing it has no effect. To unset it, set it to an empty string `""`. * * For HTTP and HTTPS health checks, the default is `/`. * * For gRPC health checks, the default is `/AWS.ALB/healthcheck`. */ path: string; /** * The port the load balancer uses when performing health checks on targets. * Valid values are either `traffic-port`, to use the same port as the target group, or a valid port number between `1` and `65536`. * Default is `traffic-port`. */ port?: string; /** * Protocol the load balancer uses when performing health checks on targets. * Must be one of `TCP`, `HTTP`, or `HTTPS`. * The `TCP` protocol is not supported for health checks if the protocol of the target group is `HTTP` or `HTTPS`. * Default is `HTTP`. * Cannot be specified when the `targetType` is `lambda`. */ protocol?: string; /** * Amount of time, in seconds, during which no response from a target means a failed health check. The range is 2–120 seconds. For target groups with a protocol of HTTP, the default is 6 seconds. For target groups with a protocol of TCP, TLS or HTTPS, the default is 10 seconds. For target groups with a protocol of GENEVE, the default is 5 seconds. If the target type is lambda, the default is 30 seconds. */ timeout: number; /** * Number of consecutive health check failures required before considering a target unhealthy. The range is 2-10. Defaults to 3. */ unhealthyThreshold?: number; } interface TargetGroupStickiness { /** * Only used when the type is `lbCookie`. The time period, in seconds, during which requests from a client should be routed to the same target. After this time period expires, the load balancer-generated cookie is considered stale. The range is 1 second to 1 week (604800 seconds). The default value is 1 day (86400 seconds). */ cookieDuration?: number; /** * Name of the application based cookie. AWSALB, AWSALBAPP, and AWSALBTG prefixes are reserved and cannot be used. Only needed when type is `appCookie`. */ cookieName?: string; /** * Boolean to enable / disable `stickiness`. Default is `true`. */ enabled?: boolean; /** * The type of sticky sessions. The only current possible values are `lbCookie`, `appCookie` for ALBs, `sourceIp` for NLBs, and `sourceIpDestIp`, `sourceIpDestIpProto` for GWLBs. */ type: string; } interface TargetGroupTargetFailover { /** * Indicates how the GWLB handles existing flows when a target is deregistered. Possible values are `rebalance` and `noRebalance`. Must match the attribute value set for `onUnhealthy`. Default: `noRebalance`. */ onDeregistration: string; /** * Indicates how the GWLB handles existing flows when a target is unhealthy. Possible values are `rebalance` and `noRebalance`. Must match the attribute value set for `onDeregistration`. Default: `noRebalance`. */ onUnhealthy: string; } interface TargetGroupTargetGroupHealth { /** * Block to configure DNS Failover requirements. See DNS Failover below for details on attributes. */ dnsFailover?: outputs.alb.TargetGroupTargetGroupHealthDnsFailover; /** * Block to configure Unhealthy State Routing requirements. See Unhealthy State Routing below for details on attributes. */ unhealthyStateRouting?: outputs.alb.TargetGroupTargetGroupHealthUnhealthyStateRouting; } interface TargetGroupTargetGroupHealthDnsFailover { /** * The minimum number of targets that must be healthy. If the number of healthy targets is below this value, mark the zone as unhealthy in DNS, so that traffic is routed only to healthy zones. The possible values are `off` or an integer from `1` to the maximum number of targets. The default is `off`. */ minimumHealthyTargetsCount?: string; /** * The minimum percentage of targets that must be healthy. If the percentage of healthy targets is below this value, mark the zone as unhealthy in DNS, so that traffic is routed only to healthy zones. The possible values are `off` or an integer from `1` to `100`. The default is `off`. */ minimumHealthyTargetsPercentage?: string; } interface TargetGroupTargetGroupHealthUnhealthyStateRouting { /** * The minimum number of targets that must be healthy. If the number of healthy targets is below this value, send traffic to all targets, including unhealthy targets. The possible values are `1` to the maximum number of targets. The default is `1`. */ minimumHealthyTargetsCount?: number; /** * The minimum percentage of targets that must be healthy. If the percentage of healthy targets is below this value, send traffic to all targets, including unhealthy targets. The possible values are `off` or an integer from `1` to `100`. The default is `off`. */ minimumHealthyTargetsPercentage?: string; } interface TargetGroupTargetHealthState { /** * Indicates whether the load balancer terminates connections to unhealthy targets. Possible values are `true` or `false`. Default: `true`. */ enableUnhealthyConnectionTermination: boolean; /** * Indicates the time to wait for in-flight requests to complete when a target becomes unhealthy. The range is `0-360000`. This value has to be set only if `enableUnhealthyConnectionTermination` is set to false. Default: `0`. */ unhealthyDrainingInterval?: number; } } export declare namespace amp { interface AnomalyDetectorConfiguration { /** * Configuration block for the Random Cut Forest anomaly detection algorithm. See `randomCutForest` below. */ randomCutForest: outputs.amp.AnomalyDetectorConfigurationRandomCutForest; } interface AnomalyDetectorConfigurationRandomCutForest { /** * Configuration block for suppressing anomalies when the observed value is slightly above the expected value. See `ignoreNearExpectedFromAbove` below. */ ignoreNearExpectedFromAbove?: outputs.amp.AnomalyDetectorConfigurationRandomCutForestIgnoreNearExpectedFromAbove; /** * Configuration block for suppressing anomalies when the observed value is slightly below the expected value. See `ignoreNearExpectedFromBelow` below. */ ignoreNearExpectedFromBelow?: outputs.amp.AnomalyDetectorConfigurationRandomCutForestIgnoreNearExpectedFromBelow; /** * PromQL query used to select the time series for anomaly detection. */ query: string; /** * Number of data points used to train the model. Must be at least `256`. */ sampleSize: number; /** * Number of consecutive data points that form a single input to the model. Must be at least `2`. */ shingleSize: number; } interface AnomalyDetectorConfigurationRandomCutForestIgnoreNearExpectedFromAbove { /** * Absolute amount by which the observed value may exceed the expected value before being reported as an anomaly. Conflicts with `ratio`. */ amount?: number; /** * Ratio by which the observed value may exceed the expected value before being reported as an anomaly. Must be at least `0`. Conflicts with `amount`. */ ratio?: number; } interface AnomalyDetectorConfigurationRandomCutForestIgnoreNearExpectedFromBelow { /** * Absolute amount by which the observed value may exceed the expected value before being reported as an anomaly. Conflicts with `ratio`. */ amount?: number; /** * Ratio by which the observed value may exceed the expected value before being reported as an anomaly. Must be at least `0`. Conflicts with `amount`. */ ratio?: number; } interface AnomalyDetectorMissingDataAction { /** * Whether to treat missing data points as anomalies. Must be set to `true`. Conflicts with `skip`. */ markAsAnomaly?: boolean; /** * Whether to skip missing data points without reporting them as anomalies. Must be set to `true`. Conflicts with `markAsAnomaly`. */ skip?: boolean; } interface AnomalyDetectorTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface QueryLoggingConfigurationDestination { /** * Configuration block for CloudWatch Logs destination. See `cloudwatchLogs`. */ cloudwatchLogs: outputs.amp.QueryLoggingConfigurationDestinationCloudwatchLogs; /** * A list of filter configurations that specify which logs should be sent to the destination. See `filters`. */ filters: outputs.amp.QueryLoggingConfigurationDestinationFilters; } interface QueryLoggingConfigurationDestinationCloudwatchLogs { /** * The ARN of the CloudWatch log group to which query logs will be sent. The ARN must end with `:*` */ logGroupArn: string; } interface QueryLoggingConfigurationDestinationFilters { /** * The Query Samples Processed (QSP) threshold above which queries will be logged. Queries processing more samples than this threshold will be captured in logs. */ qspThreshold: number; } interface QueryLoggingConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ResourcePolicyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ScraperDestination { /** * Configuration block for an Amazon Managed Prometheus workspace destination. See `amp` Block for details. */ amp?: outputs.amp.ScraperDestinationAmp; /** * Configuration block for a CloudWatch Metrics destination. See `cloudwatch` Block for details. * * > **NOTE:** Either `amp` or `cloudwatch` must be specified, but not both. */ cloudwatch?: outputs.amp.ScraperDestinationCloudwatch; } interface ScraperDestinationAmp { /** * ARN of the prometheus workspace. */ workspaceArn: string; } interface ScraperDestinationCloudwatch { /** * ARN of the CloudWatch dataset. Use `arn:aws:cloudwatch:{region}:{account}:dataset/default` for the default dataset. */ datasetArn: string; } interface ScraperExporter { /** * Configuration block for an OpenSearch exporter. See `opensearch` Block for details. */ opensearch: outputs.amp.ScraperExporterOpensearch; } interface ScraperExporterOpensearch { /** * ARN of the OpenSearch domain. */ domainArn: string; } interface ScraperLoggingConfigurationLoggingDestination { /** * Configuration block for CloudWatch Logs destination. See `cloudwatchLogs` Block below. */ cloudwatchLogs: outputs.amp.ScraperLoggingConfigurationLoggingDestinationCloudwatchLogs; } interface ScraperLoggingConfigurationLoggingDestinationCloudwatchLogs { /** * ARN of the CloudWatch Logs log group. Must end with `:*`. */ logGroupArn: string; } interface ScraperLoggingConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ScraperRoleConfiguration { /** * ARN of the source role configuration. Must be an IAM role ARN. */ sourceRoleArn?: string; /** * ARN of the target role configuration. Must be an IAM role ARN. */ targetRoleArn?: string; } interface ScraperSource { /** * Configuration block for an EKS cluster source. See `eks` Block for details. */ eks?: outputs.amp.ScraperSourceEks; /** * Configuration block for a VPC source. See `vpc` Block for details. * * > **NOTE:** Either `eks` or `vpc` must be specified, but not both. */ vpc?: outputs.amp.ScraperSourceVpc; } interface ScraperSourceEks { /** * ARN of the source EKS cluster. */ clusterArn: string; /** * List of the security group IDs for the Amazon EKS cluster VPC configuration. */ securityGroupIds: string[]; /** * List of subnet IDs. Must be in at least two different availability zones. */ subnetIds: string[]; } interface ScraperSourceVpc { /** * List of security group IDs for the VPC configuration. */ securityGroupIds: string[]; /** * List of subnet IDs. Must be in at least two different availability zones. */ subnetIds: string[]; } interface ScraperTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface WorkspaceConfigurationLimitsPerLabelSet { /** * Map of label key-value pairs that identify the metrics to which the limits apply. An empty map represents the default bucket for metrics that don't match any other label set. */ labelSet: { [key: string]: string; }; /** * Configuration block for the limits to apply to the specified label set. Detailed below. */ limits: outputs.amp.WorkspaceConfigurationLimitsPerLabelSetLimits; } interface WorkspaceConfigurationLimitsPerLabelSetLimits { /** * Maximum number of active time series that can be ingested for metrics matching the label set. */ maxSeries: number; } interface WorkspaceConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface WorkspaceLoggingConfiguration { /** * The ARN of the CloudWatch log group to which the vended log data will be published. This log group must exist. The ARN must end with `:*` */ logGroupArn: string; } } export declare namespace amplify { interface AppAutoBranchCreationConfig { /** * Basic authorization credentials for the autocreated branch. */ basicAuthCredentials?: string; /** * Build specification (build spec) for the autocreated branch. */ buildSpec?: string; /** * Enables auto building for the autocreated branch. */ enableAutoBuild?: boolean; /** * Enables basic authorization for the autocreated branch. */ enableBasicAuth?: boolean; /** * Enables performance mode for the branch. */ enablePerformanceMode?: boolean; /** * Enables pull request previews for the autocreated branch. */ enablePullRequestPreview?: boolean; /** * Environment variables for the autocreated branch. */ environmentVariables?: { [key: string]: string; }; /** * Framework for the autocreated branch. */ framework?: string; /** * Amplify environment name for the pull request. */ pullRequestEnvironmentName?: string; /** * Describes the current stage for the autocreated branch. Valid values: `PRODUCTION`, `BETA`, `DEVELOPMENT`, `EXPERIMENTAL`, `PULL_REQUEST`. */ stage?: string; } interface AppCacheConfig { /** * Type of cache configuration to use for an Amplify app. Valid values: `AMPLIFY_MANAGED`, `AMPLIFY_MANAGED_NO_COOKIES`. */ type: string; } interface AppCustomRule { /** * Condition for a URL rewrite or redirect rule, such as a country code. */ condition?: string; /** * Source pattern for a URL rewrite or redirect rule. */ source: string; /** * Status code for a URL rewrite or redirect rule. Valid values: `200`, `301`, `302`, `404`, `404-200`. */ status?: string; /** * Target pattern for a URL rewrite or redirect rule. */ target: string; } interface AppJobConfig { /** * Size of the build instance. Valid values: `STANDARD_8GB`, `LARGE_16GB`, and `XLARGE_72GB`. Default: `STANDARD_8GB`. */ buildComputeType: string; } interface AppProductionBranch { /** * Branch name for the production branch. */ branchName: string; /** * Last deploy time of the production branch. */ lastDeployTime: string; /** * Status of the production branch. */ status: string; /** * Thumbnail URL for the production branch. */ thumbnailUrl: string; } interface DomainAssociationCertificateSettings { /** * DNS records for certificate verification in a space-delimited format (` CNAME `). */ certificateVerificationDnsRecord: string; /** * ARN for the custom certificate. * Required when `type` is `CUSTOM`. */ customCertificateArn?: string; /** * The certificate type. * Valid values are `AMPLIFY_MANAGED` and `CUSTOM`. */ type: string; } interface DomainAssociationSubDomain { /** * Branch name setting for the subdomain. */ branchName: string; /** * DNS record for the subdomain in a space-prefixed and space-delimited format (` CNAME `). */ dnsRecord: string; /** * Prefix setting for the subdomain. */ prefix: string; /** * Verified status of the subdomain. */ verified: boolean; } } export declare namespace apigateway { interface AccountThrottleSetting { /** * Absolute maximum number of times API Gateway allows the API to be called per second. */ burstLimit: number; /** * Number of times API Gateway allows the API to be called per second on average. */ rateLimit: number; } interface DocumentationPartLocation { /** * HTTP verb of a method. The default value is `*` for any method. */ method?: string; /** * Name of the targeted API entity. */ name?: string; /** * URL path of the target. The default value is `/` for the root resource. */ path?: string; /** * HTTP status code of a response. The default value is `*` for any status code. */ statusCode?: string; /** * Type of API entity to which the documentation content appliesE.g., `API`, `METHOD` or `REQUEST_BODY` */ type: string; } interface DomainNameEndpointConfiguration { /** * IP address types that can invoke a DomainName. Valid values: `ipv4`, `dualstack`. Use `ipv4` to allow only IPv4 addresses to invoke a DomainName, or use `dualstack` to allow both IPv4 and IPv6 addresses to invoke a DomainName. For the `PRIVATE` endpoint type, only `dualstack` is supported. Terraform performs drift detection for this argument only when the value is provided. */ ipAddressType: string; /** * List of endpoint types of an API or its custom domain name. For an edge-optimized API and its custom domain name, the endpoint type is `EDGE`. For a regional API and its custom domain name, the endpoint type is `REGIONAL`. For a private API, the endpoint type is `PRIVATE`. */ types: string; } interface DomainNameMutualTlsAuthentication { /** * Amazon S3 URL that specifies the truststore for mutual TLS authentication, for example, `s3://bucket-name/key-name`. The truststore can contain certificates from public or private certificate authorities. To update the truststore, upload a new version to S3, and then update your custom domain name to use the new version. */ truststoreUri: string; /** * Version of the S3 object that contains the truststore. To specify a version, you must have versioning enabled for the S3 bucket. */ truststoreVersion?: string; } interface GetApiKeysItem { /** * Date and time when the API Key was created. */ createdDate: string; /** * Amazon Web Services Marketplace customer identifier, when integrating with the Amazon Web Services SaaS Marketplace. */ customerId: string; /** * Description of the API Key. */ description: string; /** * Whether the API Key is enabled. */ enabled: boolean; /** * ID of the API Key. */ id: string; /** * Date and time when the API Key was last updated. */ lastUpdatedDate: string; /** * Name of the API Key. */ name: string; /** * List of stage keys associated with the API Key. */ stageKeys: string[]; /** * Map of tags for the resource. */ tags: { [key: string]: string; }; /** * Value of the API Key. */ value: string; } interface GetDomainNameEndpointConfiguration { /** * IP address types that can invoke a DomainName. */ ipAddressType: string; /** * List of endpoint types. */ types: string[]; } interface GetRestApiEndpointConfiguration { /** * IP address types that can invoke a REST API. */ ipAddressType: string; /** * List of endpoint types. */ types: string[]; /** * Set of VPC Endpoint identifiers. */ vpcEndpointIds: string[]; } interface IntegrationTlsConfig { /** * Whether or not API Gateway skips verification that the certificate for an integration endpoint is issued by a [supported certificate authority](https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-supported-certificate-authorities-for-http-endpoints.html). This isn’t recommended, but it enables you to use certificates that are signed by private certificate authorities, or certificates that are self-signed. If enabled, API Gateway still performs basic certificate validation, which includes checking the certificate's expiration date, hostname, and presence of a root certificate authority. Supported only for `HTTP` and `HTTP_PROXY` integrations. */ insecureSkipVerification?: boolean; } interface MethodSettingsSettings { /** * Whether the cached responses are encrypted. */ cacheDataEncrypted: boolean; /** * Time to live (TTL), in seconds, for cached responses. The higher the TTL, the longer the response will be cached. */ cacheTtlInSeconds: number; /** * Whether responses should be cached and returned for requests. A cache cluster must be enabled on the stage for responses to be cached. */ cachingEnabled: boolean; /** * Whether data trace logging is enabled for this method, which effects the log entries pushed to Amazon CloudWatch Logs. */ dataTraceEnabled: boolean; /** * Logging level for this method, which effects the log entries pushed to Amazon CloudWatch Logs. The available levels are `OFF`, `ERROR`, and `INFO`. */ loggingLevel: string; /** * Whether Amazon CloudWatch metrics are enabled for this method. */ metricsEnabled: boolean; /** * Whether authorization is required for a cache invalidation request. */ requireAuthorizationForCacheControl: boolean; /** * Throttling burst limit. Default: `-1` (throttling disabled). */ throttlingBurstLimit?: number; /** * Throttling rate limit. Default: `-1` (throttling disabled). */ throttlingRateLimit?: number; /** * How to handle unauthorized requests for cache invalidation. The available values are `FAIL_WITH_403`, `SUCCEED_WITH_RESPONSE_HEADER`, `SUCCEED_WITHOUT_RESPONSE_HEADER`. */ unauthorizedCacheControlHeaderStrategy: string; } interface RestApiEndpointConfiguration { /** * IP address types that can invoke a REST API. Valid values: `ipv4`, `dualstack`. Use `ipv4` to allow only IPv4 addresses to invoke an API, or use `dualstack` to allow both IPv4 and IPv6 addresses to invoke an API. For the `PRIVATE` endpoint type, only `dualstack` is supported. The provider performs drift detection for this argument only when the value is provided. */ ipAddressType: string; /** * List of endpoint types. This resource currently only supports managing a single value. Valid values: `EDGE`, `REGIONAL` or `PRIVATE`. If unspecified, defaults to `EDGE`. If set to `PRIVATE` recommend to set `putRestApiMode` = `merge` to not cause the endpoints and associated Route53 records to be deleted. Refer to the [documentation](https://docs.aws.amazon.com/apigateway/latest/developerguide/create-regional-api.html) for more information on the difference between edge-optimized and regional APIs. */ types: string; /** * Set of VPC Endpoint identifiers. It is only supported for `PRIVATE` endpoint type. If importing an OpenAPI specification via the `body` argument, this corresponds to the [`x-amazon-apigateway-endpoint-configuration` extension `vpcEndpointIds` property](https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-swagger-extensions-endpoint-configuration.html). If the argument value is provided and is different than the OpenAPI value, **the argument value will override the OpenAPI value**. */ vpcEndpointIds: string[]; } interface RestApiPutTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface StageAccessLogSettings { /** * ARN of the CloudWatch Logs log group or Kinesis Data Firehose delivery stream to receive access logs. If you specify a Kinesis Data Firehose delivery stream, the stream name must begin with `amazon-apigateway-`. Automatically removes trailing `:*` if present. */ destinationArn: string; /** * Formatting and values recorded in the logs. For more information on configuring the log format rules visit the AWS [documentation](https://docs.aws.amazon.com/apigateway/latest/developerguide/set-up-logging.html) */ format: string; } interface StageCanarySettings { /** * ID of the deployment that the canary points to. */ deploymentId: string; /** * Percent `0.0` - `100.0` of traffic to divert to the canary deployment. */ percentTraffic?: number; /** * Map of overridden stage `variables` (including new variables) for the canary deployment. */ stageVariableOverrides?: { [key: string]: string; }; /** * Whether the canary deployment uses the stage cache. Defaults to false. */ useStageCache?: boolean; } interface UsagePlanApiStage { /** * API ID of the associated API stage in a usage plan. */ apiId: string; /** * API stage name of the associated API stage in a usage plan. * * The following arguments are optional: */ stage: string; /** * Throttling limits applied to the API stage. See `throttle` Block below. */ throttles?: outputs.apigateway.UsagePlanApiStageThrottle[]; } interface UsagePlanApiStageThrottle { /** * API request burst limit, the maximum rate limit over a time ranging from one to a few seconds, depending upon whether the underlying token bucket is at its full capacity. */ burstLimit?: number; /** * Method to apply the throttle settings for. Specify the path and method, for example `/test/GET`. * * The following arguments are optional: */ path: string; /** * API request steady-state rate limit. */ rateLimit?: number; } interface UsagePlanQuotaSettings { /** * Maximum number of requests that can be made in a given time period. */ limit: number; /** * Number of requests subtracted from the given limit in the initial time period. */ offset?: number; /** * Time period in which the limit applies. Valid values are `DAY`, `WEEK`, or `MONTH`. * * The following arguments are optional: */ period: string; } interface UsagePlanThrottleSettings { /** * API request burst limit, the maximum rate limit over a time ranging from one to a few seconds, depending upon whether the underlying token bucket is at its full capacity. */ burstLimit?: number; /** * API request steady-state rate limit. */ rateLimit?: number; } } export declare namespace apigatewayv2 { interface ApiCorsConfiguration { /** * Whether credentials are included in the CORS request. */ allowCredentials?: boolean; /** * Set of allowed HTTP headers. */ allowHeaders?: string[]; /** * Set of allowed HTTP methods. */ allowMethods?: string[]; /** * Set of allowed origins. */ allowOrigins?: string[]; /** * Set of exposed HTTP headers. */ exposeHeaders?: string[]; /** * Number of seconds that the browser should cache preflight request results. */ maxAge?: number; } interface AuthorizerJwtConfiguration { /** * List of the intended recipients of the JWT. A valid JWT must provide an aud that matches at least one entry in this list. */ audiences?: string[]; /** * Base domain of the identity provider that issues JSON Web Tokens, such as the `endpoint` attribute of the `aws.cognito.UserPool` resource. */ issuer?: string; } interface DomainNameDomainNameConfiguration { /** * ARN of an AWS-managed certificate that will be used by the endpoint for the domain name. AWS Certificate Manager is the only supported source. Use the `aws.acm.Certificate` resource to configure an ACM certificate. */ certificateArn: string; /** * Endpoint type. Valid values: `REGIONAL`. */ endpointType: string; /** * Amazon Route 53 Hosted Zone ID of the endpoint. */ hostedZoneId: string; /** * IP address types that can invoke the domain name. Valid values: `ipv4`, `dualstack`. Use `ipv4` to allow only IPv4 addresses to invoke your domain name, or use `dualstack` to allow both IPv4 and IPv6 addresses to invoke your domain name. Defaults to `ipv4`. */ ipAddressType: string; /** * ARN of the AWS-issued certificate used to validate custom domain ownership (when `certificateArn` is issued via an ACM Private CA or `mutualTlsAuthentication` is configured with an ACM-imported certificate.) */ ownershipVerificationCertificateArn: string; /** * TLS version of the [security policy](https://docs.aws.amazon.com/apigateway/latest/developerguide/apigateway-custom-domain-tls-version.html) for the domain name. Valid values: `TLS_1_2`. */ securityPolicy: string; /** * Target domain name. */ targetDomainName: string; } interface DomainNameMutualTlsAuthentication { /** * Amazon S3 URL that specifies the truststore for mutual TLS authentication, for example, `s3://bucket-name/key-name`. The truststore can contain certificates from public or private certificate authorities. To update the truststore, upload a new version to S3, and then update your custom domain name to use the new version. */ truststoreUri: string; /** * Version of the S3 object that contains the truststore. To specify a version, you must have versioning enabled for the S3 bucket. */ truststoreVersion?: string; } interface GetApiCorsConfiguration { /** * Whether credentials are included in the CORS request. */ allowCredentials: boolean; /** * Set of allowed HTTP headers. */ allowHeaders: string[]; /** * Set of allowed HTTP methods. */ allowMethods: string[]; /** * Set of allowed origins. */ allowOrigins: string[]; /** * Set of exposed HTTP headers. */ exposeHeaders: string[]; /** * Number of seconds that the browser should cache preflight request results. */ maxAge: number; } interface IntegrationResponseParameter { /** * Key-value map. The key of this map identifies the location of the request parameter to change, and how to change it. The corresponding value specifies the new data for the parameter. See the [Amazon API Gateway Developer Guide](https://docs.aws.amazon.com/apigateway/latest/developerguide/http-api-parameter-mapping.html) for details. */ mappings: { [key: string]: string; }; /** * HTTP status code in the range 200-599. */ statusCode: string; } interface IntegrationTlsConfig { /** * If you specify a server name, API Gateway uses it to verify the hostname on the integration's certificate. The server name is also included in the TLS handshake to support Server Name Indication (SNI) or virtual hosting. */ serverNameToVerify?: string; } interface RouteRequestParameter { /** * Request parameter key. This is a [request data mapping parameter](https://docs.aws.amazon.com/apigateway/latest/developerguide/websocket-api-data-mapping.html#websocket-mapping-request-parameters). */ requestParameterKey: string; /** * Whether the parameter is required. */ required: boolean; } interface RoutingRuleAction { /** * Configuration to invoke a stage of a target API. Only REST APIs are supported. See below. */ invokeApi: outputs.apigatewayv2.RoutingRuleActionInvokeApi; } interface RoutingRuleActionInvokeApi { /** * API identifier of the target API. */ apiId: string; /** * Name of the target stage. */ stage: string; /** * Whether to strip the base path when forwarding the request to the target API. */ stripBasePath?: boolean; } interface RoutingRuleCondition { /** * Base path to be matched. See below. */ matchBasePaths?: outputs.apigatewayv2.RoutingRuleConditionMatchBasePaths; /** * Headers to be matched. See below. */ matchHeaders?: outputs.apigatewayv2.RoutingRuleConditionMatchHeaders; } interface RoutingRuleConditionMatchBasePaths { /** * List of strings of the case sensitive base path to be matched. */ anyOfs: string[]; } interface RoutingRuleConditionMatchHeaders { /** * Configuration of the headers to be matched. There is a match if any of the header name and header value globs are matched. See below. */ anyOf: outputs.apigatewayv2.RoutingRuleConditionMatchHeadersAnyOf; } interface RoutingRuleConditionMatchHeadersAnyOf { /** * Case insensitive header name to be matched. The header name must be less than 40 characters and the only allowed characters are a-z, A-Z, 0-9, and the following special characters: *?-!#$%&'.^_`|~. */ header: string; /** * Case sensitive header glob value to be matched against entire header value. The header glob value must be less than 128 characters and the only allowed characters are a-z, A-Z, 0-9, and the following special characters: \*?-!#$%&'.^_`|~. Wildcard matching is supported for header glob values but must be for \*prefix-match, suffix-match*, or \*infix*-match. */ valueGlob: string; } interface StageAccessLogSettings { /** * ARN of the CloudWatch Logs log group to receive access logs. Any trailing `:*` is trimmed from the ARN. */ destinationArn: string; /** * Single line [format](https://docs.aws.amazon.com/apigateway/latest/developerguide/set-up-logging.html#apigateway-cloudwatch-log-formats) of the access logs of data. Refer to log settings for [HTTP](https://docs.aws.amazon.com/apigateway/latest/developerguide/http-api-logging-variables.html) or [Websocket](https://docs.aws.amazon.com/apigateway/latest/developerguide/websocket-api-logging.html). */ format: string; } interface StageDefaultRouteSettings { /** * Whether data trace logging is enabled for the default route. Affects the log entries pushed to Amazon CloudWatch Logs. Defaults to `false`. Supported only for WebSocket APIs. */ dataTraceEnabled?: boolean; /** * Whether detailed metrics are enabled for the default route. Defaults to `false`. */ detailedMetricsEnabled?: boolean; /** * Logging level for the default route. Affects the log entries pushed to Amazon CloudWatch Logs. Valid values: `ERROR`, `INFO`, `OFF`. Defaults to `OFF`. Supported only for WebSocket APIs. This provider will only perform drift detection of its value when present in a configuration. */ loggingLevel: string; /** * Throttling burst limit for the default route. */ throttlingBurstLimit?: number; /** * Throttling rate limit for the default route. */ throttlingRateLimit?: number; } interface StageRouteSetting { /** * Whether data trace logging is enabled for the route. Affects the log entries pushed to Amazon CloudWatch Logs. Defaults to `false`. Supported only for WebSocket APIs. */ dataTraceEnabled?: boolean; /** * Whether detailed metrics are enabled for the route. Defaults to `false`. */ detailedMetricsEnabled?: boolean; /** * Logging level for the route. Affects the log entries pushed to Amazon CloudWatch Logs. Valid values: `ERROR`, `INFO`, `OFF`. Defaults to `OFF`. Supported only for WebSocket APIs. This provider will only perform drift detection of its value when present in a configuration. */ loggingLevel: string; /** * Route key. */ routeKey: string; /** * Throttling burst limit for the route. */ throttlingBurstLimit?: number; /** * Throttling rate limit for the route. */ throttlingRateLimit?: number; } } export declare namespace appautoscaling { interface PolicyPredictiveScalingPolicyConfiguration { /** * Behavior applied if the forecast capacity approaches or exceeds the maximum capacity. Valid values are `HonorMaxCapacity` and `IncreaseMaxCapacity`. */ maxCapacityBreachBehavior?: string; /** * Size of the capacity buffer to use when the forecast capacity is close to or exceeds the maximum capacity. The value is specified as a percentage relative to the forecast capacity. Required if the `maxCapacityBreachBehavior` argument is set to `IncreaseMaxCapacity`, and cannot be used otherwise. */ maxCapacityBuffer?: number; /** * Metrics and target utilization to use for predictive scaling. See `predictive_scaling_policy_configuration.metric_specification` Block for details. */ metricSpecifications: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecification[]; /** * Predictive scaling mode. Valid values are `ForecastOnly` and `ForecastAndScale`. */ mode: string; /** * Amount of time, in seconds, that the start time can be advanced. */ schedulingBufferTime: number; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecification { /** * Customized capacity metric specification. See `predictive_scaling_policy_configuration.metric_specification.customized_capacity_metric_specification` Block for details. */ customizedCapacityMetricSpecification?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecification; /** * Customized load metric specification. See `predictive_scaling_policy_configuration.metric_specification.customized_load_metric_specification` Block for details. */ customizedLoadMetricSpecification?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecification; /** * Customized scaling metric specification. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification` Block for details. */ customizedScalingMetricSpecification?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecification; /** * Predefined load metric specification. See `predictive_scaling_policy_configuration.metric_specification.predefined_load_metric_specification` Block for details. */ predefinedLoadMetricSpecification?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationPredefinedLoadMetricSpecification; /** * Predefined metric pair specification that determines the appropriate scaling metric and load metric to use. See `predictive_scaling_policy_configuration.metric_specification.predefined_metric_pair_specification` Block for details. */ predefinedMetricPairSpecification?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationPredefinedMetricPairSpecification; /** * Predefined scaling metric specification. See `predictive_scaling_policy_configuration.metric_specification.predefined_scaling_metric_specification` Block for details. */ predefinedScalingMetricSpecification?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationPredefinedScalingMetricSpecification; targetValue: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecification { /** * One or more metric data queries to provide data points for a metric specification. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification.metric_data_query` Block for details. */ metricDataQueries: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQuery[]; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQuery { expression?: string; id: string; label?: string; metricStat?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStat; returnData?: boolean; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStat { metric: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetric; stat: string; unit?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetric { /** * Dimensions of the metric. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification.metric_data_query.metric_stat.metric.dimension` Block for details. */ dimensions?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetricDimension[]; metricName?: string; namespace?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetricDimension { /** * Name of the policy. Must be between 1 and 255 characters in length. */ name: string; value: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecification { /** * One or more metric data queries to provide data points for a metric specification. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification.metric_data_query` Block for details. */ metricDataQueries: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQuery[]; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQuery { expression?: string; id: string; label?: string; metricStat?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStat; returnData?: boolean; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStat { metric: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetric; stat: string; unit?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetric { /** * Dimensions of the metric. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification.metric_data_query.metric_stat.metric.dimension` Block for details. */ dimensions?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetricDimension[]; metricName?: string; namespace?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetricDimension { /** * Name of the policy. Must be between 1 and 255 characters in length. */ name: string; value: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecification { /** * One or more metric data queries to provide data points for a metric specification. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification.metric_data_query` Block for details. */ metricDataQueries: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQuery[]; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQuery { expression?: string; id: string; label?: string; metricStat?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStat; returnData?: boolean; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStat { metric: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetric; stat: string; unit?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetric { /** * Dimensions of the metric. See `predictive_scaling_policy_configuration.metric_specification.customized_scaling_metric_specification.metric_data_query.metric_stat.metric.dimension` Block for details. */ dimensions?: outputs.appautoscaling.PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetricDimension[]; metricName?: string; namespace?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetricDimension { /** * Name of the policy. Must be between 1 and 255 characters in length. */ name: string; value: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationPredefinedLoadMetricSpecification { predefinedMetricType: string; resourceLabel?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationPredefinedMetricPairSpecification { predefinedMetricType: string; resourceLabel?: string; } interface PolicyPredictiveScalingPolicyConfigurationMetricSpecificationPredefinedScalingMetricSpecification { predefinedMetricType: string; resourceLabel?: string; } interface PolicyStepScalingPolicyConfiguration { /** * Whether the adjustment is an absolute number or a percentage of the current capacity. Valid values are `ChangeInCapacity`, `ExactCapacity`, and `PercentChangeInCapacity`. */ adjustmentType?: string; /** * Amount of time, in seconds, after a scaling activity completes and before the next scaling activity can start. */ cooldown?: number; /** * Aggregation type for the policy's metrics. Valid values are `Minimum`, `Maximum`, and `Average`. Without a value, AWS treats the aggregation type as `Average`. */ metricAggregationType?: string; /** * Minimum number to adjust your scalable dimension as a result of a scaling activity. If the adjustment type is `PercentChangeInCapacity`, the scaling policy changes the scalable dimension of the scalable target by this amount. */ minAdjustmentMagnitude?: number; /** * Set of adjustments that manage scaling. See `step_scaling_policy_configuration.step_adjustment` Block for details. */ stepAdjustments?: outputs.appautoscaling.PolicyStepScalingPolicyConfigurationStepAdjustment[]; } interface PolicyStepScalingPolicyConfigurationStepAdjustment { /** * Lower bound for the difference between the alarm threshold and the CloudWatch metric. Without a value, AWS treats this bound as negative infinity. */ metricIntervalLowerBound?: string; /** * Upper bound for the difference between the alarm threshold and the CloudWatch metric. Without a value, AWS treats this bound as infinity. The upper bound must be greater than the lower bound. */ metricIntervalUpperBound?: string; /** * Number of members by which to scale, when the adjustment bounds are breached. A positive value scales up. A negative value scales down. */ scalingAdjustment: number; } interface PolicyTargetTrackingScalingPolicyConfiguration { /** * Custom CloudWatch metric. See the [AWS Customized Metric Specification](https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_CustomizedMetricSpecification.html) documentation. See `target_tracking_scaling_policy_configuration.customized_metric_specification` Block for details. */ customizedMetricSpecification?: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecification; /** * Whether scale in by the target tracking policy is disabled. If `true`, scale in is disabled and the target tracking policy does not remove capacity from the scalable resource. Otherwise, scale in is enabled and the target tracking policy can remove capacity from the scalable resource. Defaults to `false`. */ disableScaleIn?: boolean; /** * Predefined metric. See `target_tracking_scaling_policy_configuration.predefined_metric_specification` Block for details. */ predefinedMetricSpecification?: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationPredefinedMetricSpecification; /** * Amount of time, in seconds, after a scale in activity completes before another scale in activity can start. */ scaleInCooldown?: number; /** * Amount of time, in seconds, after a scale out activity completes before another scale out activity can start. */ scaleOutCooldown?: number; /** * Target value for the metric. */ targetValue: number; } interface PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecification { /** * Dimensions of the metric. See `target_tracking_scaling_policy_configuration.customized_metric_specification.metrics.metric_stat.metric.dimensions` Block for details. */ dimensions?: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationDimension[]; metricName?: string; /** * Metrics to include, as a metric data query. See `target_tracking_scaling_policy_configuration.customized_metric_specification.metrics` Block for details. */ metrics?: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetric[]; namespace?: string; /** * Statistic of the metric. Valid values are `Average`, `Minimum`, `Maximum`, `SampleCount`, and `Sum`. */ statistic?: string; unit?: string; } interface PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationDimension { /** * Name of the policy. Must be between 1 and 255 characters in length. */ name: string; value: string; } interface PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetric { expression?: string; id: string; label?: string; metricStat?: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetricMetricStat; returnData?: boolean; } interface PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetricMetricStat { metric: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetricMetricStatMetric; stat: string; unit?: string; } interface PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetricMetricStatMetric { /** * Dimensions of the metric. See `target_tracking_scaling_policy_configuration.customized_metric_specification.metrics.metric_stat.metric.dimensions` Block for details. */ dimensions?: outputs.appautoscaling.PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetricMetricStatMetricDimension[]; metricName: string; namespace: string; } interface PolicyTargetTrackingScalingPolicyConfigurationCustomizedMetricSpecificationMetricMetricStatMetricDimension { /** * Name of the policy. Must be between 1 and 255 characters in length. */ name: string; value: string; } interface PolicyTargetTrackingScalingPolicyConfigurationPredefinedMetricSpecification { predefinedMetricType: string; resourceLabel?: string; } interface ScheduledActionScalableTargetAction { /** * Maximum capacity. At least one of `maxCapacity` or `minCapacity` must be set. */ maxCapacity?: number; /** * Minimum capacity. At least one of `minCapacity` or `maxCapacity` must be set. */ minCapacity?: number; } interface TargetSuspendedState { /** * Whether scale in by a target tracking scaling policy or a step scaling policy is suspended. Default is `false`. */ dynamicScalingInSuspended?: boolean; /** * Whether scale out by a target tracking scaling policy or a step scaling policy is suspended. Default is `false`. */ dynamicScalingOutSuspended?: boolean; /** * Whether scheduled scaling is suspended. Default is `false`. */ scheduledScalingSuspended?: boolean; } } export declare namespace appconfig { interface ConfigurationProfileValidator { /** * Either the JSON Schema content or the ARN of an AWS Lambda function. */ content?: string; /** * Type of validator. Valid values: `JSON_SCHEMA` and `LAMBDA`. */ type: string; } interface EnvironmentMonitor { /** * ARN of the Amazon CloudWatch alarm. */ alarmArn: string; /** * ARN of an IAM role for AWS AppConfig to monitor `alarmArn`. */ alarmRoleArn?: string; } interface EventIntegrationEventFilter { /** * Source of the events. */ source: string; } interface ExtensionActionPoint { /** * Action the extension performs during the AppConfig workflow. Detailed below. */ actions: outputs.appconfig.ExtensionActionPointAction[]; /** * Point at which to perform the defined actions. Valid points are `PRE_CREATE_HOSTED_CONFIGURATION_VERSION`, `PRE_START_DEPLOYMENT`, `ON_DEPLOYMENT_START`, `ON_DEPLOYMENT_STEP`, `ON_DEPLOYMENT_BAKING`, `ON_DEPLOYMENT_COMPLETE`, `ON_DEPLOYMENT_ROLLED_BACK`. */ point: string; } interface ExtensionActionPointAction { /** * Information about the action. */ description?: string; /** * Action name. */ name: string; /** * ARN for an Identity and Access Management assume role. */ roleArn?: string; /** * Extension URI associated to the action point in the extension definition. The URI can be an ARN for one of the following: an Lambda function, an Amazon Simple Queue Service queue, an Amazon Simple Notification Service topic, or the Amazon EventBridge default event bus. */ uri: string; } interface ExtensionParameter { /** * Information about the parameter. */ description?: string; /** * Parameter name. */ name: string; /** * Whether a parameter value must be specified in the extension association. */ required?: boolean; } interface GetConfigurationProfileValidator { /** * Either the JSON Schema content or the ARN of an AWS Lambda function. */ content: string; /** * Type of validator. Valid values: JSON_SCHEMA and LAMBDA. */ type: string; } interface GetEnvironmentMonitor { /** * ARN of the Amazon CloudWatch alarm. */ alarmArn: string; /** * ARN of an IAM role for AWS AppConfig to monitor. */ alarmRoleArn: string; } } export declare namespace appfabric { interface AppAuthorizationConnectionAuthRequest { /** * Authorization code returned by the application after permission is granted in the application OAuth page (after clicking on the AuthURL). */ code: string; /** * Redirect URL that is specified in the AuthURL and the application client. */ redirectUri: string; } interface AppAuthorizationConnectionTenant { /** * Display name of the tenant. */ tenantDisplayName: string; /** * ID of the application tenant. */ tenantIdentifier: string; } interface AppAuthorizationConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface AppAuthorizationCredential { /** * API key credential information. See `apiKeyCredential` Block for details. */ apiKeyCredentials?: outputs.appfabric.AppAuthorizationCredentialApiKeyCredential[]; /** * OAuth2 client credential information. See `oauth2Credential` Block for details. */ oauth2Credential?: outputs.appfabric.AppAuthorizationCredentialOauth2Credential; } interface AppAuthorizationCredentialApiKeyCredential { /** * API key. */ apiKey: string; } interface AppAuthorizationCredentialOauth2Credential { /** * Client ID of the client application. */ clientId: string; /** * Client secret of the client application. */ clientSecret: string; } interface AppAuthorizationTenant { /** * Display name of the tenant. */ tenantDisplayName: string; /** * ID of the application tenant. */ tenantIdentifier: string; } interface AppAuthorizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface IngestionDestinationDestinationConfiguration { /** * Audit log destination configuration. See `destination_configuration.audit_log` Block below. */ auditLog: outputs.appfabric.IngestionDestinationDestinationConfigurationAuditLog; } interface IngestionDestinationDestinationConfigurationAuditLog { /** * Destination for the audit log. Only one destination, either `firehoseStream` or `s3Bucket`, can be specified. See `destination_configuration.audit_log.destination` Block below. */ destination: outputs.appfabric.IngestionDestinationDestinationConfigurationAuditLogDestination; } interface IngestionDestinationDestinationConfigurationAuditLogDestination { /** * Amazon Data Firehose delivery stream destination. See `destination_configuration.audit_log.destination.firehose_stream` Block below. */ firehoseStream?: outputs.appfabric.IngestionDestinationDestinationConfigurationAuditLogDestinationFirehoseStream; /** * Amazon S3 bucket destination. See `destination_configuration.audit_log.destination.s3_bucket` Block below. */ s3Bucket?: outputs.appfabric.IngestionDestinationDestinationConfigurationAuditLogDestinationS3Bucket; } interface IngestionDestinationDestinationConfigurationAuditLogDestinationFirehoseStream { /** * Name of the Amazon Data Firehose delivery stream. */ streamName: string; } interface IngestionDestinationDestinationConfigurationAuditLogDestinationS3Bucket { /** * Name of the Amazon S3 bucket. */ bucketName: string; /** * Object key to use. */ prefix?: string; } interface IngestionDestinationProcessingConfiguration { /** * Audit log processing configuration. See `processing_configuration.audit_log` Block below. */ auditLog: outputs.appfabric.IngestionDestinationProcessingConfigurationAuditLog; } interface IngestionDestinationProcessingConfigurationAuditLog { /** * Format in which the audit logs need to be formatted. Valid values: `json`, `parquet`. */ format: string; /** * Event schema in which the audit logs need to be formatted. Valid values: `ocsf`, `raw`. */ schema: string; } interface IngestionDestinationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace appflow { interface ConnectorProfileConnectorProfileConfig { /** * Connector-specific credentials required by each connector. See `connectorProfileCredentials` Block for details. */ connectorProfileCredentials: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentials; /** * Connector-specific properties of the profile configuration. See `connectorProfileProperties` Block for details. */ connectorProfileProperties: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileProperties; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentials { /** * Connector-specific credentials required when using Amplitude. See `connector_profile_config.connector_profile_credentials.amplitude` Block for details. */ amplitude?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsAmplitude; /** * Connector-specific profile credentials required when using the custom connector. See `connector_profile_config.connector_profile_credentials.custom_connector` Block for details. */ customConnector?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnector; /** * Connector-specific credentials required when using Datadog. See `connector_profile_config.connector_profile_credentials.datadog` Block for details. */ datadog?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsDatadog; /** * Connector-specific credentials required when using Dynatrace. See `connector_profile_config.connector_profile_credentials.dynatrace` Block for details. */ dynatrace?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsDynatrace; /** * Connector-specific credentials required when using Google Analytics. See `connector_profile_config.connector_profile_credentials.google_analytics` Block for details. */ googleAnalytics?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsGoogleAnalytics; /** * Connector-specific credentials required when using Amazon Honeycode. See `connector_profile_config.connector_profile_credentials.honeycode` Block for details. */ honeycode?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsHoneycode; /** * Connector-specific credentials required when using Infor Nexus. See `connector_profile_config.connector_profile_credentials.infor_nexus` Block for details. */ inforNexus?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsInforNexus; /** * Connector-specific credentials required when using Marketo. See `connector_profile_config.connector_profile_credentials.marketo` Block for details. */ marketo?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsMarketo; /** * Connector-specific credentials required when using Amazon Redshift. See `connector_profile_config.connector_profile_credentials.redshift` Block for details. */ redshift?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsRedshift; /** * Connector-specific credentials required when using Salesforce. See `connector_profile_config.connector_profile_credentials.salesforce` Block for details. */ salesforce?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSalesforce; /** * Connector-specific credentials required when using SAPOData. See `connector_profile_config.connector_profile_credentials.sapo_data` Block for details. */ sapoData?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoData; /** * Connector-specific credentials required when using ServiceNow. See `connector_profile_config.connector_profile_credentials.service_now` Block for details. */ serviceNow?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsServiceNow; /** * Connector-specific credentials required when using Singular. See `connector_profile_config.connector_profile_credentials.singular` Block for details. */ singular?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSingular; /** * Connector-specific credentials required when using Slack. See `connector_profile_config.connector_profile_credentials.slack` Block for details. */ slack?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSlack; /** * Connector-specific credentials required when using Snowflake. See `connector_profile_config.connector_profile_credentials.snowflake` Block for details. */ snowflake?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSnowflake; /** * Connector-specific credentials required when using Trend Micro. See `connector_profile_config.connector_profile_credentials.trendmicro` Block for details. */ trendmicro?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsTrendmicro; /** * Connector-specific credentials required when using Veeva. See `connector_profile_config.connector_profile_credentials.veeva` Block for details. */ veeva?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsVeeva; /** * Connector-specific credentials required when using Zendesk. See `connector_profile_config.connector_profile_credentials.zendesk` Block for details. */ zendesk?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsZendesk; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsAmplitude { /** * Unique alphanumeric identifier used to authenticate a user, developer, or calling program to your API. */ apiKey: string; /** * Secret Access Key portion of the credentials. */ secretKey: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnector { /** * Unique alphanumeric identifier used to authenticate a user, developer, or calling program to your API. */ apiKey?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorApiKey; /** * Authentication type that the custom connector uses for authenticating while creating a connector profile. One of: `APIKEY`, `BASIC`, `CUSTOM`, `OAUTH2`. */ authenticationType: string; /** * Basic credentials that are required for the authentication of the user. See `connector_profile_config.connector_profile_credentials.custom_connector.basic` Block for details. */ basic?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorBasic; /** * Credentials required when the connector uses the custom authentication mechanism. See `connector_profile_config.connector_profile_credentials.custom_connector.custom` Block for details. */ custom?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorCustom; /** * OAuth 2.0 credentials required for the authentication of the user. See `connector_profile_config.connector_profile_credentials.custom_connector.oauth2` Block for details. */ oauth2?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorOauth2; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorApiKey { /** * Unique alphanumeric identifier used to authenticate a user, developer, or calling program to your API. */ apiKey: string; /** * Secret Access Key portion of the credentials. */ apiSecretKey?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorBasic { /** * Password that corresponds to the user name. */ password: string; /** * Name of the user. */ username: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorCustom { /** * Map that holds custom authentication credentials. */ credentialsMap?: { [key: string]: string; }; /** * Custom authentication type that the connector uses. */ customAuthenticationType: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorOauth2 { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Identifier for the desired client. */ clientId?: string; /** * Client secret used by the OAuth client to authenticate to the authorization server. */ clientSecret?: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorOauth2OauthRequest; /** * Refresh token used to refresh an expired access token. */ refreshToken?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsCustomConnectorOauth2OauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsDatadog { /** * Unique alphanumeric identifier used to authenticate a user, developer, or calling program to your API. */ apiKey: string; /** * Application key, used in conjunction with your API key, that gives you full access to Datadog's programmatic API. Application keys are associated with the user account that created them and are used to log all requests made to the API. */ applicationKey: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsDynatrace { /** * API token used by the Dynatrace API to authenticate various API calls. */ apiToken: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsGoogleAnalytics { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Identifier for the desired client. */ clientId: string; /** * Client secret used by the OAuth client to authenticate to the authorization server. */ clientSecret: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsGoogleAnalyticsOauthRequest; /** * Refresh token used to refresh an expired access token. */ refreshToken?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsGoogleAnalyticsOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsHoneycode { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsHoneycodeOauthRequest; /** * Refresh token used to refresh an expired access token. */ refreshToken?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsHoneycodeOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsInforNexus { /** * Access Key portion of the credentials. */ accessKeyId: string; /** * Encryption keys used to encrypt data. */ datakey: string; /** * Secret key used to sign requests. */ secretAccessKey: string; /** * Identifier for the user. */ userId: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsMarketo { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Identifier for the desired client. */ clientId: string; /** * Client secret used by the OAuth client to authenticate to the authorization server. */ clientSecret: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsMarketoOauthRequest; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsMarketoOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsRedshift { /** * Password that corresponds to the user name. */ password: string; /** * Name of the user. */ username: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSalesforce { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Secret manager ARN, which contains the client ID and client secret of the connected app. */ clientCredentialsArn?: string; /** * JSON web token (JWT) that authorizes access to Salesforce records. */ jwtToken?: string; /** * OAuth 2.0 grant type used by the connector for OAuth 2.0 authentication. One of: `AUTHORIZATION_CODE`, `CLIENT_CREDENTIALS`. */ oauth2GrantType?: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSalesforceOauthRequest; /** * Refresh token used to refresh an expired access token. */ refreshToken?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSalesforceOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoData { /** * SAPOData basic authentication credentials. See `connector_profile_config.connector_profile_credentials.sapo_data.basic_auth_credentials` Block for details. */ basicAuthCredentials?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoDataBasicAuthCredentials; /** * SAPOData OAuth type authentication credentials. See `connector_profile_config.connector_profile_credentials.sapo_data.oauth_credentials` Block for details. */ oauthCredentials?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoDataOauthCredentials; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoDataBasicAuthCredentials { /** * Password that corresponds to the user name. */ password: string; /** * Name of the user. */ username: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoDataOauthCredentials { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Identifier for the desired client. */ clientId: string; /** * Client secret used by the OAuth client to authenticate to the authorization server. */ clientSecret: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoDataOauthCredentialsOauthRequest; /** * Refresh token used to refresh an expired access token. */ refreshToken?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSapoDataOauthCredentialsOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsServiceNow { /** * Password that corresponds to the user name. */ password: string; /** * Name of the user. */ username: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSingular { /** * Unique alphanumeric identifier used to authenticate a user, developer, or calling program to your API. */ apiKey: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSlack { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Identifier for the desired client. */ clientId: string; /** * Client secret used by the OAuth client to authenticate to the authorization server. */ clientSecret: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSlackOauthRequest; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSlackOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsSnowflake { /** * Password that corresponds to the user name. */ password: string; /** * Name of the user. */ username: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsTrendmicro { /** * Secret Access Key portion of the credentials. */ apiSecretKey: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsVeeva { /** * Password that corresponds to the user name. */ password: string; /** * Name of the user. */ username: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsZendesk { /** * Credentials used to access protected Zendesk resources. */ accessToken?: string; /** * Identifier for the desired client. */ clientId: string; /** * Client secret used by the OAuth client to authenticate to the authorization server. */ clientSecret: string; /** * OAuth requirement needed to request security tokens from the connector endpoint. See `connector_profile_config.connector_profile_credentials.zendesk.oauth_request` Block for details. */ oauthRequest?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsZendeskOauthRequest; } interface ConnectorProfileConnectorProfileConfigConnectorProfileCredentialsZendeskOauthRequest { /** * Code provided by the connector when it has been authenticated via the connected app. */ authCode?: string; /** * URL to which the authentication server redirects the browser after authorization has been granted. */ redirectUri?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfileProperties { /** * Connector-specific credentials required when using Amplitude. See `connector_profile_config.connector_profile_credentials.amplitude` Block for details. */ amplitude?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesAmplitude; /** * Connector-specific profile properties required when using the custom connector. See `connector_profile_config.connector_profile_properties.custom_connector` Block for details. */ customConnector?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesCustomConnector; /** * Connector-specific properties required when using Datadog. See `connector_profile_config.connector_profile_properties.datadog` Block for details. */ datadog?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesDatadog; /** * Connector-specific properties required when using Dynatrace. See `connector_profile_config.connector_profile_properties.dynatrace` Block for details. */ dynatrace?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesDynatrace; /** * Connector-specific credentials required when using Google Analytics. See `connector_profile_config.connector_profile_credentials.google_analytics` Block for details. */ googleAnalytics?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesGoogleAnalytics; /** * Connector-specific credentials required when using Amazon Honeycode. See `connector_profile_config.connector_profile_credentials.honeycode` Block for details. */ honeycode?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesHoneycode; /** * Connector-specific properties required when using Infor Nexus. See `connector_profile_config.connector_profile_properties.infor_nexus` Block for details. */ inforNexus?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesInforNexus; /** * Connector-specific properties required when using Marketo. See `connector_profile_config.connector_profile_properties.marketo` Block for details. */ marketo?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesMarketo; /** * Connector-specific properties required when using Amazon Redshift. See `connector_profile_config.connector_profile_properties.redshift` Block for details. */ redshift?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesRedshift; /** * Connector-specific properties required when using Salesforce. See `connector_profile_config.connector_profile_properties.salesforce` Block for details. */ salesforce?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSalesforce; /** * Connector-specific properties required when using SAPOData. See `connector_profile_config.connector_profile_properties.sapo_data` Block for details. */ sapoData?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSapoData; /** * Connector-specific properties required when using ServiceNow. See `connector_profile_config.connector_profile_properties.service_now` Block for details. */ serviceNow?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesServiceNow; /** * Connector-specific credentials required when using Singular. See `connector_profile_config.connector_profile_credentials.singular` Block for details. */ singular?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSingular; /** * Connector-specific properties required when using Slack. See `connector_profile_config.connector_profile_properties.slack` Block for details. */ slack?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSlack; /** * Connector-specific properties required when using Snowflake. See `connector_profile_config.connector_profile_properties.snowflake` Block for details. */ snowflake?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSnowflake; /** * Connector-specific credentials required when using Trend Micro. See `connector_profile_config.connector_profile_credentials.trendmicro` Block for details. */ trendmicro?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesTrendmicro; /** * Connector-specific properties required when using Veeva. See `connector_profile_config.connector_profile_properties.veeva` Block for details. */ veeva?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesVeeva; /** * Connector-specific properties required when using Zendesk. See `connector_profile_config.connector_profile_properties.zendesk` Block for details. */ zendesk?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesZendesk; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesAmplitude { } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesCustomConnector { /** * OAuth 2.0 properties required for OAuth 2.0 authentication. See `connector_profile_config.connector_profile_properties.custom_connector.oauth2_properties` Block for details. */ oauth2Properties?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesCustomConnectorOauth2Properties; /** * Map of properties that are required to create a profile for the custom connector. */ profileProperties?: { [key: string]: string; }; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesCustomConnectorOauth2Properties { /** * OAuth 2.0 grant type used by the connector for OAuth 2.0 authentication. One of: `AUTHORIZATION_CODE`, `CLIENT_CREDENTIALS`. */ oauth2GrantType: string; /** * Token URL required to fetch access and refresh tokens using the authorization code, and to refresh an expired access token using the refresh token. */ tokenUrl: string; /** * Map of properties associated with your token URL. Use this parameter to provide any additional details that the connector requires to authenticate your request. */ tokenUrlCustomProperties?: { [key: string]: string; }; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesDatadog { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesDynatrace { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesGoogleAnalytics { } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesHoneycode { } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesInforNexus { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesMarketo { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesRedshift { /** * Name of the Amazon S3 bucket associated with Snowflake. */ bucketName: string; /** * Bucket path that refers to the Amazon S3 bucket associated with Snowflake. */ bucketPrefix?: string; /** * Unique ID that's assigned to an Amazon Redshift cluster. */ clusterIdentifier?: string; /** * ARN of the IAM role that permits AppFlow to access the database through Data API. */ dataApiRoleArn?: string; /** * Name of an Amazon Redshift database. */ databaseName?: string; /** * JDBC URL of the Amazon Redshift cluster. */ databaseUrl?: string; /** * ARN of the IAM role. */ roleArn: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSalesforce { /** * Location of the Zendesk resource. */ instanceUrl?: string; /** * Whether the connector profile applies to a sandbox or production environment. */ isSandboxEnvironment?: boolean; /** * Whether Amazon AppFlow uses the private network to send metadata and authorization calls to Salesforce. Amazon AppFlow sends private calls through AWS PrivateLink. These calls travel through AWS infrastructure without being exposed to the public internet. */ usePrivatelinkForMetadataAndAuthorization?: boolean; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSapoData { /** * Location of the SAPOData resource. */ applicationHostUrl: string; /** * Application path to catalog service. */ applicationServicePath: string; /** * Client number for the client creating the connection. */ clientNumber: string; /** * Logon language of the SAPOData instance. */ logonLanguage?: string; /** * SAPOData OAuth properties required for OAuth type authentication. See `connector_profile_config.connector_profile_properties.sapo_data.oauth_properties` Block for details. */ oauthProperties?: outputs.appflow.ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSapoDataOauthProperties; /** * Port number of the SAPOData instance. */ portNumber: number; /** * Snowflake Private Link service name to be used for private data transfers. */ privateLinkServiceName?: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSapoDataOauthProperties { /** * Authorization code URL required to redirect to the SAP Login Page to fetch the authorization code for OAuth type authentication. */ authCodeUrl: string; /** * OAuth scopes required for OAuth type authentication. */ oauthScopes: string[]; /** * Token URL required to fetch access and refresh tokens using the authorization code, and to refresh an expired access token using the refresh token. */ tokenUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesServiceNow { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSingular { } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSlack { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesSnowflake { /** * Name of the account. */ accountName?: string; /** * Name of the Amazon S3 bucket associated with Snowflake. */ bucketName: string; /** * Bucket path that refers to the Amazon S3 bucket associated with Snowflake. */ bucketPrefix?: string; /** * Snowflake Private Link service name to be used for private data transfers. */ privateLinkServiceName?: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: string; /** * Name of the Amazon S3 stage that was created while setting up an Amazon S3 stage in the Snowflake account. This is written in the following format: `..`. */ stage: string; /** * Name of the Snowflake warehouse. */ warehouse: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesTrendmicro { } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesVeeva { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface ConnectorProfileConnectorProfileConfigConnectorProfilePropertiesZendesk { /** * Location of the Zendesk resource. */ instanceUrl: string; } interface FlowDestinationFlowConfig { /** * API version that the destination connector uses. */ apiVersion?: string; /** * Name of the connector profile. Must be unique for each connector profile in the AWS account. */ connectorProfileName?: string; /** * Type of connector, such as Salesforce, Amplitude, and so on. Valid values are `Salesforce`, `Singular`, `Slack`, `Redshift`, `S3`, `Marketo`, `Googleanalytics`, `Zendesk`, `Servicenow`, `Datadog`, `Trendmicro`, `Snowflake`, `Dynatrace`, `Infornexus`, `Amplitude`, `Veeva`, `EventBridge`, `LookoutMetrics`, `Upsolver`, `Honeycode`, `CustomerProfiles`, `SAPOData`, and `CustomConnector`. */ connectorType: string; /** * Information required to query a particular connector. See the `destination_flow_config.destination_connector_properties` Block for details. */ destinationConnectorProperties: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorProperties; } interface FlowDestinationFlowConfigDestinationConnectorProperties { customConnector?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesCustomConnector; /** * Properties required to query Amazon Connect Customer Profiles. See the `destination_flow_config.destination_connector_properties.customer_profiles` Block for details. */ customerProfiles?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesCustomerProfiles; /** * Properties required to query Amazon EventBridge. See the `destination_flow_config.destination_connector_properties.event_bridge` Block for details. */ eventBridge?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesEventBridge; /** * Properties required to query Amazon Honeycode. See the `destination_flow_config.destination_connector_properties.honeycode` Block for details. */ honeycode?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesHoneycode; lookoutMetrics?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesLookoutMetrics; marketo?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesMarketo; /** * Properties required to query Amazon Redshift. See the `destination_flow_config.destination_connector_properties.redshift` Block for details. */ redshift?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesRedshift; s3: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesS3; salesforce?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSalesforce; sapoData?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSapoData; /** * Properties required to query Snowflake. See the `destination_flow_config.destination_connector_properties.snowflake` Block for details. */ snowflake?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSnowflake; /** * Properties required to query Upsolver. See the `destination_flow_config.destination_connector_properties.upsolver` Block for details. */ upsolver?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolver; zendesk?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesZendesk; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesCustomConnector { customProperties?: { [key: string]: string; }; entityName: string; /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesCustomConnectorErrorHandlingConfig; /** * Name of the field that Amazon AppFlow uses as an ID when performing a write operation such as update or delete. */ idFieldNames?: string[]; /** * Type of write operation to be performed in Zendesk. When the value is `UPSERT`, `idFieldNames` is required. Valid values are `INSERT`, `UPSERT`, `UPDATE`, and `DELETE`. */ writeOperationType?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesCustomConnectorErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesCustomerProfiles { /** * Unique name of the Amazon Connect Customer Profiles domain. */ domainName: string; /** * Object specified in the Amazon Connect Customer Profiles flow destination. */ objectTypeName?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesEventBridge { /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesEventBridgeErrorHandlingConfig; object: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesEventBridgeErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesHoneycode { /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesHoneycodeErrorHandlingConfig; object: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesHoneycodeErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesLookoutMetrics { } interface FlowDestinationFlowConfigDestinationConnectorPropertiesMarketo { /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesMarketoErrorHandlingConfig; object: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesMarketoErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesRedshift { bucketPrefix?: string; /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesRedshiftErrorHandlingConfig; /** * Intermediate bucket that Amazon AppFlow uses when moving data into Amazon Snowflake. */ intermediateBucketName: string; object: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesRedshiftErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesS3 { bucketName: string; bucketPrefix: string; /** * Configuration that determines how Amazon AppFlow formats the flow output data when Upsolver is used as the destination. See the `destination_flow_config.destination_connector_properties.upsolver.s3_output_format_config` Block for details. */ s3OutputFormatConfig: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesS3S3OutputFormatConfig; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesS3S3OutputFormatConfig { /** * Aggregation settings that you can use to customize the output format of your flow data. See the `destination_flow_config.destination_connector_properties.upsolver.s3_output_format_config.aggregation_config` Block for details. */ aggregationConfig: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesS3S3OutputFormatConfigAggregationConfig; /** * File type that Amazon AppFlow places in the Upsolver Amazon S3 bucket. Valid values are `CSV`, `JSON`, and `PARQUET`. */ fileType?: string; /** * Prefix that Amazon AppFlow applies to the folder name in the Amazon S3 bucket. See the `destination_flow_config.destination_connector_properties.upsolver.s3_output_format_config.prefix_config` Block for details. */ prefixConfig: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesS3S3OutputFormatConfigPrefixConfig; /** * Whether to preserve the data types from the source system. Only valid for the `PARQUET` file type. */ preserveSourceDataTyping: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesS3S3OutputFormatConfigAggregationConfig { /** * Whether Amazon AppFlow aggregates the flow records into a single file, or leaves them unaggregated. Valid values are `None` and `SingleFile`. */ aggregationType: string; /** * Desired file size, in MB, for each output file that Amazon AppFlow writes to the flow destination. */ targetFileSize: number; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesS3S3OutputFormatConfigPrefixConfig { /** * Level of granularity included in the prefix. Valid values are `YEAR`, `MONTH`, `DAY`, `HOUR`, and `MINUTE`. */ prefixFormat?: string; /** * Whether the destination file path includes either or both of the selected elements. Valid values are `EXECUTION_ID` and `SCHEMA_VERSION`. */ prefixHierarchies: string[]; /** * Format of the prefix, and whether it applies to the file name, file path, or both. Valid values are `FILENAME`, `PATH`, and `PATH_AND_FILENAME`. */ prefixType?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSalesforce { dataTransferApi?: string; /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSalesforceErrorHandlingConfig; /** * Name of the field that Amazon AppFlow uses as an ID when performing a write operation such as update or delete. */ idFieldNames?: string[]; object: string; /** * Type of write operation to be performed in Zendesk. When the value is `UPSERT`, `idFieldNames` is required. Valid values are `INSERT`, `UPSERT`, `UPDATE`, and `DELETE`. */ writeOperationType?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSalesforceErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSapoData { /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSapoDataErrorHandlingConfig; /** * Name of the field that Amazon AppFlow uses as an ID when performing a write operation such as update or delete. */ idFieldNames?: string[]; objectPath: string; /** * Settings that determine how Amazon AppFlow handles the success response it gets from the connector after placing data. See the `destination_flow_config.destination_connector_properties.sapo_data.success_response_handling_config` Block for details. */ successResponseHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSapoDataSuccessResponseHandlingConfig; /** * Type of write operation to be performed in Zendesk. When the value is `UPSERT`, `idFieldNames` is required. Valid values are `INSERT`, `UPSERT`, `UPDATE`, and `DELETE`. */ writeOperationType?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSapoDataErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSapoDataSuccessResponseHandlingConfig { bucketName?: string; bucketPrefix?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSnowflake { bucketPrefix?: string; /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesSnowflakeErrorHandlingConfig; /** * Intermediate bucket that Amazon AppFlow uses when moving data into Amazon Snowflake. */ intermediateBucketName: string; object: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesSnowflakeErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolver { bucketName: string; bucketPrefix?: string; /** * Configuration that determines how Amazon AppFlow formats the flow output data when Upsolver is used as the destination. See the `destination_flow_config.destination_connector_properties.upsolver.s3_output_format_config` Block for details. */ s3OutputFormatConfig: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolverS3OutputFormatConfig; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolverS3OutputFormatConfig { /** * Aggregation settings that you can use to customize the output format of your flow data. See the `destination_flow_config.destination_connector_properties.upsolver.s3_output_format_config.aggregation_config` Block for details. */ aggregationConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolverS3OutputFormatConfigAggregationConfig; /** * File type that Amazon AppFlow places in the Upsolver Amazon S3 bucket. Valid values are `CSV`, `JSON`, and `PARQUET`. */ fileType?: string; /** * Prefix that Amazon AppFlow applies to the folder name in the Amazon S3 bucket. See the `destination_flow_config.destination_connector_properties.upsolver.s3_output_format_config.prefix_config` Block for details. */ prefixConfig: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolverS3OutputFormatConfigPrefixConfig; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolverS3OutputFormatConfigAggregationConfig { /** * Whether Amazon AppFlow aggregates the flow records into a single file, or leaves them unaggregated. Valid values are `None` and `SingleFile`. */ aggregationType?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesUpsolverS3OutputFormatConfigPrefixConfig { /** * Level of granularity included in the prefix. Valid values are `YEAR`, `MONTH`, `DAY`, `HOUR`, and `MINUTE`. */ prefixFormat?: string; /** * Whether the destination file path includes either or both of the selected elements. Valid values are `EXECUTION_ID` and `SCHEMA_VERSION`. */ prefixHierarchies: string[]; /** * Format of the prefix, and whether it applies to the file name, file path, or both. Valid values are `FILENAME`, `PATH`, and `PATH_AND_FILENAME`. */ prefixType: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesZendesk { /** * Settings that determine how Amazon AppFlow handles an error when placing data in the destination. See the `destination_flow_config.destination_connector_properties.zendesk.error_handling_config` Block for details. */ errorHandlingConfig?: outputs.appflow.FlowDestinationFlowConfigDestinationConnectorPropertiesZendeskErrorHandlingConfig; /** * Name of the field that Amazon AppFlow uses as an ID when performing a write operation such as update or delete. */ idFieldNames?: string[]; object: string; /** * Type of write operation to be performed in Zendesk. When the value is `UPSERT`, `idFieldNames` is required. Valid values are `INSERT`, `UPSERT`, `UPDATE`, and `DELETE`. */ writeOperationType?: string; } interface FlowDestinationFlowConfigDestinationConnectorPropertiesZendeskErrorHandlingConfig { bucketName?: string; bucketPrefix?: string; /** * Whether to fail the flow after the first instance of a failure when attempting to place data in the destination. */ failOnFirstDestinationError?: boolean; } interface FlowMetadataCatalogConfig { /** * Configuration that determines how Amazon AppFlow catalogs data with the AWS Glue Data Catalog. See the `metadata_catalog_config.glue_data_catalog` Block for details. */ glueDataCatalog?: outputs.appflow.FlowMetadataCatalogConfigGlueDataCatalog; } interface FlowMetadataCatalogConfigGlueDataCatalog { /** * Name of an existing Glue database to store the metadata tables that Amazon AppFlow creates. */ databaseName: string; /** * ARN of the IAM role that grants Amazon AppFlow the permissions it needs to create Data Catalog tables, databases, and partitions. */ roleArn: string; /** * Naming prefix for each Data Catalog table that Amazon AppFlow creates. */ tablePrefix: string; } interface FlowSourceFlowConfig { /** * API version that the source connector uses. */ apiVersion?: string; /** * Name of the connector profile. Must be unique for each connector profile in the AWS account. */ connectorProfileName?: string; /** * Type of connector, such as Salesforce, Amplitude, and so on. Valid values are `Salesforce`, `Singular`, `Slack`, `Redshift`, `S3`, `Marketo`, `Googleanalytics`, `Zendesk`, `Servicenow`, `Datadog`, `Trendmicro`, `Snowflake`, `Dynatrace`, `Infornexus`, `Amplitude`, `Veeva`, `EventBridge`, `LookoutMetrics`, `Upsolver`, `Honeycode`, `CustomerProfiles`, `SAPOData`, and `CustomConnector`. */ connectorType: string; /** * Configuration for a scheduled incremental data pull. When a valid configuration is provided, the specified fields are used when querying for the incremental data pull. See the `source_flow_config.incremental_pull_config` Block for details. */ incrementalPullConfig?: outputs.appflow.FlowSourceFlowConfigIncrementalPullConfig; /** * Information required to query a particular source connector. See the `source_flow_config.source_connector_properties` Block for details. */ sourceConnectorProperties: outputs.appflow.FlowSourceFlowConfigSourceConnectorProperties; } interface FlowSourceFlowConfigIncrementalPullConfig { /** * Field that specifies the date time or timestamp field as the criteria to use when importing incremental records from the source. */ datetimeTypeFieldName?: string; } interface FlowSourceFlowConfigSourceConnectorProperties { amplitude?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesAmplitude; customConnector?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesCustomConnector; datadog?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesDatadog; dynatrace?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesDynatrace; googleAnalytics?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesGoogleAnalytics; inforNexus?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesInforNexus; marketo?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesMarketo; s3: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesS3; salesforce?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesSalesforce; sapoData?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesSapoData; serviceNow?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesServiceNow; singular?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesSingular; slack?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesSlack; trendmicro?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesTrendmicro; veeva?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesVeeva; zendesk?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesZendesk; } interface FlowSourceFlowConfigSourceConnectorPropertiesAmplitude { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesCustomConnector { customProperties?: { [key: string]: string; }; entityName: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesDatadog { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesDynatrace { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesGoogleAnalytics { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesInforNexus { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesMarketo { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesS3 { bucketName: string; bucketPrefix: string; /** * When you use Amazon S3 as the source, configuration format that you provide for the flow input data. See the `source_flow_config.source_connector_properties.s3.s3_input_format_config` Block for details. */ s3InputFormatConfig?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesS3S3InputFormatConfig; } interface FlowSourceFlowConfigSourceConnectorPropertiesS3S3InputFormatConfig { /** * File type that Amazon AppFlow gets from your Amazon S3 bucket. Valid values are `CSV` and `JSON`. */ s3InputFileType?: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesSalesforce { dataTransferApi?: string; /** * Whether to enable dynamic fetching of new (recently added) fields in the Salesforce objects while running a flow. */ enableDynamicFieldUpdate?: boolean; /** * Whether to include deleted files in the flow run. */ includeDeletedRecords?: boolean; object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesSapoData { objectPath: string; /** * Page size for each concurrent process that transfers OData records from your SAP instance. See the `source_flow_config.source_connector_properties.sapo_data.pagination_config` Block for details. */ paginationConfig?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesSapoDataPaginationConfig; /** * Number of concurrent processes that transfer OData records from your SAP instance. See the `source_flow_config.source_connector_properties.sapo_data.parallelism_config` Block for details. */ parallelismConfig?: outputs.appflow.FlowSourceFlowConfigSourceConnectorPropertiesSapoDataParallelismConfig; } interface FlowSourceFlowConfigSourceConnectorPropertiesSapoDataPaginationConfig { /** * Maximum number of processes that Amazon AppFlow runs at the same time when it retrieves your data from your SAP application. */ maxPageSize: number; } interface FlowSourceFlowConfigSourceConnectorPropertiesSapoDataParallelismConfig { /** * Maximum number of processes that Amazon AppFlow runs at the same time when it retrieves your data from your SAP application. */ maxPageSize: number; } interface FlowSourceFlowConfigSourceConnectorPropertiesServiceNow { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesSingular { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesSlack { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesTrendmicro { object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesVeeva { /** * Document type specified in the Veeva document extract flow. */ documentType?: string; /** * Whether to include all versions of files in the Veeva document extract flow. */ includeAllVersions?: boolean; /** * Whether to include file renditions in the Veeva document extract flow. */ includeRenditions?: boolean; /** * Whether to include source files in the Veeva document extract flow. */ includeSourceFiles?: boolean; object: string; } interface FlowSourceFlowConfigSourceConnectorPropertiesZendesk { object: string; } interface FlowTask { /** * Operation to be performed on the provided source fields. See the `task.connector_operator` Block for details. */ connectorOperators?: outputs.appflow.FlowTaskConnectorOperator[]; /** * Field in a destination connector, or a field value against which Amazon AppFlow validates a source field. */ destinationField?: string; /** * Source fields to which a particular task is applied. */ sourceFields: string[]; /** * Map used to store task-related information. The execution service looks for particular information based on the `TaskType`. Valid keys are `VALUE`, `VALUES`, `DATA_TYPE`, `UPPER_BOUND`, `LOWER_BOUND`, `SOURCE_DATA_TYPE`, `DESTINATION_DATA_TYPE`, `VALIDATION_ACTION`, `MASK_VALUE`, `MASK_LENGTH`, `TRUNCATE_LENGTH`, `MATH_OPERATION_FIELDS_ORDER`, `CONCAT_FORMAT`, `SUBFIELD_CATEGORY_MAP`, and `EXCLUDE_SOURCE_FIELDS_LIST`. */ taskProperties?: { [key: string]: string; }; /** * Particular task implementation that Amazon AppFlow performs. Valid values are `Arithmetic`, `Filter`, `Map`, `Map_all`, `Mask`, `Merge`, `Passthrough`, `Truncate`, and `Validate`. */ taskType: string; } interface FlowTaskConnectorOperator { amplitude?: string; customConnector?: string; datadog?: string; dynatrace?: string; googleAnalytics?: string; inforNexus?: string; marketo?: string; s3?: string; salesforce?: string; sapoData?: string; serviceNow?: string; singular?: string; slack?: string; trendmicro?: string; veeva?: string; zendesk?: string; } interface FlowTriggerConfig { /** * Configuration details of a schedule-triggered flow as defined by the user. Currently, these settings only apply to the `Scheduled` trigger type. See the `trigger_config.trigger_properties` Block for details. */ triggerProperties: outputs.appflow.FlowTriggerConfigTriggerProperties; /** * Type of flow trigger. Valid values are `Scheduled`, `Event`, and `OnDemand`. */ triggerType: string; } interface FlowTriggerConfigTriggerProperties { /** * Configuration details of a schedule-triggered flow. See the `trigger_config.trigger_properties.scheduled` Block for details. */ scheduled?: outputs.appflow.FlowTriggerConfigTriggerPropertiesScheduled; } interface FlowTriggerConfigTriggerPropertiesScheduled { /** * Whether a scheduled flow has an incremental data transfer or a complete data transfer for each flow run. Valid values are `Incremental` and `Complete`. */ dataPullMode?: string; /** * Date range for the records to import from the connector in the first flow run. Must be a valid RFC3339 timestamp. */ firstExecutionFrom?: string; /** * Scheduled end time for a schedule-triggered flow. Must be a valid RFC3339 timestamp. */ scheduleEndTime?: string; /** * Scheduling expression that determines the rate at which the schedule runs, for example `rate(5minutes)`. */ scheduleExpression: string; /** * Offset that is added to the time interval for a schedule-triggered flow. Maximum value of 36000. */ scheduleOffset?: number; /** * Scheduled start time for a schedule-triggered flow. Must be a valid RFC3339 timestamp. */ scheduleStartTime?: string; /** * Time zone used when referring to the date and time of a scheduled-triggered flow, such as `America/New_York`. */ timezone?: string; } } export declare namespace appintegrations { interface DataIntegrationScheduleConfig { /** * Start date for objects to import in the first flow run as an Unix/epoch timestamp in milliseconds or in ISO-8601 format. This needs to be a time in the past, meaning that the data created or updated before this given date will not be downloaded. */ firstExecutionFrom: string; /** * Name of the object to pull from the data source. Examples of objects in Salesforce include `Case`, `Account`, or `Lead`. */ object: string; /** * How often the data should be pulled from data source. Examples include `rate(1 hour)`, `rate(3 hours)`, `rate(1 day)`. */ scheduleExpression: string; } interface GetEventIntegrationEventFilter { /** * Source of the events. */ source: string; } } export declare namespace appmesh { interface GatewayRouteSpec { /** * Specification of a gRPC gateway route. See `grpcRoute` Block for details. */ grpcRoute?: outputs.appmesh.GatewayRouteSpecGrpcRoute; /** * Specification of an HTTP/2 gateway route. See `http2Route` Block for details. */ http2Route?: outputs.appmesh.GatewayRouteSpecHttp2Route; /** * Specification of an HTTP gateway route. See `httpRoute` Block for details. */ httpRoute?: outputs.appmesh.GatewayRouteSpecHttpRoute; /** * Priority for the gateway route, between `0` and `1000`. */ priority?: number; } interface GatewayRouteSpecGrpcRoute { /** * Action to take if a match is determined. See `spec.grpc_route.action` Block for details. */ action: outputs.appmesh.GatewayRouteSpecGrpcRouteAction; /** * Criteria for determining a request match. See `spec.grpc_route.match` Block for details. */ match: outputs.appmesh.GatewayRouteSpecGrpcRouteMatch; } interface GatewayRouteSpecGrpcRouteAction { /** * Target that traffic is routed to when a request matches the gateway route. See `spec.http2_route.action.target` Block for details. */ target: outputs.appmesh.GatewayRouteSpecGrpcRouteActionTarget; } interface GatewayRouteSpecGrpcRouteActionTarget { /** * Port number to match from the request. */ port?: number; /** * Virtual service gateway route target. See `spec.http2_route.action.target.virtual_service` Block for details. */ virtualService: outputs.appmesh.GatewayRouteSpecGrpcRouteActionTargetVirtualService; } interface GatewayRouteSpecGrpcRouteActionTargetVirtualService { /** * Name of the virtual service that traffic is routed to. Must be between 1 and 255 characters in length. */ virtualServiceName: string; } interface GatewayRouteSpecGrpcRouteMatch { /** * Port number to match from the request. */ port?: number; /** * Fully qualified domain name for the service to match from the request. */ serviceName: string; } interface GatewayRouteSpecHttp2Route { /** * Action to take if a match is determined. See `spec.http2_route.action` Block for details. */ action: outputs.appmesh.GatewayRouteSpecHttp2RouteAction; /** * Criteria for determining a request match. See `spec.http2_route.match` Block for details. */ match: outputs.appmesh.GatewayRouteSpecHttp2RouteMatch; } interface GatewayRouteSpecHttp2RouteAction { /** * Gateway route action to rewrite. See `spec.http2_route.action.rewrite` Block for details. */ rewrite?: outputs.appmesh.GatewayRouteSpecHttp2RouteActionRewrite; /** * Target that traffic is routed to when a request matches the gateway route. See `spec.http2_route.action.target` Block for details. */ target: outputs.appmesh.GatewayRouteSpecHttp2RouteActionTarget; } interface GatewayRouteSpecHttp2RouteActionRewrite { /** * Host name to match on. See `spec.http2_route.match.hostname` Block for details. */ hostname?: outputs.appmesh.GatewayRouteSpecHttp2RouteActionRewriteHostname; /** * Client request path to match on. See `spec.http2_route.match.path` Block for details. */ path?: outputs.appmesh.GatewayRouteSpecHttp2RouteActionRewritePath; /** * Header value sent by the client must begin with the specified characters. */ prefix?: outputs.appmesh.GatewayRouteSpecHttp2RouteActionRewritePrefix; } interface GatewayRouteSpecHttp2RouteActionRewriteHostname { /** * Default target host name to write to. Valid values: `ENABLED`, `DISABLED`. */ defaultTargetHostname: string; } interface GatewayRouteSpecHttp2RouteActionRewritePath { /** * Exact query parameter to match on. */ exact: string; } interface GatewayRouteSpecHttp2RouteActionRewritePrefix { /** * Default prefix used to replace the incoming route prefix when rewritten. Valid values: `ENABLED`, `DISABLED`. */ defaultPrefix?: string; /** * Value used to replace the incoming route prefix when rewritten. */ value?: string; } interface GatewayRouteSpecHttp2RouteActionTarget { /** * Port number to match from the request. */ port?: number; /** * Virtual service gateway route target. See `spec.http2_route.action.target.virtual_service` Block for details. */ virtualService: outputs.appmesh.GatewayRouteSpecHttp2RouteActionTargetVirtualService; } interface GatewayRouteSpecHttp2RouteActionTargetVirtualService { /** * Name of the virtual service that traffic is routed to. Must be between 1 and 255 characters in length. */ virtualServiceName: string; } interface GatewayRouteSpecHttp2RouteMatch { /** * Client request headers to match on. See `spec.http2_route.match.header` Block for details. */ headers?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchHeader[]; /** * Host name to match on. See `spec.http2_route.match.hostname` Block for details. */ hostname?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchHostname; /** * Client request path to match on. See `spec.http2_route.match.path` Block for details. */ path?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchPath; /** * Port number to match from the request. */ port?: number; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Client request query parameters to match on. See `spec.http2_route.match.query_parameter` Block for details. */ queryParameters?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchQueryParameter[]; } interface GatewayRouteSpecHttp2RouteMatchHeader { /** * If `true`, the match is on the opposite of the `match` method and value. Default is `false`. */ invert?: boolean; match?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchHeaderMatch; /** * Name to use for the gateway route. Must be between 1 and 255 characters in length. */ name: string; } interface GatewayRouteSpecHttp2RouteMatchHeaderMatch { /** * Exact query parameter to match on. */ exact?: string; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Object that specifies the range of numbers that the header value sent by the client must be included in. See `spec.http2_route.match.header.match.range` Block for details. */ range?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchHeaderMatchRange; /** * Regex used to match the path. */ regex?: string; /** * Specified ending characters of the host name to match on. */ suffix?: string; } interface GatewayRouteSpecHttp2RouteMatchHeaderMatchRange { /** * End of the range. */ end: number; /** * Start of the range. */ start: number; } interface GatewayRouteSpecHttp2RouteMatchHostname { /** * Exact query parameter to match on. */ exact?: string; /** * Specified ending characters of the host name to match on. */ suffix?: string; } interface GatewayRouteSpecHttp2RouteMatchPath { /** * Exact query parameter to match on. */ exact?: string; /** * Regex used to match the path. */ regex?: string; } interface GatewayRouteSpecHttp2RouteMatchQueryParameter { match?: outputs.appmesh.GatewayRouteSpecHttp2RouteMatchQueryParameterMatch; /** * Name to use for the gateway route. Must be between 1 and 255 characters in length. */ name: string; } interface GatewayRouteSpecHttp2RouteMatchQueryParameterMatch { /** * Exact query parameter to match on. */ exact?: string; } interface GatewayRouteSpecHttpRoute { /** * Action to take if a match is determined. See `spec.http_route.action` Block for details. */ action: outputs.appmesh.GatewayRouteSpecHttpRouteAction; /** * Criteria for determining a request match. See `spec.http_route.match` Block for details. */ match: outputs.appmesh.GatewayRouteSpecHttpRouteMatch; } interface GatewayRouteSpecHttpRouteAction { /** * Gateway route action to rewrite. See `spec.http2_route.action.rewrite` Block for details. */ rewrite?: outputs.appmesh.GatewayRouteSpecHttpRouteActionRewrite; /** * Target that traffic is routed to when a request matches the gateway route. See `spec.http2_route.action.target` Block for details. */ target: outputs.appmesh.GatewayRouteSpecHttpRouteActionTarget; } interface GatewayRouteSpecHttpRouteActionRewrite { /** * Host name to match on. See `spec.http2_route.match.hostname` Block for details. */ hostname?: outputs.appmesh.GatewayRouteSpecHttpRouteActionRewriteHostname; /** * Client request path to match on. See `spec.http2_route.match.path` Block for details. */ path?: outputs.appmesh.GatewayRouteSpecHttpRouteActionRewritePath; /** * Header value sent by the client must begin with the specified characters. */ prefix?: outputs.appmesh.GatewayRouteSpecHttpRouteActionRewritePrefix; } interface GatewayRouteSpecHttpRouteActionRewriteHostname { /** * Default target host name to write to. Valid values: `ENABLED`, `DISABLED`. */ defaultTargetHostname: string; } interface GatewayRouteSpecHttpRouteActionRewritePath { /** * Exact query parameter to match on. */ exact: string; } interface GatewayRouteSpecHttpRouteActionRewritePrefix { /** * Default prefix used to replace the incoming route prefix when rewritten. Valid values: `ENABLED`, `DISABLED`. */ defaultPrefix?: string; /** * Value used to replace the incoming route prefix when rewritten. */ value?: string; } interface GatewayRouteSpecHttpRouteActionTarget { /** * Port number to match from the request. */ port?: number; /** * Virtual service gateway route target. See `spec.http2_route.action.target.virtual_service` Block for details. */ virtualService: outputs.appmesh.GatewayRouteSpecHttpRouteActionTargetVirtualService; } interface GatewayRouteSpecHttpRouteActionTargetVirtualService { /** * Name of the virtual service that traffic is routed to. Must be between 1 and 255 characters in length. */ virtualServiceName: string; } interface GatewayRouteSpecHttpRouteMatch { /** * Client request headers to match on. See `spec.http2_route.match.header` Block for details. */ headers?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchHeader[]; /** * Host name to match on. See `spec.http2_route.match.hostname` Block for details. */ hostname?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchHostname; /** * Client request path to match on. See `spec.http2_route.match.path` Block for details. */ path?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchPath; /** * Port number to match from the request. */ port?: number; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Client request query parameters to match on. See `spec.http2_route.match.query_parameter` Block for details. */ queryParameters?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchQueryParameter[]; } interface GatewayRouteSpecHttpRouteMatchHeader { /** * If `true`, the match is on the opposite of the `match` method and value. Default is `false`. */ invert?: boolean; match?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchHeaderMatch; /** * Name to use for the gateway route. Must be between 1 and 255 characters in length. */ name: string; } interface GatewayRouteSpecHttpRouteMatchHeaderMatch { /** * Exact query parameter to match on. */ exact?: string; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Object that specifies the range of numbers that the header value sent by the client must be included in. See `spec.http2_route.match.header.match.range` Block for details. */ range?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchHeaderMatchRange; /** * Regex used to match the path. */ regex?: string; /** * Specified ending characters of the host name to match on. */ suffix?: string; } interface GatewayRouteSpecHttpRouteMatchHeaderMatchRange { /** * End of the range. */ end: number; /** * Start of the range. */ start: number; } interface GatewayRouteSpecHttpRouteMatchHostname { /** * Exact query parameter to match on. */ exact?: string; /** * Specified ending characters of the host name to match on. */ suffix?: string; } interface GatewayRouteSpecHttpRouteMatchPath { /** * Exact query parameter to match on. */ exact?: string; /** * Regex used to match the path. */ regex?: string; } interface GatewayRouteSpecHttpRouteMatchQueryParameter { match?: outputs.appmesh.GatewayRouteSpecHttpRouteMatchQueryParameterMatch; /** * Name to use for the gateway route. Must be between 1 and 255 characters in length. */ name: string; } interface GatewayRouteSpecHttpRouteMatchQueryParameterMatch { /** * Exact query parameter to match on. */ exact?: string; } interface GetGatewayRouteSpec { grpcRoutes: outputs.appmesh.GetGatewayRouteSpecGrpcRoute[]; http2Routes: outputs.appmesh.GetGatewayRouteSpecHttp2Route[]; httpRoutes: outputs.appmesh.GetGatewayRouteSpecHttpRoute[]; priority: number; } interface GetGatewayRouteSpecGrpcRoute { actions: outputs.appmesh.GetGatewayRouteSpecGrpcRouteAction[]; matches: outputs.appmesh.GetGatewayRouteSpecGrpcRouteMatch[]; } interface GetGatewayRouteSpecGrpcRouteAction { targets: outputs.appmesh.GetGatewayRouteSpecGrpcRouteActionTarget[]; } interface GetGatewayRouteSpecGrpcRouteActionTarget { port: number; virtualServices: outputs.appmesh.GetGatewayRouteSpecGrpcRouteActionTargetVirtualService[]; } interface GetGatewayRouteSpecGrpcRouteActionTargetVirtualService { virtualServiceName: string; } interface GetGatewayRouteSpecGrpcRouteMatch { port: number; serviceName: string; } interface GetGatewayRouteSpecHttp2Route { actions: outputs.appmesh.GetGatewayRouteSpecHttp2RouteAction[]; matches: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatch[]; } interface GetGatewayRouteSpecHttp2RouteAction { rewrites: outputs.appmesh.GetGatewayRouteSpecHttp2RouteActionRewrite[]; targets: outputs.appmesh.GetGatewayRouteSpecHttp2RouteActionTarget[]; } interface GetGatewayRouteSpecHttp2RouteActionRewrite { hostnames: outputs.appmesh.GetGatewayRouteSpecHttp2RouteActionRewriteHostname[]; paths: outputs.appmesh.GetGatewayRouteSpecHttp2RouteActionRewritePath[]; prefixes: outputs.appmesh.GetGatewayRouteSpecHttp2RouteActionRewritePrefix[]; } interface GetGatewayRouteSpecHttp2RouteActionRewriteHostname { defaultTargetHostname: string; } interface GetGatewayRouteSpecHttp2RouteActionRewritePath { exact: string; } interface GetGatewayRouteSpecHttp2RouteActionRewritePrefix { defaultPrefix: string; value: string; } interface GetGatewayRouteSpecHttp2RouteActionTarget { port: number; virtualServices: outputs.appmesh.GetGatewayRouteSpecHttp2RouteActionTargetVirtualService[]; } interface GetGatewayRouteSpecHttp2RouteActionTargetVirtualService { virtualServiceName: string; } interface GetGatewayRouteSpecHttp2RouteMatch { headers: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchHeader[]; hostnames: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchHostname[]; paths: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchPath[]; port: number; prefix: string; queryParameters: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchQueryParameter[]; } interface GetGatewayRouteSpecHttp2RouteMatchHeader { invert: boolean; matches: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchHeaderMatch[]; /** * Name of the gateway route. */ name: string; } interface GetGatewayRouteSpecHttp2RouteMatchHeaderMatch { exact: string; prefix: string; ranges: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchHeaderMatchRange[]; regex: string; suffix: string; } interface GetGatewayRouteSpecHttp2RouteMatchHeaderMatchRange { end: number; start: number; } interface GetGatewayRouteSpecHttp2RouteMatchHostname { exact: string; suffix: string; } interface GetGatewayRouteSpecHttp2RouteMatchPath { exact: string; regex: string; } interface GetGatewayRouteSpecHttp2RouteMatchQueryParameter { matches: outputs.appmesh.GetGatewayRouteSpecHttp2RouteMatchQueryParameterMatch[]; /** * Name of the gateway route. */ name: string; } interface GetGatewayRouteSpecHttp2RouteMatchQueryParameterMatch { exact: string; } interface GetGatewayRouteSpecHttpRoute { actions: outputs.appmesh.GetGatewayRouteSpecHttpRouteAction[]; matches: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatch[]; } interface GetGatewayRouteSpecHttpRouteAction { rewrites: outputs.appmesh.GetGatewayRouteSpecHttpRouteActionRewrite[]; targets: outputs.appmesh.GetGatewayRouteSpecHttpRouteActionTarget[]; } interface GetGatewayRouteSpecHttpRouteActionRewrite { hostnames: outputs.appmesh.GetGatewayRouteSpecHttpRouteActionRewriteHostname[]; paths: outputs.appmesh.GetGatewayRouteSpecHttpRouteActionRewritePath[]; prefixes: outputs.appmesh.GetGatewayRouteSpecHttpRouteActionRewritePrefix[]; } interface GetGatewayRouteSpecHttpRouteActionRewriteHostname { defaultTargetHostname: string; } interface GetGatewayRouteSpecHttpRouteActionRewritePath { exact: string; } interface GetGatewayRouteSpecHttpRouteActionRewritePrefix { defaultPrefix: string; value: string; } interface GetGatewayRouteSpecHttpRouteActionTarget { port: number; virtualServices: outputs.appmesh.GetGatewayRouteSpecHttpRouteActionTargetVirtualService[]; } interface GetGatewayRouteSpecHttpRouteActionTargetVirtualService { virtualServiceName: string; } interface GetGatewayRouteSpecHttpRouteMatch { headers: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchHeader[]; hostnames: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchHostname[]; paths: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchPath[]; port: number; prefix: string; queryParameters: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchQueryParameter[]; } interface GetGatewayRouteSpecHttpRouteMatchHeader { invert: boolean; matches: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchHeaderMatch[]; /** * Name of the gateway route. */ name: string; } interface GetGatewayRouteSpecHttpRouteMatchHeaderMatch { exact: string; prefix: string; ranges: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchHeaderMatchRange[]; regex: string; suffix: string; } interface GetGatewayRouteSpecHttpRouteMatchHeaderMatchRange { end: number; start: number; } interface GetGatewayRouteSpecHttpRouteMatchHostname { exact: string; suffix: string; } interface GetGatewayRouteSpecHttpRouteMatchPath { exact: string; regex: string; } interface GetGatewayRouteSpecHttpRouteMatchQueryParameter { matches: outputs.appmesh.GetGatewayRouteSpecHttpRouteMatchQueryParameterMatch[]; /** * Name of the gateway route. */ name: string; } interface GetGatewayRouteSpecHttpRouteMatchQueryParameterMatch { exact: string; } interface GetMeshSpec { egressFilters: outputs.appmesh.GetMeshSpecEgressFilter[]; serviceDiscoveries: outputs.appmesh.GetMeshSpecServiceDiscovery[]; } interface GetMeshSpecEgressFilter { type: string; } interface GetMeshSpecServiceDiscovery { ipPreference: string; } interface GetRouteSpec { grpcRoutes: outputs.appmesh.GetRouteSpecGrpcRoute[]; http2Routes: outputs.appmesh.GetRouteSpecHttp2Route[]; httpRoutes: outputs.appmesh.GetRouteSpecHttpRoute[]; priority: number; tcpRoutes: outputs.appmesh.GetRouteSpecTcpRoute[]; } interface GetRouteSpecGrpcRoute { actions: outputs.appmesh.GetRouteSpecGrpcRouteAction[]; matches: outputs.appmesh.GetRouteSpecGrpcRouteMatch[]; retryPolicies: outputs.appmesh.GetRouteSpecGrpcRouteRetryPolicy[]; timeouts: outputs.appmesh.GetRouteSpecGrpcRouteTimeout[]; } interface GetRouteSpecGrpcRouteAction { weightedTargets: outputs.appmesh.GetRouteSpecGrpcRouteActionWeightedTarget[]; } interface GetRouteSpecGrpcRouteActionWeightedTarget { port: number; virtualNode: string; weight: number; } interface GetRouteSpecGrpcRouteMatch { metadatas: outputs.appmesh.GetRouteSpecGrpcRouteMatchMetadata[]; methodName: string; port: number; prefix: string; serviceName: string; } interface GetRouteSpecGrpcRouteMatchMetadata { invert: boolean; matches: outputs.appmesh.GetRouteSpecGrpcRouteMatchMetadataMatch[]; /** * Name of the route. */ name: string; } interface GetRouteSpecGrpcRouteMatchMetadataMatch { exact: string; prefix: string; ranges: outputs.appmesh.GetRouteSpecGrpcRouteMatchMetadataMatchRange[]; regex: string; suffix: string; } interface GetRouteSpecGrpcRouteMatchMetadataMatchRange { end: number; start: number; } interface GetRouteSpecGrpcRouteRetryPolicy { grpcRetryEvents: string[]; httpRetryEvents: string[]; maxRetries: number; perRetryTimeouts: outputs.appmesh.GetRouteSpecGrpcRouteRetryPolicyPerRetryTimeout[]; tcpRetryEvents: string[]; } interface GetRouteSpecGrpcRouteRetryPolicyPerRetryTimeout { unit: string; value: number; } interface GetRouteSpecGrpcRouteTimeout { idles: outputs.appmesh.GetRouteSpecGrpcRouteTimeoutIdle[]; perRequests: outputs.appmesh.GetRouteSpecGrpcRouteTimeoutPerRequest[]; } interface GetRouteSpecGrpcRouteTimeoutIdle { unit: string; value: number; } interface GetRouteSpecGrpcRouteTimeoutPerRequest { unit: string; value: number; } interface GetRouteSpecHttp2Route { actions: outputs.appmesh.GetRouteSpecHttp2RouteAction[]; matches: outputs.appmesh.GetRouteSpecHttp2RouteMatch[]; retryPolicies: outputs.appmesh.GetRouteSpecHttp2RouteRetryPolicy[]; timeouts: outputs.appmesh.GetRouteSpecHttp2RouteTimeout[]; } interface GetRouteSpecHttp2RouteAction { weightedTargets: outputs.appmesh.GetRouteSpecHttp2RouteActionWeightedTarget[]; } interface GetRouteSpecHttp2RouteActionWeightedTarget { port: number; virtualNode: string; weight: number; } interface GetRouteSpecHttp2RouteMatch { headers: outputs.appmesh.GetRouteSpecHttp2RouteMatchHeader[]; method: string; paths: outputs.appmesh.GetRouteSpecHttp2RouteMatchPath[]; port: number; prefix: string; queryParameters: outputs.appmesh.GetRouteSpecHttp2RouteMatchQueryParameter[]; scheme: string; } interface GetRouteSpecHttp2RouteMatchHeader { invert: boolean; matches: outputs.appmesh.GetRouteSpecHttp2RouteMatchHeaderMatch[]; /** * Name of the route. */ name: string; } interface GetRouteSpecHttp2RouteMatchHeaderMatch { exact: string; prefix: string; ranges: outputs.appmesh.GetRouteSpecHttp2RouteMatchHeaderMatchRange[]; regex: string; suffix: string; } interface GetRouteSpecHttp2RouteMatchHeaderMatchRange { end: number; start: number; } interface GetRouteSpecHttp2RouteMatchPath { exact: string; regex: string; } interface GetRouteSpecHttp2RouteMatchQueryParameter { matches: outputs.appmesh.GetRouteSpecHttp2RouteMatchQueryParameterMatch[]; /** * Name of the route. */ name: string; } interface GetRouteSpecHttp2RouteMatchQueryParameterMatch { exact: string; } interface GetRouteSpecHttp2RouteRetryPolicy { httpRetryEvents: string[]; maxRetries: number; perRetryTimeouts: outputs.appmesh.GetRouteSpecHttp2RouteRetryPolicyPerRetryTimeout[]; tcpRetryEvents: string[]; } interface GetRouteSpecHttp2RouteRetryPolicyPerRetryTimeout { unit: string; value: number; } interface GetRouteSpecHttp2RouteTimeout { idles: outputs.appmesh.GetRouteSpecHttp2RouteTimeoutIdle[]; perRequests: outputs.appmesh.GetRouteSpecHttp2RouteTimeoutPerRequest[]; } interface GetRouteSpecHttp2RouteTimeoutIdle { unit: string; value: number; } interface GetRouteSpecHttp2RouteTimeoutPerRequest { unit: string; value: number; } interface GetRouteSpecHttpRoute { actions: outputs.appmesh.GetRouteSpecHttpRouteAction[]; matches: outputs.appmesh.GetRouteSpecHttpRouteMatch[]; retryPolicies: outputs.appmesh.GetRouteSpecHttpRouteRetryPolicy[]; timeouts: outputs.appmesh.GetRouteSpecHttpRouteTimeout[]; } interface GetRouteSpecHttpRouteAction { weightedTargets: outputs.appmesh.GetRouteSpecHttpRouteActionWeightedTarget[]; } interface GetRouteSpecHttpRouteActionWeightedTarget { port: number; virtualNode: string; weight: number; } interface GetRouteSpecHttpRouteMatch { headers: outputs.appmesh.GetRouteSpecHttpRouteMatchHeader[]; method: string; paths: outputs.appmesh.GetRouteSpecHttpRouteMatchPath[]; port: number; prefix: string; queryParameters: outputs.appmesh.GetRouteSpecHttpRouteMatchQueryParameter[]; scheme: string; } interface GetRouteSpecHttpRouteMatchHeader { invert: boolean; matches: outputs.appmesh.GetRouteSpecHttpRouteMatchHeaderMatch[]; /** * Name of the route. */ name: string; } interface GetRouteSpecHttpRouteMatchHeaderMatch { exact: string; prefix: string; ranges: outputs.appmesh.GetRouteSpecHttpRouteMatchHeaderMatchRange[]; regex: string; suffix: string; } interface GetRouteSpecHttpRouteMatchHeaderMatchRange { end: number; start: number; } interface GetRouteSpecHttpRouteMatchPath { exact: string; regex: string; } interface GetRouteSpecHttpRouteMatchQueryParameter { matches: outputs.appmesh.GetRouteSpecHttpRouteMatchQueryParameterMatch[]; /** * Name of the route. */ name: string; } interface GetRouteSpecHttpRouteMatchQueryParameterMatch { exact: string; } interface GetRouteSpecHttpRouteRetryPolicy { httpRetryEvents: string[]; maxRetries: number; perRetryTimeouts: outputs.appmesh.GetRouteSpecHttpRouteRetryPolicyPerRetryTimeout[]; tcpRetryEvents: string[]; } interface GetRouteSpecHttpRouteRetryPolicyPerRetryTimeout { unit: string; value: number; } interface GetRouteSpecHttpRouteTimeout { idles: outputs.appmesh.GetRouteSpecHttpRouteTimeoutIdle[]; perRequests: outputs.appmesh.GetRouteSpecHttpRouteTimeoutPerRequest[]; } interface GetRouteSpecHttpRouteTimeoutIdle { unit: string; value: number; } interface GetRouteSpecHttpRouteTimeoutPerRequest { unit: string; value: number; } interface GetRouteSpecTcpRoute { actions: outputs.appmesh.GetRouteSpecTcpRouteAction[]; matches: outputs.appmesh.GetRouteSpecTcpRouteMatch[]; timeouts: outputs.appmesh.GetRouteSpecTcpRouteTimeout[]; } interface GetRouteSpecTcpRouteAction { weightedTargets: outputs.appmesh.GetRouteSpecTcpRouteActionWeightedTarget[]; } interface GetRouteSpecTcpRouteActionWeightedTarget { port: number; virtualNode: string; weight: number; } interface GetRouteSpecTcpRouteMatch { port: number; } interface GetRouteSpecTcpRouteTimeout { idles: outputs.appmesh.GetRouteSpecTcpRouteTimeoutIdle[]; } interface GetRouteSpecTcpRouteTimeoutIdle { unit: string; value: number; } interface GetVirtualGatewaySpec { backendDefaults: outputs.appmesh.GetVirtualGatewaySpecBackendDefault[]; listeners: outputs.appmesh.GetVirtualGatewaySpecListener[]; loggings: outputs.appmesh.GetVirtualGatewaySpecLogging[]; } interface GetVirtualGatewaySpecBackendDefault { clientPolicies: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicy[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicy { tls: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTl[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTl { certificates: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlCertificate[]; enforce: boolean; ports: number[]; validations: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidation[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlCertificate { files: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlCertificateFile[]; sds: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlCertificateSd[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlCertificateFile { certificateChain: string; privateKey: string; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlCertificateSd { secretName: string; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidation { subjectAlternativeNames: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationSubjectAlternativeName[]; trusts: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrust[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationSubjectAlternativeName { matches: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationSubjectAlternativeNameMatch[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationSubjectAlternativeNameMatch { exacts: string[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrust { acms: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrustAcm[]; files: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrustFile[]; sds: outputs.appmesh.GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrustSd[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrustAcm { certificateAuthorityArns: string[]; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrustFile { certificateChain: string; } interface GetVirtualGatewaySpecBackendDefaultClientPolicyTlValidationTrustSd { secretName: string; } interface GetVirtualGatewaySpecListener { connectionPools: outputs.appmesh.GetVirtualGatewaySpecListenerConnectionPool[]; healthChecks: outputs.appmesh.GetVirtualGatewaySpecListenerHealthCheck[]; portMappings: outputs.appmesh.GetVirtualGatewaySpecListenerPortMapping[]; tls: outputs.appmesh.GetVirtualGatewaySpecListenerTl[]; } interface GetVirtualGatewaySpecListenerConnectionPool { grpcs: outputs.appmesh.GetVirtualGatewaySpecListenerConnectionPoolGrpc[]; http2s: outputs.appmesh.GetVirtualGatewaySpecListenerConnectionPoolHttp2[]; https: outputs.appmesh.GetVirtualGatewaySpecListenerConnectionPoolHttp[]; } interface GetVirtualGatewaySpecListenerConnectionPoolGrpc { maxRequests: number; } interface GetVirtualGatewaySpecListenerConnectionPoolHttp { maxConnections: number; maxPendingRequests: number; } interface GetVirtualGatewaySpecListenerConnectionPoolHttp2 { maxRequests: number; } interface GetVirtualGatewaySpecListenerHealthCheck { healthyThreshold: number; intervalMillis: number; path: string; port: number; protocol: string; timeoutMillis: number; unhealthyThreshold: number; } interface GetVirtualGatewaySpecListenerPortMapping { port: number; protocol: string; } interface GetVirtualGatewaySpecListenerTl { certificates: outputs.appmesh.GetVirtualGatewaySpecListenerTlCertificate[]; mode: string; validations: outputs.appmesh.GetVirtualGatewaySpecListenerTlValidation[]; } interface GetVirtualGatewaySpecListenerTlCertificate { acms: outputs.appmesh.GetVirtualGatewaySpecListenerTlCertificateAcm[]; files: outputs.appmesh.GetVirtualGatewaySpecListenerTlCertificateFile[]; sds: outputs.appmesh.GetVirtualGatewaySpecListenerTlCertificateSd[]; } interface GetVirtualGatewaySpecListenerTlCertificateAcm { certificateArn: string; } interface GetVirtualGatewaySpecListenerTlCertificateFile { certificateChain: string; privateKey: string; } interface GetVirtualGatewaySpecListenerTlCertificateSd { secretName: string; } interface GetVirtualGatewaySpecListenerTlValidation { subjectAlternativeNames: outputs.appmesh.GetVirtualGatewaySpecListenerTlValidationSubjectAlternativeName[]; trusts: outputs.appmesh.GetVirtualGatewaySpecListenerTlValidationTrust[]; } interface GetVirtualGatewaySpecListenerTlValidationSubjectAlternativeName { matches: outputs.appmesh.GetVirtualGatewaySpecListenerTlValidationSubjectAlternativeNameMatch[]; } interface GetVirtualGatewaySpecListenerTlValidationSubjectAlternativeNameMatch { exacts: string[]; } interface GetVirtualGatewaySpecListenerTlValidationTrust { files: outputs.appmesh.GetVirtualGatewaySpecListenerTlValidationTrustFile[]; sds: outputs.appmesh.GetVirtualGatewaySpecListenerTlValidationTrustSd[]; } interface GetVirtualGatewaySpecListenerTlValidationTrustFile { certificateChain: string; } interface GetVirtualGatewaySpecListenerTlValidationTrustSd { secretName: string; } interface GetVirtualGatewaySpecLogging { accessLogs: outputs.appmesh.GetVirtualGatewaySpecLoggingAccessLog[]; } interface GetVirtualGatewaySpecLoggingAccessLog { files: outputs.appmesh.GetVirtualGatewaySpecLoggingAccessLogFile[]; } interface GetVirtualGatewaySpecLoggingAccessLogFile { formats: outputs.appmesh.GetVirtualGatewaySpecLoggingAccessLogFileFormat[]; path: string; } interface GetVirtualGatewaySpecLoggingAccessLogFileFormat { jsons: outputs.appmesh.GetVirtualGatewaySpecLoggingAccessLogFileFormatJson[]; text: string; } interface GetVirtualGatewaySpecLoggingAccessLogFileFormatJson { key: string; value: string; } interface GetVirtualNodeSpec { /** * Defaults for backends. See `spec.backend_defaults` Block for details. */ backendDefaults: outputs.appmesh.GetVirtualNodeSpecBackendDefault[]; /** * Backends to which the virtual node sends outbound traffic. See `spec.backend` Block for details. */ backends: outputs.appmesh.GetVirtualNodeSpecBackend[]; /** * Listeners from which the virtual node receives inbound traffic. See `spec.listener` Block for details. */ listeners: outputs.appmesh.GetVirtualNodeSpecListener[]; /** * Inbound and outbound access logging information for the virtual node. See `spec.logging` Block for details. */ loggings: outputs.appmesh.GetVirtualNodeSpecLogging[]; /** * Service discovery information for the virtual node. See `spec.service_discovery` Block for details. */ serviceDiscoveries: outputs.appmesh.GetVirtualNodeSpecServiceDiscovery[]; } interface GetVirtualNodeSpecBackend { /** * Virtual service used as a backend for a virtual node. See `spec.backend.virtual_service` Block for details. */ virtualServices: outputs.appmesh.GetVirtualNodeSpecBackendVirtualService[]; } interface GetVirtualNodeSpecBackendDefault { /** * Default client policy for virtual service backends. See `spec.backend_defaults.client_policy` Block for details. */ clientPolicies: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicy[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicy { /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTl[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTl { /** * Listener's TLS certificate. See `spec.listener.tls.certificate` Block for details. */ certificates: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlCertificate[]; /** * Whether the policy is enforced. */ enforce: boolean; /** * One or more ports that the policy is enforced for. */ ports: number[]; /** * Listener's TLS validation context. See `spec.listener.tls.validation` Block for details. */ validations: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidation[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlCertificate { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlCertificateFile[]; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlCertificateSd[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the virtual node that the proxy is running on. */ privateKey: string; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlCertificateSd { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidation { /** * SANs for a TLS validation context. See `spec.listener.tls.validation.subject_alternative_names` Block for details. */ subjectAlternativeNames: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationSubjectAlternativeName[]; /** * TLS validation context trust. See `spec.listener.tls.validation.trust` Block for details. */ trusts: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrust[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationSubjectAlternativeName { /** * Criteria for determining a SAN's match. See `spec.listener.tls.validation.subject_alternative_names.match` Block for details. */ matches: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationSubjectAlternativeNameMatch[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationSubjectAlternativeNameMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrust { /** * AWS Certificate Manager (ACM) certificate. See `spec.listener.tls.certificate.acm` Block for details. */ acms: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrustAcm[]; /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrustFile[]; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds: outputs.appmesh.GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrustSd[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrustAcm { /** * One or more ACM ARNs. */ certificateAuthorityArns: string[]; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. */ certificateChain: string; } interface GetVirtualNodeSpecBackendDefaultClientPolicyTlValidationTrustSd { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface GetVirtualNodeSpecBackendVirtualService { /** * Default client policy for virtual service backends. See `spec.backend_defaults.client_policy` Block for details. */ clientPolicies: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicy[]; /** * Name of the virtual service that is acting as a virtual node backend. */ virtualServiceName: string; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicy { /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTl[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTl { /** * Listener's TLS certificate. See `spec.listener.tls.certificate` Block for details. */ certificates: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlCertificate[]; /** * Whether the policy is enforced. */ enforce: boolean; /** * One or more ports that the policy is enforced for. */ ports: number[]; /** * Listener's TLS validation context. See `spec.listener.tls.validation` Block for details. */ validations: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidation[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlCertificate { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlCertificateFile[]; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlCertificateSd[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the virtual node that the proxy is running on. */ privateKey: string; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlCertificateSd { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidation { /** * SANs for a TLS validation context. See `spec.listener.tls.validation.subject_alternative_names` Block for details. */ subjectAlternativeNames: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationSubjectAlternativeName[]; /** * TLS validation context trust. See `spec.listener.tls.validation.trust` Block for details. */ trusts: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrust[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationSubjectAlternativeName { /** * Criteria for determining a SAN's match. See `spec.listener.tls.validation.subject_alternative_names.match` Block for details. */ matches: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationSubjectAlternativeNameMatch[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationSubjectAlternativeNameMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrust { /** * AWS Certificate Manager (ACM) certificate. See `spec.listener.tls.certificate.acm` Block for details. */ acms: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrustAcm[]; /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrustFile[]; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds: outputs.appmesh.GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrustSd[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrustAcm { /** * One or more ACM ARNs. */ certificateAuthorityArns: string[]; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. */ certificateChain: string; } interface GetVirtualNodeSpecBackendVirtualServiceClientPolicyTlValidationTrustSd { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface GetVirtualNodeSpecListener { /** * Connection pool information for the listener. See `spec.listener.connection_pool` Block for details. */ connectionPools: outputs.appmesh.GetVirtualNodeSpecListenerConnectionPool[]; /** * Health check information for the listener. See `spec.listener.health_check` Block for details. */ healthChecks: outputs.appmesh.GetVirtualNodeSpecListenerHealthCheck[]; /** * Outlier detection information for the listener. See `spec.listener.outlier_detection` Block for details. */ outlierDetections: outputs.appmesh.GetVirtualNodeSpecListenerOutlierDetection[]; /** * Port mapping information for the listener. See `spec.listener.port_mapping` Block for details. */ portMappings: outputs.appmesh.GetVirtualNodeSpecListenerPortMapping[]; /** * Timeouts for different protocols. See `spec.listener.timeout` Block for details. */ timeouts: outputs.appmesh.GetVirtualNodeSpecListenerTimeout[]; /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls: outputs.appmesh.GetVirtualNodeSpecListenerTl[]; } interface GetVirtualNodeSpecListenerConnectionPool { /** * Timeouts for gRPC listeners. See `spec.listener.timeout.grpc` Block for details. */ grpcs: outputs.appmesh.GetVirtualNodeSpecListenerConnectionPoolGrpc[]; /** * Timeouts for HTTP2 listeners. See `spec.listener.timeout.http2` Block for details. */ http2s: outputs.appmesh.GetVirtualNodeSpecListenerConnectionPoolHttp2[]; /** * Timeouts for HTTP listeners. See `spec.listener.timeout.http` Block for details. */ https: outputs.appmesh.GetVirtualNodeSpecListenerConnectionPoolHttp[]; /** * Timeouts for TCP listeners. See `spec.listener.timeout.tcp` Block for details. */ tcps: outputs.appmesh.GetVirtualNodeSpecListenerConnectionPoolTcp[]; } interface GetVirtualNodeSpecListenerConnectionPoolGrpc { /** * Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster. */ maxRequests: number; } interface GetVirtualNodeSpecListenerConnectionPoolHttp { /** * Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster. */ maxConnections: number; /** * Number of overflowing requests after `maxConnections` Envoy will queue to upstream cluster. */ maxPendingRequests: number; } interface GetVirtualNodeSpecListenerConnectionPoolHttp2 { /** * Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster. */ maxRequests: number; } interface GetVirtualNodeSpecListenerConnectionPoolTcp { /** * Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster. */ maxConnections: number; } interface GetVirtualNodeSpecListenerHealthCheck { /** * Number of consecutive successful health checks that must occur before declaring listener healthy. */ healthyThreshold: number; /** * Time period in milliseconds between each health check execution. */ intervalMillis: number; /** * File path to write access logs to. */ path: string; /** * Port used for the port mapping. */ port: number; /** * Protocol used for the port mapping. */ protocol: string; /** * Amount of time to wait when receiving a response from the health check, in milliseconds. */ timeoutMillis: number; /** * Number of consecutive failed health checks that must occur before declaring a virtual node unhealthy. */ unhealthyThreshold: number; } interface GetVirtualNodeSpecListenerOutlierDetection { /** * Base amount of time for which a host is ejected. See `spec.listener.outlier_detection.base_ejection_duration` Block for details. */ baseEjectionDurations: outputs.appmesh.GetVirtualNodeSpecListenerOutlierDetectionBaseEjectionDuration[]; /** * Time interval between ejection sweep analysis. See `spec.listener.outlier_detection.interval` Block for details. */ intervals: outputs.appmesh.GetVirtualNodeSpecListenerOutlierDetectionInterval[]; /** * Maximum percentage of hosts in load balancing pool for upstream service that can be ejected. */ maxEjectionPercent: number; /** * Number of consecutive `5xx` errors required for ejection. */ maxServerErrors: number; } interface GetVirtualNodeSpecListenerOutlierDetectionBaseEjectionDuration { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerOutlierDetectionInterval { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerPortMapping { /** * Port used for the port mapping. */ port: number; /** * Protocol used for the port mapping. */ protocol: string; } interface GetVirtualNodeSpecListenerTimeout { /** * Timeouts for gRPC listeners. See `spec.listener.timeout.grpc` Block for details. */ grpcs: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutGrpc[]; /** * Timeouts for HTTP2 listeners. See `spec.listener.timeout.http2` Block for details. */ http2s: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutHttp2[]; /** * Timeouts for HTTP listeners. See `spec.listener.timeout.http` Block for details. */ https: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutHttp[]; /** * Timeouts for TCP listeners. See `spec.listener.timeout.tcp` Block for details. */ tcps: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutTcp[]; } interface GetVirtualNodeSpecListenerTimeoutGrpc { /** * Idle timeout. See `spec.listener.timeout.tcp.idle` Block for details. */ idles: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutGrpcIdle[]; /** * Per request timeout. See `spec.listener.timeout.http2.per_request` Block for details. */ perRequests: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutGrpcPerRequest[]; } interface GetVirtualNodeSpecListenerTimeoutGrpcIdle { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTimeoutGrpcPerRequest { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTimeoutHttp { /** * Idle timeout. See `spec.listener.timeout.tcp.idle` Block for details. */ idles: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutHttpIdle[]; /** * Per request timeout. See `spec.listener.timeout.http2.per_request` Block for details. */ perRequests: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutHttpPerRequest[]; } interface GetVirtualNodeSpecListenerTimeoutHttp2 { /** * Idle timeout. See `spec.listener.timeout.tcp.idle` Block for details. */ idles: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutHttp2Idle[]; /** * Per request timeout. See `spec.listener.timeout.http2.per_request` Block for details. */ perRequests: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutHttp2PerRequest[]; } interface GetVirtualNodeSpecListenerTimeoutHttp2Idle { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTimeoutHttp2PerRequest { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTimeoutHttpIdle { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTimeoutHttpPerRequest { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTimeoutTcp { /** * Idle timeout. See `spec.listener.timeout.tcp.idle` Block for details. */ idles: outputs.appmesh.GetVirtualNodeSpecListenerTimeoutTcpIdle[]; } interface GetVirtualNodeSpecListenerTimeoutTcpIdle { /** * Unit of time. */ unit: string; /** * Value for the JSON. */ value: number; } interface GetVirtualNodeSpecListenerTl { /** * Listener's TLS certificate. See `spec.listener.tls.certificate` Block for details. */ certificates: outputs.appmesh.GetVirtualNodeSpecListenerTlCertificate[]; /** * Listener's TLS mode. */ mode: string; /** * Listener's TLS validation context. See `spec.listener.tls.validation` Block for details. */ validations: outputs.appmesh.GetVirtualNodeSpecListenerTlValidation[]; } interface GetVirtualNodeSpecListenerTlCertificate { /** * AWS Certificate Manager (ACM) certificate. See `spec.listener.tls.certificate.acm` Block for details. */ acms: outputs.appmesh.GetVirtualNodeSpecListenerTlCertificateAcm[]; /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecListenerTlCertificateFile[]; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds: outputs.appmesh.GetVirtualNodeSpecListenerTlCertificateSd[]; } interface GetVirtualNodeSpecListenerTlCertificateAcm { /** * ARN for the certificate. */ certificateArn: string; } interface GetVirtualNodeSpecListenerTlCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the virtual node that the proxy is running on. */ privateKey: string; } interface GetVirtualNodeSpecListenerTlCertificateSd { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface GetVirtualNodeSpecListenerTlValidation { /** * SANs for a TLS validation context. See `spec.listener.tls.validation.subject_alternative_names` Block for details. */ subjectAlternativeNames: outputs.appmesh.GetVirtualNodeSpecListenerTlValidationSubjectAlternativeName[]; /** * TLS validation context trust. See `spec.listener.tls.validation.trust` Block for details. */ trusts: outputs.appmesh.GetVirtualNodeSpecListenerTlValidationTrust[]; } interface GetVirtualNodeSpecListenerTlValidationSubjectAlternativeName { /** * Criteria for determining a SAN's match. See `spec.listener.tls.validation.subject_alternative_names.match` Block for details. */ matches: outputs.appmesh.GetVirtualNodeSpecListenerTlValidationSubjectAlternativeNameMatch[]; } interface GetVirtualNodeSpecListenerTlValidationSubjectAlternativeNameMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface GetVirtualNodeSpecListenerTlValidationTrust { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecListenerTlValidationTrustFile[]; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds: outputs.appmesh.GetVirtualNodeSpecListenerTlValidationTrustSd[]; } interface GetVirtualNodeSpecListenerTlValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. */ certificateChain: string; } interface GetVirtualNodeSpecListenerTlValidationTrustSd { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface GetVirtualNodeSpecLogging { /** * Access log configuration for a virtual node. See `spec.logging.access_log` Block for details. */ accessLogs: outputs.appmesh.GetVirtualNodeSpecLoggingAccessLog[]; } interface GetVirtualNodeSpecLoggingAccessLog { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ files: outputs.appmesh.GetVirtualNodeSpecLoggingAccessLogFile[]; } interface GetVirtualNodeSpecLoggingAccessLogFile { /** * Format for the logs. See `spec.logging.access_log.file.format` Block for details. */ formats: outputs.appmesh.GetVirtualNodeSpecLoggingAccessLogFileFormat[]; /** * File path to write access logs to. */ path: string; } interface GetVirtualNodeSpecLoggingAccessLogFileFormat { /** * Logging format for JSON. See `spec.logging.access_log.file.format.json` Block for details. */ jsons: outputs.appmesh.GetVirtualNodeSpecLoggingAccessLogFileFormatJson[]; /** * Logging format for text. */ text: string; } interface GetVirtualNodeSpecLoggingAccessLogFileFormatJson { /** * Key for the JSON. */ key: string; /** * Value for the JSON. */ value: string; } interface GetVirtualNodeSpecServiceDiscovery { /** * AWS Cloud Map information for the virtual node. See `spec.service_discovery.aws_cloud_map` Block for details. */ awsCloudMaps: outputs.appmesh.GetVirtualNodeSpecServiceDiscoveryAwsCloudMap[]; /** * DNS service name for the virtual node. See `spec.service_discovery.dns` Block for details. */ dns: outputs.appmesh.GetVirtualNodeSpecServiceDiscoveryDn[]; } interface GetVirtualNodeSpecServiceDiscoveryAwsCloudMap { /** * String map that contains attributes with values that you can use to filter instances by any custom attribute that you specified when you registered the instance. */ attributes: { [key: string]: string; }; /** * Name of the AWS Cloud Map namespace to use. */ namespaceName: string; /** * Name of the AWS Cloud Map service to use. */ serviceName: string; } interface GetVirtualNodeSpecServiceDiscoveryDn { /** * DNS host name for your virtual node. */ hostname: string; /** * Preferred IP version that this virtual node uses. */ ipPreference: string; /** * DNS response type for the virtual node. */ responseType: string; } interface GetVirtualRouterSpec { listeners: outputs.appmesh.GetVirtualRouterSpecListener[]; } interface GetVirtualRouterSpecListener { portMappings: outputs.appmesh.GetVirtualRouterSpecListenerPortMapping[]; } interface GetVirtualRouterSpecListenerPortMapping { port: number; protocol: string; } interface GetVirtualServiceSpec { providers: outputs.appmesh.GetVirtualServiceSpecProvider[]; } interface GetVirtualServiceSpecProvider { virtualNodes: outputs.appmesh.GetVirtualServiceSpecProviderVirtualNode[]; virtualRouters: outputs.appmesh.GetVirtualServiceSpecProviderVirtualRouter[]; } interface GetVirtualServiceSpecProviderVirtualNode { virtualNodeName: string; } interface GetVirtualServiceSpecProviderVirtualRouter { virtualRouterName: string; } interface MeshSpec { /** * Egress filter rules for the service mesh. See `egressFilter` Block for details. */ egressFilter?: outputs.appmesh.MeshSpecEgressFilter; /** * Service discovery information for the service mesh. See `serviceDiscovery` Block for details. */ serviceDiscovery?: outputs.appmesh.MeshSpecServiceDiscovery; } interface MeshSpecEgressFilter { /** * Egress filter type. By default, the type is `DROP_ALL`. Valid values are `ALLOW_ALL` and `DROP_ALL`. */ type?: string; } interface MeshSpecServiceDiscovery { /** * IP version to use to control traffic within the mesh. Valid values are `IPv6_PREFERRED`, `IPv4_PREFERRED`, `IPv4_ONLY`, and `IPv6_ONLY`. */ ipPreference?: string; } interface RouteSpec { /** * GRPC routing information for the route. See `spec.grpc_route` Block for details. */ grpcRoute?: outputs.appmesh.RouteSpecGrpcRoute; /** * HTTP/2 routing information for the route. See `spec.http2_route` Block for details. */ http2Route?: outputs.appmesh.RouteSpecHttp2Route; /** * HTTP routing information for the route. See `spec.http_route` Block for details. */ httpRoute?: outputs.appmesh.RouteSpecHttpRoute; /** * Priority for the route, between `0` and `1000`. Routes are matched based on the specified value, where `0` is the highest priority. */ priority?: number; /** * TCP routing information for the route. See `spec.tcp_route` Block for details. */ tcpRoute?: outputs.appmesh.RouteSpecTcpRoute; } interface RouteSpecGrpcRoute { /** * Action to take if a match is determined. See `spec.tcp_route.action` Block for details. */ action: outputs.appmesh.RouteSpecGrpcRouteAction; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecGrpcRouteMatch; /** * Retry policy. See `spec.http_route.retry_policy` Block for details. */ retryPolicy?: outputs.appmesh.RouteSpecGrpcRouteRetryPolicy; /** * Types of timeouts. See `spec.tcp_route.timeout` Block for details. */ timeout?: outputs.appmesh.RouteSpecGrpcRouteTimeout; } interface RouteSpecGrpcRouteAction { /** * Targets that traffic is routed to when a request matches the route. You can specify one or more targets and their relative weights with which to distribute traffic. See `spec.tcp_route.action.weighted_target` Block for details. */ weightedTargets: outputs.appmesh.RouteSpecGrpcRouteActionWeightedTarget[]; } interface RouteSpecGrpcRouteActionWeightedTarget { /** * Port number to match from the request. */ port: number; /** * Virtual node to associate with the weighted target. Must be between 1 and 255 characters in length. */ virtualNode: string; /** * Relative weight of the weighted target. An integer between 0 and 100. */ weight: number; } interface RouteSpecGrpcRouteMatch { /** * Data to match from the gRPC request. See `spec.grpc_route.match.metadata` Block for details. */ metadatas?: outputs.appmesh.RouteSpecGrpcRouteMatchMetadata[]; /** * Method name to match from the request. If you specify a name, you must also specify a `serviceName`. */ methodName?: string; /** * Port number to match from the request. */ port?: number; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Fully qualified domain name for the service to match from the request. */ serviceName?: string; } interface RouteSpecGrpcRouteMatchMetadata { /** * Whether to match on the opposite of the `match` method and value. Default is `false`. */ invert?: boolean; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecGrpcRouteMatchMetadataMatch; /** * Name to use for the route. Must be between 1 and 255 characters in length. */ name: string; } interface RouteSpecGrpcRouteMatchMetadataMatch { /** * Exact query parameter to match on. */ exact?: string; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Object that specifies the range of numbers that the header value sent by the client must be included in. See `spec.http_route.match.header.match.range` Block for details. */ range?: outputs.appmesh.RouteSpecGrpcRouteMatchMetadataMatchRange; /** * Regex used to match the path. */ regex?: string; /** * Header value sent by the client must end with the specified characters. */ suffix?: string; } interface RouteSpecGrpcRouteMatchMetadataMatchRange { /** * End of the range. */ end: number; /** * Start of the range. */ start: number; } interface RouteSpecGrpcRouteRetryPolicy { /** * List of gRPC retry events. Valid values: `cancelled`, `deadline-exceeded`, `internal`, `resource-exhausted`, `unavailable`. */ grpcRetryEvents?: string[]; /** * List of HTTP retry events. Valid values: `client-error` (HTTP status code 409), `gateway-error` (HTTP status codes 502, 503, and 504), `server-error` (HTTP status codes 500, 501, 502, 503, 504, 505, 506, 507, 508, 510, and 511), `stream-error` (retry on refused stream). */ httpRetryEvents?: string[]; /** * Maximum number of retries. */ maxRetries: number; /** * Per-retry timeout. See `spec.http_route.retry_policy.per_retry_timeout` Block for details. */ perRetryTimeout: outputs.appmesh.RouteSpecGrpcRouteRetryPolicyPerRetryTimeout; /** * List of TCP retry events. The only valid value is `connection-error`. You must specify at least one value for `httpRetryEvents`, or at least one value for `tcpRetryEvents`. */ tcpRetryEvents?: string[]; } interface RouteSpecGrpcRouteRetryPolicyPerRetryTimeout { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecGrpcRouteTimeout { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.tcp_route.timeout.idle` Block for details. */ idle?: outputs.appmesh.RouteSpecGrpcRouteTimeoutIdle; /** * Per request timeout. See `spec.http_route.timeout.per_request` Block for details. */ perRequest?: outputs.appmesh.RouteSpecGrpcRouteTimeoutPerRequest; } interface RouteSpecGrpcRouteTimeoutIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecGrpcRouteTimeoutPerRequest { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecHttp2Route { /** * Action to take if a match is determined. See `spec.tcp_route.action` Block for details. */ action: outputs.appmesh.RouteSpecHttp2RouteAction; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match: outputs.appmesh.RouteSpecHttp2RouteMatch; /** * Retry policy. See `spec.http_route.retry_policy` Block for details. */ retryPolicy?: outputs.appmesh.RouteSpecHttp2RouteRetryPolicy; /** * Types of timeouts. See `spec.tcp_route.timeout` Block for details. */ timeout?: outputs.appmesh.RouteSpecHttp2RouteTimeout; } interface RouteSpecHttp2RouteAction { /** * Targets that traffic is routed to when a request matches the route. You can specify one or more targets and their relative weights with which to distribute traffic. See `spec.tcp_route.action.weighted_target` Block for details. */ weightedTargets: outputs.appmesh.RouteSpecHttp2RouteActionWeightedTarget[]; } interface RouteSpecHttp2RouteActionWeightedTarget { /** * Port number to match from the request. */ port: number; /** * Virtual node to associate with the weighted target. Must be between 1 and 255 characters in length. */ virtualNode: string; /** * Relative weight of the weighted target. An integer between 0 and 100. */ weight: number; } interface RouteSpecHttp2RouteMatch { /** * Client request headers to match on. See `spec.http_route.match.header` Block for details. */ headers?: outputs.appmesh.RouteSpecHttp2RouteMatchHeader[]; /** * Client request header method to match on. Valid values: `GET`, `HEAD`, `POST`, `PUT`, `DELETE`, `CONNECT`, `OPTIONS`, `TRACE`, `PATCH`. */ method?: string; /** * Client request path to match on. See `spec.http_route.match.path` Block for details. */ path?: outputs.appmesh.RouteSpecHttp2RouteMatchPath; /** * Port number to match from the request. */ port?: number; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Client request query parameters to match on. See `spec.http_route.match.query_parameter` Block for details. */ queryParameters?: outputs.appmesh.RouteSpecHttp2RouteMatchQueryParameter[]; /** * Client request header scheme to match on. Valid values: `http`, `https`. */ scheme?: string; } interface RouteSpecHttp2RouteMatchHeader { /** * Whether to match on the opposite of the `match` method and value. Default is `false`. */ invert?: boolean; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecHttp2RouteMatchHeaderMatch; /** * Name to use for the route. Must be between 1 and 255 characters in length. */ name: string; } interface RouteSpecHttp2RouteMatchHeaderMatch { /** * Exact query parameter to match on. */ exact?: string; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Object that specifies the range of numbers that the header value sent by the client must be included in. See `spec.http_route.match.header.match.range` Block for details. */ range?: outputs.appmesh.RouteSpecHttp2RouteMatchHeaderMatchRange; /** * Regex used to match the path. */ regex?: string; /** * Header value sent by the client must end with the specified characters. */ suffix?: string; } interface RouteSpecHttp2RouteMatchHeaderMatchRange { /** * End of the range. */ end: number; /** * Start of the range. */ start: number; } interface RouteSpecHttp2RouteMatchPath { /** * Exact query parameter to match on. */ exact?: string; /** * Regex used to match the path. */ regex?: string; } interface RouteSpecHttp2RouteMatchQueryParameter { /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecHttp2RouteMatchQueryParameterMatch; /** * Name to use for the route. Must be between 1 and 255 characters in length. */ name: string; } interface RouteSpecHttp2RouteMatchQueryParameterMatch { /** * Exact query parameter to match on. */ exact?: string; } interface RouteSpecHttp2RouteRetryPolicy { /** * List of HTTP retry events. Valid values: `client-error` (HTTP status code 409), `gateway-error` (HTTP status codes 502, 503, and 504), `server-error` (HTTP status codes 500, 501, 502, 503, 504, 505, 506, 507, 508, 510, and 511), `stream-error` (retry on refused stream). */ httpRetryEvents?: string[]; /** * Maximum number of retries. */ maxRetries: number; /** * Per-retry timeout. See `spec.http_route.retry_policy.per_retry_timeout` Block for details. */ perRetryTimeout: outputs.appmesh.RouteSpecHttp2RouteRetryPolicyPerRetryTimeout; /** * List of TCP retry events. The only valid value is `connection-error`. You must specify at least one value for `httpRetryEvents`, or at least one value for `tcpRetryEvents`. */ tcpRetryEvents?: string[]; } interface RouteSpecHttp2RouteRetryPolicyPerRetryTimeout { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecHttp2RouteTimeout { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.tcp_route.timeout.idle` Block for details. */ idle?: outputs.appmesh.RouteSpecHttp2RouteTimeoutIdle; /** * Per request timeout. See `spec.http_route.timeout.per_request` Block for details. */ perRequest?: outputs.appmesh.RouteSpecHttp2RouteTimeoutPerRequest; } interface RouteSpecHttp2RouteTimeoutIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecHttp2RouteTimeoutPerRequest { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecHttpRoute { /** * Action to take if a match is determined. See `spec.tcp_route.action` Block for details. */ action: outputs.appmesh.RouteSpecHttpRouteAction; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match: outputs.appmesh.RouteSpecHttpRouteMatch; /** * Retry policy. See `spec.http_route.retry_policy` Block for details. */ retryPolicy?: outputs.appmesh.RouteSpecHttpRouteRetryPolicy; /** * Types of timeouts. See `spec.tcp_route.timeout` Block for details. */ timeout?: outputs.appmesh.RouteSpecHttpRouteTimeout; } interface RouteSpecHttpRouteAction { /** * Targets that traffic is routed to when a request matches the route. You can specify one or more targets and their relative weights with which to distribute traffic. See `spec.tcp_route.action.weighted_target` Block for details. */ weightedTargets: outputs.appmesh.RouteSpecHttpRouteActionWeightedTarget[]; } interface RouteSpecHttpRouteActionWeightedTarget { /** * Port number to match from the request. */ port: number; /** * Virtual node to associate with the weighted target. Must be between 1 and 255 characters in length. */ virtualNode: string; /** * Relative weight of the weighted target. An integer between 0 and 100. */ weight: number; } interface RouteSpecHttpRouteMatch { /** * Client request headers to match on. See `spec.http_route.match.header` Block for details. */ headers?: outputs.appmesh.RouteSpecHttpRouteMatchHeader[]; /** * Client request header method to match on. Valid values: `GET`, `HEAD`, `POST`, `PUT`, `DELETE`, `CONNECT`, `OPTIONS`, `TRACE`, `PATCH`. */ method?: string; /** * Client request path to match on. See `spec.http_route.match.path` Block for details. */ path?: outputs.appmesh.RouteSpecHttpRouteMatchPath; /** * Port number to match from the request. */ port?: number; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Client request query parameters to match on. See `spec.http_route.match.query_parameter` Block for details. */ queryParameters?: outputs.appmesh.RouteSpecHttpRouteMatchQueryParameter[]; /** * Client request header scheme to match on. Valid values: `http`, `https`. */ scheme?: string; } interface RouteSpecHttpRouteMatchHeader { /** * Whether to match on the opposite of the `match` method and value. Default is `false`. */ invert?: boolean; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecHttpRouteMatchHeaderMatch; /** * Name to use for the route. Must be between 1 and 255 characters in length. */ name: string; } interface RouteSpecHttpRouteMatchHeaderMatch { /** * Exact query parameter to match on. */ exact?: string; /** * Header value sent by the client must begin with the specified characters. */ prefix?: string; /** * Object that specifies the range of numbers that the header value sent by the client must be included in. See `spec.http_route.match.header.match.range` Block for details. */ range?: outputs.appmesh.RouteSpecHttpRouteMatchHeaderMatchRange; /** * Regex used to match the path. */ regex?: string; /** * Header value sent by the client must end with the specified characters. */ suffix?: string; } interface RouteSpecHttpRouteMatchHeaderMatchRange { /** * End of the range. */ end: number; /** * Start of the range. */ start: number; } interface RouteSpecHttpRouteMatchPath { /** * Exact query parameter to match on. */ exact?: string; /** * Regex used to match the path. */ regex?: string; } interface RouteSpecHttpRouteMatchQueryParameter { /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecHttpRouteMatchQueryParameterMatch; /** * Name to use for the route. Must be between 1 and 255 characters in length. */ name: string; } interface RouteSpecHttpRouteMatchQueryParameterMatch { /** * Exact query parameter to match on. */ exact?: string; } interface RouteSpecHttpRouteRetryPolicy { /** * List of HTTP retry events. Valid values: `client-error` (HTTP status code 409), `gateway-error` (HTTP status codes 502, 503, and 504), `server-error` (HTTP status codes 500, 501, 502, 503, 504, 505, 506, 507, 508, 510, and 511), `stream-error` (retry on refused stream). */ httpRetryEvents?: string[]; /** * Maximum number of retries. */ maxRetries: number; /** * Per-retry timeout. See `spec.http_route.retry_policy.per_retry_timeout` Block for details. */ perRetryTimeout: outputs.appmesh.RouteSpecHttpRouteRetryPolicyPerRetryTimeout; /** * List of TCP retry events. The only valid value is `connection-error`. You must specify at least one value for `httpRetryEvents`, or at least one value for `tcpRetryEvents`. */ tcpRetryEvents?: string[]; } interface RouteSpecHttpRouteRetryPolicyPerRetryTimeout { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecHttpRouteTimeout { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.tcp_route.timeout.idle` Block for details. */ idle?: outputs.appmesh.RouteSpecHttpRouteTimeoutIdle; /** * Per request timeout. See `spec.http_route.timeout.per_request` Block for details. */ perRequest?: outputs.appmesh.RouteSpecHttpRouteTimeoutPerRequest; } interface RouteSpecHttpRouteTimeoutIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecHttpRouteTimeoutPerRequest { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface RouteSpecTcpRoute { /** * Action to take if a match is determined. See `spec.tcp_route.action` Block for details. */ action: outputs.appmesh.RouteSpecTcpRouteAction; /** * Criteria for determining a TCP request match. See `spec.tcp_route.match` Block for details. */ match?: outputs.appmesh.RouteSpecTcpRouteMatch; /** * Types of timeouts. See `spec.tcp_route.timeout` Block for details. */ timeout?: outputs.appmesh.RouteSpecTcpRouteTimeout; } interface RouteSpecTcpRouteAction { /** * Targets that traffic is routed to when a request matches the route. You can specify one or more targets and their relative weights with which to distribute traffic. See `spec.tcp_route.action.weighted_target` Block for details. */ weightedTargets: outputs.appmesh.RouteSpecTcpRouteActionWeightedTarget[]; } interface RouteSpecTcpRouteActionWeightedTarget { /** * Port number to match from the request. */ port: number; /** * Virtual node to associate with the weighted target. Must be between 1 and 255 characters in length. */ virtualNode: string; /** * Relative weight of the weighted target. An integer between 0 and 100. */ weight: number; } interface RouteSpecTcpRouteMatch { /** * Port number to match from the request. */ port?: number; } interface RouteSpecTcpRouteTimeout { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.tcp_route.timeout.idle` Block for details. */ idle?: outputs.appmesh.RouteSpecTcpRouteTimeoutIdle; } interface RouteSpecTcpRouteTimeoutIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Number of time units. Minimum value of `0`. */ value: number; } interface VirtualGatewaySpec { /** * Defaults for backends. See `backendDefaults` Block for details. */ backendDefaults?: outputs.appmesh.VirtualGatewaySpecBackendDefaults; /** * Listeners that the mesh endpoint is expected to receive inbound traffic from. You can specify one listener. See `listener` Block for details. */ listeners: outputs.appmesh.VirtualGatewaySpecListener[]; /** * Inbound and outbound access logging information for the virtual gateway. See `logging` Block for details. */ logging?: outputs.appmesh.VirtualGatewaySpecLogging; } interface VirtualGatewaySpecBackendDefaults { /** * Default client policy for virtual gateway backends. See `clientPolicy` Block for details. */ clientPolicy?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicy; } interface VirtualGatewaySpecBackendDefaultsClientPolicy { /** * TLS client policy. See `spec.backend_defaults.client_policy.tls` Block for details. */ tls?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTls; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTls { /** * Listener's TLS certificate. */ certificate?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsCertificate; /** * Whether the policy is enforced. Default is `true`. */ enforce?: boolean; /** * One or more ports that the policy is enforced for. */ ports?: number[]; /** * Listener's TLS validation context. */ validation: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidation; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsCertificate { file?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsCertificateFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. */ sds?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsCertificateSds; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ privateKey: string; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsCertificateSds { /** * Name of the secret for a virtual gateway's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidation { /** * SANs for a virtual gateway's listener's TLS validation context. */ subjectAlternativeNames?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNames; /** * TLS validation context trust. */ trust: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrust; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNames { /** * Criteria for determining a SAN's match. */ match: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNamesMatch; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNamesMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrust { /** * AWS Certificate Manager (ACM) certificate. */ acm?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrustAcm; file?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrustFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. */ sds?: outputs.appmesh.VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrustSds; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrustAcm { /** * One or more ACM ARNs. */ certificateAuthorityArns: string[]; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; } interface VirtualGatewaySpecBackendDefaultsClientPolicyTlsValidationTrustSds { /** * Name of the secret for a virtual gateway's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualGatewaySpecListener { /** * Connection pool information for the listener. See `connectionPool` Block for details. */ connectionPool?: outputs.appmesh.VirtualGatewaySpecListenerConnectionPool; /** * Health check information for the listener. See `healthCheck` Block for details. */ healthCheck?: outputs.appmesh.VirtualGatewaySpecListenerHealthCheck; /** * Port mapping information for the listener. See `portMapping` Block for details. */ portMapping: outputs.appmesh.VirtualGatewaySpecListenerPortMapping; /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls?: outputs.appmesh.VirtualGatewaySpecListenerTls; } interface VirtualGatewaySpecListenerConnectionPool { /** * Connection pool information for gRPC listeners. See `grpc` Block for details. */ grpc?: outputs.appmesh.VirtualGatewaySpecListenerConnectionPoolGrpc; /** * Connection pool information for HTTP listeners. See `http` Block for details. */ http?: outputs.appmesh.VirtualGatewaySpecListenerConnectionPoolHttp; /** * Connection pool information for HTTP2 listeners. See `http2` Block for details. */ http2?: outputs.appmesh.VirtualGatewaySpecListenerConnectionPoolHttp2; } interface VirtualGatewaySpecListenerConnectionPoolGrpc { /** * Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster. Minimum value of `1`. */ maxRequests: number; } interface VirtualGatewaySpecListenerConnectionPoolHttp { /** * Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster. Minimum value of `1`. */ maxConnections: number; /** * Number of overflowing requests after `maxConnections` Envoy will queue to upstream cluster. Minimum value of `1`. */ maxPendingRequests?: number; } interface VirtualGatewaySpecListenerConnectionPoolHttp2 { /** * Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster. Minimum value of `1`. */ maxRequests: number; } interface VirtualGatewaySpecListenerHealthCheck { /** * Number of consecutive successful health checks that must occur before declaring listener healthy. */ healthyThreshold: number; /** * Time period in milliseconds between each health check execution. */ intervalMillis: number; /** * Destination path for the health check request. This is only required if the specified protocol is `http` or `http2`. */ path?: string; /** * Destination port for the health check request. This port must match the port defined in the `portMapping` for the listener. */ port: number; /** * Protocol for the health check request. Valid values are `http`, `http2`, and `grpc`. */ protocol: string; /** * Amount of time to wait when receiving a response from the health check, in milliseconds. */ timeoutMillis: number; /** * Number of consecutive failed health checks that must occur before declaring a virtual gateway unhealthy. */ unhealthyThreshold: number; } interface VirtualGatewaySpecListenerPortMapping { /** * Port used for the port mapping. */ port: number; /** * Protocol used for the port mapping. Valid values are `http`, `http2`, `tcp` and `grpc`. */ protocol: string; } interface VirtualGatewaySpecListenerTls { /** * Listener's TLS certificate. */ certificate: outputs.appmesh.VirtualGatewaySpecListenerTlsCertificate; /** * Listener's TLS mode. Valid values: `DISABLED`, `PERMISSIVE`, `STRICT`. */ mode: string; /** * Listener's TLS validation context. */ validation?: outputs.appmesh.VirtualGatewaySpecListenerTlsValidation; } interface VirtualGatewaySpecListenerTlsCertificate { /** * AWS Certificate Manager (ACM) certificate. */ acm?: outputs.appmesh.VirtualGatewaySpecListenerTlsCertificateAcm; file?: outputs.appmesh.VirtualGatewaySpecListenerTlsCertificateFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. */ sds?: outputs.appmesh.VirtualGatewaySpecListenerTlsCertificateSds; } interface VirtualGatewaySpecListenerTlsCertificateAcm { /** * ARN for the certificate. */ certificateArn: string; } interface VirtualGatewaySpecListenerTlsCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ privateKey: string; } interface VirtualGatewaySpecListenerTlsCertificateSds { /** * Name of the secret for a virtual gateway's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualGatewaySpecListenerTlsValidation { /** * SANs for a virtual gateway's listener's TLS validation context. */ subjectAlternativeNames?: outputs.appmesh.VirtualGatewaySpecListenerTlsValidationSubjectAlternativeNames; /** * TLS validation context trust. */ trust: outputs.appmesh.VirtualGatewaySpecListenerTlsValidationTrust; } interface VirtualGatewaySpecListenerTlsValidationSubjectAlternativeNames { /** * Criteria for determining a SAN's match. */ match: outputs.appmesh.VirtualGatewaySpecListenerTlsValidationSubjectAlternativeNamesMatch; } interface VirtualGatewaySpecListenerTlsValidationSubjectAlternativeNamesMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface VirtualGatewaySpecListenerTlsValidationTrust { file?: outputs.appmesh.VirtualGatewaySpecListenerTlsValidationTrustFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. */ sds?: outputs.appmesh.VirtualGatewaySpecListenerTlsValidationTrustSds; } interface VirtualGatewaySpecListenerTlsValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; } interface VirtualGatewaySpecListenerTlsValidationTrustSds { /** * Name of the secret for a virtual gateway's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualGatewaySpecLogging { /** * Access log configuration for a virtual gateway. See `accessLog` Block for details. */ accessLog?: outputs.appmesh.VirtualGatewaySpecLoggingAccessLog; } interface VirtualGatewaySpecLoggingAccessLog { /** * File object to send virtual gateway access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualGatewaySpecLoggingAccessLogFile; } interface VirtualGatewaySpecLoggingAccessLogFile { /** * Specified format for the logs. See `format` Block for details. */ format?: outputs.appmesh.VirtualGatewaySpecLoggingAccessLogFileFormat; path: string; } interface VirtualGatewaySpecLoggingAccessLogFileFormat { /** * Logging format for JSON. See `json` Block for details. */ jsons?: outputs.appmesh.VirtualGatewaySpecLoggingAccessLogFileFormatJson[]; /** * Logging format for text. Must be between 1 and 1000 characters in length. */ text?: string; } interface VirtualGatewaySpecLoggingAccessLogFileFormatJson { /** * Specified key for the JSON. Must be between 1 and 100 characters in length. */ key: string; /** * Specified value for the JSON. Must be between 1 and 100 characters in length. */ value: string; } interface VirtualNodeSpec { /** * Defaults for backends. See `spec.backend_defaults` Block for details. */ backendDefaults?: outputs.appmesh.VirtualNodeSpecBackendDefaults; /** * Backends to which the virtual node is expected to send outbound traffic. See `spec.backend` Block for details. */ backends?: outputs.appmesh.VirtualNodeSpecBackend[]; /** * Listeners from which the virtual node is expected to receive inbound traffic. See `spec.listener` Block for details. */ listeners?: outputs.appmesh.VirtualNodeSpecListener[]; /** * Inbound and outbound access logging information for the virtual node. See `spec.logging` Block for details. */ logging?: outputs.appmesh.VirtualNodeSpecLogging; /** * Service discovery information for the virtual node. See `spec.service_discovery` Block for details. */ serviceDiscovery?: outputs.appmesh.VirtualNodeSpecServiceDiscovery; } interface VirtualNodeSpecBackend { /** * Virtual service to use as a backend for a virtual node. See `spec.backend.virtual_service` Block for details. */ virtualService: outputs.appmesh.VirtualNodeSpecBackendVirtualService; } interface VirtualNodeSpecBackendDefaults { /** * Default client policy for virtual service backends. See `spec.backend_defaults.client_policy` Block for details. */ clientPolicy?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicy; } interface VirtualNodeSpecBackendDefaultsClientPolicy { /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTls; } interface VirtualNodeSpecBackendDefaultsClientPolicyTls { /** * Listener's TLS certificate. See `spec.listener.tls.certificate` Block for details. */ certificate?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsCertificate; /** * Whether the policy is enforced. Default is `true`. */ enforce?: boolean; /** * One or more ports that the policy is enforced for. */ ports?: number[]; /** * Listener's TLS validation context. See `spec.listener.tls.validation` Block for details. */ validation: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidation; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsCertificate { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsCertificateFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsCertificateSds; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the virtual node that the proxy is running on. Must be between 1 and 255 characters in length. */ privateKey: string; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsCertificateSds { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidation { /** * SANs for a TLS validation context. See `spec.listener.tls.validation.subject_alternative_names` Block for details. */ subjectAlternativeNames?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNames; /** * TLS validation context trust. See `spec.listener.tls.validation.trust` Block for details. */ trust: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrust; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNames { /** * Criteria for determining a SAN's match. See `spec.listener.tls.validation.subject_alternative_names.match` Block for details. */ match: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNamesMatch; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationSubjectAlternativeNamesMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrust { /** * AWS Certificate Manager (ACM) certificate. See `spec.listener.tls.certificate.acm` Block for details. */ acm?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrustAcm; /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrustFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds?: outputs.appmesh.VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrustSds; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrustAcm { /** * One or more ACM ARNs. */ certificateAuthorityArns: string[]; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; } interface VirtualNodeSpecBackendDefaultsClientPolicyTlsValidationTrustSds { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualNodeSpecBackendVirtualService { /** * Default client policy for virtual service backends. See `spec.backend_defaults.client_policy` Block for details. */ clientPolicy?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicy; /** * Name of the virtual service that is acting as a virtual node backend. Must be between 1 and 255 characters in length. */ virtualServiceName: string; } interface VirtualNodeSpecBackendVirtualServiceClientPolicy { /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTls; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTls { /** * Listener's TLS certificate. See `spec.listener.tls.certificate` Block for details. */ certificate?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsCertificate; /** * Whether the policy is enforced. Default is `true`. */ enforce?: boolean; /** * One or more ports that the policy is enforced for. */ ports?: number[]; /** * Listener's TLS validation context. See `spec.listener.tls.validation` Block for details. */ validation: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidation; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsCertificate { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsCertificateFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsCertificateSds; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the virtual node that the proxy is running on. Must be between 1 and 255 characters in length. */ privateKey: string; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsCertificateSds { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidation { /** * SANs for a TLS validation context. See `spec.listener.tls.validation.subject_alternative_names` Block for details. */ subjectAlternativeNames?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationSubjectAlternativeNames; /** * TLS validation context trust. See `spec.listener.tls.validation.trust` Block for details. */ trust: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrust; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationSubjectAlternativeNames { /** * Criteria for determining a SAN's match. See `spec.listener.tls.validation.subject_alternative_names.match` Block for details. */ match: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationSubjectAlternativeNamesMatch; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationSubjectAlternativeNamesMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrust { /** * AWS Certificate Manager (ACM) certificate. See `spec.listener.tls.certificate.acm` Block for details. */ acm?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrustAcm; /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrustFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds?: outputs.appmesh.VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrustSds; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrustAcm { /** * One or more ACM ARNs. */ certificateAuthorityArns: string[]; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; } interface VirtualNodeSpecBackendVirtualServiceClientPolicyTlsValidationTrustSds { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualNodeSpecListener { /** * Connection pool information for the listener. See `spec.listener.connection_pool` Block for details. */ connectionPool?: outputs.appmesh.VirtualNodeSpecListenerConnectionPool; /** * Health check information for the listener. See `spec.listener.health_check` Block for details. */ healthCheck?: outputs.appmesh.VirtualNodeSpecListenerHealthCheck; /** * Outlier detection information for the listener. See `spec.listener.outlier_detection` Block for details. */ outlierDetection?: outputs.appmesh.VirtualNodeSpecListenerOutlierDetection; /** * Port mapping information for the listener. See `spec.listener.port_mapping` Block for details. */ portMapping: outputs.appmesh.VirtualNodeSpecListenerPortMapping; /** * Timeouts for different protocols. See `spec.listener.timeout` Block for details. */ timeout?: outputs.appmesh.VirtualNodeSpecListenerTimeout; /** * TLS properties for the listener. See `spec.listener.tls` Block for details. */ tls?: outputs.appmesh.VirtualNodeSpecListenerTls; } interface VirtualNodeSpecListenerConnectionPool { /** * Timeouts for gRPC listeners. See `spec.listener.timeout.grpc` Block for details. */ grpc?: outputs.appmesh.VirtualNodeSpecListenerConnectionPoolGrpc; /** * Timeouts for HTTP2 listeners. See `spec.listener.timeout.http2` Block for details. */ http2s?: outputs.appmesh.VirtualNodeSpecListenerConnectionPoolHttp2[]; /** * Timeouts for HTTP listeners. See `spec.listener.timeout.http` Block for details. */ https?: outputs.appmesh.VirtualNodeSpecListenerConnectionPoolHttp[]; /** * Timeouts for TCP listeners. See `spec.listener.timeout.tcp` Block for details. */ tcps?: outputs.appmesh.VirtualNodeSpecListenerConnectionPoolTcp[]; } interface VirtualNodeSpecListenerConnectionPoolGrpc { /** * Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster. Minimum value of `1`. */ maxRequests: number; } interface VirtualNodeSpecListenerConnectionPoolHttp { /** * Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster. Minimum value of `1`. */ maxConnections: number; /** * Number of overflowing requests after `maxConnections` Envoy will queue to upstream cluster. Minimum value of `1`. */ maxPendingRequests?: number; } interface VirtualNodeSpecListenerConnectionPoolHttp2 { /** * Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster. Minimum value of `1`. */ maxRequests: number; } interface VirtualNodeSpecListenerConnectionPoolTcp { /** * Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster. Minimum value of `1`. */ maxConnections: number; } interface VirtualNodeSpecListenerHealthCheck { /** * Number of consecutive successful health checks that must occur before declaring listener healthy. */ healthyThreshold: number; /** * Time period in milliseconds between each health check execution. */ intervalMillis: number; /** * File path to write access logs to. You can use `/dev/stdout` to send access logs to standard out. Must be between 1 and 255 characters in length. */ path?: string; /** * Port used for the port mapping. */ port: number; /** * Protocol used for the port mapping. Valid values are `http`, `http2`, `tcp` and `grpc`. */ protocol: string; /** * Amount of time to wait when receiving a response from the health check, in milliseconds. */ timeoutMillis: number; /** * Number of consecutive failed health checks that must occur before declaring a virtual node unhealthy. */ unhealthyThreshold: number; } interface VirtualNodeSpecListenerOutlierDetection { /** * Base amount of time for which a host is ejected. See `spec.listener.outlier_detection.base_ejection_duration` Block for details. */ baseEjectionDuration: outputs.appmesh.VirtualNodeSpecListenerOutlierDetectionBaseEjectionDuration; /** * Time interval between ejection sweep analysis. See `spec.listener.outlier_detection.interval` Block for details. */ interval: outputs.appmesh.VirtualNodeSpecListenerOutlierDetectionInterval; /** * Maximum percentage of hosts in load balancing pool for upstream service that can be ejected. Will eject at least one host regardless of the value. Minimum value of `0`. Maximum value of `100`. */ maxEjectionPercent: number; /** * Number of consecutive `5xx` errors required for ejection. Minimum value of `1`. */ maxServerErrors: number; } interface VirtualNodeSpecListenerOutlierDetectionBaseEjectionDuration { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerOutlierDetectionInterval { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerPortMapping { /** * Port used for the port mapping. */ port: number; /** * Protocol used for the port mapping. Valid values are `http`, `http2`, `tcp` and `grpc`. */ protocol: string; } interface VirtualNodeSpecListenerTimeout { /** * Timeouts for gRPC listeners. See `spec.listener.timeout.grpc` Block for details. */ grpc?: outputs.appmesh.VirtualNodeSpecListenerTimeoutGrpc; /** * Timeouts for HTTP listeners. See `spec.listener.timeout.http` Block for details. */ http?: outputs.appmesh.VirtualNodeSpecListenerTimeoutHttp; /** * Timeouts for HTTP2 listeners. See `spec.listener.timeout.http2` Block for details. */ http2?: outputs.appmesh.VirtualNodeSpecListenerTimeoutHttp2; /** * Timeouts for TCP listeners. See `spec.listener.timeout.tcp` Block for details. */ tcp?: outputs.appmesh.VirtualNodeSpecListenerTimeoutTcp; } interface VirtualNodeSpecListenerTimeoutGrpc { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.listener.timeout.tcp.idle` Block for details. */ idle?: outputs.appmesh.VirtualNodeSpecListenerTimeoutGrpcIdle; /** * Per request timeout. See `spec.listener.timeout.http2.per_request` Block for details. */ perRequest?: outputs.appmesh.VirtualNodeSpecListenerTimeoutGrpcPerRequest; } interface VirtualNodeSpecListenerTimeoutGrpcIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTimeoutGrpcPerRequest { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTimeoutHttp { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.listener.timeout.tcp.idle` Block for details. */ idle?: outputs.appmesh.VirtualNodeSpecListenerTimeoutHttpIdle; /** * Per request timeout. See `spec.listener.timeout.http2.per_request` Block for details. */ perRequest?: outputs.appmesh.VirtualNodeSpecListenerTimeoutHttpPerRequest; } interface VirtualNodeSpecListenerTimeoutHttp2 { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.listener.timeout.tcp.idle` Block for details. */ idle?: outputs.appmesh.VirtualNodeSpecListenerTimeoutHttp2Idle; /** * Per request timeout. See `spec.listener.timeout.http2.per_request` Block for details. */ perRequest?: outputs.appmesh.VirtualNodeSpecListenerTimeoutHttp2PerRequest; } interface VirtualNodeSpecListenerTimeoutHttp2Idle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTimeoutHttp2PerRequest { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTimeoutHttpIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTimeoutHttpPerRequest { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTimeoutTcp { /** * Idle timeout. An idle timeout bounds the amount of time that a connection may be idle. See `spec.listener.timeout.tcp.idle` Block for details. */ idle?: outputs.appmesh.VirtualNodeSpecListenerTimeoutTcpIdle; } interface VirtualNodeSpecListenerTimeoutTcpIdle { /** * Unit of time. Valid values: `ms`, `s`. */ unit: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: number; } interface VirtualNodeSpecListenerTls { /** * Listener's TLS certificate. See `spec.listener.tls.certificate` Block for details. */ certificate: outputs.appmesh.VirtualNodeSpecListenerTlsCertificate; /** * Listener's TLS mode. Valid values: `DISABLED`, `PERMISSIVE`, `STRICT`. */ mode: string; /** * Listener's TLS validation context. See `spec.listener.tls.validation` Block for details. */ validation?: outputs.appmesh.VirtualNodeSpecListenerTlsValidation; } interface VirtualNodeSpecListenerTlsCertificate { /** * AWS Certificate Manager (ACM) certificate. See `spec.listener.tls.certificate.acm` Block for details. */ acm?: outputs.appmesh.VirtualNodeSpecListenerTlsCertificateAcm; /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecListenerTlsCertificateFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds?: outputs.appmesh.VirtualNodeSpecListenerTlsCertificateSds; } interface VirtualNodeSpecListenerTlsCertificateAcm { /** * ARN for the certificate. */ certificateArn: string; } interface VirtualNodeSpecListenerTlsCertificateFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; /** * Private key for a certificate stored on the file system of the virtual node that the proxy is running on. Must be between 1 and 255 characters in length. */ privateKey: string; } interface VirtualNodeSpecListenerTlsCertificateSds { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualNodeSpecListenerTlsValidation { /** * SANs for a TLS validation context. See `spec.listener.tls.validation.subject_alternative_names` Block for details. */ subjectAlternativeNames?: outputs.appmesh.VirtualNodeSpecListenerTlsValidationSubjectAlternativeNames; /** * TLS validation context trust. See `spec.listener.tls.validation.trust` Block for details. */ trust: outputs.appmesh.VirtualNodeSpecListenerTlsValidationTrust; } interface VirtualNodeSpecListenerTlsValidationSubjectAlternativeNames { /** * Criteria for determining a SAN's match. See `spec.listener.tls.validation.subject_alternative_names.match` Block for details. */ match: outputs.appmesh.VirtualNodeSpecListenerTlsValidationSubjectAlternativeNamesMatch; } interface VirtualNodeSpecListenerTlsValidationSubjectAlternativeNamesMatch { /** * Values sent must match the specified values exactly. */ exacts: string[]; } interface VirtualNodeSpecListenerTlsValidationTrust { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecListenerTlsValidationTrustFile; /** * TLS validation context trust for a [Secret Discovery Service](https://www.envoyproxy.io/docs/envoy/latest/configuration/security/secret#secret-discovery-service-sds) certificate. See `spec.listener.tls.validation.trust.sds` Block for details. */ sds?: outputs.appmesh.VirtualNodeSpecListenerTlsValidationTrustSds; } interface VirtualNodeSpecListenerTlsValidationTrustFile { /** * Certificate trust chain for a certificate stored on the file system of the mesh endpoint that the proxy is running on. Must be between 1 and 255 characters in length. */ certificateChain: string; } interface VirtualNodeSpecListenerTlsValidationTrustSds { /** * Name of the secret for a virtual node's TLS Secret Discovery Service validation context trust. */ secretName: string; } interface VirtualNodeSpecLogging { /** * Access log configuration for a virtual node. See `spec.logging.access_log` Block for details. */ accessLog?: outputs.appmesh.VirtualNodeSpecLoggingAccessLog; } interface VirtualNodeSpecLoggingAccessLog { /** * File object to send virtual node access logs to. See `spec.logging.access_log.file` Block for details. */ file?: outputs.appmesh.VirtualNodeSpecLoggingAccessLogFile; } interface VirtualNodeSpecLoggingAccessLogFile { /** * Format for the logs. See `spec.logging.access_log.file.format` Block for details. */ format?: outputs.appmesh.VirtualNodeSpecLoggingAccessLogFileFormat; /** * File path to write access logs to. You can use `/dev/stdout` to send access logs to standard out. Must be between 1 and 255 characters in length. */ path: string; } interface VirtualNodeSpecLoggingAccessLogFileFormat { /** * Logging format for JSON. See `spec.logging.access_log.file.format.json` Block for details. */ jsons?: outputs.appmesh.VirtualNodeSpecLoggingAccessLogFileFormatJson[]; /** * Logging format for text. Must be between 1 and 1000 characters in length. */ text?: string; } interface VirtualNodeSpecLoggingAccessLogFileFormatJson { /** * Key for the JSON. Must be between 1 and 100 characters in length. */ key: string; /** * Value for the JSON. Must be between 1 and 100 characters in length. */ value: string; } interface VirtualNodeSpecServiceDiscovery { /** * Any AWS Cloud Map information for the virtual node. See `spec.service_discovery.aws_cloud_map` Block for details. */ awsCloudMap?: outputs.appmesh.VirtualNodeSpecServiceDiscoveryAwsCloudMap; /** * DNS service name for the virtual node. See `spec.service_discovery.dns` Block for details. */ dns?: outputs.appmesh.VirtualNodeSpecServiceDiscoveryDns; } interface VirtualNodeSpecServiceDiscoveryAwsCloudMap { /** * String map that contains attributes with values that you can use to filter instances by any custom attribute that you specified when you registered the instance. Only instances that match all of the specified key/value pairs will be returned. */ attributes?: { [key: string]: string; }; /** * Name of the AWS Cloud Map namespace to use. Use the `aws.servicediscovery.HttpNamespace` resource to configure a Cloud Map namespace. Must be between 1 and 1024 characters in length. */ namespaceName: string; /** * Name of the AWS Cloud Map service to use. Use the `aws.servicediscovery.Service` resource to configure a Cloud Map service. Must be between 1 and 1024 characters in length. */ serviceName: string; } interface VirtualNodeSpecServiceDiscoveryDns { /** * DNS host name for your virtual node. */ hostname: string; /** * Preferred IP version that this virtual node uses. Valid values: `IPv6_PREFERRED`, `IPv4_PREFERRED`, `IPv4_ONLY`, `IPv6_ONLY`. */ ipPreference?: string; /** * DNS response type for the virtual node. Valid values: `LOADBALANCER`, `ENDPOINTS`. */ responseType?: string; } interface VirtualRouterSpec { /** * Listeners that the virtual router is expected to receive inbound traffic from. Currently only one listener is supported per virtual router. See `listener` Block for details. */ listeners?: outputs.appmesh.VirtualRouterSpecListener[]; } interface VirtualRouterSpecListener { /** * Port mapping information for the listener. See `portMapping` Block for details. */ portMapping: outputs.appmesh.VirtualRouterSpecListenerPortMapping; } interface VirtualRouterSpecListenerPortMapping { /** * Port used for the port mapping. */ port: number; /** * Protocol used for the port mapping. Valid values are `http`,`http2`, `tcp` and `grpc`. */ protocol: string; } interface VirtualServiceSpec { /** * App Mesh object that is acting as the provider for a virtual service. You can specify a single virtual node or virtual router. See `provider` Block for details. */ provider?: outputs.appmesh.VirtualServiceSpecProvider; } interface VirtualServiceSpecProvider { /** * Virtual node associated with a virtual service. See `virtualNode` Block for details. */ virtualNode?: outputs.appmesh.VirtualServiceSpecProviderVirtualNode; /** * Virtual router associated with a virtual service. See `virtualRouter` Block for details. */ virtualRouter?: outputs.appmesh.VirtualServiceSpecProviderVirtualRouter; } interface VirtualServiceSpecProviderVirtualNode { /** * Name of the virtual node that is acting as a service provider. Must be between 1 and 255 characters in length. */ virtualNodeName: string; } interface VirtualServiceSpecProviderVirtualRouter { /** * Name of the virtual router that is acting as a service provider. Must be between 1 and 255 characters in length. */ virtualRouterName: string; } } export declare namespace apprunner { interface CustomDomainAssociationCertificateValidationRecord { /** * Certificate CNAME record name. */ name: string; /** * Current state of the certificate CNAME record validation. It should change to `SUCCESS` after App Runner completes validation with your DNS. */ status: string; /** * Record type, always `CNAME`. */ type: string; /** * Certificate CNAME record value. */ value: string; } interface DeploymentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface ObservabilityConfigurationTraceConfiguration { /** * Implementation provider chosen for tracing App Runner services. Valid values: `AWSXRAY`. */ vendor?: string; } interface ServiceEncryptionConfiguration { /** * ARN of the KMS key used for encryption. */ kmsKey: string; } interface ServiceHealthCheckConfiguration { /** * Number of consecutive checks that must succeed before App Runner decides that the service is healthy. Defaults to 1. Minimum value of 1. Maximum value of 20. */ healthyThreshold?: number; /** * Time interval, in seconds, between health checks. Defaults to 5. Minimum value of 1. Maximum value of 20. */ interval?: number; /** * URL to send requests to for health checks. Defaults to `/`. Minimum length of 0. Maximum length of 51200. */ path?: string; /** * IP protocol that App Runner uses to perform health checks for your service. Valid values: `TCP`, `HTTP`. Defaults to `TCP`. If you set protocol to `HTTP`, App Runner sends health check requests to the HTTP path specified by `path`. */ protocol?: string; /** * Time, in seconds, to wait for a health check response before deciding it failed. Defaults to 2. Minimum value of 1. Maximum value of 20. */ timeout?: number; /** * Number of consecutive checks that must fail before App Runner decides that the service is unhealthy. Defaults to 5. Minimum value of 1. Maximum value of 20. */ unhealthyThreshold?: number; } interface ServiceInstanceConfiguration { /** * Number of CPU units reserved for each instance of your App Runner service represented as a String. Defaults to `1024`. Valid values: `256|512|1024|2048|4096|(0.25|0.5|1|2|4) vCPU`. */ cpu?: string; /** * ARN of an IAM role that provides permissions to your App Runner service. These are permissions that your code needs when it calls any AWS APIs. */ instanceRoleArn?: string; /** * Amount of memory, in MB or GB, reserved for each instance of your App Runner service. Defaults to `2048`. Valid values: `512|1024|2048|3072|4096|6144|8192|10240|12288|(0.5|1|2|3|4|6|8|10|12) GB`. */ memory?: string; } interface ServiceNetworkConfiguration { /** * Network configuration settings for outbound message traffic. See `egressConfiguration` below. */ egressConfiguration: outputs.apprunner.ServiceNetworkConfigurationEgressConfiguration; /** * Network configuration settings for inbound network traffic. See `ingressConfiguration` below. */ ingressConfiguration: outputs.apprunner.ServiceNetworkConfigurationIngressConfiguration; /** * App Runner provides you with the option to choose between IP version 4 (IPv4) and dual stack (IPv4 and IPv6) for your incoming public network configuration. Valid values: `IPV4`, `DUAL_STACK`. Default: `IPV4`. */ ipAddressType?: string; } interface ServiceNetworkConfigurationEgressConfiguration { /** * Type of egress configuration. Valid values are: `DEFAULT` and `VPC`. */ egressType: string; /** * ARN of the App Runner VPC connector that you want to associate with your App Runner service. Only valid when `EgressType = VPC`. */ vpcConnectorArn?: string; } interface ServiceNetworkConfigurationIngressConfiguration { /** * Whether your App Runner service is publicly accessible. To make the service publicly accessible set it to `true`. To make the service privately accessible, from only within an Amazon VPC, set it to `false`. */ isPubliclyAccessible?: boolean; } interface ServiceObservabilityConfiguration { /** * ARN of the observability configuration that is associated with the service. Specified only when `observabilityEnabled` is `true`. */ observabilityConfigurationArn?: string; /** * When `true`, an observability configuration resource is associated with the service. */ observabilityEnabled: boolean; } interface ServiceSourceConfiguration { /** * Configuration for resources needed to authenticate access to some source repositories. See `authenticationConfiguration` below. */ authenticationConfiguration?: outputs.apprunner.ServiceSourceConfigurationAuthenticationConfiguration; /** * Whether continuous integration from the source repository is enabled for the App Runner service. If set to `true`, each repository change (source code commit or new image version) starts a deployment. Defaults to `true`. */ autoDeploymentsEnabled?: boolean; /** * Description of a source code repository. See `codeRepository` below. */ codeRepository?: outputs.apprunner.ServiceSourceConfigurationCodeRepository; /** * Description of a source image repository. See `imageRepository` below. */ imageRepository?: outputs.apprunner.ServiceSourceConfigurationImageRepository; } interface ServiceSourceConfigurationAuthenticationConfiguration { /** * ARN of the IAM role that grants the App Runner service access to a source repository. Required for ECR image repositories (but not for ECR Public) */ accessRoleArn?: string; /** * ARN of the App Runner connection that enables the App Runner service to connect to a source repository. Required for GitHub code repositories. */ connectionArn?: string; } interface ServiceSourceConfigurationCodeRepository { /** * Configuration for building and running the service from a source code repository. See `codeConfiguration` below. */ codeConfiguration?: outputs.apprunner.ServiceSourceConfigurationCodeRepositoryCodeConfiguration; /** * Location of the repository that contains the source code. */ repositoryUrl: string; /** * Version that should be used within the source code repository. See `sourceCodeVersion` below. */ sourceCodeVersion: outputs.apprunner.ServiceSourceConfigurationCodeRepositorySourceCodeVersion; /** * Path of the directory that stores source code and configuration files. The build and start commands also execute from here. The path is absolute from root and, if not specified, defaults to the repository root. */ sourceDirectory: string; } interface ServiceSourceConfigurationCodeRepositoryCodeConfiguration { /** * Basic configuration for building and running the App Runner service. Use this parameter to quickly launch an App Runner service without providing an apprunner.yaml file in the source code repository (or ignoring the file if it exists). See `codeConfigurationValues` below. */ codeConfigurationValues?: outputs.apprunner.ServiceSourceConfigurationCodeRepositoryCodeConfigurationCodeConfigurationValues; /** * Source of the App Runner configuration. Valid values: `REPOSITORY`, `API`. Use `REPOSITORY` to have App Runner read configuration values from the `apprunner.yaml` file in the source code repository and ignore `codeConfigurationValues`. Use `API` to have App Runner use the configuration values provided in `codeConfigurationValues` and ignore the `apprunner.yaml` file in the source code repository. */ configurationSource: string; } interface ServiceSourceConfigurationCodeRepositoryCodeConfigurationCodeConfigurationValues { /** * Command App Runner runs to build your application. */ buildCommand?: string; /** * Port that your application listens to in the container. Defaults to `"8080"`. */ port?: string; /** * Runtime environment type for building and running an App Runner service. Represents a programming language runtime. Valid values: `PYTHON_3`, `NODEJS_12`, `NODEJS_14`, `NODEJS_16`, `CORRETTO_8`, `CORRETTO_11`, `GO_1`, `DOTNET_6`, `PHP_81`, `RUBY_31`. */ runtime: string; /** * Secrets and parameters available to your service as environment variables. A map of key/value pairs, where the key is the desired name of the Secret in the environment (i.e. it does not have to match the name of the secret in Secrets Manager or SSM Parameter Store), and the value is the ARN of the secret from AWS Secrets Manager or the ARN of the parameter in AWS SSM Parameter Store. */ runtimeEnvironmentSecrets?: { [key: string]: string; }; /** * Environment variables available to your running App Runner service. A map of key/value pairs. Keys with a prefix of `AWSAPPRUNNER` are reserved for system use and aren't valid. */ runtimeEnvironmentVariables?: { [key: string]: string; }; /** * Command App Runner runs to start your application. */ startCommand?: string; } interface ServiceSourceConfigurationCodeRepositorySourceCodeVersion { /** * Type of version identifier. For a git-based repository, branches represent versions. Valid values: `BRANCH`. */ type: string; /** * Source code version. For a git-based repository, a branch name maps to a specific version. App Runner uses the most recent commit to the branch. */ value: string; } interface ServiceSourceConfigurationImageRepository { /** * Configuration for running the identified image. See `imageConfiguration` below. */ imageConfiguration?: outputs.apprunner.ServiceSourceConfigurationImageRepositoryImageConfiguration; /** * Identifier of an image. For an image in Amazon Elastic Container Registry (Amazon ECR), this is an image name. For the image name format, see Pulling an image in the Amazon ECR User Guide. */ imageIdentifier: string; /** * Type of the image repository. This reflects the repository provider and whether the repository is private or public. Valid values: `ECR`, `ECR_PUBLIC`. */ imageRepositoryType: string; } interface ServiceSourceConfigurationImageRepositoryImageConfiguration { /** * Port that your application listens to in the container. Defaults to `"8080"`. */ port?: string; /** * Secrets and parameters available to your service as environment variables. A map of key/value pairs, where the key is the desired name of the Secret in the environment (i.e. it does not have to match the name of the secret in Secrets Manager or SSM Parameter Store), and the value is the ARN of the secret from AWS Secrets Manager or the ARN of the parameter in AWS SSM Parameter Store. */ runtimeEnvironmentSecrets?: { [key: string]: string; }; /** * Environment variables available to your running App Runner service. A map of key/value pairs. Keys with a prefix of `AWSAPPRUNNER` are reserved for system use and aren't valid. */ runtimeEnvironmentVariables?: { [key: string]: string; }; /** * Command App Runner runs to start the application in the source image. If specified, this command overrides the Docker image’s default start command. */ startCommand?: string; } interface VpcIngressConnectionIngressVpcConfiguration { /** * ID of the VPC endpoint that your App Runner service connects to. */ vpcEndpointId?: string; /** * ID of the VPC that is used for the VPC endpoint. */ vpcId?: string; } } export declare namespace appstream { interface DirectoryConfigCertificateBasedAuthProperties { /** * ARN of the AWS Certificate Manager Private CA resource. */ certificateAuthorityArn?: string; /** * Status of the certificate-based authentication properties. Valid values - ["DISABLED", "ENABLED", "ENABLED_NO_DIRECTORY_LOGIN_FALLBACK"]. */ status?: string; } interface DirectoryConfigServiceAccountCredentials { /** * User name of the account. This account must have the following privileges: create computer objects, join computers to the domain, and change/reset the password on descendant computer objects for the organizational units specified. */ accountName: string; /** * Password for the account. */ accountPassword: string; } interface FleetComputeCapacity { /** * Number of currently available instances that can be used to stream sessions. */ available: number; /** * Desired number of streaming instances. */ desiredInstances?: number; /** * Desired number of user sessions for a multi-session fleet. This is not allowed for single-session fleets. */ desiredSessions?: number; /** * Number of instances in use for streaming. */ inUse: number; /** * Total number of simultaneous streaming instances that are running. */ running: number; } interface FleetDomainJoinInfo { /** * Fully qualified name of the directory (for example, corp.example.com). */ directoryName: string; /** * Distinguished name of the organizational unit for computer accounts. */ organizationalUnitDistinguishedName: string; } interface FleetVpcConfig { /** * Identifiers of the security groups for the fleet or image builder. */ securityGroupIds: string[]; /** * Identifiers of the subnets to which a network interface is attached from the fleet instance or image builder instance. */ subnetIds: string[]; } interface GetImageApplication { /** * App block ARN of the application. */ appBlockArn: string; /** * ARN of the image being searched for. Cannot be used with `nameRegex` or `name`. */ arn: string; /** * Time at which this image was created. */ createdTime: string; /** * Description of image. */ description: string; /** * Image name to display. */ displayName: string; /** * Whether the application is enabled. */ enabled: boolean; /** * S3 location of the application icon and contains the following: */ iconS3Locations: outputs.appstream.GetImageApplicationIconS3Location[]; /** * URL of the application icon. This URL may be time-limited. */ iconUrl: string; /** * List of the instance families of the application. */ instanceFamilies: string[]; /** * Arguments that are passed to the application at its launch. */ launchParameters: string; /** * Path to the application's executable in the instance. */ launchPath: string; /** * String to string map that contains additional attributes used to describe the application. */ metadata: { [key: string]: string; }; /** * Name of the image being searched for. Cannot be used with `nameRegex` or `arn`. */ name: string; /** * Array of strings describing the platforms on which the application can run. Values will be from: WINDOWS | WINDOWS_SERVER_2016 | WINDOWS_SERVER_2019 | WINDOWS_SERVER_2022 | AMAZON_LINUX2 */ platforms: string[]; /** * Working directory for the application. */ workingDirectory: string; } interface GetImageApplicationIconS3Location { /** * Name of the S3 bucket containing the icon. */ s3Bucket: string; /** * S3 key of the icon. */ s3Key: string; } interface GetImageImagePermission { /** * Whether the image can be used for a fleet. */ allowFleet: boolean; /** * Whether the image can be used for an image builder. */ allowImageBuilder: boolean; } interface GetImageStateChangeReason { /** * State change reason code. */ code: string; /** * State change reason message. */ message: string; } interface ImageBuilderAccessEndpoint { /** * Type of interface endpoint. For valid values, refer to the [AWS documentation](https://docs.aws.amazon.com/appstream2/latest/APIReference/API_AccessEndpoint.html). */ endpointType: string; /** * Identifier (ID) of the interface VPC endpoint. */ vpceId: string; } interface ImageBuilderDomainJoinInfo { /** * Fully qualified name of the directory (for example, corp.example.com). */ directoryName?: string; /** * Distinguished name of the organizational unit for computer accounts. */ organizationalUnitDistinguishedName?: string; } interface ImageBuilderVpcConfig { /** * Identifiers of the security groups for the image builder or image builder. */ securityGroupIds: string[]; /** * Identifier of the subnet to which a network interface is attached from the image builder instance. */ subnetIds: string[]; } interface StackAccessEndpoint { /** * Type of the interface endpoint. See the [`AccessEndpoint` AWS API documentation](https://docs.aws.amazon.com/appstream2/latest/APIReference/API_AccessEndpoint.html) for valid values. */ endpointType: string; /** * ID of the VPC in which the interface endpoint is used. */ vpceId: string; } interface StackApplicationSettings { /** * Whether application settings should be persisted. */ enabled: boolean; /** * Name of the settings group. Required when `enabled` is `true`. Can be up to 100 characters. */ settingsGroup?: string; } interface StackStorageConnector { /** * Type of storage connector. Valid values are `HOMEFOLDERS`, `GOOGLE_DRIVE`, or `ONE_DRIVE`. */ connectorType: string; /** * Names of the domains for the account. */ domains: string[]; /** * ARN of the storage connector. */ resourceIdentifier: string; } interface StackStreamingExperienceSettings { /** * Preferred protocol that you want to use while streaming your application. Valid values are `TCP` and `UDP`. */ preferredProtocol?: string; } interface StackUserSetting { /** * Action that is enabled or disabled. Valid values are `AUTO_TIME_ZONE_REDIRECTION`, `CLIPBOARD_COPY_FROM_LOCAL_DEVICE`, `CLIPBOARD_COPY_TO_LOCAL_DEVICE`, `DOMAIN_PASSWORD_SIGNIN`, `DOMAIN_SMART_CARD_SIGNIN`, `FILE_UPLOAD`, `FILE_DOWNLOAD`, or `PRINTING_TO_LOCAL_DEVICE`. */ action: string; /** * Whether the action is enabled or disabled. Valid values are `ENABLED` or `DISABLED`. */ permission: string; } } export declare namespace appsync { interface ApiEventConfig { /** * List of authentication providers. See `event_config.auth_provider` Block below. */ authProviders: outputs.appsync.ApiEventConfigAuthProvider[]; /** * List of authentication modes for connections. See `event_config.connection_auth_mode` Block below. */ connectionAuthModes: outputs.appsync.ApiEventConfigConnectionAuthMode[]; /** * List of default authentication modes for publishing. See `event_config.default_publish_auth_mode` Block below. */ defaultPublishAuthModes: outputs.appsync.ApiEventConfigDefaultPublishAuthMode[]; /** * List of default authentication modes for subscribing. See `event_config.default_subscribe_auth_mode` Block below. */ defaultSubscribeAuthModes: outputs.appsync.ApiEventConfigDefaultSubscribeAuthMode[]; /** * Logging configuration. See `logConfig` Block below. */ logConfig?: outputs.appsync.ApiEventConfigLogConfig; } interface ApiEventConfigAuthProvider { /** * Type of authentication provider. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA`. */ authType: string; /** * Configuration for Cognito user pool authentication. Required when `authType` is `AMAZON_COGNITO_USER_POOLS`. See `cognitoConfig` Block below. */ cognitoConfig?: outputs.appsync.ApiEventConfigAuthProviderCognitoConfig; /** * Configuration for Lambda authorization. Required when `authType` is `AWS_LAMBDA`. See `lambdaAuthorizerConfig` Block below. */ lambdaAuthorizerConfig?: outputs.appsync.ApiEventConfigAuthProviderLambdaAuthorizerConfig; /** * Configuration for OpenID Connect. Required when `authType` is `OPENID_CONNECT`. See `openidConnectConfig` Block below. */ openidConnectConfig?: outputs.appsync.ApiEventConfigAuthProviderOpenidConnectConfig; } interface ApiEventConfigAuthProviderCognitoConfig { /** * Regular expression for matching the client ID. */ appIdClientRegex?: string; /** * AWS region where the user pool is located. */ awsRegion: string; /** * ID of the Cognito user pool. */ userPoolId: string; } interface ApiEventConfigAuthProviderLambdaAuthorizerConfig { /** * TTL in seconds for the authorization result cache. */ authorizerResultTtlInSeconds: number; /** * URI of the Lambda function for authorization. */ authorizerUri: string; /** * Regular expression for identity validation. */ identityValidationExpression?: string; } interface ApiEventConfigAuthProviderOpenidConnectConfig { /** * TTL in seconds for the authentication token. */ authTtl: number; /** * Client ID for the OpenID Connect provider. */ clientId?: string; /** * TTL in seconds for the issued at time. */ iatTtl: number; /** * Issuer URL for the OpenID Connect provider. */ issuer: string; } interface ApiEventConfigConnectionAuthMode { /** * Type of authentication. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA`. */ authType: string; } interface ApiEventConfigDefaultPublishAuthMode { /** * Type of authentication. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA`. */ authType: string; } interface ApiEventConfigDefaultSubscribeAuthMode { /** * Type of authentication. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA`. */ authType: string; } interface ApiEventConfigLogConfig { /** * ARN of the IAM role for CloudWatch logs. */ cloudwatchLogsRoleArn: string; /** * Log level. Valid values: `NONE`, `ERROR`, `ALL`, `INFO`, `DEBUG`. */ logLevel: string; } interface ChannelNamespaceHandlerConfigs { /** * Handler configuration for published events. See `onPublish` below. */ onPublish?: outputs.appsync.ChannelNamespaceHandlerConfigsOnPublish; /** * Handler configuration for subscribe requests. See `onSubscribe` below. */ onSubscribe?: outputs.appsync.ChannelNamespaceHandlerConfigsOnSubscribe; } interface ChannelNamespaceHandlerConfigsOnPublish { /** * Behavior for the handler. Valid values: `CODE`, `DIRECT`. */ behavior: string; /** * Integration data source configuration for the handler. See `integration` below. */ integration: outputs.appsync.ChannelNamespaceHandlerConfigsOnPublishIntegration; } interface ChannelNamespaceHandlerConfigsOnPublishIntegration { /** * Unique name of the data source that has been configured on the API. */ dataSourceName: string; /** * Configuration for a Lambda data source. See `lambdaConfig` below. */ lambdaConfig?: outputs.appsync.ChannelNamespaceHandlerConfigsOnPublishIntegrationLambdaConfig; } interface ChannelNamespaceHandlerConfigsOnPublishIntegrationLambdaConfig { /** * Invocation type for a Lambda data source. Valid values: `REQUEST_RESPONSE`, `EVENT`. */ invokeType?: string; } interface ChannelNamespaceHandlerConfigsOnSubscribe { /** * Behavior for the handler. Valid values: `CODE`, `DIRECT`. */ behavior: string; /** * Integration data source configuration for the handler. See `integration` below. */ integration: outputs.appsync.ChannelNamespaceHandlerConfigsOnSubscribeIntegration; } interface ChannelNamespaceHandlerConfigsOnSubscribeIntegration { /** * Unique name of the data source that has been configured on the API. */ dataSourceName: string; /** * Configuration for a Lambda data source. See `lambdaConfig` below. */ lambdaConfig?: outputs.appsync.ChannelNamespaceHandlerConfigsOnSubscribeIntegrationLambdaConfig; } interface ChannelNamespaceHandlerConfigsOnSubscribeIntegrationLambdaConfig { /** * Invocation type for a Lambda data source. Valid values: `REQUEST_RESPONSE`, `EVENT`. */ invokeType?: string; } interface ChannelNamespacePublishAuthMode { /** * Type of authentication. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA`. */ authType: string; } interface ChannelNamespaceSubscribeAuthMode { /** * Type of authentication. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA`. */ authType: string; } interface DataSourceDynamodbConfig { /** * DeltaSyncConfig for a versioned data source. See `deltaSyncConfig` Block for details. */ deltaSyncConfig?: outputs.appsync.DataSourceDynamodbConfigDeltaSyncConfig; /** * AWS region of the DynamoDB table. Defaults to current region. */ region: string; /** * Name of the DynamoDB table. */ tableName: string; /** * Set to `true` to use Amazon Cognito credentials with this data source. */ useCallerCredentials?: boolean; /** * Detects Conflict Detection and Resolution with this data source. */ versioned?: boolean; } interface DataSourceDynamodbConfigDeltaSyncConfig { /** * Number of minutes that an Item is stored in the data source. */ baseTableTtl?: number; /** * Table name. */ deltaSyncTableName: string; /** * Number of minutes that a Delta Sync log entry is stored in the Delta Sync table. */ deltaSyncTableTtl?: number; } interface DataSourceElasticsearchConfig { /** * HTTP endpoint of the Elasticsearch domain. */ endpoint: string; /** * AWS region of Elasticsearch domain. Defaults to current region. */ region: string; } interface DataSourceEventBridgeConfig { /** * ARN for the EventBridge bus. */ eventBusArn: string; } interface DataSourceHttpConfig { /** * Authorization configuration in case the HTTP endpoint requires authorization. See `authorizationConfig` Block for details. */ authorizationConfig?: outputs.appsync.DataSourceHttpConfigAuthorizationConfig; /** * HTTP URL. */ endpoint: string; } interface DataSourceHttpConfigAuthorizationConfig { /** * Authorization type that the HTTP endpoint requires. Default values is `AWS_IAM`. */ authorizationType?: string; /** * Identity and Access Management (IAM) settings. See `awsIamConfig` Block for details. */ awsIamConfig?: outputs.appsync.DataSourceHttpConfigAuthorizationConfigAwsIamConfig; } interface DataSourceHttpConfigAuthorizationConfigAwsIamConfig { /** * Signing Amazon Web Services Region for IAM authorization. */ signingRegion?: string; /** * Signing service name for IAM authorization. */ signingServiceName?: string; } interface DataSourceLambdaConfig { /** * ARN for the Lambda function. */ functionArn: string; } interface DataSourceOpensearchserviceConfig { /** * HTTP endpoint of the OpenSearch domain. */ endpoint: string; /** * AWS region of the OpenSearch domain. Defaults to current region. */ region: string; } interface DataSourceRelationalDatabaseConfig { /** * Amazon RDS HTTP endpoint configuration. See `httpEndpointConfig` Block for details. */ httpEndpointConfig?: outputs.appsync.DataSourceRelationalDatabaseConfigHttpEndpointConfig; /** * Source type for the relational database. Valid values: `RDS_HTTP_ENDPOINT`. */ sourceType?: string; } interface DataSourceRelationalDatabaseConfigHttpEndpointConfig { /** * AWS secret store ARN for database credentials. */ awsSecretStoreArn: string; /** * Logical database name. */ databaseName?: string; /** * Amazon RDS cluster identifier. */ dbClusterIdentifier: string; /** * AWS Region for RDS HTTP endpoint. Defaults to current region. */ region: string; /** * Logical schema name. */ schema?: string; } interface FunctionRuntime { /** * Name of the runtime to use. Currently, the only allowed value is `APPSYNC_JS`. */ name: string; /** * Version of the runtime to use. Currently, the only allowed version is `1.0.0`. */ runtimeVersion: string; } interface FunctionSyncConfig { /** * Conflict Detection strategy to use. Valid values are `NONE` and `VERSION`. */ conflictDetection?: string; /** * Conflict Resolution strategy to perform in the event of a conflict. Valid values are `NONE`, `OPTIMISTIC_CONCURRENCY`, `AUTOMERGE`, and `LAMBDA`. */ conflictHandler?: string; /** * Lambda Conflict Handler Config when configuring `LAMBDA` as the Conflict Handler. See `lambdaConflictHandlerConfig` Block for details. */ lambdaConflictHandlerConfig?: outputs.appsync.FunctionSyncConfigLambdaConflictHandlerConfig; } interface FunctionSyncConfigLambdaConflictHandlerConfig { /** * ARN for the Lambda function to use as the Conflict Handler. */ lambdaConflictHandlerArn?: string; } interface GraphQLApiAdditionalAuthenticationProvider { /** * Authentication type. Valid values: `API_KEY`, `AWS_IAM`, `AMAZON_COGNITO_USER_POOLS`, `OPENID_CONNECT`, `AWS_LAMBDA` */ authenticationType: string; /** * Nested argument containing Lambda authorizer configuration. See `lambdaAuthorizerConfig` Block for details. */ lambdaAuthorizerConfig?: outputs.appsync.GraphQLApiAdditionalAuthenticationProviderLambdaAuthorizerConfig; /** * Nested argument containing OpenID Connect configuration. See `openidConnectConfig` Block for details. */ openidConnectConfig?: outputs.appsync.GraphQLApiAdditionalAuthenticationProviderOpenidConnectConfig; /** * Amazon Cognito User Pool configuration. See `additional_authentication_provider.user_pool_config` Block for details. */ userPoolConfig?: outputs.appsync.GraphQLApiAdditionalAuthenticationProviderUserPoolConfig; } interface GraphQLApiAdditionalAuthenticationProviderLambdaAuthorizerConfig { /** * Number of seconds a response should be cached for. The default is 5 minutes (300 seconds). The Lambda function can override this by returning a `ttlOverride` key in its response. A value of 0 disables caching of responses. Minimum value of 0. Maximum value of 3600. */ authorizerResultTtlInSeconds?: number; /** * ARN of the Lambda function to be called for authorization. Note: This Lambda function must have a resource-based policy assigned to it, to allow `lambda:InvokeFunction` from service principal `appsync.amazonaws.com`. */ authorizerUri: string; /** * Regular expression for validation of tokens before the Lambda function is called. */ identityValidationExpression?: string; } interface GraphQLApiAdditionalAuthenticationProviderOpenidConnectConfig { /** * Number of milliseconds a token is valid after being authenticated. */ authTtl?: number; /** * Client identifier of the Relying party at the OpenID identity provider. This identifier is typically obtained when the Relying party is registered with the OpenID identity provider. You can specify a regular expression so the AWS AppSync can validate against multiple client identifiers at a time. */ clientId?: string; /** * Number of milliseconds a token is valid after being issued to a user. */ iatTtl?: number; /** * Issuer for the OpenID Connect configuration. The issuer returned by discovery MUST exactly match the value of iss in the ID Token. */ issuer: string; } interface GraphQLApiAdditionalAuthenticationProviderUserPoolConfig { /** * Regular expression for validating the incoming Amazon Cognito User Pool app client ID. */ appIdClientRegex?: string; /** * AWS region in which the user pool was created. */ awsRegion: string; /** * User pool ID. */ userPoolId: string; } interface GraphQLApiEnhancedMetricsConfig { /** * How data source metrics will be emitted to CloudWatch. Valid values: `FULL_REQUEST_DATA_SOURCE_METRICS`, `PER_DATA_SOURCE_METRICS` */ dataSourceLevelMetricsBehavior: string; /** * How operation metrics will be emitted to CloudWatch. Valid values: `ENABLED`, `DISABLED` */ operationLevelMetricsConfig: string; /** * How resolver metrics will be emitted to CloudWatch. Valid values: `FULL_REQUEST_RESOLVER_METRICS`, `PER_RESOLVER_METRICS` */ resolverLevelMetricsBehavior: string; } interface GraphQLApiLambdaAuthorizerConfig { /** * Number of seconds a response should be cached for. The default is 5 minutes (300 seconds). The Lambda function can override this by returning a `ttlOverride` key in its response. A value of 0 disables caching of responses. Minimum value of 0. Maximum value of 3600. */ authorizerResultTtlInSeconds?: number; /** * ARN of the Lambda function to be called for authorization. Note: This Lambda function must have a resource-based policy assigned to it, to allow `lambda:InvokeFunction` from service principal `appsync.amazonaws.com`. */ authorizerUri: string; /** * Regular expression for validation of tokens before the Lambda function is called. */ identityValidationExpression?: string; } interface GraphQLApiLogConfig { /** * ARN of the service role that AWS AppSync will assume to publish to Amazon CloudWatch logs in your account. */ cloudwatchLogsRoleArn: string; /** * Set to TRUE to exclude sections that contain information such as headers, context, and evaluated mapping templates, regardless of logging level. Valid values: `true`, `false`. Default value: `false` */ excludeVerboseContent?: boolean; /** * Field logging level. Valid values: `ALL`, `ERROR`, `NONE`. */ fieldLogLevel: string; } interface GraphQLApiOpenidConnectConfig { /** * Number of milliseconds a token is valid after being authenticated. */ authTtl?: number; /** * Client identifier of the Relying party at the OpenID identity provider. This identifier is typically obtained when the Relying party is registered with the OpenID identity provider. You can specify a regular expression so the AWS AppSync can validate against multiple client identifiers at a time. */ clientId?: string; /** * Number of milliseconds a token is valid after being issued to a user. */ iatTtl?: number; /** * Issuer for the OpenID Connect configuration. The issuer returned by discovery MUST exactly match the value of iss in the ID Token. */ issuer: string; } interface GraphQLApiUserPoolConfig { /** * Regular expression for validating the incoming Amazon Cognito User Pool app client ID. */ appIdClientRegex?: string; /** * AWS region in which the user pool was created. */ awsRegion: string; /** * Action that you want your GraphQL API to take when a request that uses Amazon Cognito User Pool authentication doesn't match the Amazon Cognito User Pool configuration. Valid: `ALLOW` and `DENY` */ defaultAction: string; /** * User pool ID. */ userPoolId: string; } interface ResolverCachingConfig { /** * Caching keys for a resolver that has caching activated. Valid values are entries from the $context.arguments, $context.source, and $context.identity maps. */ cachingKeys?: string[]; /** * TTL in seconds for a resolver that has caching activated. Valid values are between `1` and `3600` seconds. */ ttl?: number; } interface ResolverPipelineConfig { /** * List of Function objects. */ functions?: string[]; } interface ResolverRuntime { /** * Name of the runtime to use. Currently, the only allowed value is `APPSYNC_JS`. */ name: string; /** * Version of the runtime to use. Currently, the only allowed version is `1.0.0`. */ runtimeVersion: string; } interface ResolverSyncConfig { /** * Conflict Detection strategy to use. Valid values are `NONE` and `VERSION`. */ conflictDetection?: string; /** * Conflict Resolution strategy to perform in the event of a conflict. Valid values are `NONE`, `OPTIMISTIC_CONCURRENCY`, `AUTOMERGE`, and `LAMBDA`. */ conflictHandler?: string; /** * Lambda Conflict Handler Config when configuring `LAMBDA` as the Conflict Handler. See Lambda Conflict Handler Config. */ lambdaConflictHandlerConfig?: outputs.appsync.ResolverSyncConfigLambdaConflictHandlerConfig; } interface ResolverSyncConfigLambdaConflictHandlerConfig { /** * ARN for the Lambda function to use as the Conflict Handler. */ lambdaConflictHandlerArn?: string; } interface SourceApiAssociationSourceApiAssociationConfig { /** * Merge type. Valid values: `MANUAL_MERGE`, `AUTO_MERGE` */ mergeType: string; } interface SourceApiAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace arcregionswitch { interface GetRoute53HealthChecksHealthCheck { /** * ID of the Route53 health check. */ healthCheckId: string; /** * Hosted zone ID for the health check. */ hostedZoneId: string; /** * Record name for the health check. */ recordName: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Status of the health check. Valid values: `healthy`, `unhealthy`, `unknown`. */ status: string; } interface PlanAssociatedAlarm { /** * Type of alarm. Valid values: `applicationHealth`, `trigger`. */ alarmType: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Name of the alarm. */ mapBlockKey: string; /** * Resource identifier (ARN) of the CloudWatch alarm. */ resourceIdentifier: string; } interface PlanReportConfiguration { /** * Output destination for the report. See `reportOutput` Block for details. */ reportOutputs?: outputs.arcregionswitch.PlanReportConfigurationReportOutput[]; } interface PlanReportConfigurationReportOutput { /** * S3 output configuration. See `s3Configuration` Block for details. */ s3Configurations?: outputs.arcregionswitch.PlanReportConfigurationReportOutputS3Configuration[]; } interface PlanReportConfigurationReportOutputS3Configuration { /** * Account ID of the S3 bucket owner. */ bucketOwner: string; /** * S3 bucket path where reports will be stored. */ bucketPath: string; } interface PlanTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface PlanTrigger { /** * Action to trigger. Valid values: `activate`, `deactivate`. */ action: string; /** * Conditions that must be met. See `conditions` Block for details. */ conditions?: outputs.arcregionswitch.PlanTriggerCondition[]; /** * Description of the trigger. */ description?: string; /** * Minimum delay in minutes between executions. */ minDelayMinutesBetweenExecutions: number; /** * Target region for the trigger. */ targetRegion: string; } interface PlanTriggerCondition { /** * Name of the associated alarm. */ associatedAlarmName: string; /** * Condition to check. Valid values: `red`, `green`. */ condition: string; } interface PlanWorkflow { /** * Steps in the workflow. See `step` Block for details. */ steps?: outputs.arcregionswitch.PlanWorkflowStep[]; /** * Description of the workflow. */ workflowDescription?: string; /** * Action to perform. Valid values: `activate`, `deactivate`. */ workflowTargetAction: string; /** * Target region for the workflow. */ workflowTargetRegion?: string; } interface PlanWorkflowStep { /** * Configuration for ARC routing control. See `arcRoutingControlConfig` Block for details. */ arcRoutingControlConfigs?: outputs.arcregionswitch.PlanWorkflowStepArcRoutingControlConfig[]; /** * Configuration for Aurora provisioned scaling. See `auroraProvisionedScalingConfig` Block for details. */ auroraProvisionedScalingConfigs?: outputs.arcregionswitch.PlanWorkflowStepAuroraProvisionedScalingConfig[]; /** * Configuration for Aurora Serverless scaling. See `auroraServerlessScalingConfig` Block for details. */ auroraServerlessScalingConfigs?: outputs.arcregionswitch.PlanWorkflowStepAuroraServerlessScalingConfig[]; /** * Configuration for Lambda function execution. See `customActionLambdaConfig` Block for details. */ customActionLambdaConfigs?: outputs.arcregionswitch.PlanWorkflowStepCustomActionLambdaConfig[]; /** * Description of the step. */ description?: string; /** * Configuration for DocumentDB global cluster operations. See `documentDbConfig` Block for details. */ documentDbConfigs?: outputs.arcregionswitch.PlanWorkflowStepDocumentDbConfig[]; /** * Configuration for EC2 Auto Scaling group capacity increase. See `ec2AsgCapacityIncreaseConfig` Block for details. */ ec2AsgCapacityIncreaseConfigs?: outputs.arcregionswitch.PlanWorkflowStepEc2AsgCapacityIncreaseConfig[]; /** * Configuration for ECS service capacity increase. See `ecsCapacityIncreaseConfig` Block for details. */ ecsCapacityIncreaseConfigs?: outputs.arcregionswitch.PlanWorkflowStepEcsCapacityIncreaseConfig[]; /** * Configuration for EKS resource scaling. See `eksResourceScalingConfig` Block for details. */ eksResourceScalingConfigs?: outputs.arcregionswitch.PlanWorkflowStepEksResourceScalingConfig[]; /** * Configuration for manual approval steps. See `executionApprovalConfig` Block for details. */ executionApprovalConfigs?: outputs.arcregionswitch.PlanWorkflowStepExecutionApprovalConfig[]; /** * Type of execution block. Valid values: `ARCRegionSwitchPlan`, `ARCRoutingControl`, `AuroraGlobalDatabase`, `CustomActionLambda`, `DocumentDb`, `EC2AutoScaling`, `ECSServiceScaling`, `EKSResourceScaling`, `ManualApproval`, `Parallel`, `RdsCreateCrossRegionReplica`, `RdsPromoteReadReplica`, `Route53HealthCheck`. */ executionBlockType: string; /** * Configuration for Aurora Global Database operations. See `globalAuroraConfig` Block for details. */ globalAuroraConfigs?: outputs.arcregionswitch.PlanWorkflowStepGlobalAuroraConfig[]; /** * Configuration for Lambda event source mapping operations. See `lambdaEventSourceMappingConfig` Block for details. */ lambdaEventSourceMappingConfigs?: outputs.arcregionswitch.PlanWorkflowStepLambdaEventSourceMappingConfig[]; /** * Name of the step. */ name: string; /** * Configuration for Neptune global database operations. See `neptuneGlobalDatabaseConfig` Block for details. */ neptuneGlobalDatabaseConfigs?: outputs.arcregionswitch.PlanWorkflowStepNeptuneGlobalDatabaseConfig[]; /** * Configuration for parallel execution of multiple steps. See `parallelConfig` Block for details. */ parallelConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfig[]; /** * Configuration for creating cross-region RDS read replicas. See `rdsCreateCrossRegionReadReplicaConfig` Block for details. */ rdsCreateCrossRegionReadReplicaConfigs?: outputs.arcregionswitch.PlanWorkflowStepRdsCreateCrossRegionReadReplicaConfig[]; /** * Configuration for promoting RDS read replicas. See `rdsPromoteReadReplicaConfig` Block for details. */ rdsPromoteReadReplicaConfigs?: outputs.arcregionswitch.PlanWorkflowStepRdsPromoteReadReplicaConfig[]; /** * Configuration for executing a nested region switch plan. See `regionSwitchPlanConfig` Block for details. */ regionSwitchPlanConfigs?: outputs.arcregionswitch.PlanWorkflowStepRegionSwitchPlanConfig[]; /** * Configuration for Route53 health check operations. See `route53HealthCheckConfig` Block for details. */ route53HealthCheckConfigs?: outputs.arcregionswitch.PlanWorkflowStepRoute53HealthCheckConfig[]; } interface PlanWorkflowStepArcRoutingControlConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Regions and their routing controls. See `regionAndRoutingControls` Block for details. */ regionAndRoutingControls?: outputs.arcregionswitch.PlanWorkflowStepArcRoutingControlConfigRegionAndRoutingControl[]; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepArcRoutingControlConfigRegionAndRoutingControl { /** * AWS region. */ region: string; /** * Routing controls. See `routingControl` Block for details. */ routingControls?: outputs.arcregionswitch.PlanWorkflowStepArcRoutingControlConfigRegionAndRoutingControlRoutingControl[]; } interface PlanWorkflowStepArcRoutingControlConfigRegionAndRoutingControlRoutingControl { /** * ARN of the routing control. */ routingControlArn: string; /** * State of the routing control. Valid values: `On`, `Off`. */ state: string; } interface PlanWorkflowStepAuroraProvisionedScalingConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Map of regions to Aurora instance ARNs. */ instanceArns: { [key: string]: string; }; /** * Map of regions to database cluster ARNs. */ regionDatabaseClusterArns: { [key: string]: string; }; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepAuroraServerlessScalingConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Map of regions to database cluster ARNs. */ regionDatabaseClusterArns: { [key: string]: string; }; /** * Target capacity percentage. */ targetPercent?: number; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepCustomActionLambdaConfig { /** * Lambda function configuration. See `lambda` Block for details. */ lambdas?: outputs.arcregionswitch.PlanWorkflowStepCustomActionLambdaConfigLambda[]; /** * Region where the Lambda function should run. Valid values: `activatingRegion`, `deactivatingRegion`. */ regionToRun: string; /** * Retry interval in minutes. */ retryIntervalMinutes: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.custom_action_lambda_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepCustomActionLambdaConfigUngraceful[]; } interface PlanWorkflowStepCustomActionLambdaConfigLambda { /** * ARN of the Lambda function. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepCustomActionLambdaConfigUngraceful { behavior: string; } interface PlanWorkflowStepDocumentDbConfig { /** * Behavior for global cluster operations. Valid values: `switchoverOnly`, `failover`. */ behavior: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * List of DocumentDB cluster ARNs. */ databaseClusterArns: string[]; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.document_db_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepDocumentDbConfigUngraceful[]; } interface PlanWorkflowStepDocumentDbConfigUngraceful { ungraceful: string; } interface PlanWorkflowStepEc2AsgCapacityIncreaseConfig { /** * Auto Scaling group configuration. See `asg` Block for details. */ asgs?: outputs.arcregionswitch.PlanWorkflowStepEc2AsgCapacityIncreaseConfigAsg[]; /** * Capacity monitoring approach. Valid values: `sampledMaxInLast24Hours`, `autoscalingMaxInLast24Hours`. */ capacityMonitoringApproach: string; /** * Target capacity percentage. */ targetPercent?: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.ec2_asg_capacity_increase_config.ungraceful` Block for details. */ ungraceful?: outputs.arcregionswitch.PlanWorkflowStepEc2AsgCapacityIncreaseConfigUngraceful; } interface PlanWorkflowStepEc2AsgCapacityIncreaseConfigAsg { /** * ARN of the Auto Scaling group. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepEc2AsgCapacityIncreaseConfigUngraceful { /** * Minimum success percentage required. */ minimumSuccessPercentage: number; } interface PlanWorkflowStepEcsCapacityIncreaseConfig { /** * Capacity monitoring approach. Valid values: `sampledMaxInLast24Hours`, `containerInsightsMaxInLast24Hours`. */ capacityMonitoringApproach: string; /** * ECS service configuration. See `service` Block for details. */ services?: outputs.arcregionswitch.PlanWorkflowStepEcsCapacityIncreaseConfigService[]; /** * Target capacity percentage. */ targetPercent?: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.ecs_capacity_increase_config.ungraceful` Block for details. */ ungraceful?: outputs.arcregionswitch.PlanWorkflowStepEcsCapacityIncreaseConfigUngraceful; } interface PlanWorkflowStepEcsCapacityIncreaseConfigService { /** * ARN of the ECS cluster. */ clusterArn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * ARN of the ECS service. */ serviceArn: string; } interface PlanWorkflowStepEcsCapacityIncreaseConfigUngraceful { /** * Minimum success percentage required. */ minimumSuccessPercentage: number; } interface PlanWorkflowStepEksResourceScalingConfig { /** * Capacity monitoring approach. Valid values: `sampledMaxInLast24Hours`, `autoscalingMaxInLast24Hours`. */ capacityMonitoringApproach: string; /** * EKS clusters. See `eksClusters` Block for details. */ eksClusters?: outputs.arcregionswitch.PlanWorkflowStepEksResourceScalingConfigEksCluster[]; /** * Kubernetes resource type. See `kubernetesResourceType` Block for details. */ kubernetesResourceTypes?: outputs.arcregionswitch.PlanWorkflowStepEksResourceScalingConfigKubernetesResourceType[]; /** * Scaling resources. See `scalingResources` Block for details. */ scalingResources?: outputs.arcregionswitch.PlanWorkflowStepEksResourceScalingConfigScalingResource[]; /** * Target capacity percentage. */ targetPercent: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.eks_resource_scaling_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepEksResourceScalingConfigUngraceful[]; } interface PlanWorkflowStepEksResourceScalingConfigEksCluster { /** * ARN of the EKS cluster. */ clusterArn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepEksResourceScalingConfigKubernetesResourceType { /** * Kubernetes API version. */ apiVersion: string; /** * Kubernetes resource kind. */ kind: string; } interface PlanWorkflowStepEksResourceScalingConfigScalingResource { /** * Kubernetes namespace. */ namespace: string; /** * Resources to scale. See `resources` Block for details. */ resources?: outputs.arcregionswitch.PlanWorkflowStepEksResourceScalingConfigScalingResourceResource[]; } interface PlanWorkflowStepEksResourceScalingConfigScalingResourceResource { /** * Name of the Horizontal Pod Autoscaler. */ hpaName?: string; /** * Name of the Kubernetes object. */ name: string; /** * Kubernetes namespace. */ namespace: string; /** * Name of the resource. */ resourceName: string; } interface PlanWorkflowStepEksResourceScalingConfigUngraceful { /** * Minimum success percentage required. */ minimumSuccessPercentage: number; } interface PlanWorkflowStepExecutionApprovalConfig { /** * ARN of the IAM role for approval. */ approvalRole: string; /** * Timeout in minutes for the approval. */ timeoutMinutes?: number; } interface PlanWorkflowStepGlobalAuroraConfig { /** * Behavior for Aurora operations. Valid values: `switchoverOnly`, `failover`. */ behavior: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * List of database cluster ARNs. */ databaseClusterArns: string[]; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.global_aurora_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepGlobalAuroraConfigUngraceful[]; } interface PlanWorkflowStepGlobalAuroraConfigUngraceful { ungraceful: string; } interface PlanWorkflowStepLambdaEventSourceMappingConfig { /** * Action to perform on the event source mapping. */ action: string; /** * Event source mappings per region. See `regionEventSourceMapping` Block for details. */ regionEventSourceMappings?: outputs.arcregionswitch.PlanWorkflowStepLambdaEventSourceMappingConfigRegionEventSourceMapping[]; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.lambda_event_source_mapping_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepLambdaEventSourceMappingConfigUngraceful[]; } interface PlanWorkflowStepLambdaEventSourceMappingConfigRegionEventSourceMapping { /** * ARN of the event source mapping. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * AWS region. */ region: string; } interface PlanWorkflowStepLambdaEventSourceMappingConfigUngraceful { behavior: string; } interface PlanWorkflowStepNeptuneGlobalDatabaseConfig { /** * Behavior for global database operations. */ behavior: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Map of regions to database cluster ARNs. */ regionDatabaseClusterArns: { [key: string]: string; }; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.neptune_global_database_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepNeptuneGlobalDatabaseConfigUngraceful[]; } interface PlanWorkflowStepNeptuneGlobalDatabaseConfigUngraceful { ungraceful: string; } interface PlanWorkflowStepParallelConfig { /** * Steps to execute in parallel. See `step` Block for details. The parallel step schema matches `step` Block but does not support `parallelConfig` to prevent infinite nesting. */ steps?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStep[]; } interface PlanWorkflowStepParallelConfigStep { /** * Configuration for ARC routing control. See `arcRoutingControlConfig` Block for details. */ arcRoutingControlConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepArcRoutingControlConfig[]; /** * Configuration for Aurora provisioned scaling. See `auroraProvisionedScalingConfig` Block for details. */ auroraProvisionedScalingConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepAuroraProvisionedScalingConfig[]; /** * Configuration for Aurora Serverless scaling. See `auroraServerlessScalingConfig` Block for details. */ auroraServerlessScalingConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepAuroraServerlessScalingConfig[]; /** * Configuration for Lambda function execution. See `customActionLambdaConfig` Block for details. */ customActionLambdaConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepCustomActionLambdaConfig[]; /** * Description of the step. */ description?: string; /** * Configuration for DocumentDB global cluster operations. See `documentDbConfig` Block for details. */ documentDbConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepDocumentDbConfig[]; /** * Configuration for EC2 Auto Scaling group capacity increase. See `ec2AsgCapacityIncreaseConfig` Block for details. */ ec2AsgCapacityIncreaseConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEc2AsgCapacityIncreaseConfig[]; /** * Configuration for ECS service capacity increase. See `ecsCapacityIncreaseConfig` Block for details. */ ecsCapacityIncreaseConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEcsCapacityIncreaseConfig[]; /** * Configuration for EKS resource scaling. See `eksResourceScalingConfig` Block for details. */ eksResourceScalingConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEksResourceScalingConfig[]; /** * Configuration for manual approval steps. See `executionApprovalConfig` Block for details. */ executionApprovalConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepExecutionApprovalConfig[]; /** * Type of execution block. Valid values: `ARCRegionSwitchPlan`, `ARCRoutingControl`, `AuroraGlobalDatabase`, `CustomActionLambda`, `DocumentDb`, `EC2AutoScaling`, `ECSServiceScaling`, `EKSResourceScaling`, `ManualApproval`, `Parallel`, `RdsCreateCrossRegionReplica`, `RdsPromoteReadReplica`, `Route53HealthCheck`. */ executionBlockType: string; /** * Configuration for Aurora Global Database operations. See `globalAuroraConfig` Block for details. */ globalAuroraConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepGlobalAuroraConfig[]; /** * Configuration for Lambda event source mapping operations. See `lambdaEventSourceMappingConfig` Block for details. */ lambdaEventSourceMappingConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepLambdaEventSourceMappingConfig[]; /** * Name of the step. */ name: string; /** * Configuration for Neptune global database operations. See `neptuneGlobalDatabaseConfig` Block for details. */ neptuneGlobalDatabaseConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepNeptuneGlobalDatabaseConfig[]; /** * Configuration for creating cross-region RDS read replicas. See `rdsCreateCrossRegionReadReplicaConfig` Block for details. */ rdsCreateCrossRegionReadReplicaConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepRdsCreateCrossRegionReadReplicaConfig[]; /** * Configuration for promoting RDS read replicas. See `rdsPromoteReadReplicaConfig` Block for details. */ rdsPromoteReadReplicaConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepRdsPromoteReadReplicaConfig[]; /** * Configuration for executing a nested region switch plan. See `regionSwitchPlanConfig` Block for details. */ regionSwitchPlanConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepRegionSwitchPlanConfig[]; /** * Configuration for Route53 health check operations. See `route53HealthCheckConfig` Block for details. */ route53HealthCheckConfigs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepRoute53HealthCheckConfig[]; } interface PlanWorkflowStepParallelConfigStepArcRoutingControlConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Regions and their routing controls. See `regionAndRoutingControls` Block for details. */ regionAndRoutingControls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepArcRoutingControlConfigRegionAndRoutingControl[]; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepArcRoutingControlConfigRegionAndRoutingControl { /** * AWS region. */ region: string; /** * Routing controls. See `routingControl` Block for details. */ routingControls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepArcRoutingControlConfigRegionAndRoutingControlRoutingControl[]; } interface PlanWorkflowStepParallelConfigStepArcRoutingControlConfigRegionAndRoutingControlRoutingControl { /** * ARN of the routing control. */ routingControlArn: string; /** * State of the routing control. Valid values: `On`, `Off`. */ state: string; } interface PlanWorkflowStepParallelConfigStepAuroraProvisionedScalingConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Map of regions to Aurora instance ARNs. */ instanceArns: { [key: string]: string; }; /** * Map of regions to database cluster ARNs. */ regionDatabaseClusterArns: { [key: string]: string; }; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepAuroraServerlessScalingConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Map of regions to database cluster ARNs. */ regionDatabaseClusterArns: { [key: string]: string; }; /** * Target capacity percentage. */ targetPercent?: number; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepCustomActionLambdaConfig { /** * Lambda function configuration. See `lambda` Block for details. */ lambdas?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepCustomActionLambdaConfigLambda[]; /** * Region where the Lambda function should run. Valid values: `activatingRegion`, `deactivatingRegion`. */ regionToRun: string; /** * Retry interval in minutes. */ retryIntervalMinutes: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.custom_action_lambda_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepCustomActionLambdaConfigUngraceful[]; } interface PlanWorkflowStepParallelConfigStepCustomActionLambdaConfigLambda { /** * ARN of the Lambda function. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepParallelConfigStepCustomActionLambdaConfigUngraceful { behavior: string; } interface PlanWorkflowStepParallelConfigStepDocumentDbConfig { /** * Behavior for global cluster operations. Valid values: `switchoverOnly`, `failover`. */ behavior: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * List of DocumentDB cluster ARNs. */ databaseClusterArns: string[]; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.document_db_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepDocumentDbConfigUngraceful[]; } interface PlanWorkflowStepParallelConfigStepDocumentDbConfigUngraceful { ungraceful: string; } interface PlanWorkflowStepParallelConfigStepEc2AsgCapacityIncreaseConfig { /** * Auto Scaling group configuration. See `asg` Block for details. */ asgs?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEc2AsgCapacityIncreaseConfigAsg[]; /** * Capacity monitoring approach. Valid values: `sampledMaxInLast24Hours`, `autoscalingMaxInLast24Hours`. */ capacityMonitoringApproach: string; /** * Target capacity percentage. */ targetPercent?: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.ec2_asg_capacity_increase_config.ungraceful` Block for details. */ ungraceful?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEc2AsgCapacityIncreaseConfigUngraceful; } interface PlanWorkflowStepParallelConfigStepEc2AsgCapacityIncreaseConfigAsg { /** * ARN of the Auto Scaling group. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepParallelConfigStepEc2AsgCapacityIncreaseConfigUngraceful { /** * Minimum success percentage required. */ minimumSuccessPercentage: number; } interface PlanWorkflowStepParallelConfigStepEcsCapacityIncreaseConfig { /** * Capacity monitoring approach. Valid values: `sampledMaxInLast24Hours`, `containerInsightsMaxInLast24Hours`. */ capacityMonitoringApproach: string; /** * ECS service configuration. See `service` Block for details. */ services?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEcsCapacityIncreaseConfigService[]; /** * Target capacity percentage. */ targetPercent?: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.ecs_capacity_increase_config.ungraceful` Block for details. */ ungraceful?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEcsCapacityIncreaseConfigUngraceful; } interface PlanWorkflowStepParallelConfigStepEcsCapacityIncreaseConfigService { /** * ARN of the ECS cluster. */ clusterArn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * ARN of the ECS service. */ serviceArn: string; } interface PlanWorkflowStepParallelConfigStepEcsCapacityIncreaseConfigUngraceful { /** * Minimum success percentage required. */ minimumSuccessPercentage: number; } interface PlanWorkflowStepParallelConfigStepEksResourceScalingConfig { /** * Capacity monitoring approach. Valid values: `sampledMaxInLast24Hours`, `autoscalingMaxInLast24Hours`. */ capacityMonitoringApproach: string; /** * EKS clusters. See `eksClusters` Block for details. */ eksClusters?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEksResourceScalingConfigEksCluster[]; /** * Kubernetes resource type. See `kubernetesResourceType` Block for details. */ kubernetesResourceTypes?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEksResourceScalingConfigKubernetesResourceType[]; /** * Scaling resources. See `scalingResources` Block for details. */ scalingResources?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEksResourceScalingConfigScalingResource[]; /** * Target capacity percentage. */ targetPercent: number; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.eks_resource_scaling_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEksResourceScalingConfigUngraceful[]; } interface PlanWorkflowStepParallelConfigStepEksResourceScalingConfigEksCluster { /** * ARN of the EKS cluster. */ clusterArn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepParallelConfigStepEksResourceScalingConfigKubernetesResourceType { /** * Kubernetes API version. */ apiVersion: string; /** * Kubernetes resource kind. */ kind: string; } interface PlanWorkflowStepParallelConfigStepEksResourceScalingConfigScalingResource { /** * Kubernetes namespace. */ namespace: string; /** * Resources to scale. See `resources` Block for details. */ resources?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepEksResourceScalingConfigScalingResourceResource[]; } interface PlanWorkflowStepParallelConfigStepEksResourceScalingConfigScalingResourceResource { /** * Name of the Horizontal Pod Autoscaler. */ hpaName?: string; /** * Name of the Kubernetes object. */ name: string; /** * Kubernetes namespace. */ namespace: string; /** * Name of the resource. */ resourceName: string; } interface PlanWorkflowStepParallelConfigStepEksResourceScalingConfigUngraceful { /** * Minimum success percentage required. */ minimumSuccessPercentage: number; } interface PlanWorkflowStepParallelConfigStepExecutionApprovalConfig { /** * ARN of the IAM role for approval. */ approvalRole: string; /** * Timeout in minutes for the approval. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepGlobalAuroraConfig { /** * Behavior for Aurora operations. Valid values: `switchoverOnly`, `failover`. */ behavior: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * List of database cluster ARNs. */ databaseClusterArns: string[]; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.global_aurora_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepGlobalAuroraConfigUngraceful[]; } interface PlanWorkflowStepParallelConfigStepGlobalAuroraConfigUngraceful { ungraceful: string; } interface PlanWorkflowStepParallelConfigStepLambdaEventSourceMappingConfig { /** * Action to perform on the event source mapping. */ action: string; /** * Event source mappings per region. See `regionEventSourceMapping` Block for details. */ regionEventSourceMappings?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepLambdaEventSourceMappingConfigRegionEventSourceMapping[]; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.lambda_event_source_mapping_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepLambdaEventSourceMappingConfigUngraceful[]; } interface PlanWorkflowStepParallelConfigStepLambdaEventSourceMappingConfigRegionEventSourceMapping { /** * ARN of the event source mapping. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * AWS region. */ region: string; } interface PlanWorkflowStepParallelConfigStepLambdaEventSourceMappingConfigUngraceful { behavior: string; } interface PlanWorkflowStepParallelConfigStepNeptuneGlobalDatabaseConfig { /** * Behavior for global database operations. */ behavior: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Global cluster identifier. */ globalClusterIdentifier: string; /** * Map of regions to database cluster ARNs. */ regionDatabaseClusterArns: { [key: string]: string; }; /** * Timeout in minutes. */ timeoutMinutes?: number; /** * Ungraceful behavior configuration. See `workflow.step.neptune_global_database_config.ungraceful` Block for details. */ ungracefuls?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepNeptuneGlobalDatabaseConfigUngraceful[]; } interface PlanWorkflowStepParallelConfigStepNeptuneGlobalDatabaseConfigUngraceful { ungraceful: string; } interface PlanWorkflowStepParallelConfigStepRdsCreateCrossRegionReadReplicaConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * Map of source DB instance identifiers to target DB instance ARNs. */ dbInstanceArnMap: { [key: string]: string; }; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepRdsPromoteReadReplicaConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * Map of source DB instance identifiers to target DB instance ARNs. */ dbInstanceArnMap: { [key: string]: string; }; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepRegionSwitchPlanConfig { /** * ARN of the nested region switch plan. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepParallelConfigStepRoute53HealthCheckConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Route53 hosted zone ID. */ hostedZoneId: string; /** * DNS record name. */ recordName: string; /** * Configuration block for record sets. See `recordSet` Block for details. */ recordSets?: outputs.arcregionswitch.PlanWorkflowStepParallelConfigStepRoute53HealthCheckConfigRecordSet[]; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepParallelConfigStepRoute53HealthCheckConfigRecordSet { /** * Record set identifier. */ recordSetIdentifier: string; /** * AWS region. */ region: string; } interface PlanWorkflowStepRdsCreateCrossRegionReadReplicaConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * Map of source DB instance identifiers to target DB instance ARNs. */ dbInstanceArnMap: { [key: string]: string; }; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepRdsPromoteReadReplicaConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * Map of source DB instance identifiers to target DB instance ARNs. */ dbInstanceArnMap: { [key: string]: string; }; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepRegionSwitchPlanConfig { /** * ARN of the nested region switch plan. */ arn: string; /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; } interface PlanWorkflowStepRoute53HealthCheckConfig { /** * ARN of the cross-account role to assume. */ crossAccountRole?: string; /** * External ID for cross-account role assumption. */ externalId?: string; /** * Route53 hosted zone ID. */ hostedZoneId: string; /** * DNS record name. */ recordName: string; /** * Configuration block for record sets. See `recordSet` Block for details. */ recordSets?: outputs.arcregionswitch.PlanWorkflowStepRoute53HealthCheckConfigRecordSet[]; /** * Timeout in minutes. */ timeoutMinutes?: number; } interface PlanWorkflowStepRoute53HealthCheckConfigRecordSet { /** * Record set identifier. */ recordSetIdentifier: string; /** * AWS region. */ region: string; } } export declare namespace arczonalshift { interface ZonalAutoshiftConfigurationBlockingAlarm { /** * ARN of the CloudWatch alarm. */ alarmIdentifier: string; /** * Type of control condition. Valid value: `CLOUDWATCH`. */ type: string; } interface ZonalAutoshiftConfigurationOutcomeAlarm { /** * ARN of the CloudWatch alarm. */ alarmIdentifier: string; /** * Type of control condition. Valid value: `CLOUDWATCH`. */ type: string; } } export declare namespace athena { interface CapacityReservationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DatabaseAclConfiguration { /** * Amazon S3 canned ACL that Athena should specify when storing query results. Valid value is `BUCKET_OWNER_FULL_CONTROL`. * * > **NOTE:** When Athena queries are executed, result files may be created in the specified bucket. Consider using `forceDestroy` on the bucket too in order to avoid any problems when destroying the bucket. */ s3AclOption: string; } interface DatabaseEncryptionConfiguration { /** * Type of key; one of `SSE_S3`, `SSE_KMS`, `CSE_KMS` */ encryptionOption: string; /** * KMS key ARN or ID; required for key types `SSE_KMS` and `CSE_KMS`. */ kmsKey?: string; } interface WorkgroupConfiguration { /** * Integer for the upper data usage limit (cutoff) for the amount of bytes a single query in a workgroup is allowed to scan. Must be at least `10485760`. */ bytesScannedCutoffPerQuery?: number; /** * Configuration block to specify the KMS key that is used to encrypt the user's data stores in Athena. This setting applies to the PySpark engine for Athena notebooks. See Customer Content Encryption Configuration below. */ customerContentEncryptionConfiguration?: outputs.athena.WorkgroupConfigurationCustomerContentEncryptionConfiguration; /** * Boolean indicating whether a minimum level of encryption is enforced for the workgroup for query and calculation results written to Amazon S3. */ enableMinimumEncryptionConfiguration: boolean; /** * Boolean whether the settings for the workgroup override client-side settings. For more information, see [Workgroup Settings Override Client-Side Settings](https://docs.aws.amazon.com/athena/latest/ug/workgroups-settings-override.html). Defaults to `true`. */ enforceWorkgroupConfiguration?: boolean; /** * Configuration block for the Athena Engine Versioning. For more information, see [Athena Engine Versioning](https://docs.aws.amazon.com/athena/latest/ug/engine-versions.html). See Engine Version below. */ engineVersion?: outputs.athena.WorkgroupConfigurationEngineVersion; /** * Role used to access user resources in notebook sessions and IAM Identity Center enabled workgroups. The property is required for IAM Identity Center enabled workgroups. */ executionRole?: string; /** * Configuration block to set up an IAM Identity Center enabled workgroup. See Identity Center Configuration below. */ identityCenterConfiguration?: outputs.athena.WorkgroupConfigurationIdentityCenterConfiguration; /** * Configuration block for storing results in Athena owned storage. See Managed Query Results Configuration below. */ managedQueryResultsConfiguration?: outputs.athena.WorkgroupConfigurationManagedQueryResultsConfiguration; /** * Configuration block for managed log persistence, delivering logs to Amazon S3 buckets, Amazon CloudWatch log groups etc. Only applicable to Apache Spark engine. See Monitoring Configuration below. */ monitoringConfiguration?: outputs.athena.WorkgroupConfigurationMonitoringConfiguration; /** * Boolean whether Amazon CloudWatch metrics are enabled for the workgroup. Defaults to `true`. */ publishCloudwatchMetricsEnabled?: boolean; /** * Configuration block for S3 access grants. See Query Results S3 Access Grants Configuration below. */ queryResultsS3AccessGrantsConfiguration?: outputs.athena.WorkgroupConfigurationQueryResultsS3AccessGrantsConfiguration; /** * If set to true , allows members assigned to a workgroup to reference Amazon S3 Requester Pays buckets in queries. If set to false , workgroup members cannot query data from Requester Pays buckets, and queries that retrieve data from Requester Pays buckets cause an error. The default is false . For more information about Requester Pays buckets, see [Requester Pays Buckets](https://docs.aws.amazon.com/AmazonS3/latest/dev/RequesterPaysBuckets.html) in the S3 Developer Guide. */ requesterPaysEnabled?: boolean; /** * Configuration block with result settings. See Result Configuration below. */ resultConfiguration?: outputs.athena.WorkgroupConfigurationResultConfiguration; } interface WorkgroupConfigurationCustomerContentEncryptionConfiguration { kmsKey?: string; } interface WorkgroupConfigurationEngineVersion { /** * The engine version on which the query runs. If `selectedEngineVersion` is set to `AUTO`, the effective engine version is chosen by Athena. */ effectiveEngineVersion: string; /** * Requested engine version. Defaults to `AUTO`. */ selectedEngineVersion?: string; } interface WorkgroupConfigurationIdentityCenterConfiguration { /** * Specifies whether the workgroup is IAM Identity Center supported. */ enableIdentityCenter?: boolean; /** * The IAM Identity Center instance ARN that the workgroup associates to. */ identityCenterInstanceArn?: string; } interface WorkgroupConfigurationManagedQueryResultsConfiguration { /** * If set to `true`, allows you to store query results in Athena owned storage. If set to `false`, workgroup member stores query results in the location specified under `result_configuration.output_location`. The default is `false`. A workgroup cannot have the `result_configuration.output_location` set when this is `true`. */ enabled?: boolean; /** * Configuration block for the encryption configuration. See Managed Query Results Encryption Configuration below. */ encryptionConfiguration?: outputs.athena.WorkgroupConfigurationManagedQueryResultsConfigurationEncryptionConfiguration; } interface WorkgroupConfigurationManagedQueryResultsConfigurationEncryptionConfiguration { kmsKey?: string; } interface WorkgroupConfigurationMonitoringConfiguration { /** * Configuration block for delivering logs to Amazon CloudWatch log groups. See CloudWatch Logging Configuration below. */ cloudWatchLoggingConfiguration?: outputs.athena.WorkgroupConfigurationMonitoringConfigurationCloudWatchLoggingConfiguration; /** * Configuration block for managed log persistence. See Managed Logging Configuration below. */ managedLoggingConfiguration?: outputs.athena.WorkgroupConfigurationMonitoringConfigurationManagedLoggingConfiguration; /** * Configuration block for delivering logs to Amazon S3 buckets. See S3 Logging Configuration below. */ s3LoggingConfiguration?: outputs.athena.WorkgroupConfigurationMonitoringConfigurationS3LoggingConfiguration; } interface WorkgroupConfigurationMonitoringConfigurationCloudWatchLoggingConfiguration { enabled: boolean; /** * Name of the log group in Amazon CloudWatch Logs where you want to publish your logs. */ logGroup?: string; /** * Prefix for the CloudWatch log stream name. */ logStreamNamePrefix?: string; /** * Repeatable block defining log types to be delivered to CloudWatch. */ logTypes?: outputs.athena.WorkgroupConfigurationMonitoringConfigurationCloudWatchLoggingConfigurationLogType[]; } interface WorkgroupConfigurationMonitoringConfigurationCloudWatchLoggingConfigurationLogType { /** * Type of worker to deliver logs to CloudWatch (for example, `SPARK_DRIVER` and `SPARK_EXECUTOR`). */ key: string; /** * List of log types to be delivered to CloudWatch (for example, `STDOUT` and `STDERR`). */ values: string[]; } interface WorkgroupConfigurationMonitoringConfigurationManagedLoggingConfiguration { /** * Boolean whether managed log persistence is enabled for the workgroup. */ enabled: boolean; kmsKey?: string; } interface WorkgroupConfigurationMonitoringConfigurationS3LoggingConfiguration { /** * Boolean whether Amazon S3 logging is enabled for the workgroup. */ enabled: boolean; /** * KMS key ARN to encrypt the logs published to the given Amazon S3 destination. */ kmsKey?: string; /** * Amazon S3 destination URI (`s3://bucket/prefix`) for log publishing. */ logLocation?: string; } interface WorkgroupConfigurationQueryResultsS3AccessGrantsConfiguration { /** * The authentication type used for Amazon S3 access grants. Currently, only `DIRECTORY_IDENTITY` is supported. */ authenticationType: string; /** * When enabled, appends the user ID as an Amazon S3 path prefix to the query result output location. Defaults to `false`. */ createUserLevelPrefix?: boolean; /** * Specifies whether Amazon S3 access grants are enabled for query results. */ enableS3AccessGrants: boolean; } interface WorkgroupConfigurationResultConfiguration { /** * That an Amazon S3 canned ACL should be set to control ownership of stored query results. See ACL Configuration below. */ aclConfiguration?: outputs.athena.WorkgroupConfigurationResultConfigurationAclConfiguration; /** * Configuration block with encryption settings. See Encryption Configuration below. */ encryptionConfiguration?: outputs.athena.WorkgroupConfigurationResultConfigurationEncryptionConfiguration; /** * AWS account ID that you expect to be the owner of the Amazon S3 bucket. */ expectedBucketOwner?: string; /** * Location in Amazon S3 where your query results are stored, such as `s3://path/to/query/bucket/`. For more information, see [Queries and Query Result Files](https://docs.aws.amazon.com/athena/latest/ug/querying.html). */ outputLocation?: string; } interface WorkgroupConfigurationResultConfigurationAclConfiguration { /** * Amazon S3 canned ACL that Athena should specify when storing query results. Valid value is `BUCKET_OWNER_FULL_CONTROL`. */ s3AclOption: string; } interface WorkgroupConfigurationResultConfigurationEncryptionConfiguration { /** * Whether Amazon S3 server-side encryption with Amazon S3-managed keys (`SSE_S3`), server-side encryption with KMS-managed keys (`SSE_KMS`), or client-side encryption with KMS-managed keys (`CSE_KMS`) is used. If a query runs in a workgroup and the workgroup overrides client-side settings, then the workgroup's setting for encryption is used. It specifies whether query results must be encrypted, for all queries that run in this workgroup. */ encryptionOption?: string; /** * For `SSE_KMS` and `CSE_KMS`, this is the KMS key ARN. */ kmsKeyArn?: string; } } export declare namespace auditmanager { interface AssessmentAssessmentReportsDestination { /** * Destination of the assessment report. This value be in the form `s3://{bucket_name}`. */ destination: string; /** * Destination type. Currently, `S3` is the only valid value. */ destinationType: string; } interface AssessmentRole { /** * ARN of the IAM role. */ roleArn: string; /** * Type of customer persona. For assessment creation, type must always be `PROCESS_OWNER`. */ roleType: string; } interface AssessmentRolesAll { /** * ARN of the IAM role. */ roleArn: string; /** * Type of customer persona. For assessment creation, type must always be `PROCESS_OWNER`. */ roleType: string; } interface AssessmentScope { /** * Amazon Web Services accounts that are in scope for the assessment. See `awsAccounts` below. */ awsAccounts?: outputs.auditmanager.AssessmentScopeAwsAccount[]; /** * Amazon Web Services services that are included in the scope of the assessment. See `awsServices` below. */ awsServices?: outputs.auditmanager.AssessmentScopeAwsService[]; } interface AssessmentScopeAwsAccount { /** * Identifier for the Amazon Web Services account. */ id: string; } interface AssessmentScopeAwsService { /** * Name of the Amazon Web Service. */ serviceName: string; } interface ControlControlMappingSource { /** * Description of the source. */ sourceDescription?: string; /** * Frequency of evidence collection. Valid values are `DAILY`, `WEEKLY`, or `MONTHLY`. */ sourceFrequency?: string; /** * Unique identifier for the source. */ sourceId: string; /** * Keyword to search for in CloudTrail logs, Config rules, Security Hub checks, and Amazon Web Services API names. See `sourceKeyword` below. */ sourceKeyword: outputs.auditmanager.ControlControlMappingSourceSourceKeyword; /** * Name of the source. */ sourceName: string; /** * Setup option for the data source. This option reflects if the evidence collection is automated or manual. Valid values are `System_Controls_Mapping` (automated) and `Procedural_Controls_Mapping` (manual). */ sourceSetUpOption: string; /** * Type of data source for evidence collection. If `sourceSetUpOption` is manual, the only valid value is `MANUAL`. If `sourceSetUpOption` is automated, valid values are `AWS_Cloudtrail`, `AWS_Config`, `AWS_Security_Hub`, or `AWS_API_Call`. * * The following arguments are optional: */ sourceType: string; /** * Instructions for troubleshooting the control. */ troubleshootingText?: string; } interface ControlControlMappingSourceSourceKeyword { /** * Input method for the keyword. Valid values are `INPUT_TEXT`, `SELECT_FROM_LIST`, or `UPLOAD_FILE`. */ keywordInputType: string; /** * Value of the keyword that's used when mapping a control data source. For example, this can be a CloudTrail event name, a rule name for Config, a Security Hub control, or the name of an Amazon Web Services API call. See the [Audit Manager supported control data sources documentation](https://docs.aws.amazon.com/audit-manager/latest/userguide/control-data-sources.html) for more information. */ keywordValue: string; } interface FrameworkControlSet { /** * Configuration block(s) for the controls within the control set. See `controls` Block below for details. */ controls?: outputs.auditmanager.FrameworkControlSetControl[]; /** * Unique identifier for the framework. */ id: string; /** * Name of the control set. */ name: string; } interface FrameworkControlSetControl { /** * Unique identifier of the control. */ id: string; } interface GetControlControlMappingSource { sourceDescription: string; sourceFrequency: string; sourceId: string; sourceKeywords: outputs.auditmanager.GetControlControlMappingSourceSourceKeyword[]; sourceName: string; sourceSetUpOption: string; sourceType: string; troubleshootingText: string; } interface GetControlControlMappingSourceSourceKeyword { keywordInputType: string; keywordValue: string; } interface GetFrameworkControlSet { controls: outputs.auditmanager.GetFrameworkControlSetControl[]; /** * Unique identifier for the framework. */ id: string; /** * Name of the framework. */ name: string; } interface GetFrameworkControlSetControl { /** * Unique identifier for the framework. */ id: string; } } export declare namespace autoscaling { interface GetAmiIdsFilter { /** * Name of the DescribeAutoScalingGroup filter. The recommended values are: `tag-key`, `tag-value`, and `tag:` */ name: string; /** * Value of the filter. */ values: string[]; } interface GetGroupInstanceMaintenancePolicy { /** * Upper limit on the number of instances that are in the InService or Pending state with a healthy status during an instance replacement activity. */ maxHealthyPercentage: number; /** * Lower limit on the number of instances that must be in the InService state with a healthy status during an instance replacement activity. */ minHealthyPercentage: number; } interface GetGroupLaunchTemplate { /** * ID of the launch template. */ id: string; /** * Specify the exact name of the desired autoscaling group. */ name: string; /** * Template version. */ version: string; } interface GetGroupMixedInstancesPolicy { /** * List of instances distribution objects. */ instancesDistributions: outputs.autoscaling.GetGroupMixedInstancesPolicyInstancesDistribution[]; /** * List of launch templates along with the overrides. */ launchTemplates: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplate[]; } interface GetGroupMixedInstancesPolicyInstancesDistribution { /** * Strategy used when launching on-demand instances. */ onDemandAllocationStrategy: string; /** * Absolute minimum amount of desired capacity that must be fulfilled by on-demand instances. */ onDemandBaseCapacity: number; /** * Percentages of On-Demand Instances and Spot Instances for your additional capacity beyond `onDemandBaseCapacity`. */ onDemandPercentageAboveBaseCapacity: number; /** * Strategy used when launching Spot instances. */ spotAllocationStrategy: string; /** * Number of Spot pools per availability zone to allocate capacity. */ spotInstancePools: number; /** * Maximum price per unit hour that the user is willing to pay for the Spot instances. */ spotMaxPrice: string; } interface GetGroupMixedInstancesPolicyLaunchTemplate { /** * List of overriding launch template specification objects. */ launchTemplateSpecifications: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateLaunchTemplateSpecification[]; /** * List of properties overriding the same properties in the launch template. */ overrides: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverride[]; } interface GetGroupMixedInstancesPolicyLaunchTemplateLaunchTemplateSpecification { /** * ID of the launch template. */ launchTemplateId: string; /** * Name of the launch template. */ launchTemplateName: string; /** * Template version. */ version: string; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverride { /** * List of instance requirements objects. */ instanceRequirements: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirement[]; /** * Overriding instance type. */ instanceType: string; /** * List of overriding launch template specification objects. */ launchTemplateSpecifications: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideLaunchTemplateSpecification[]; /** * Number of capacity units, which gives the instance type a proportional weight to other instance types. */ weightedCapacity: string; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirement { /** * List of objects describing the minimum and maximum number of accelerators for an instance type. */ acceleratorCounts: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementAcceleratorCount[]; /** * List of accelerator manufacturer names. */ acceleratorManufacturers: string[]; /** * List of accelerator names. */ acceleratorNames: string[]; /** * List of objects describing the minimum and maximum total memory of the accelerators. */ acceleratorTotalMemoryMibs: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementAcceleratorTotalMemoryMib[]; /** * List of accelerator types. */ acceleratorTypes: string[]; /** * List of instance types to apply the specified attributes against. */ allowedInstanceTypes: string[]; /** * Whether bare metal instances are included, excluded, or required. */ bareMetal: string; /** * List of objects describing the minimum and maximum baseline EBS bandwidth (Mbps). */ baselineEbsBandwidthMbps: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementBaselineEbsBandwidthMbp[]; /** * Whether burstable performance instance types are included, excluded, or required. */ burstablePerformance: string; /** * List of CPU manufacturer names. */ cpuManufacturers: string[]; /** * List of excluded instance types. */ excludedInstanceTypes: string[]; /** * List of instance generation names. */ instanceGenerations: string[]; /** * Whether instance types with instance store volumes are included, excluded, or required. */ localStorage: string; /** * List of local storage type names. */ localStorageTypes: string[]; /** * Price protection threshold for Spot Instances. */ maxSpotPriceAsPercentageOfOptimalOnDemandPrice: number; /** * List of objects describing the minimum and maximum amount of memory (GiB) per vCPU. */ memoryGibPerVcpus: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementMemoryGibPerVcpus[]; /** * List of objects describing the minimum and maximum amount of memory (MiB). */ memoryMibs: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementMemoryMib[]; /** * List of objects describing the minimum and maximum amount of network bandwidth (Gbps). */ networkBandwidthGbps: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementNetworkBandwidthGbp[]; /** * List of objects describing the minimum and maximum amount of network interfaces. */ networkInterfaceCounts: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementNetworkInterfaceCount[]; /** * Price protection threshold for On-Demand Instances. */ onDemandMaxPricePercentageOverLowestPrice: number; /** * Whether instance types must support On-Demand Instance Hibernation. */ requireHibernateSupport: boolean; /** * Price protection threshold for Spot Instances. */ spotMaxPricePercentageOverLowestPrice: number; /** * List of objects describing the minimum and maximum total storage (GB). */ totalLocalStorageGbs: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementTotalLocalStorageGb[]; /** * List of objects describing the minimum and maximum number of vCPUs. */ vcpuCounts: outputs.autoscaling.GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementVcpuCount[]; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementAcceleratorCount { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementAcceleratorTotalMemoryMib { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementBaselineEbsBandwidthMbp { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementMemoryGibPerVcpus { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementMemoryMib { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementNetworkBandwidthGbp { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementNetworkInterfaceCount { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementTotalLocalStorageGb { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementVcpuCount { /** * Maximum. */ max: number; /** * Minimum. */ min: number; } interface GetGroupMixedInstancesPolicyLaunchTemplateOverrideLaunchTemplateSpecification { /** * ID of the launch template. */ launchTemplateId: string; /** * Name of the launch template. */ launchTemplateName: string; /** * Template version. */ version: string; } interface GetGroupTag { /** * Key. */ key: string; /** * Whether the tag is propagated to Amazon EC2 instances launched via this ASG. */ propagateAtLaunch: boolean; /** * Value. */ value: string; } interface GetGroupTrafficSource { /** * Identifier of the traffic source. For Application Load Balancers, Gateway Load Balancers, Network Load Balancers, and VPC Lattice, this will be the ARN for a target group in this account and Region. For Classic Load Balancers, this will be the name of the Classic Load Balancer in this account and Region. */ identifier: string; /** * Traffic source type. */ type: string; } interface GetGroupWarmPool { /** * List of instance reuse policy objects. */ instanceReusePolicies: outputs.autoscaling.GetGroupWarmPoolInstanceReusePolicy[]; /** * Total maximum number of instances that are allowed to be in the warm pool or in any state except Terminated for the Auto Scaling group. */ maxGroupPreparedCapacity: number; /** * Minimum number of instances to maintain in the warm pool. */ minSize: number; /** * Instance state to transition to after the lifecycle actions are complete. */ poolState: string; } interface GetGroupWarmPoolInstanceReusePolicy { /** * Whether instances in the Auto Scaling group can be returned to the warm pool on scale in. */ reuseOnScaleIn: boolean; } interface GroupAvailabilityZoneDistribution { /** * The strategy to use for distributing capacity across the Availability Zones. Valid values are `balanced-only`, `balanced-best-effort`, and `reservations-then-balanced`. Default is `balanced-best-effort`. When `reservations-then-balanced` is set, you must also specify Capacity Reservations to prioritize through `capacityReservationSpecification` (or via a launch template) using a Capacity Reservation ID or Capacity Reservation resource group ARN. */ capacityDistributionStrategy?: string; } interface GroupCapacityReservationSpecification { /** * Capacity Reservation preference helps you use Capacity Reservations efficiently by prioritizing reserved capacity in a Capacity Reservation before using On-Demand capacity. Valid values are `default`, `capacity-reservations-only`, `capacity-reservations-first` and `none`. Default is `default`. */ capacityReservationPreference: string; /** * Describes a target Capacity Reservation or Capacity Reservation resource group. */ capacityReservationTarget?: outputs.autoscaling.GroupCapacityReservationSpecificationCapacityReservationTarget; } interface GroupCapacityReservationSpecificationCapacityReservationTarget { /** * List of On-Demand Capacity Reservation Ids. Conflicts with `capacityReservationResourceGroupArns`. */ capacityReservationIds?: string[]; /** * List of On-Demand Capacity Reservation Resource Group Arns. Conflicts with `capacityReservationIds`. */ capacityReservationResourceGroupArns?: string[]; } interface GroupInitialLifecycleHook { defaultResult: string; heartbeatTimeout?: number; lifecycleTransition: string; /** * Name of the Auto Scaling Group. By default generated by Pulumi. Conflicts with `namePrefix`. */ name: string; notificationMetadata?: string; notificationTargetArn?: string; roleArn?: string; } interface GroupInstanceLifecyclePolicy { /** * Conditions that trigger instance retention behavior. Defined below. */ retentionTriggers: outputs.autoscaling.GroupInstanceLifecyclePolicyRetentionTriggers; } interface GroupInstanceLifecyclePolicyRetentionTriggers { /** * Action to take when a termination lifecycle hook is abandoned due to failure, timeout, or explicit abandonment. Valid values are `retain` and `terminate`. Set to `retain` to move instances to a retained state instead of terminating them. Retained instances don't count toward desired capacity and remain until you terminate them. */ terminateHookAbandon: string; } interface GroupInstanceMaintenancePolicy { /** * Specifies the upper limit on the number of instances that are in the InService or Pending state with a healthy status during an instance replacement activity. */ maxHealthyPercentage: number; /** * Specifies the lower limit on the number of instances that must be in the InService state with a healthy status during an instance replacement activity. */ minHealthyPercentage: number; } interface GroupInstanceRefresh { /** * Override default parameters for Instance Refresh. */ preferences?: outputs.autoscaling.GroupInstanceRefreshPreferences; /** * Strategy to use for instance refresh. The only allowed value is `Rolling`. See [StartInstanceRefresh Action](https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_StartInstanceRefresh.html#API_StartInstanceRefresh_RequestParameters) for more information. */ strategy: string; /** * Set of additional property names that will trigger an Instance Refresh. A refresh will always be triggered by a change in any of `launchConfiguration`, `launchTemplate`, or `mixedInstancesPolicy`. * * > **NOTE:** A refresh is started when any of the following Auto Scaling Group properties change: `launchConfiguration`, `launchTemplate`, `mixedInstancesPolicy`. Additional properties can be specified in the `triggers` property of `instanceRefresh`. * * > **NOTE:** A refresh will not start when `version = "$Latest"` is configured in the `launchTemplate` block. To trigger the instance refresh when a launch template is changed, configure `version` to use the `latestVersion` attribute of the `aws.ec2.LaunchTemplate` resource. * * > **NOTE:** Auto Scaling Groups support up to one active instance refresh at a time. When this resource is updated, any existing refresh is cancelled. * * > **NOTE:** Depending on health check settings and group size, an instance refresh may take a long time or fail. This resource does not wait for the instance refresh to complete. */ triggers?: string[]; } interface GroupInstanceRefreshPreferences { /** * Alarm Specification for Instance Refresh. */ alarmSpecification?: outputs.autoscaling.GroupInstanceRefreshPreferencesAlarmSpecification; /** * Automatically rollback if instance refresh fails. Defaults to `false`. This option may only be set to `true` when specifying a `launchTemplate` or `mixedInstancesPolicy`. */ autoRollback?: boolean; /** * Number of seconds to wait after a checkpoint. Defaults to `3600`. */ checkpointDelay?: string; /** * List of percentages for each checkpoint. Values must be unique and in ascending order. To replace all instances, the final number must be `100`. */ checkpointPercentages?: number[]; /** * Number of seconds until a newly launched instance is configured and ready to use. Default behavior is to use the Auto Scaling Group's health check grace period. */ instanceWarmup?: string; /** * Amount of capacity in the Auto Scaling group that can be in service and healthy, or pending, to support your workload when an instance refresh is in place, as a percentage of the desired capacity of the Auto Scaling group. Values must be between `100` and `200`, defaults to `100`. */ maxHealthyPercentage?: number; /** * Amount of capacity in the Auto Scaling group that must remain healthy during an instance refresh to allow the operation to continue, as a percentage of the desired capacity of the Auto Scaling group. Defaults to `90`. */ minHealthyPercentage?: number; /** * Behavior when encountering instances protected from scale in are found. Available behaviors are `Refresh`, `Ignore`, and `Wait`. Default is `Ignore`. */ scaleInProtectedInstances?: string; /** * Skip replacing instances that already have your desired configuration. Defaults to `false`. */ skipMatching?: boolean; /** * Behavior when encountering instances in the `Standby` state in are found. Available behaviors are `Terminate`, `Ignore`, and `Wait`. Default is `Ignore`. */ standbyInstances?: string; } interface GroupInstanceRefreshPreferencesAlarmSpecification { /** * List of Cloudwatch alarms. If any of these alarms goes into ALARM state, Instance Refresh is failed. */ alarms?: string[]; } interface GroupLaunchTemplate { /** * ID of the launch template. Conflicts with `name`. */ id: string; /** * Name of the launch template. Conflicts with `id`. */ name: string; /** * Template version. Can be version number, `$Latest`, or `$Default`. (Default: `$Default`). */ version: string; } interface GroupMixedInstancesPolicy { /** * Nested argument containing settings on how to mix on-demand and Spot instances in the Auto Scaling group. Defined below. */ instancesDistribution: outputs.autoscaling.GroupMixedInstancesPolicyInstancesDistribution; /** * Nested argument containing launch template settings along with the overrides to specify multiple instance types and weights. Defined below. */ launchTemplate: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplate; } interface GroupMixedInstancesPolicyInstancesDistribution { /** * Strategy to use when launching on-demand instances. Valid values: `prioritized`, `lowest-price`. Default: `prioritized`. */ onDemandAllocationStrategy: string; /** * Absolute minimum amount of desired capacity that must be fulfilled by on-demand instances. Default: `0`. */ onDemandBaseCapacity: number; /** * Percentage split between on-demand and Spot instances above the base on-demand capacity. Default: `100`. */ onDemandPercentageAboveBaseCapacity: number; /** * How to allocate capacity across the Spot pools. Valid values: `lowest-price`, `capacity-optimized`, `capacity-optimized-prioritized`, and `price-capacity-optimized`. Default: `lowest-price`. */ spotAllocationStrategy: string; /** * Number of Spot pools per availability zone to allocate capacity. EC2 Auto Scaling selects the cheapest Spot pools and evenly allocates Spot capacity across the number of Spot pools that you specify. Only available with `spotAllocationStrategy` set to `lowest-price`. Otherwise it must be set to `0`, if it has been defined before. Default: `2`. */ spotInstancePools: number; /** * Maximum price per unit hour that the user is willing to pay for the Spot instances. Default: an empty string which means the on-demand price. */ spotMaxPrice?: string; } interface GroupMixedInstancesPolicyLaunchTemplate { /** * Override the instance launch template specification in the Launch Template. */ launchTemplateSpecification: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateLaunchTemplateSpecification; /** * List of nested arguments provides the ability to specify multiple instance types. This will override the same parameter in the launch template. For on-demand instances, Auto Scaling considers the order of preference of instance types to launch based on the order specified in the overrides list. Defined below. */ overrides: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverride[]; } interface GroupMixedInstancesPolicyLaunchTemplateLaunchTemplateSpecification { /** * ID of the launch template. Conflicts with `launchTemplateName`. */ launchTemplateId: string; /** * Name of the launch template. Conflicts with `launchTemplateId`. */ launchTemplateName: string; version: string; } interface GroupMixedInstancesPolicyLaunchTemplateOverride { /** * Override the instance type in the Launch Template with instance types that satisfy the requirements. */ instanceRequirements?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirements; /** * Override the instance type in the Launch Template. */ instanceType?: string; /** * Override the instance launch template specification in the Launch Template. */ launchTemplateSpecification?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideLaunchTemplateSpecification; /** * Number of capacity units, which gives the instance type a proportional weight to other instance types. */ weightedCapacity?: string; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirements { /** * Block describing the minimum and maximum number of accelerators (GPUs, FPGAs, or AWS Inferentia chips). Default is no minimum or maximum. */ acceleratorCount?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsAcceleratorCount; /** * List of accelerator manufacturer names. Default is any manufacturer. * * ``` * Valid names: * * amazon-web-services * * amd * * nvidia * * xilinx * ``` */ acceleratorManufacturers?: string[]; /** * List of accelerator names. Default is any acclerator. * * ``` * Valid names: * * a100 - NVIDIA A100 GPUs * * v100 - NVIDIA V100 GPUs * * k80 - NVIDIA K80 GPUs * * t4 - NVIDIA T4 GPUs * * m60 - NVIDIA M60 GPUs * * radeon-pro-v520 - AMD Radeon Pro V520 GPUs * * vu9p - Xilinx VU9P FPGAs * ``` */ acceleratorNames?: string[]; /** * Block describing the minimum and maximum total memory of the accelerators. Default is no minimum or maximum. */ acceleratorTotalMemoryMib?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsAcceleratorTotalMemoryMib; /** * List of accelerator types. Default is any accelerator type. * * ``` * Valid types: * * fpga * * gpu * * inference * ``` */ acceleratorTypes?: string[]; /** * List of instance types to apply your specified attributes against. All other instance types are ignored, even if they match your specified attributes. You can use strings with one or more wild cards, represented by an asterisk (\*), to allow an instance type, size, or generation. The following are examples: `m5.8xlarge`, `c5*.*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are allowing the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are allowing all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is all instance types. * * > **NOTE:** If you specify `allowedInstanceTypes`, you can't specify `excludedInstanceTypes`. */ allowedInstanceTypes?: string[]; /** * Indicate whether bare metal instace types should be `included`, `excluded`, or `required`. Default is `excluded`. */ bareMetal?: string; /** * Block describing the minimum and maximum baseline EBS bandwidth, in Mbps. Default is no minimum or maximum. */ baselineEbsBandwidthMbps?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsBaselineEbsBandwidthMbps; /** * Indicate whether burstable performance instance types should be `included`, `excluded`, or `required`. Default is `excluded`. */ burstablePerformance?: string; /** * List of CPU manufacturer names. Default is any manufacturer. * * > **NOTE:** Don't confuse the CPU hardware manufacturer with the CPU hardware architecture. Instances will be launched with a compatible CPU architecture based on the AMI that you specify in your launch template. * * ``` * Valid names: * * amazon-web-services * * amd * * intel * ``` */ cpuManufacturers?: string[]; /** * List of instance types to exclude. You can use strings with one or more wild cards, represented by an asterisk (\*), to exclude an instance type, size, or generation. The following are examples: `m5.8xlarge`, `c5*.*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are excluding the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are excluding all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is no excluded instance types. * * > **NOTE:** If you specify `excludedInstanceTypes`, you can't specify `allowedInstanceTypes`. */ excludedInstanceTypes?: string[]; /** * List of instance generation names. Default is any generation. * * ``` * Valid names: * * current - Recommended for best performance. * * previous - For existing applications optimized for older instance types. * ``` */ instanceGenerations?: string[]; /** * Indicate whether instance types with local storage volumes are `included`, `excluded`, or `required`. Default is `included`. */ localStorage?: string; /** * List of local storage type names. Default any storage type. * * ``` * Value names: * * hdd - hard disk drive * * ssd - solid state drive * ``` */ localStorageTypes?: string[]; /** * The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Conflicts with `spotMaxPricePercentageOverLowestPrice` */ maxSpotPriceAsPercentageOfOptimalOnDemandPrice?: number; /** * Block describing the minimum and maximum amount of memory (GiB) per vCPU. Default is no minimum or maximum. */ memoryGibPerVcpu?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsMemoryGibPerVcpu; /** * Block describing the minimum and maximum amount of memory (MiB). Default is no maximum. */ memoryMib?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsMemoryMib; /** * Block describing the minimum and maximum amount of network bandwidth, in gigabits per second (Gbps). Default is no minimum or maximum. */ networkBandwidthGbps?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsNetworkBandwidthGbps; /** * Block describing the minimum and maximum number of network interfaces. Default is no minimum or maximum. */ networkInterfaceCount?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsNetworkInterfaceCount; /** * Price protection threshold for On-Demand Instances. This is the maximum you’ll pay for an On-Demand Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 20. * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ onDemandMaxPricePercentageOverLowestPrice?: number; /** * Indicate whether instance types must support On-Demand Instance Hibernation, either `true` or `false`. Default is `false`. */ requireHibernateSupport?: boolean; /** * Price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 100. Conflicts with `maxSpotPriceAsPercentageOfOptimalOnDemandPrice` * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ spotMaxPricePercentageOverLowestPrice?: number; /** * Block describing the minimum and maximum total local storage (GB). Default is no minimum or maximum. */ totalLocalStorageGb?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsTotalLocalStorageGb; /** * Block describing the minimum and maximum number of vCPUs. Default is no maximum. */ vcpuCount?: outputs.autoscaling.GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsVcpuCount; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsAcceleratorCount { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsAcceleratorTotalMemoryMib { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsBaselineEbsBandwidthMbps { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsMemoryGibPerVcpu { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsMemoryMib { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsNetworkBandwidthGbps { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsNetworkInterfaceCount { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsTotalLocalStorageGb { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideInstanceRequirementsVcpuCount { max?: number; min?: number; } interface GroupMixedInstancesPolicyLaunchTemplateOverrideLaunchTemplateSpecification { /** * ID of the launch template. Conflicts with `launchTemplateName`. */ launchTemplateId: string; /** * Name of the launch template. Conflicts with `launchTemplateId`. */ launchTemplateName: string; version: string; } interface GroupTag { /** * Key */ key: string; /** * Enables propagation of the tag to * Amazon EC2 instances launched via this ASG * * To declare multiple tags, additional `tag` blocks can be specified. * * > **NOTE:** Other AWS APIs may automatically add special tags to their associated Auto Scaling Group for management purposes, such as ECS Capacity Providers adding the `AmazonECSManaged` tag. These generally should be included in the configuration so the provider does not attempt to remove them and so if the `minSize` was greater than zero on creation, that these tag(s) are applied to any initial EC2 Instances in the Auto Scaling Group. If these tag(s) were missing in the Auto Scaling Group configuration on creation, affected EC2 Instances missing the tags may require manual intervention of adding the tags to ensure they work properly with the other AWS service. */ propagateAtLaunch: boolean; /** * Value */ value: string; } interface GroupTrafficSource { /** * Identifies the traffic source. For Application Load Balancers, Gateway Load Balancers, Network Load Balancers, and VPC Lattice, this will be the ARN for a target group in this account and Region. For Classic Load Balancers, this will be the name of the Classic Load Balancer in this account and Region. */ identifier: string; /** * Provides additional context for the value of Identifier. * The following lists the valid values: * `elb` if `identifier` is the name of a Classic Load Balancer. * `elbv2` if `identifier` is the ARN of an Application Load Balancer, Gateway Load Balancer, or Network Load Balancer target group. * `vpc-lattice` if `identifier` is the ARN of a VPC Lattice target group. */ type?: string; } interface GroupWarmPool { /** * Whether instances in the Auto Scaling group can be returned to the warm pool on scale in. The default is to terminate instances in the Auto Scaling group when the group scales in. */ instanceReusePolicy?: outputs.autoscaling.GroupWarmPoolInstanceReusePolicy; /** * Total maximum number of instances that are allowed to be in the warm pool or in any state except Terminated for the Auto Scaling group. */ maxGroupPreparedCapacity?: number; /** * Minimum number of instances to maintain in the warm pool. This helps you to ensure that there is always a certain number of warmed instances available to handle traffic spikes. Defaults to 0 if not specified. */ minSize?: number; /** * Sets the instance state to transition to after the lifecycle hooks finish. Valid values are: Stopped (default), Running or Hibernated. */ poolState?: string; } interface GroupWarmPoolInstanceReusePolicy { /** * Whether instances in the Auto Scaling group can be returned to the warm pool on scale in. */ reuseOnScaleIn?: boolean; } interface PolicyPredictiveScalingConfiguration { /** * Defines the behavior that should be applied if the forecast capacity approaches or exceeds the maximum capacity of the Auto Scaling group. Valid values are `HonorMaxCapacity` or `IncreaseMaxCapacity`. Default is `HonorMaxCapacity`. */ maxCapacityBreachBehavior?: string; /** * Size of the capacity buffer to use when the forecast capacity is close to or exceeds the maximum capacity. Valid range is `0` to `100`. If set to `0`, Amazon EC2 Auto Scaling may scale capacity higher than the maximum capacity to equal but not exceed forecast capacity. */ maxCapacityBuffer?: string; /** * This structure includes the metrics and target utilization to use for predictive scaling. */ metricSpecification: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecification; /** * Predictive scaling mode. Valid values are `ForecastAndScale` and `ForecastOnly`. Default is `ForecastOnly`. */ mode?: string; /** * Amount of time, in seconds, by which the instance launch time can be advanced. Minimum is `0`. */ schedulingBufferTime?: string; } interface PolicyPredictiveScalingConfigurationMetricSpecification { /** * Customized capacity metric specification. The field is only valid when you use `customizedLoadMetricSpecification` */ customizedCapacityMetricSpecification?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecification; /** * Customized load metric specification. */ customizedLoadMetricSpecification?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecification; /** * Customized scaling metric specification. */ customizedScalingMetricSpecification?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecification; /** * Predefined load metric specification. */ predefinedLoadMetricSpecification?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationPredefinedLoadMetricSpecification; /** * Metric pair specification from which Amazon EC2 Auto Scaling determines the appropriate scaling metric and load metric to use. */ predefinedMetricPairSpecification?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationPredefinedMetricPairSpecification; /** * Predefined scaling metric specification. */ predefinedScalingMetricSpecification?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationPredefinedScalingMetricSpecification; /** * Target value for the metric. */ targetValue: number; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecification { /** * List of up to 10 structures that defines custom capacity metric in predictive scaling policy */ metricDataQueries: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQuery[]; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQuery { /** * Math expression used on the returned metric. You must specify either `expression` or `metricStat`, but not both. */ expression?: string; /** * Short name for the metric used in predictive scaling policy. */ id: string; /** * Human-readable label for this metric or expression. */ label?: string; /** * Structure that defines CloudWatch metric to be used in predictive scaling policy. You must specify either `expression` or `metricStat`, but not both. */ metricStat?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStat; /** * Boolean that indicates whether to return the timestamps and raw data values of this metric, the default is true */ returnData?: boolean; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStat { /** * Structure that defines the CloudWatch metric to return, including the metric name, namespace, and dimensions. */ metric: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetric; /** * Statistic of the metrics to return. */ stat: string; /** * Unit of the metrics to return. */ unit?: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetric { /** * Dimensions of the metric. */ dimensions?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetricDimension[]; /** * Name of the metric. */ metricName: string; /** * Namespace of the metric. */ namespace: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedCapacityMetricSpecificationMetricDataQueryMetricStatMetricDimension { /** * Name of the dimension. */ name: string; /** * Value of the dimension. */ value: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecification { /** * List of up to 10 structures that defines custom load metric in predictive scaling policy */ metricDataQueries: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQuery[]; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQuery { /** * Math expression used on the returned metric. You must specify either `expression` or `metricStat`, but not both. */ expression?: string; /** * Short name for the metric used in predictive scaling policy. */ id: string; /** * Human-readable label for this metric or expression. */ label?: string; /** * Structure that defines CloudWatch metric to be used in predictive scaling policy. You must specify either `expression` or `metricStat`, but not both. */ metricStat?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStat; /** * Boolean that indicates whether to return the timestamps and raw data values of this metric, the default is true */ returnData?: boolean; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStat { /** * Structure that defines the CloudWatch metric to return, including the metric name, namespace, and dimensions. */ metric: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetric; /** * Statistic of the metrics to return. */ stat: string; /** * Unit of the metrics to return. */ unit?: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetric { /** * Dimensions of the metric. */ dimensions?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetricDimension[]; /** * Name of the metric. */ metricName: string; /** * Namespace of the metric. */ namespace: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedLoadMetricSpecificationMetricDataQueryMetricStatMetricDimension { /** * Name of the dimension. */ name: string; /** * Value of the dimension. */ value: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecification { /** * List of up to 10 structures that defines custom scaling metric in predictive scaling policy */ metricDataQueries: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQuery[]; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQuery { /** * Math expression used on the returned metric. You must specify either `expression` or `metricStat`, but not both. */ expression?: string; /** * Short name for the metric used in predictive scaling policy. */ id: string; /** * Human-readable label for this metric or expression. */ label?: string; /** * Structure that defines CloudWatch metric to be used in predictive scaling policy. You must specify either `expression` or `metricStat`, but not both. */ metricStat?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStat; /** * Boolean that indicates whether to return the timestamps and raw data values of this metric, the default is true */ returnData?: boolean; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStat { /** * Structure that defines the CloudWatch metric to return, including the metric name, namespace, and dimensions. */ metric: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetric; /** * Statistic of the metrics to return. */ stat: string; /** * Unit of the metrics to return. */ unit?: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetric { /** * Dimensions of the metric. */ dimensions?: outputs.autoscaling.PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetricDimension[]; /** * Name of the metric. */ metricName: string; /** * Namespace of the metric. */ namespace: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationCustomizedScalingMetricSpecificationMetricDataQueryMetricStatMetricDimension { /** * Name of the dimension. */ name: string; /** * Value of the dimension. */ value: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationPredefinedLoadMetricSpecification { /** * Metric type. Valid values are `ASGTotalCPUUtilization`, `ASGTotalNetworkIn`, `ASGTotalNetworkOut`, or `ALBTargetGroupRequestCount`. */ predefinedMetricType: string; /** * Label that uniquely identifies a specific Application Load Balancer target group from which to determine the request count served by your Auto Scaling group. You create the resource label by appending the final portion of the load balancer ARN and the final portion of the target group ARN into a single value, separated by a forward slash (/). Refer to [PredefinedMetricSpecification](https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_PredefinedMetricSpecification.html) for more information. */ resourceLabel?: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationPredefinedMetricPairSpecification { /** * Which metrics to use. There are two different types of metrics for each metric type: one is a load metric and one is a scaling metric. For example, if the metric type is `ASGCPUUtilization`, the Auto Scaling group's total CPU metric is used as the load metric, and the average CPU metric is used for the scaling metric. Valid values are `ASGCPUUtilization`, `ASGNetworkIn`, `ASGNetworkOut`, or `ALBRequestCount`. */ predefinedMetricType: string; /** * Label that uniquely identifies a specific Application Load Balancer target group from which to determine the request count served by your Auto Scaling group. You create the resource label by appending the final portion of the load balancer ARN and the final portion of the target group ARN into a single value, separated by a forward slash (/). Refer to [PredefinedMetricSpecification](https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_PredefinedMetricSpecification.html) for more information. */ resourceLabel?: string; } interface PolicyPredictiveScalingConfigurationMetricSpecificationPredefinedScalingMetricSpecification { /** * Describes a scaling metric for a predictive scaling policy. Valid values are `ASGAverageCPUUtilization`, `ASGAverageNetworkIn`, `ASGAverageNetworkOut`, or `ALBRequestCountPerTarget`. */ predefinedMetricType: string; /** * Label that uniquely identifies a specific Application Load Balancer target group from which to determine the request count served by your Auto Scaling group. You create the resource label by appending the final portion of the load balancer ARN and the final portion of the target group ARN into a single value, separated by a forward slash (/). Refer to [PredefinedMetricSpecification](https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_PredefinedMetricSpecification.html) for more information. */ resourceLabel?: string; } interface PolicyStepAdjustment { /** * Lower bound for the * difference between the alarm threshold and the CloudWatch metric. * Without a value, AWS will treat this bound as negative infinity. */ metricIntervalLowerBound?: string; /** * Upper bound for the * difference between the alarm threshold and the CloudWatch metric. * Without a value, AWS will treat this bound as positive infinity. The upper bound * must be greater than the lower bound. * * Notice the bounds are **relative** to the alarm threshold, meaning that the starting point is not 0%, but the alarm threshold. Check the official [docs](https://docs.aws.amazon.com/autoscaling/ec2/userguide/as-scaling-simple-step.html#as-scaling-steps) for a detailed example. * * The following arguments are only available to "TargetTrackingScaling" type policies: */ metricIntervalUpperBound?: string; /** * Number of members by which to * scale, when the adjustment bounds are breached. A positive value scales * up. A negative value scales down. */ scalingAdjustment: number; } interface PolicyTargetTrackingConfiguration { /** * Customized metric. Conflicts with `predefinedMetricSpecification`. */ customizedMetricSpecification?: outputs.autoscaling.PolicyTargetTrackingConfigurationCustomizedMetricSpecification; /** * Whether scale in by the target tracking policy is disabled. */ disableScaleIn?: boolean; /** * Predefined metric. Conflicts with `customizedMetricSpecification`. */ predefinedMetricSpecification?: outputs.autoscaling.PolicyTargetTrackingConfigurationPredefinedMetricSpecification; /** * Target value for the metric. */ targetValue: number; } interface PolicyTargetTrackingConfigurationCustomizedMetricSpecification { /** * Dimensions of the metric. */ metricDimensions?: outputs.autoscaling.PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricDimension[]; /** * Name of the metric. */ metricName?: string; /** * Metrics to include, as a metric data query. */ metrics?: outputs.autoscaling.PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetric[]; /** * Namespace of the metric. */ namespace?: string; /** * The period of the metric in seconds. */ period?: number; /** * Statistic of the metric. */ statistic?: string; /** * Unit of the metric. */ unit?: string; } interface PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetric { /** * Math expression used on the returned metric. You must specify either `expression` or `metricStat`, but not both. */ expression?: string; /** * Short name for the metric used in target tracking scaling policy. */ id: string; /** * Human-readable label for this metric or expression. */ label?: string; /** * Structure that defines CloudWatch metric to be used in target tracking scaling policy. You must specify either `expression` or `metricStat`, but not both. */ metricStat?: outputs.autoscaling.PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricMetricStat; /** * Boolean that indicates whether to return the timestamps and raw data values of this metric, the default is true */ returnData?: boolean; } interface PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricDimension { /** * Name of the dimension. */ name: string; /** * Value of the dimension. */ value: string; } interface PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricMetricStat { /** * Structure that defines the CloudWatch metric to return, including the metric name, namespace, and dimensions. */ metric: outputs.autoscaling.PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricMetricStatMetric; /** * The period of the metric in seconds. */ period?: number; /** * Statistic of the metrics to return. */ stat: string; /** * Unit of the metrics to return. */ unit?: string; } interface PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricMetricStatMetric { /** * Dimensions of the metric. */ dimensions?: outputs.autoscaling.PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricMetricStatMetricDimension[]; /** * Name of the metric. */ metricName: string; /** * Namespace of the metric. */ namespace: string; } interface PolicyTargetTrackingConfigurationCustomizedMetricSpecificationMetricMetricStatMetricDimension { /** * Name of the dimension. */ name: string; /** * Value of the dimension. */ value: string; } interface PolicyTargetTrackingConfigurationPredefinedMetricSpecification { /** * Metric type. */ predefinedMetricType: string; /** * Identifies the resource associated with the metric type. */ resourceLabel?: string; } interface TagTag { /** * Tag name. */ key: string; /** * Whether to propagate the tags to instances launched by the ASG. */ propagateAtLaunch: boolean; /** * Tag value. */ value: string; } interface TrafficSourceAttachmentTrafficSource { /** * Identifies the traffic source. For Application Load Balancers, Gateway Load Balancers, Network Load Balancers, and VPC Lattice, this will be the ARN for a target group in this account and Region. For Classic Load Balancers, this will be the name of the Classic Load Balancer in this account and Region. */ identifier: string; /** * Provides additional context for the value of `identifier`. * The following lists the valid values: * `elb` if `identifier` is the name of a Classic Load Balancer. * `elbv2` if `identifier` is the ARN of an Application Load Balancer, Gateway Load Balancer, or Network Load Balancer target group. * `vpc-lattice` if `identifier` is the ARN of a VPC Lattice target group. */ type: string; } } export declare namespace autoscalingplans { interface ScalingPlanApplicationSource { /** * ARN of a AWS CloudFormation stack. */ cloudformationStackArn?: string; /** * Set of tags. */ tagFilters?: outputs.autoscalingplans.ScalingPlanApplicationSourceTagFilter[]; } interface ScalingPlanApplicationSourceTagFilter { /** * Tag key. */ key: string; /** * Tag values. */ values?: string[]; } interface ScalingPlanScalingInstruction { /** * Customized load metric to use for predictive scaling. You must specify either `customizedLoadMetricSpecification` or `predefinedLoadMetricSpecification` when configuring predictive scaling. * More details can be found in the [AWS Auto Scaling API Reference](https://docs.aws.amazon.com/autoscaling/plans/APIReference/API_CustomizedLoadMetricSpecification.html). */ customizedLoadMetricSpecification?: outputs.autoscalingplans.ScalingPlanScalingInstructionCustomizedLoadMetricSpecification; /** * Boolean controlling whether dynamic scaling by AWS Auto Scaling is disabled. Defaults to `false`. */ disableDynamicScaling?: boolean; /** * Maximum capacity of the resource. The exception to this upper limit is if you specify a non-default setting for `predictiveScalingMaxCapacityBehavior`. */ maxCapacity: number; /** * Minimum capacity of the resource. */ minCapacity: number; /** * Predefined load metric to use for predictive scaling. You must specify either `predefinedLoadMetricSpecification` or `customizedLoadMetricSpecification` when configuring predictive scaling. * More details can be found in the [AWS Auto Scaling API Reference](https://docs.aws.amazon.com/autoscaling/plans/APIReference/API_PredefinedLoadMetricSpecification.html). */ predefinedLoadMetricSpecification?: outputs.autoscalingplans.ScalingPlanScalingInstructionPredefinedLoadMetricSpecification; /** * Defines the behavior that should be applied if the forecast capacity approaches or exceeds the maximum capacity specified for the resource. * Valid values: `SetForecastCapacityToMaxCapacity`, `SetMaxCapacityAboveForecastCapacity`, `SetMaxCapacityToForecastCapacity`. */ predictiveScalingMaxCapacityBehavior?: string; /** * Size of the capacity buffer to use when the forecast capacity is close to or exceeds the maximum capacity. */ predictiveScalingMaxCapacityBuffer: number; /** * Predictive scaling mode. Valid values: `ForecastAndScale`, `ForecastOnly`. */ predictiveScalingMode?: string; /** * ID of the resource. This string consists of the resource type and unique identifier. */ resourceId: string; /** * Scalable dimension associated with the resource. Valid values: `autoscaling:autoScalingGroup:DesiredCapacity`, `dynamodb:index:ReadCapacityUnits`, `dynamodb:index:WriteCapacityUnits`, `dynamodb:table:ReadCapacityUnits`, `dynamodb:table:WriteCapacityUnits`, `ecs:service:DesiredCount`, `ec2:spot-fleet-request:TargetCapacity`, `rds:cluster:ReadReplicaCount`. */ scalableDimension: string; /** * Controls whether a resource's externally created scaling policies are kept or replaced. Valid values: `KeepExternalPolicies`, `ReplaceExternalPolicies`. Defaults to `KeepExternalPolicies`. */ scalingPolicyUpdateBehavior?: string; /** * Amount of time, in seconds, to buffer the run time of scheduled scaling actions when scaling out. */ scheduledActionBufferTime?: number; /** * Namespace of the AWS service. Valid values: `autoscaling`, `dynamodb`, `ecs`, `ec2`, `rds`. */ serviceNamespace: string; /** * Structure that defines new target tracking configurations. Each of these structures includes a specific scaling metric and a target value for the metric, along with various parameters to use with dynamic scaling. * More details can be found in the [AWS Auto Scaling API Reference](https://docs.aws.amazon.com/autoscaling/plans/APIReference/API_TargetTrackingConfiguration.html). */ targetTrackingConfigurations: outputs.autoscalingplans.ScalingPlanScalingInstructionTargetTrackingConfiguration[]; } interface ScalingPlanScalingInstructionCustomizedLoadMetricSpecification { /** * Dimensions of the metric. */ dimensions?: { [key: string]: string; }; /** * Name of the metric. */ metricName: string; /** * Namespace of the metric. */ namespace: string; /** * Statistic of the metric. Currently, the value must always be `Sum`. */ statistic: string; /** * Unit of the metric. */ unit?: string; } interface ScalingPlanScalingInstructionPredefinedLoadMetricSpecification { /** * Metric type. Valid values: `ALBTargetGroupRequestCount`, `ASGTotalCPUUtilization`, `ASGTotalNetworkIn`, `ASGTotalNetworkOut`. */ predefinedLoadMetricType: string; /** * Identifies the resource associated with the metric type. */ resourceLabel?: string; } interface ScalingPlanScalingInstructionTargetTrackingConfiguration { /** * Customized metric. You can specify either `customizedScalingMetricSpecification` or `predefinedScalingMetricSpecification`. * More details can be found in the [AWS Auto Scaling API Reference](https://docs.aws.amazon.com/autoscaling/plans/APIReference/API_CustomizedScalingMetricSpecification.html). */ customizedScalingMetricSpecification?: outputs.autoscalingplans.ScalingPlanScalingInstructionTargetTrackingConfigurationCustomizedScalingMetricSpecification; /** * Boolean indicating whether scale in by the target tracking scaling policy is disabled. Defaults to `false`. */ disableScaleIn?: boolean; /** * Estimated time, in seconds, until a newly launched instance can contribute to the CloudWatch metrics. * This value is used only if the resource is an Auto Scaling group. */ estimatedInstanceWarmup?: number; /** * Predefined metric. You can specify either `predefinedScalingMetricSpecification` or `customizedScalingMetricSpecification`. * More details can be found in the [AWS Auto Scaling API Reference](https://docs.aws.amazon.com/autoscaling/plans/APIReference/API_PredefinedScalingMetricSpecification.html). */ predefinedScalingMetricSpecification?: outputs.autoscalingplans.ScalingPlanScalingInstructionTargetTrackingConfigurationPredefinedScalingMetricSpecification; /** * Amount of time, in seconds, after a scale in activity completes before another scale in activity can start. * This value is not used if the scalable resource is an Auto Scaling group. */ scaleInCooldown?: number; /** * Amount of time, in seconds, after a scale-out activity completes before another scale-out activity can start. * This value is not used if the scalable resource is an Auto Scaling group. */ scaleOutCooldown?: number; /** * Target value for the metric. */ targetValue: number; } interface ScalingPlanScalingInstructionTargetTrackingConfigurationCustomizedScalingMetricSpecification { /** * Dimensions of the metric. */ dimensions?: { [key: string]: string; }; /** * Name of the metric. */ metricName: string; /** * Namespace of the metric. */ namespace: string; /** * Statistic of the metric. Valid values: `Average`, `Maximum`, `Minimum`, `SampleCount`, `Sum`. */ statistic: string; /** * Unit of the metric. */ unit?: string; } interface ScalingPlanScalingInstructionTargetTrackingConfigurationPredefinedScalingMetricSpecification { /** * Metric type. Valid values: `ALBRequestCountPerTarget`, `ASGAverageCPUUtilization`, `ASGAverageNetworkIn`, `ASGAverageNetworkOut`, `DynamoDBReadCapacityUtilization`, `DynamoDBWriteCapacityUtilization`, `ECSServiceAverageCPUUtilization`, `ECSServiceAverageMemoryUtilization`, `EC2SpotFleetRequestAverageCPUUtilization`, `EC2SpotFleetRequestAverageNetworkIn`, `EC2SpotFleetRequestAverageNetworkOut`, `RDSReaderAverageCPUUtilization`, `RDSReaderAverageDatabaseConnections`. */ predefinedScalingMetricType: string; /** * Identifies the resource associated with the metric type. */ resourceLabel?: string; } } export declare namespace backup { interface FrameworkControl { /** * One or more input parameter blocks. An example of a control with two parameters is: "backup plan frequency is at least daily and the retention period is at least 1 year". The first parameter is daily. The second parameter is 1 year. Detailed below. */ inputParameters?: outputs.backup.FrameworkControlInputParameter[]; /** * Name of a control. This name is between 1 and 256 characters. */ name: string; /** * Scope of a control. The control scope defines what the control will evaluate. Three examples of control scopes are: a specific backup plan, all backup plans with a specific tag, or all backup plans. Detailed below. */ scope?: outputs.backup.FrameworkControlScope; } interface FrameworkControlInputParameter { /** * Name of a parameter, for example, BackupPlanFrequency. */ name?: string; /** * Value of parameter, for example, hourly. */ value?: string; } interface FrameworkControlScope { /** * ID of the only AWS resource that you want your control scope to contain. Minimum number of 1 item. Maximum number of 100 items. */ complianceResourceIds: string[]; /** * Whether the control scope includes one or more types of resources, such as EFS or RDS. */ complianceResourceTypes: string[]; /** * Tag key-value pair applied to those AWS resources that you want to trigger an evaluation for a rule. A maximum of one key-value pair can be provided. */ tags?: { [key: string]: string; }; } interface GetFrameworkControl { /** * One or more input parameter blocks. An example of a control with two parameters is: "backup plan frequency is at least daily and the retention period is at least 1 year". The first parameter is daily. The second parameter is 1 year. Detailed below. */ inputParameters: outputs.backup.GetFrameworkControlInputParameter[]; /** * Backup framework name. */ name: string; /** * Scope of a control. The control scope defines what the control will evaluate. Three examples of control scopes are: a specific backup plan, all backup plans with a specific tag, or all backup plans. Detailed below. */ scopes: outputs.backup.GetFrameworkControlScope[]; } interface GetFrameworkControlInputParameter { /** * Backup framework name. */ name: string; /** * Value of parameter, for example, hourly. */ value: string; } interface GetFrameworkControlScope { /** * ID of the only AWS resource that you want your control scope to contain. */ complianceResourceIds: string[]; /** * Whether the control scope includes one or more types of resources, such as EFS or RDS. */ complianceResourceTypes: string[]; /** * Tag key-value pair applied to those AWS resources that you want to trigger an evaluation for a rule. A maximum of one key-value pair can be provided. */ tags: { [key: string]: string; }; } interface GetPlanRule { /** * Amount of time in minutes AWS Backup attempts a backup before canceling the job and returning an error. */ completionWindow: number; /** * Configuration block(s) with copy operation settings. See below. */ copyActions: outputs.backup.GetPlanRuleCopyAction[]; /** * Whether AWS Backup creates continuous backups. */ enableContinuousBackup: boolean; /** * Lifecycle defining when a recovery point transitions to cold storage and when it expires. See below. */ lifecycles: outputs.backup.GetPlanRuleLifecycle[]; /** * Metadata that you can assign to help organize the resources that you create. */ recoveryPointTags?: { [key: string]: string; }; /** * Display name of a backup rule. */ ruleName: string; /** * Configuration block(s) with malware scanning settings. See below. */ scanActions: outputs.backup.GetPlanRuleScanAction[]; /** * CRON expression specifying when AWS Backup initiates a backup job. */ schedule: string; /** * Timezone in which the schedule expression is set. */ scheduleExpressionTimezone: string; /** * Amount of time in minutes before beginning a backup. */ startWindow: number; /** * ARN of the logically air-gapped backup vault where the recovery point is copied. */ targetLogicallyAirGappedBackupVaultArn: string; /** * Name of a logical container where backups are stored. */ targetVaultName: string; } interface GetPlanRuleCopyAction { /** * ARN of the destination backup vault for the copied backup. */ destinationVaultArn: string; /** * Lifecycle defining when a recovery point transitions to cold storage and when it expires. See below. */ lifecycles: outputs.backup.GetPlanRuleCopyActionLifecycle[]; } interface GetPlanRuleCopyActionLifecycle { /** * Number of days after creation that a recovery point is moved to cold storage. */ coldStorageAfter: number; /** * Number of days after creation that a recovery point is deleted. */ deleteAfter: number; /** * Whether the recovery point is transitioned to cold storage for supported resource types. */ optInToArchiveForSupportedResources: boolean; } interface GetPlanRuleLifecycle { /** * Number of days after creation that a recovery point is moved to cold storage. */ coldStorageAfter: number; /** * Number of days after creation that a recovery point is deleted. */ deleteAfter: number; /** * Whether the recovery point is transitioned to cold storage for supported resource types. */ optInToArchiveForSupportedResources: boolean; } interface GetPlanRuleScanAction { /** * Malware scanner used for the scan setting. */ malwareScanner: string; /** * Mode of the malware scan. */ scanMode: string; } interface GetPlanScanSetting { /** * Malware scanner used for the scan setting. */ malwareScanner: string; /** * Resource types to scan. */ resourceTypes: string[]; /** * ARN of the IAM role used by the scanner. */ scannerRoleArn: string; } interface GetReportPlanReportDeliveryChannel { /** * List of the format of your reports: CSV, JSON, or both. */ formats: string[]; /** * Unique name of the S3 bucket that receives your reports. */ s3BucketName: string; /** * Prefix for where Backup Audit Manager delivers your reports to Amazon S3. The prefix is this part of the following path: s3://your-bucket-name/prefix/Backup/us-west-2/year/month/day/report-name. */ s3KeyPrefix: string; } interface GetReportPlanReportSetting { /** * List of accounts a report covers. */ accounts: string[]; /** * ARNs of the frameworks a report covers. */ frameworkArns: string[]; /** * Number of frameworks a report covers. */ numberOfFrameworks: number; /** * List of Organizational Units a report covers. */ organizationUnits: string[]; /** * List of regions a report covers. */ regions: string[]; /** * Report template for the report. Reports are built using a report template. */ reportTemplate: string; } interface LogicallyAirGappedVaultTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface PlanAdvancedBackupSetting { /** * Backup option for a selected resource. This option is only available for Windows VSS backup jobs. Set to `{ WindowsVSS = "enabled" }` to enable Windows VSS backup option and create a VSS Windows backup. */ backupOptions: { [key: string]: string; }; /** * Type of AWS resource to be backed up. For VSS Windows backups, the only supported resource type is Amazon EC2. Valid values: `EC2`. */ resourceType: string; } interface PlanRule { /** * Amount of time in minutes AWS Backup attempts a backup before canceling the job and returning an error. */ completionWindow?: number; /** * Configuration block(s) with copy operation settings. Detailed below. */ copyActions?: outputs.backup.PlanRuleCopyAction[]; /** * Enable continuous backups for supported resources. */ enableContinuousBackup?: boolean; /** * Lifecycle that defines when a protected resource is transitioned to cold storage and when it expires. Detailed below. */ lifecycle?: outputs.backup.PlanRuleLifecycle; /** * Metadata that you can assign to help organize the resources that you create. */ recoveryPointTags?: { [key: string]: string; }; /** * Display name for a backup rule. */ ruleName: string; /** * Block for scanning configuration for the backup rule and includes the malware scanner, and scan mode of either full or incremental. Detailed below. */ scanActions?: outputs.backup.PlanRuleScanAction[]; /** * CRON expression specifying when AWS Backup initiates a backup job. */ schedule?: string; /** * Timezone in which the schedule expression is set. Default value: `"Etc/UTC"`. */ scheduleExpressionTimezone?: string; /** * Amount of time in minutes before beginning a backup. */ startWindow?: number; /** * ARN of a logically air-gapped vault. ARN must be in the same account and region. If provided, supported fully managed resources back up directly to logically air-gapped vault, while other supported resources create a temporary (billable) snapshot in backup vault, then copy it to logically air-gapped vault. Unsupported resources only back up to the specified backup vault. */ targetLogicallyAirGappedBackupVaultArn?: string; /** * Name of a logical container where backups are stored. */ targetVaultName: string; } interface PlanRuleCopyAction { /** * ARN that uniquely identifies the destination backup vault for the copied backup. */ destinationVaultArn: string; /** * Lifecycle that defines when a protected resource is copied over to a backup vault and when it expires. Detailed below. */ lifecycle?: outputs.backup.PlanRuleCopyActionLifecycle; } interface PlanRuleCopyActionLifecycle { /** * Number of days after creation that a recovery point is moved to cold storage. */ coldStorageAfter?: number; /** * Number of days after creation that a recovery point is deleted. Must be 90 days greater than `coldStorageAfter`. */ deleteAfter?: number; /** * Whether to transition supported resources to archive (cold) storage tier in accordance with your lifecycle settings. */ optInToArchiveForSupportedResources: boolean; } interface PlanRuleLifecycle { /** * Number of days after creation that a recovery point is moved to cold storage. */ coldStorageAfter?: number; /** * Number of days after creation that a recovery point is deleted. Must be 90 days greater than `coldStorageAfter`. */ deleteAfter?: number; /** * Whether to transition supported resources to archive (cold) storage tier in accordance with your lifecycle settings. */ optInToArchiveForSupportedResources: boolean; } interface PlanRuleScanAction { /** * Malware scanner to use for the scan action. Currently only `GUARDDUTY` is supported. */ malwareScanner: string; /** * Scanning mode to use for the scan action. Valid values are `FULL_SCAN` and `INCREMENTAL_SCAN`. */ scanMode: string; } interface PlanScanSetting { /** * Malware scanner to use for the scan setting. Currently only `GUARDDUTY` is supported. */ malwareScanner: string; /** * List of resource types to apply the scan setting to. Valid values are `EBS`, `EC2`, `S3` and `ALL`. */ resourceTypes: string[]; /** * ARN of the IAM role that AWS Backup uses to scan resources. See [the AWS documentation](https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection-backup-iam-permissions.html) for details. */ scannerRoleArn: string; } interface ReportPlanReportDeliveryChannel { /** * List of the format of your reports: CSV, JSON, or both. If not specified, the default format is CSV. */ formats?: string[]; /** * Unique name of the S3 bucket that receives your reports. */ s3BucketName: string; /** * Prefix for where Backup Audit Manager delivers your reports to Amazon S3. The prefix is this part of the following path: s3://your-bucket-name/prefix/Backup/us-west-2/year/month/day/report-name. If not specified, there is no prefix. */ s3KeyPrefix?: string; } interface ReportPlanReportSetting { /** * List of accounts a report covers. */ accounts?: string[]; /** * ARNs of the frameworks a report covers. */ frameworkArns?: string[]; /** * Number of frameworks a report covers. */ numberOfFrameworks?: number; /** * List of Organizational Units a report covers. */ organizationUnits?: string[]; /** * List of regions a report covers. */ regions?: string[]; /** * Report template for the report. Reports are built using a report template. The report templates are: `RESOURCE_COMPLIANCE_REPORT` | `CONTROL_COMPLIANCE_REPORT` | `BACKUP_JOB_REPORT` | `COPY_JOB_REPORT` | `RESTORE_JOB_REPORT`. */ reportTemplate: string; } interface RestoreTestingPlanRecoveryPointSelection { /** * Algorithm used for selecting recovery points. Valid values are `RANDOM_WITHIN_WINDOW` and `LATEST_WITHIN_WINDOW`. */ algorithm: string; /** * Backup vaults to exclude from the recovery point selection. Each value must be a valid AWS ARN for a backup vault or `*` to exclude all backup vaults. */ excludeVaults: string[]; /** * Backup vaults to include in the recovery point selection. Each value must be a valid AWS ARN for a backup vault or `*` to include all backup vaults. */ includeVaults: string[]; /** * Types of recovery points to include in the selection. Valid values are `CONTINUOUS` and `SNAPSHOT`. */ recoveryPointTypes: string[]; /** * Number of days within which the recovery points should be selected. Must be a value between 1 and 365. */ selectionWindowDays: number; } interface RestoreTestingSelectionProtectedResourceConditions { /** * List of string equals conditions for resource tags. Filters the values of your tagged resources for only those resources that you tagged with the same value. Also called "exact matching.". See `stringEquals` below. */ stringEquals?: outputs.backup.RestoreTestingSelectionProtectedResourceConditionsStringEqual[]; /** * List of string not equals conditions for resource tags. Filters the values of your tagged resources for only those resources that you tagged that do not have the same value. Also called "negated matching.". See `stringNotEquals` below. */ stringNotEquals?: outputs.backup.RestoreTestingSelectionProtectedResourceConditionsStringNotEqual[]; } interface RestoreTestingSelectionProtectedResourceConditionsStringEqual { /** * Tag name, must start with one of the following prefixes: [aws:ResourceTag/] with a Minimum length of 1. Maximum length of 128, and can contain characters that are letters, white space, and numbers that can be represented in UTF-8 and the following characters: `+ - = . _ : /`. */ key: string; /** * Value of the Tag. Maximum length of 256. */ value: string; } interface RestoreTestingSelectionProtectedResourceConditionsStringNotEqual { /** * Tag name, must start with one of the following prefixes: [aws:ResourceTag/] with a Minimum length of 1. Maximum length of 128, and can contain characters that are letters, white space, and numbers that can be represented in UTF-8 and the following characters: `+ - = . _ : /`. */ key: string; /** * Value of the Tag. Maximum length of 256. */ value: string; } interface SelectionCondition { /** * Filters the values of your tagged resources for only those resources that you tagged with the same value. Also called "exact matching". See below for details. */ stringEquals?: outputs.backup.SelectionConditionStringEqual[]; /** * Filters the values of your tagged resources for matching tag values with the use of a wildcard character (`*`) anywhere in the string. For example, `prod*` or `*rod*` matches the tag value `production`. See below for details. */ stringLikes?: outputs.backup.SelectionConditionStringLike[]; /** * Filters the values of your tagged resources for only those resources that you tagged that do not have the same value. Also called "negated matching". See below for details. */ stringNotEquals?: outputs.backup.SelectionConditionStringNotEqual[]; /** * Filters the values of your tagged resources for non-matching tag values with the use of a wildcard character (`*`) anywhere in the string. See below for details. */ stringNotLikes?: outputs.backup.SelectionConditionStringNotLike[]; } interface SelectionConditionStringEqual { /** * Key for the filter. */ key: string; /** * Value for the filter. */ value: string; } interface SelectionConditionStringLike { /** * Key for the filter. */ key: string; /** * Value for the filter. */ value: string; } interface SelectionConditionStringNotEqual { /** * Key for the filter. */ key: string; /** * Value for the filter. */ value: string; } interface SelectionConditionStringNotLike { /** * Key for the filter. */ key: string; /** * Value for the filter. */ value: string; } interface SelectionSelectionTag { /** * Key for the filter. */ key: string; /** * Operation, such as `STRINGEQUALS`, that is applied to the key-value pair used to filter resources in a selection. */ type: string; /** * Value for the filter. */ value: string; } } export declare namespace batch { interface ComputeEnvironmentComputeResources { /** * Allocation strategy to use for the compute resource in case not enough instances of the best fitting instance type can be allocated. For valid values, refer to the [AWS documentation](https://docs.aws.amazon.com/batch/latest/APIReference/API_ComputeResource.html#Batch-Type-ComputeResource-allocationStrategy). Defaults to `BEST_FIT`. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ allocationStrategy?: string; /** * Integer of maximum percentage that a Spot Instance price can be when compared with the On-Demand price for that instance type before instances are launched. For example, if your bid percentage is 20% (`20`), then the Spot price must be below 20% of the current On-Demand price for that EC2 instance. If you leave this field empty, the default value is 100% of the On-Demand price. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ bidPercentage?: number; /** * Desired number of EC2 vCPUS in the compute environment. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ desiredVcpus: number; /** * Provides information used to select AMIs for EC2 instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2. This parameter isn't applicable to jobs that are running on Fargate resources, and shouldn't be specified. */ ec2Configurations: outputs.batch.ComputeEnvironmentComputeResourcesEc2Configuration[]; /** * EC2 key pair that is used for instances launched in the compute environment. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ ec2KeyPair?: string; /** * AMI ID used for instances launched in the compute environment. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. (Deprecated, use `ec2Configuration` `imageIdOverride` instead) */ imageId?: string; /** * Amazon ECS instance role applied to Amazon EC2 instances in a compute environment. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ instanceRole?: string; /** * List of instance types that may be launched. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ instanceTypes?: string[]; /** * Launch template to use for your compute resources. See details below. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ launchTemplate?: outputs.batch.ComputeEnvironmentComputeResourcesLaunchTemplate; /** * Maximum number of EC2 vCPUs that an environment can reach. */ maxVcpus: number; /** * Minimum number of EC2 vCPUs that an environment should maintain. For `EC2` or `SPOT` compute environments, if the parameter is not explicitly defined, a `0` default value will be set. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ minVcpus?: number; /** * Amazon EC2 placement group to associate with your compute resources. */ placementGroup?: string; /** * List of EC2 security group that are associated with instances launched in the compute environment. This parameter is required for Fargate compute environments. */ securityGroupIds?: string[]; /** * ARN of the Amazon EC2 Spot Fleet IAM role applied to a SPOT compute environment. This parameter is required for SPOT compute environments. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ spotIamFleetRole?: string; /** * List of VPC subnets into which the compute resources are launched. */ subnets: string[]; /** * Key-value pair tags to be applied to resources that are launched in the compute environment. This parameter isn't applicable to jobs running on Fargate resources, and shouldn't be specified. */ tags?: { [key: string]: string; }; /** * Type of compute environment. Valid items are `EC2`, `SPOT`, `FARGATE` or `FARGATE_SPOT`. */ type: string; } interface ComputeEnvironmentComputeResourcesEc2Configuration { /** * AMI ID used for instances launched in the compute environment that match the image type. This setting overrides the `imageId` argument in the `computeResources` block. */ imageIdOverride: string; /** * Kubernetes version for the compute environment. If you don't specify a value, the latest version that AWS Batch supports is used. See [Supported Kubernetes versions](https://docs.aws.amazon.com/batch/latest/userguide/supported_kubernetes_version.html) for the list of Kubernetes versions supported by AWS Batch on Amazon EKS. */ imageKubernetesVersion?: string; /** * Image type to match with the instance type to select an AMI. If the `imageIdOverride` parameter isn't specified, then a recent [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) (`ECS_AL2`) is used. */ imageType?: string; } interface ComputeEnvironmentComputeResourcesLaunchTemplate { /** * ID of the launch template. You must specify either the launch template ID or launch template name in the request, but not both. */ launchTemplateId?: string; /** * Name of the launch template. */ launchTemplateName?: string; /** * Version number of the launch template. Default: The default version of the launch template. */ version: string; } interface ComputeEnvironmentEksConfiguration { /** * ARN of the Amazon EKS cluster. */ eksClusterArn: string; /** * Namespace of the Amazon EKS cluster. AWS Batch manages pods in this namespace. */ kubernetesNamespace: string; } interface ComputeEnvironmentUpdatePolicy { /** * Job timeout (in minutes) when the compute environment infrastructure is updated. */ jobExecutionTimeoutMinutes: number; /** * Whether jobs are automatically terminated when the compute environment infrastructure is updated. */ terminateJobsOnUpdate: boolean; } interface GetComputeEnvironmentUpdatePolicy { /** * Time, in minutes, that a job can run before the compute environment infrastructure is updated. */ jobExecutionTimeoutMinutes: number; /** * Whether running jobs are terminated when the compute environment infrastructure is updated. */ terminateJobsOnUpdate: boolean; } interface GetJobDefinitionEksProperty { /** * Properties for the Kubernetes pod resources of a job. See `podProperties` below. */ podProperties: outputs.batch.GetJobDefinitionEksPropertyPodProperty[]; } interface GetJobDefinitionEksPropertyPodProperty { /** * Properties of the container that's used on the Amazon EKS pod. See `containers` below. */ containers: outputs.batch.GetJobDefinitionEksPropertyPodPropertyContainer[]; /** * DNS policy for the pod. The default value is ClusterFirst. If the hostNetwork parameter is not specified, the default is ClusterFirstWithHostNet. ClusterFirst indicates that any DNS query that does not match the configured cluster domain suffix is forwarded to the upstream nameserver inherited from the node. */ dnsPolicy: string; /** * Whether the pod uses the hosts' network IP address. The default value is true. Setting this to false enables the Kubernetes pod networking model. Most AWS Batch workloads are egress-only and don't require the overhead of IP allocation for each pod for incoming connections. */ hostNetwork: boolean; /** * List of Kubernetes secret resources. See `imagePullSecrets` below. */ imagePullSecrets: outputs.batch.GetJobDefinitionEksPropertyPodPropertyImagePullSecret[]; /** * Containers which run before application containers, always runs to completion, and must complete successfully before the next container starts. These containers are registered with the Amazon EKS Connector agent and persists the registration information in the Kubernetes backend data store. See `initContainers` below. */ initContainers: outputs.batch.GetJobDefinitionEksPropertyPodPropertyInitContainer[]; /** * Metadata about the Kubernetes pod. See `metadata` below. */ metadatas: outputs.batch.GetJobDefinitionEksPropertyPodPropertyMetadata[]; /** * Name of the service account that's used to run the pod. */ serviceAccountName: string; /** * Whether the processes in a container are shared, or visible, to other containers in the same pod. */ shareProcessNamespace: boolean; /** * List of data volumes used in a job. See `volumes` below. */ volumes: outputs.batch.GetJobDefinitionEksPropertyPodPropertyVolume[]; } interface GetJobDefinitionEksPropertyPodPropertyContainer { /** * Array of arguments to the entrypoint. */ args: string[]; /** * Command that's passed to the container. */ commands: string[]; /** * Environment variables to pass to a container. See `env` below. */ envs: outputs.batch.GetJobDefinitionEksPropertyPodPropertyContainerEnv[]; /** * Image used to start a container. */ image: string; /** * Image pull policy for the container. */ imagePullPolicy: string; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Type and amount of resources to assign to a container. See `resources` below. */ resources: outputs.batch.GetJobDefinitionEksPropertyPodPropertyContainerResource[]; /** * Security context for a job. See `securityContext` below. */ securityContexts: outputs.batch.GetJobDefinitionEksPropertyPodPropertyContainerSecurityContext[]; /** * Volume mounts for the container. See `volumeMounts` below. */ volumeMounts: outputs.batch.GetJobDefinitionEksPropertyPodPropertyContainerVolumeMount[]; } interface GetJobDefinitionEksPropertyPodPropertyContainerEnv { /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Quantity of the specified resource to reserve for the container. */ value: string; } interface GetJobDefinitionEksPropertyPodPropertyContainerResource { /** * Type and quantity of the resources to reserve for the container. */ limits: { [key: string]: string; }; /** * Type and quantity of the resources to request for the container. */ requests: { [key: string]: string; }; } interface GetJobDefinitionEksPropertyPodPropertyContainerSecurityContext { /** * Whether or not a container or a Kubernetes pod is allowed to gain more privileges than its parent process. The default value is `false`. */ allowPrivilegeEscalation: boolean; /** * When this parameter is true, the container is given elevated permissions on the host container instance (similar to the root user). */ privileged: boolean; /** * When this parameter is `true`, the container is given read-only access to its root file system. The default value is `false`. */ readOnlyRootFileSystem: boolean; /** * When this parameter is specified, the container is run as the specified group ID (gid). If this parameter isn't specified, the default is the group that's specified in the image metadata. */ runAsGroup: number; /** * When this parameter is specified, the container is run as a user with a uid other than 0. If this parameter isn't specified, so such rule is enforced. */ runAsNonRoot: boolean; /** * When this parameter is specified, the container is run as the specified user ID (uid). If this parameter isn't specified, the default is the user that's specified in the image metadata. */ runAsUser: number; } interface GetJobDefinitionEksPropertyPodPropertyContainerVolumeMount { /** * Path on the container where the volume is mounted. */ mountPath: string; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * If this value is true, the container has read-only access to the volume. */ readOnly: boolean; } interface GetJobDefinitionEksPropertyPodPropertyImagePullSecret { /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; } interface GetJobDefinitionEksPropertyPodPropertyInitContainer { /** * Array of arguments to the entrypoint. */ args: string[]; /** * Command that's passed to the container. */ commands: string[]; /** * Environment variables to pass to a container. See `env` below. */ envs: outputs.batch.GetJobDefinitionEksPropertyPodPropertyInitContainerEnv[]; /** * Image used to start a container. */ image: string; /** * Image pull policy for the container. */ imagePullPolicy: string; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Type and amount of resources to assign to a container. See `resources` below. */ resources: outputs.batch.GetJobDefinitionEksPropertyPodPropertyInitContainerResource[]; /** * Security context for a job. See `securityContext` below. */ securityContexts: outputs.batch.GetJobDefinitionEksPropertyPodPropertyInitContainerSecurityContext[]; /** * Volume mounts for the container. See `volumeMounts` below. */ volumeMounts: outputs.batch.GetJobDefinitionEksPropertyPodPropertyInitContainerVolumeMount[]; } interface GetJobDefinitionEksPropertyPodPropertyInitContainerEnv { /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Quantity of the specified resource to reserve for the container. */ value: string; } interface GetJobDefinitionEksPropertyPodPropertyInitContainerResource { /** * Type and quantity of the resources to reserve for the container. */ limits: { [key: string]: string; }; /** * Type and quantity of the resources to request for the container. */ requests: { [key: string]: string; }; } interface GetJobDefinitionEksPropertyPodPropertyInitContainerSecurityContext { /** * Whether or not a container or a Kubernetes pod is allowed to gain more privileges than its parent process. The default value is `false`. */ allowPrivilegeEscalation: boolean; /** * When this parameter is true, the container is given elevated permissions on the host container instance (similar to the root user). */ privileged: boolean; /** * When this parameter is `true`, the container is given read-only access to its root file system. The default value is `false`. */ readOnlyRootFileSystem: boolean; /** * When this parameter is specified, the container is run as the specified group ID (gid). If this parameter isn't specified, the default is the group that's specified in the image metadata. */ runAsGroup: number; /** * When this parameter is specified, the container is run as a user with a uid other than 0. If this parameter isn't specified, so such rule is enforced. */ runAsNonRoot: boolean; /** * When this parameter is specified, the container is run as the specified user ID (uid). If this parameter isn't specified, the default is the user that's specified in the image metadata. */ runAsUser: number; } interface GetJobDefinitionEksPropertyPodPropertyInitContainerVolumeMount { /** * Path on the container where the volume is mounted. */ mountPath: string; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * If this value is true, the container has read-only access to the volume. */ readOnly: boolean; } interface GetJobDefinitionEksPropertyPodPropertyMetadata { /** * Key-value pairs used to identify, sort, and organize cube resources. */ labels: { [key: string]: string; }; } interface GetJobDefinitionEksPropertyPodPropertyVolume { /** * Configuration of a Kubernetes emptyDir volume. See `emptyDir` below. */ emptyDirs: outputs.batch.GetJobDefinitionEksPropertyPodPropertyVolumeEmptyDir[]; /** * Path for the device on the host container instance. */ hostPaths: outputs.batch.GetJobDefinitionEksPropertyPodPropertyVolumeHostPath[]; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Configuration of a Kubernetes secret volume. See `secret` below. */ secrets: outputs.batch.GetJobDefinitionEksPropertyPodPropertyVolumeSecret[]; } interface GetJobDefinitionEksPropertyPodPropertyVolumeEmptyDir { /** * Medium to store the volume. */ medium: string; /** * Maximum size of the volume. By default, there's no maximum size defined. */ sizeLimit: string; } interface GetJobDefinitionEksPropertyPodPropertyVolumeHostPath { /** * Path of the file or directory on the host to mount into containers on the pod. */ path: string; } interface GetJobDefinitionEksPropertyPodPropertyVolumeSecret { /** * Whether the secret or the secret's keys must be defined. */ optional: boolean; /** * Name of the secret. The name must be allowed as a DNS subdomain name. */ secretName: string; } interface GetJobDefinitionNodeProperty { /** * Node index for the main node of a multi-node parallel job. This node index value must be fewer than the number of nodes. */ mainNode: number; /** * List of node ranges and their properties that are associated with a multi-node parallel job. See `nodeRangeProperties` below. */ nodeRangeProperties: outputs.batch.GetJobDefinitionNodePropertyNodeRangeProperty[]; /** * Number of nodes that are associated with a multi-node parallel job. */ numNodes: number; } interface GetJobDefinitionNodePropertyNodeRangeProperty { /** * Container details for the node range. See `container` below. */ containers: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainer[]; /** * Range of nodes, using node index values. A range of 0:3 indicates nodes with index values of 0 through 3. */ targetNodes: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainer { /** * Command that's passed to the container. */ commands: string[]; /** * Environment variables to pass to a container. See `environment` below. */ environments: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerEnvironment[]; /** * Amount of ephemeral storage to allocate for the task. This parameter is used to expand the total amount of ephemeral storage available, beyond the default amount, for tasks hosted on AWS Fargate. See `ephemeralStorage` below. */ ephemeralStorages: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerEphemeralStorage[]; /** * ARN of the execution role that AWS Batch can assume. For jobs that run on Fargate resources, you must provide an execution role. */ executionRoleArn: string; /** * Platform configuration for jobs that are running on Fargate resources. Jobs that are running on EC2 resources must not specify this parameter. See `fargatePlatformConfiguration` below. */ fargatePlatformConfigurations: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerFargatePlatformConfiguration[]; /** * Image used to start a container. */ image: string; /** * Instance type to use for a multi-node parallel job. */ instanceType: string; /** * ARN of the IAM role that the container can assume for AWS permissions. */ jobRoleArn: string; /** * Linux-specific modifications that are applied to the container. See `linuxParameters` below. */ linuxParameters: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerLinuxParameter[]; /** * Log configuration specification for the container. See `logConfiguration` below. */ logConfigurations: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerLogConfiguration[]; /** * Mount points for data volumes in your container. See `mountPoints` below. */ mountPoints: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerMountPoint[]; /** * Network configuration for jobs that are running on Fargate resources. See `networkConfiguration` below. */ networkConfigurations: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerNetworkConfiguration[]; /** * When this parameter is true, the container is given elevated permissions on the host container instance (similar to the root user). */ privileged: boolean; /** * When this parameter is true, the container is given read-only access to its root file system. */ readonlyRootFilesystem: boolean; /** * Type and amount of resources to assign to a container. See `resourceRequirements` below. */ resourceRequirements: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerResourceRequirement[]; /** * Compute environment architecture for AWS Batch jobs on Fargate. See `runtimePlatform` below. */ runtimePlatforms: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerRuntimePlatform[]; /** * Secrets for the container. See `secrets` below. */ secrets: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerSecret[]; /** * List of ulimits to set in the container. See `ulimits` below. */ ulimits: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerUlimit[]; /** * User name to use inside the container. */ user: string; /** * List of data volumes used in a job. See `volumes` below. */ volumes: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerVolume[]; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerEnvironment { /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Quantity of the specified resource to reserve for the container. */ value: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerEphemeralStorage { /** * Total amount, in GiB, of ephemeral storage to set for the task. */ sizeInGib: number; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerFargatePlatformConfiguration { /** * AWS Fargate platform version where the jobs are running. A platform version is specified only for jobs that are running on Fargate resources. */ platformVersion: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerLinuxParameter { /** * Host devices to expose to the container. See `devices` below. */ devices: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerLinuxParameterDevice[]; /** * If true, run an init process inside the container that forwards signals and reaps processes. */ initProcessEnabled: boolean; /** * Total amount of swap memory (in MiB) a container can use. */ maxSwap: number; /** * Value for the size (in MiB) of the `/dev/shm` volume. */ sharedMemorySize: number; /** * Value used to tune a container's memory swappiness behavior. */ swappiness: number; /** * Container path, mount options, and size (in MiB) of the tmpfs mount. See `tmpfs` below. */ tmpfs: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerLinuxParameterTmpf[]; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerLinuxParameterDevice { /** * Path on the container where the host volume is mounted. */ containerPath: string; /** * Path for the device on the host container instance. */ hostPath: string; /** * Explicit permissions to provide to the container for the device. */ permissions: string[]; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerLinuxParameterTmpf { /** * Path on the container where the host volume is mounted. */ containerPath: string; /** * List of tmpfs volume mount options. */ mountOptions: string[]; /** * Size (in MiB) of the tmpfs volume. */ size: number; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerLogConfiguration { /** * Log driver to use for the container. */ logDriver: string; /** * Configuration options to send to the log driver. */ options: { [key: string]: string; }; /** * Secrets to pass to the log configuration. See `secretOptions` below. */ secretOptions: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerLogConfigurationSecretOption[]; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerLogConfigurationSecretOption { /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Secret to expose to the container. */ valueFrom: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerMountPoint { /** * Path on the container where the host volume is mounted. */ containerPath: string; /** * If this value is true, the container has read-only access to the volume. */ readOnly: boolean; /** * Name of the volume to mount. */ sourceVolume: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerNetworkConfiguration { /** * Whether the job has a public IP address. */ assignPublicIp: boolean; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerResourceRequirement { /** * Type of resource to assign to a container. The supported resources include `GPU`, `MEMORY`, and `VCPU`. */ type: string; /** * Quantity of the specified resource to reserve for the container. */ value: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerRuntimePlatform { /** * vCPU architecture. The default value is X86_64. Valid values are X86_64 and ARM64. */ cpuArchitecture: string; /** * Operating system for the compute environment. */ operatingSystemFamily: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerSecret { /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Secret to expose to the container. */ valueFrom: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerUlimit { /** * Hard limit for the ulimit type. */ hardLimit: number; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; /** * Soft limit for the ulimit type. */ softLimit: number; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerVolume { /** * Amazon Elastic File System configuration for job storage. See `efsVolumeConfiguration` below. */ efsVolumeConfigurations: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerVolumeEfsVolumeConfiguration[]; /** * Contents of the host parameter determine whether your data volume persists on the host container instance and where it's stored. See `host` below. */ hosts: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerVolumeHost[]; /** * Name of the job definition to register. It can be up to 128 letters long. It can contain uppercase and lowercase letters, numbers, hyphens (-), and underscores (_). */ name: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerVolumeEfsVolumeConfiguration { /** * Authorization configuration details for the Amazon EFS file system. See `authorizationConfig` below. */ authorizationConfigs: outputs.batch.GetJobDefinitionNodePropertyNodeRangePropertyContainerVolumeEfsVolumeConfigurationAuthorizationConfig[]; /** * Amazon EFS file system ID to use. */ fileSystemId: string; /** * Directory within the Amazon EFS file system to mount as the root directory inside the host. */ rootDirectory: string; /** * Whether to enable encryption for Amazon EFS data in transit between the Amazon ECS host and the Amazon EFS server. */ transitEncryption: string; /** * Port to use when sending encrypted data between the Amazon ECS host and the Amazon EFS server. */ transitEncryptionPort: number; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerVolumeEfsVolumeConfigurationAuthorizationConfig { /** * Amazon EFS access point ID to use. */ accessPointId: string; /** * Whether or not to use the AWS Batch job IAM role defined in a job definition when mounting the Amazon EFS file system. */ iam: string; } interface GetJobDefinitionNodePropertyNodeRangePropertyContainerVolumeHost { /** * Path on the host container instance that's presented to the container. */ sourcePath: string; } interface GetJobDefinitionRetryStrategy { /** * Number of times to move a job to the RUNNABLE status. */ attempts: number; /** * Conditions where jobs are retried or failed. See `evaluateOnExit` below. */ evaluateOnExits: outputs.batch.GetJobDefinitionRetryStrategyEvaluateOnExit[]; } interface GetJobDefinitionRetryStrategyEvaluateOnExit { /** * Action to take if all of the specified conditions (onStatusReason, onReason, and onExitCode) are met. The values aren't case sensitive. */ action: string; /** * Glob pattern to match against the decimal representation of the ExitCode returned for a job. */ onExitCode: string; /** * Glob pattern to match against the Reason returned for a job. */ onReason: string; /** * Glob pattern to match against the StatusReason returned for a job. */ onStatusReason: string; } interface GetJobDefinitionTimeout { /** * Job timeout time (in seconds) that's measured from the job attempt's startedAt timestamp. */ attemptDurationSeconds: number; } interface GetJobQueueComputeEnvironmentOrder { /** * ARN of the compute environment. */ computeEnvironment: string; /** * Order of the compute environment. */ order: number; } interface GetJobQueueJobStateTimeLimitAction { /** * Action to take when a job is at the head of the job queue in the specified state for the specified period of time. */ action: string; /** * Approximate amount of time, in seconds, that must pass with the job in the specified state before the action is taken. */ maxTimeSeconds: number; /** * Reason to log for the action being taken. */ reason: string; /** * Ability of the queue to accept new jobs (for example, `ENABLED` or `DISABLED`). */ state: string; } interface GetSchedulingPolicyFairSharePolicy { /** * Value used to reserve some of the available maximum vCPU for fair share identifiers that have not yet been used. For more information, see [FairsharePolicy](https://docs.aws.amazon.com/batch/latest/APIReference/API_FairsharePolicy.html). */ computeReservation: number; /** * Time period to use to calculate a fair share percentage for each fair share identifier in use, in seconds. For more information, see [FairsharePolicy](https://docs.aws.amazon.com/batch/latest/APIReference/API_FairsharePolicy.html). */ shareDecaySeconds: number; /** * One or more share distribution blocks which define the weights for the fair share identifiers for the fair share policy. For more information, see [FairsharePolicy](https://docs.aws.amazon.com/batch/latest/APIReference/API_FairsharePolicy.html). The `shareDistribution` block is documented below. */ shareDistributions: outputs.batch.GetSchedulingPolicyFairSharePolicyShareDistribution[]; } interface GetSchedulingPolicyFairSharePolicyShareDistribution { /** * Fair share identifier or fair share identifier prefix. For more information, see [ShareAttributes](https://docs.aws.amazon.com/batch/latest/APIReference/API_ShareAttributes.html). */ shareIdentifier: string; /** * Weight factor for the fair share identifier. For more information, see [ShareAttributes](https://docs.aws.amazon.com/batch/latest/APIReference/API_ShareAttributes.html). */ weightFactor: number; } interface JobDefinitionEksProperties { /** * Properties for the Kubernetes pod resources of a job. See `podProperties` below. */ podProperties: outputs.batch.JobDefinitionEksPropertiesPodProperties; } interface JobDefinitionEksPropertiesPodProperties { /** * Properties of the container that's used on the Amazon EKS pod. See `containers` below. */ containers: outputs.batch.JobDefinitionEksPropertiesPodPropertiesContainer[]; /** * DNS policy for the pod. The default value is `ClusterFirst`. If the `hostNetwork` argument is not specified, the default is `ClusterFirstWithHostNet`. `ClusterFirst` indicates that any DNS query that does not match the configured cluster domain suffix is forwarded to the upstream nameserver inherited from the node. For more information, see Pod's DNS policy in the Kubernetes documentation. */ dnsPolicy?: string; /** * Whether the pod uses the hosts' network IP address. The default value is `true`. Setting this to `false` enables the Kubernetes pod networking model. Most AWS Batch workloads are egress-only and don't require the overhead of IP allocation for each pod for incoming connections. */ hostNetwork?: boolean; /** * List of Kubernetes secret resources. See `imagePullSecret` below. */ imagePullSecrets?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesImagePullSecret[]; /** * Containers which run before application containers, always runs to completion, and must complete successfully before the next container starts. These containers are registered with the Amazon EKS Connector agent and persists the registration information in the Kubernetes backend data store. See `initContainers` below. */ initContainers?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesInitContainer[]; /** * Metadata about the Kubernetes pod. See `metadata` below. */ metadata?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesMetadata; /** * Name of the service account that's used to run the pod. */ serviceAccountName?: string; /** * Whether the processes in a container are shared, or visible, to other containers in the same pod. */ shareProcessNamespace?: boolean; /** * Volumes for a job definition that uses Amazon EKS resources. See `volumes` below. */ volumes?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesVolume[]; } interface JobDefinitionEksPropertiesPodPropertiesContainer { /** * Array of arguments to the entrypoint. If this isn't specified, the CMD of the container image is used. This corresponds to the args member in the Entrypoint portion of the Pod in Kubernetes. Environment variable references are expanded using the container's environment. */ args?: string[]; /** * Entrypoint for the container. This isn't run within a shell. If this isn't specified, the ENTRYPOINT of the container image is used. Environment variable references are expanded using the container's environment. */ commands?: string[]; /** * Environment variables to pass to a container. See `env` below. */ envs?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesContainerEnv[]; /** * Docker image used to start the container. */ image: string; /** * Image pull policy for the container. Supported values are `Always`, `IfNotPresent`, and `Never`. */ imagePullPolicy?: string; /** * Name of the container. If the name isn't specified, the default name "Default" is used. Each container in a pod must have a unique name. */ name?: string; /** * Type and amount of resources to assign to a container. See `resources` below. */ resources?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesContainerResources; /** * Security context for a job. See `securityContext` below. */ securityContext?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesContainerSecurityContext; /** * Volume mounts for the container. See `volumeMounts` below. */ volumeMounts?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesContainerVolumeMount[]; } interface JobDefinitionEksPropertiesPodPropertiesContainerEnv { /** * Name of the environment variable. */ name: string; /** * Value of the environment variable. */ value: string; } interface JobDefinitionEksPropertiesPodPropertiesContainerResources { /** * Type and quantity of the resources to reserve for the container. The values vary based on the name that's specified. Limits must be equal to or greater than requests. */ limits?: { [key: string]: string; }; /** * Type and quantity of the resources to request for the container. The values vary based on the name that's specified. */ requests?: { [key: string]: string; }; } interface JobDefinitionEksPropertiesPodPropertiesContainerSecurityContext { /** * Whether or not a container or a Kubernetes pod is allowed to gain more privileges than its parent process. The default value is `false`. */ allowPrivilegeEscalation?: boolean; /** * When this parameter is `true`, the container is given elevated permissions on the host container instance. The level of permissions are similar to the root user permissions. The default value is `false`. */ privileged?: boolean; /** * When this parameter is `true`, the container is given read-only access to its root file system. The default value is `false`. */ readOnlyRootFileSystem?: boolean; /** * When this parameter is specified, the container is run as the specified group ID (gid). If this parameter isn't specified, the default is the group that's specified in the image metadata. */ runAsGroup?: number; /** * When this parameter is specified, the container is run as a user with a uid other than 0. If this parameter isn't specified, so such rule is enforced. */ runAsNonRoot?: boolean; /** * When this parameter is specified, the container is run as the specified user ID (uid). If this parameter isn't specified, the default is the user that's specified in the image metadata. */ runAsUser?: number; } interface JobDefinitionEksPropertiesPodPropertiesContainerVolumeMount { /** * Path on the container where the volume is mounted. */ mountPath: string; /** * Name the volume mount. This must match the name of one of the volumes in the pod. */ name: string; /** * Whether the container has read-only access to the volume. The default value is `false`. */ readOnly?: boolean; } interface JobDefinitionEksPropertiesPodPropertiesImagePullSecret { /** * Unique identifier. */ name: string; } interface JobDefinitionEksPropertiesPodPropertiesInitContainer { /** * Array of arguments to the entrypoint. If this isn't specified, the CMD of the container image is used. This corresponds to the args member in the Entrypoint portion of the Pod in Kubernetes. Environment variable references are expanded using the container's environment. */ args?: string[]; /** * Entrypoint for the container. This isn't run within a shell. If this isn't specified, the ENTRYPOINT of the container image is used. Environment variable references are expanded using the container's environment. */ commands?: string[]; /** * Environment variables to pass to a container. See `env` below. */ envs?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesInitContainerEnv[]; /** * Docker image used to start the container. */ image: string; /** * Image pull policy for the container. Supported values are `Always`, `IfNotPresent`, and `Never`. */ imagePullPolicy?: string; /** * Name of the container. If the name isn't specified, the default name "Default" is used. Each container in a pod must have a unique name. */ name?: string; /** * Type and amount of resources to assign to a container. See `resources` below. */ resources?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesInitContainerResources; /** * Security context for a job. See `securityContext` below. */ securityContext?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesInitContainerSecurityContext; /** * Volume mounts for the container. See `volumeMounts` below. */ volumeMounts?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesInitContainerVolumeMount[]; } interface JobDefinitionEksPropertiesPodPropertiesInitContainerEnv { /** * Name of the environment variable. */ name: string; /** * Value of the environment variable. */ value: string; } interface JobDefinitionEksPropertiesPodPropertiesInitContainerResources { /** * Type and quantity of the resources to reserve for the container. The values vary based on the name that's specified. Limits must be equal to or greater than requests. */ limits?: { [key: string]: string; }; /** * Type and quantity of the resources to request for the container. The values vary based on the name that's specified. */ requests?: { [key: string]: string; }; } interface JobDefinitionEksPropertiesPodPropertiesInitContainerSecurityContext { /** * Whether or not a container or a Kubernetes pod is allowed to gain more privileges than its parent process. The default value is `false`. */ allowPrivilegeEscalation?: boolean; /** * When this parameter is `true`, the container is given elevated permissions on the host container instance. The level of permissions are similar to the root user permissions. The default value is `false`. */ privileged?: boolean; /** * When this parameter is `true`, the container is given read-only access to its root file system. The default value is `false`. */ readOnlyRootFileSystem?: boolean; /** * When this parameter is specified, the container is run as the specified group ID (gid). If this parameter isn't specified, the default is the group that's specified in the image metadata. */ runAsGroup?: number; /** * When this parameter is specified, the container is run as a user with a uid other than 0. If this parameter isn't specified, so such rule is enforced. */ runAsNonRoot?: boolean; /** * When this parameter is specified, the container is run as the specified user ID (uid). If this parameter isn't specified, the default is the user that's specified in the image metadata. */ runAsUser?: number; } interface JobDefinitionEksPropertiesPodPropertiesInitContainerVolumeMount { /** * Path on the container where the volume is mounted. */ mountPath: string; /** * Name the volume mount. This must match the name of one of the volumes in the pod. */ name: string; /** * Whether the container has read-only access to the volume. The default value is `false`. */ readOnly?: boolean; } interface JobDefinitionEksPropertiesPodPropertiesMetadata { /** * Key-value pairs used to identify, sort, and organize kubernetes resources. */ labels?: { [key: string]: string; }; } interface JobDefinitionEksPropertiesPodPropertiesVolume { /** * Empty directory to mount on the pod. See `emptyDir` below. */ emptyDir?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesVolumeEmptyDir; /** * Path on the host that's mounted to the pod. See `hostPath` below. */ hostPath?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesVolumeHostPath; /** * Name of the volume. The name must be allowed as a DNS subdomain name. */ name?: string; /** * Secret to mount as a volume. See `secret` below. */ secret?: outputs.batch.JobDefinitionEksPropertiesPodPropertiesVolumeSecret; } interface JobDefinitionEksPropertiesPodPropertiesVolumeEmptyDir { /** * Medium to store the volume. The default value is an empty string, which uses the storage of the node. */ medium?: string; /** * Maximum size of the volume. By default, there's no maximum size defined. */ sizeLimit: string; } interface JobDefinitionEksPropertiesPodPropertiesVolumeHostPath { /** * Path of the file or directory on the host to mount into containers on the pod. */ path: string; } interface JobDefinitionEksPropertiesPodPropertiesVolumeSecret { /** * Whether the secret or the secret's keys must be defined. */ optional?: boolean; /** * Name of the secret. The name must be allowed as a DNS subdomain name. */ secretName: string; } interface JobDefinitionRetryStrategy { /** * Number of times to move a job to the `RUNNABLE` status. You may specify between `1` and `10` attempts. */ attempts?: number; /** * Evaluate on exit conditions under which the job should be retried or failed. If this parameter is specified, then the `attempts` parameter must also be specified. You may specify up to 5 configuration blocks. */ evaluateOnExits?: outputs.batch.JobDefinitionRetryStrategyEvaluateOnExit[]; } interface JobDefinitionRetryStrategyEvaluateOnExit { /** * Action to take if all of the specified conditions are met. The values are not case sensitive. Valid values: `retry`, `exit`. */ action: string; /** * Glob pattern to match against the decimal representation of the exit code returned for a job. */ onExitCode?: string; /** * Glob pattern to match against the reason returned for a job. */ onReason?: string; /** * Glob pattern to match against the status reason returned for a job. */ onStatusReason?: string; } interface JobDefinitionTimeout { /** * Time duration in seconds after which AWS Batch terminates your jobs if they have not finished. The minimum value for the timeout is `60` seconds. */ attemptDurationSeconds?: number; } interface JobQueueComputeEnvironmentOrder { /** * ARN of the compute environment. */ computeEnvironment: string; /** * Order of the compute environment. Compute environments are tried in ascending order. For example, if two compute environments are associated with a job queue, the compute environment with a lower order integer value is tried for job placement first. */ order: number; } interface JobQueueJobStateTimeLimitAction { /** * Action to take when a job is at the head of the job queue in the specified state for the specified period of time. Valid values include `"CANCEL"` */ action: string; /** * Approximate amount of time, in seconds, that must pass with the job in the specified state before the action is taken. Valid values include integers between `600` & `86400` */ maxTimeSeconds: number; /** * Reason to log for the action being taken. */ reason: string; /** * State of the job needed to trigger the action. Valid values include `"RUNNABLE"`. */ state: string; } interface JobQueueTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface SchedulingPolicyFairSharePolicy { /** * Value used to reserve some of the available maximum vCPU for fair share identifiers that have not yet been used. For more information, see [FairsharePolicy](https://docs.aws.amazon.com/batch/latest/APIReference/API_FairsharePolicy.html). */ computeReservation?: number; /** * Time period to use to calculate a fair share percentage for each fair share identifier in use, in seconds. For more information, see [FairsharePolicy](https://docs.aws.amazon.com/batch/latest/APIReference/API_FairsharePolicy.html). */ shareDecaySeconds?: number; /** * One or more share distribution blocks which define the weights for the fair share identifiers for the fair share policy. For more information, see [FairsharePolicy](https://docs.aws.amazon.com/batch/latest/APIReference/API_FairsharePolicy.html). The `shareDistribution` block is documented below. */ shareDistributions?: outputs.batch.SchedulingPolicyFairSharePolicyShareDistribution[]; } interface SchedulingPolicyFairSharePolicyShareDistribution { /** * Fair share identifier or fair share identifier prefix. For more information, see [ShareAttributes](https://docs.aws.amazon.com/batch/latest/APIReference/API_ShareAttributes.html). */ shareIdentifier: string; /** * Weight factor for the fair share identifier. For more information, see [ShareAttributes](https://docs.aws.amazon.com/batch/latest/APIReference/API_ShareAttributes.html). */ weightFactor?: number; } } export declare namespace bcmdata { interface ExportExport { /** * Data query for this specific data export. See the `dataQuery` block below. */ dataQueries?: outputs.bcmdata.ExportExportDataQuery[]; /** * Description for this specific data export. */ description?: string; /** * Destination configuration for this specific data export. See the `destinationConfigurations` block below. */ destinationConfigurations?: outputs.bcmdata.ExportExportDestinationConfiguration[]; exportArn: string; /** * Name of this specific data export. */ name: string; /** * Cadence for Amazon Web Services to update the export in your S3 bucket. See the `refreshCadence` block below. */ refreshCadences?: outputs.bcmdata.ExportExportRefreshCadence[]; } interface ExportExportDataQuery { /** * Query statement. See the [AWS documentation](https://docs.aws.amazon.com/cur/latest/userguide/dataexports-table-dictionary.html) for a list of available tables. */ queryStatement: string; /** * Table configuration. See the [AWS documentation](https://docs.aws.amazon.com/cur/latest/userguide/dataexports-table-dictionary.html) for a list of available tables. If a value is set for `tableConfigurations`, all configuration values must be set. For the Cost and Usage Report, `BILLING_VIEW_ARN` must also be set, in addition to the documented settings. */ tableConfigurations: { [key: string]: { [key: string]: string; }; }; } interface ExportExportDestinationConfiguration { /** * Object that describes the destination of the data exports file. See the `s3Destination` block below. */ s3Destinations?: outputs.bcmdata.ExportExportDestinationConfigurationS3Destination[]; } interface ExportExportDestinationConfigurationS3Destination { /** * Name of the Amazon S3 bucket used as the destination of a data export file. */ s3Bucket: string; /** * Output configuration for the data export. See the `s3OutputConfigurations` block below. */ s3OutputConfigurations?: outputs.bcmdata.ExportExportDestinationConfigurationS3DestinationS3OutputConfiguration[]; /** * S3 path prefix you want prepended to the name of your data export. */ s3Prefix: string; /** * S3 bucket region. */ s3Region: string; } interface ExportExportDestinationConfigurationS3DestinationS3OutputConfiguration { /** * Compression type for the data export. Valid values `GZIP`, `PARQUET`. */ compression: string; /** * File format for the data export. Valid values `TEXT_OR_CSV` or `PARQUET`. */ format: string; /** * Output type for the data export. Valid value `CUSTOM`. */ outputType: string; /** * Rule to follow when generating a version of the data export file. You have the choice to overwrite the previous version or to be delivered in addition to the previous versions. Overwriting exports can save on Amazon S3 storage costs. Creating new export versions allows you to track the changes in cost and usage data over time. Valid values `CREATE_NEW_REPORT` or `OVERWRITE_REPORT`. */ overwrite: string; } interface ExportExportRefreshCadence { /** * Frequency that data exports are updated. The export refreshes each time the source data updates, up to three times daily. Valid values `SYNCHRONOUS`. */ frequency: string; } interface ExportTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace bedrock { interface AgentAgentActionGroupActionGroupExecutor { /** * Custom control method for handling the information elicited from the user. Valid values: `RETURN_CONTROL`. To skip using a Lambda function and instead return the predicted action group, in addition to the parameters and information required for it, in the `InvokeAgent` response, specify `RETURN_CONTROL`. Only one of `customControl` or `lambda` can be specified. */ customControl?: string; /** * ARN of the Lambda function containing the business logic that is carried out upon invoking the action. Only one of `lambda` or `customControl` can be specified. */ lambda?: string; } interface AgentAgentActionGroupApiSchema { /** * JSON or YAML-formatted payload defining the OpenAPI schema for the action group. Only one of `payload` or `s3` can be specified. */ payload?: string; /** * Details about the S3 object containing the OpenAPI schema for the action group. Only one of `s3` or `payload` can be specified. See `s3` Block for details. */ s3?: outputs.bedrock.AgentAgentActionGroupApiSchemaS3; } interface AgentAgentActionGroupApiSchemaS3 { /** * Name of the S3 bucket. */ s3BucketName?: string; /** * S3 object key containing the resource. */ s3ObjectKey?: string; } interface AgentAgentActionGroupFunctionSchema { /** * List of functions. Each function describes an action in the action group. See `memberFunctions` Block for details. */ memberFunctions?: outputs.bedrock.AgentAgentActionGroupFunctionSchemaMemberFunctions; } interface AgentAgentActionGroupFunctionSchemaMemberFunctions { /** * Functions that each define an action in the action group. See `functions` Block for details. */ functions?: outputs.bedrock.AgentAgentActionGroupFunctionSchemaMemberFunctionsFunction[]; } interface AgentAgentActionGroupFunctionSchemaMemberFunctionsFunction { /** * Description of the function and its purpose. */ description?: string; /** * Name for the function. */ name: string; /** * Parameters that the agent elicits from the user to fulfill the function. See `parameters` Block for details. */ parameters?: outputs.bedrock.AgentAgentActionGroupFunctionSchemaMemberFunctionsFunctionParameter[]; } interface AgentAgentActionGroupFunctionSchemaMemberFunctionsFunctionParameter { /** * Description of the parameter. Helps the foundation model determine how to elicit the parameters from the user. */ description?: string; /** * Name of the parameter. * * **Note:** The argument name `mapBlockKey` may seem out of context, but is necessary for backward compatibility reasons in the provider. */ mapBlockKey: string; /** * Whether the parameter is required for the agent to complete the function for action group invocation. */ required?: boolean; /** * Data type of the parameter. Valid values: `string`, `number`, `integer`, `boolean`, `array`. */ type: string; } interface AgentAgentActionGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentAgentAliasRoutingConfiguration { /** * Version of the agent with which the alias is associated. */ agentVersion: string; /** * ARN of the Provisioned Throughput assigned to the agent alias. */ provisionedThroughput: string; } interface AgentAgentAliasTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentAgentCollaboratorAgentDescriptor { /** * ARN of the Alias of an Agent to use as the collaborator. */ aliasArn: string; } interface AgentAgentCollaboratorTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentAgentGuardrailConfiguration { /** * Unique identifier of the guardrail. */ guardrailIdentifier: string; /** * Version of the guardrail. */ guardrailVersion: string; } interface AgentAgentKnowledgeBaseAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentAgentMemoryConfiguration { /** * Type of memory being stored by the agent. See [AWS API documentation](https://docs.aws.amazon.com/bedrock/latest/APIReference/API_agent_MemoryConfiguration.html) for possible values. */ enabledMemoryTypes: string[]; /** * Configuration block for `SESSION_SUMMARY` memory type enabled for the agent. See `sessionSummaryConfiguration` Block for details. */ sessionSummaryConfigurations: outputs.bedrock.AgentAgentMemoryConfigurationSessionSummaryConfiguration[]; /** * Number of days the agent is configured to retain the conversational context. Minimum value of 0, maximum value of 30. */ storageDays: number; } interface AgentAgentMemoryConfigurationSessionSummaryConfiguration { /** * Maximum number of recent session summaries to include in the agent's prompt context. */ maxRecentSessions: number; } interface AgentAgentPromptOverrideConfiguration { /** * ARN of the Lambda function to use when parsing the raw foundation model output in parts of the agent sequence. If you specify this field, at least one of the `promptConfigurations` block must contain a `parserMode` value that is set to `OVERRIDDEN`. */ overrideLambda: string; /** * Configurations to override a prompt template in one part of an agent sequence. See `promptConfigurations` Block for details. */ promptConfigurations: outputs.bedrock.AgentAgentPromptOverrideConfigurationPromptConfiguration[]; } interface AgentAgentPromptOverrideConfigurationPromptConfiguration { /** * prompt template with which to replace the default prompt template. You can use placeholder variables in the base prompt template to customize the prompt. For more information, see [Prompt template placeholder variables](https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-placeholders.html). */ basePromptTemplate: string; /** * Inference parameters to use when the agent invokes a foundation model in the part of the agent sequence defined by the `promptType`. For more information, see [Inference parameters for foundation models](https://docs.aws.amazon.com/bedrock/latest/userguide/model-parameters.html). See `inferenceConfiguration` Block for details. */ inferenceConfigurations: outputs.bedrock.AgentAgentPromptOverrideConfigurationPromptConfigurationInferenceConfiguration[]; /** * Whether to override the default parser Lambda function when parsing the raw foundation model output in the part of the agent sequence defined by the `promptType`. If you set the argument as `OVERRIDDEN`, the `overrideLambda` argument in the `promptOverrideConfiguration` block must be specified with the ARN of a Lambda function. Valid values: `DEFAULT`, `OVERRIDDEN`. */ parserMode: string; /** * Whether to override the default prompt template for this `promptType`. Set this argument to `OVERRIDDEN` to use the prompt that you provide in the `basePromptTemplate`. If you leave it as `DEFAULT`, the agent uses a default prompt template. Valid values: `DEFAULT`, `OVERRIDDEN`. */ promptCreationMode: string; /** * Whether to allow the agent to carry out the step specified in the `promptType`. If you set this argument to `DISABLED`, the agent skips that step. Valid Values: `ENABLED`, `DISABLED`. */ promptState: string; /** * Step in the agent sequence that this prompt configuration applies to. Valid values: `PRE_PROCESSING`, `ORCHESTRATION`, `POST_PROCESSING`, `KNOWLEDGE_BASE_RESPONSE_GENERATION`. */ promptType: string; } interface AgentAgentPromptOverrideConfigurationPromptConfigurationInferenceConfiguration { /** * Maximum number of tokens to allow in the generated response. */ maxLength: number; /** * List of stop sequences. A stop sequence is a sequence of characters that causes the model to stop generating the response. */ stopSequences: string[]; /** * Likelihood of the model selecting higher-probability options while generating a response. A lower value makes the model more likely to choose higher-probability options, while a higher value makes the model more likely to choose lower-probability options. */ temperature: number; /** * Number of top most-likely candidates, between 0 and 500, from which the model chooses the next token in the sequence. */ topK: number; /** * Top percentage of the probability distribution of next tokens, between 0 and 1 (denoting 0% and 100%), from which the model chooses the next token in the sequence. */ topP: number; } interface AgentAgentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentDataSourceDataSourceConfiguration { /** * Configuration details for the Confluence data source. See `data_source_configuration.confluence_configuration` Block for details. */ confluenceConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationConfluenceConfiguration; /** * Configuration details for a Managed Knowledge Base connector data source. See `managedKnowledgeBaseConnectorConfiguration` Block for details. */ managedKnowledgeBaseConnectorConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfiguration; /** * Configuration details for the S3 object that contains the data source. See `s3Configuration` Block for details. */ s3Configuration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationS3Configuration; /** * Configuration details for the Salesforce data source. See `data_source_configuration.salesforce_configuration` Block for details. */ salesforceConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSalesforceConfiguration; /** * Configuration details for the SharePoint data source. See `data_source_configuration.share_point_configuration` Block for details. */ sharePointConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSharePointConfiguration; /** * Type of storage for the data source. Valid values: `S3`, `WEB`, `CONFLUENCE`, `SALESFORCE`, `SHAREPOINT`, `CUSTOM`, `REDSHIFT_METADATA`, `MANAGED_KNOWLEDGE_BASE_CONNECTOR`. */ type: string; /** * Configuration details for the web data source. See `data_source_configuration.web_configuration` Block for details. */ webConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationWebConfiguration; } interface AgentDataSourceDataSourceConfigurationConfluenceConfiguration { /** * Configuration for Confluence content. See `data_source_configuration.confluence_configuration.crawler_configuration` Block for details. */ crawlerConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfiguration; /** * Endpoint information to connect to your Confluence data source. See `data_source_configuration.confluence_configuration.source_configuration` Block for details. */ sourceConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationConfluenceConfigurationSourceConfiguration; } interface AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfiguration { /** * Object configuration used to filter crawled content. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration` Block for details. */ filterConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfigurationFilterConfiguration; } interface AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfigurationFilterConfiguration { /** * Configuration for filtering objects or content types of the data source. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration.pattern_object_filter` Block for details. */ patternObjectFilters?: outputs.bedrock.AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilter[]; /** * Type of filtering to apply to objects or content of the data source. For example, the `PATTERN` type uses regular expression patterns to filter content. */ type: string; } interface AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilter { /** * Filters applied to your data source content. Minimum of 1 filter and maximum of 25 filters. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration.pattern_object_filter.filters` Block for details. */ filters?: outputs.bedrock.AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilterFilter[]; } interface AgentDataSourceDataSourceConfigurationConfluenceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilterFilter { /** * One or more exclusion regular expression patterns to exclude object types that match the pattern. */ exclusionFilters?: string[]; /** * One or more inclusion regular expression patterns to include object types that match the pattern. */ inclusionFilters?: string[]; /** * Object type or content type of the data source. */ objectType: string; } interface AgentDataSourceDataSourceConfigurationConfluenceConfigurationSourceConfiguration { /** * Supported authentication type to authenticate and connect to your SharePoint site. Valid values: `OAUTH2_CLIENT_CREDENTIALS`, `OAUTH2_SHAREPOINT_APP_ONLY_CLIENT_CREDENTIALS`. */ authType: string; /** * ARN of an AWS Secrets Manager secret that stores your authentication credentials for your SharePoint site. For more information on the key-value pairs that must be included in your secret, depending on your authentication type, see SharePoint connection configuration. Pattern: `^arn:aws(|-cn|-us-gov):secretsmanager:[a-z0-9-]{1,20}:([0-9]{12}|):secret:[a-zA-Z0-9!/_+=.@-]{1,512}$`. */ credentialsSecretArn: string; /** * Supported host type, whether online/cloud or server/on-premises. Valid values: `ONLINE`. */ hostType: string; /** * Salesforce host URL or instance URL. Pattern: `^https://[A-Za-z0-9][^\s]*$`. */ hostUrl: string; } interface AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfiguration { /** * JSON-encoded string containing the connector-specific parameters. The structure depends on the connector type (S3, SharePoint, Google Drive, etc.). See [Managed Knowledge Base connector parameters](https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-base-connectors.html) for details on each connector type. */ connectorParameters?: string; /** * Configuration for deletion protection on the data source. See `deletionProtectionConfiguration` Block for details. */ deletionProtectionConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationDeletionProtectionConfiguration; /** * Configuration for extracting media content (images, audio, video) from documents. See `mediaExtractionConfiguration` Block for details. */ mediaExtractionConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfiguration; } interface AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationDeletionProtectionConfiguration { /** * Enable or disable deletion protection for the connector. Valid values: `ENABLED`, `DISABLED`. */ deletionProtectionStatus: string; /** * Maximum percentage of documents that a sync job can delete from your index. */ deletionProtectionThreshold: number; } interface AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfiguration { /** * Configuration for extracting audio content. See `audioExtractionConfiguration` Block for details. */ audioExtractionConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfigurationAudioExtractionConfiguration; /** * Configuration for extracting image content. See `imageExtractionConfiguration` Block for details. */ imageExtractionConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfigurationImageExtractionConfiguration; /** * Configuration for extracting video content. See `videoExtractionConfiguration` Block for details. */ videoExtractionConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfigurationVideoExtractionConfiguration; } interface AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfigurationAudioExtractionConfiguration { /** * Whether audio extraction is enabled. Valid values: `ENABLED`, `DISABLED`. */ audioExtractionStatus: string; } interface AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfigurationImageExtractionConfiguration { /** * Whether image extraction is enabled. Valid values: `ENABLED`, `DISABLED`. */ imageExtractionStatus: string; } interface AgentDataSourceDataSourceConfigurationManagedKnowledgeBaseConnectorConfigurationMediaExtractionConfigurationVideoExtractionConfiguration { /** * Whether video extraction is enabled. Valid values: `ENABLED`, `DISABLED`. */ videoExtractionStatus: string; } interface AgentDataSourceDataSourceConfigurationS3Configuration { /** * ARN of the bucket that contains the data source. */ bucketArn: string; /** * Bucket account owner ID for the S3 bucket. */ bucketOwnerAccountId?: string; /** * List of S3 prefixes that define the object containing the data sources. For more information, see [Organizing objects using prefixes](https://docs.aws.amazon.com/AmazonS3/latest/userguide/using-prefixes.html). */ inclusionPrefixes?: string[]; } interface AgentDataSourceDataSourceConfigurationSalesforceConfiguration { /** * Configuration for Salesforce content. See `data_source_configuration.salesforce_configuration.crawler_configuration` Block for details. */ crawlerConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfiguration; /** * Endpoint information to connect to your Salesforce data source. See `data_source_configuration.salesforce_configuration.source_configuration` Block for details. */ sourceConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSalesforceConfigurationSourceConfiguration; } interface AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfiguration { /** * Object configuration used to filter crawled content. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration` Block for details. */ filterConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfigurationFilterConfiguration; } interface AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfigurationFilterConfiguration { /** * Configuration for filtering objects or content types of the data source. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration.pattern_object_filter` Block for details. */ patternObjectFilters?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilter[]; /** * Type of filtering to apply to objects or content of the data source. For example, the `PATTERN` type uses regular expression patterns to filter content. */ type: string; } interface AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilter { /** * Filters applied to your data source content. Minimum of 1 filter and maximum of 25 filters. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration.pattern_object_filter.filters` Block for details. */ filters?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilterFilter[]; } interface AgentDataSourceDataSourceConfigurationSalesforceConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilterFilter { /** * One or more exclusion regular expression patterns to exclude object types that match the pattern. */ exclusionFilters?: string[]; /** * One or more inclusion regular expression patterns to include object types that match the pattern. */ inclusionFilters?: string[]; /** * Object type or content type of the data source. */ objectType: string; } interface AgentDataSourceDataSourceConfigurationSalesforceConfigurationSourceConfiguration { /** * Supported authentication type to authenticate and connect to your SharePoint site. Valid values: `OAUTH2_CLIENT_CREDENTIALS`, `OAUTH2_SHAREPOINT_APP_ONLY_CLIENT_CREDENTIALS`. */ authType: string; /** * ARN of an AWS Secrets Manager secret that stores your authentication credentials for your SharePoint site. For more information on the key-value pairs that must be included in your secret, depending on your authentication type, see SharePoint connection configuration. Pattern: `^arn:aws(|-cn|-us-gov):secretsmanager:[a-z0-9-]{1,20}:([0-9]{12}|):secret:[a-zA-Z0-9!/_+=.@-]{1,512}$`. */ credentialsSecretArn: string; /** * Salesforce host URL or instance URL. Pattern: `^https://[A-Za-z0-9][^\s]*$`. */ hostUrl: string; } interface AgentDataSourceDataSourceConfigurationSharePointConfiguration { /** * Configuration for SharePoint content. See `data_source_configuration.share_point_configuration.crawler_configuration` Block for details. */ crawlerConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfiguration; /** * Endpoint information to connect to your SharePoint data source. See `data_source_configuration.share_point_configuration.source_configuration` Block for details. */ sourceConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSharePointConfigurationSourceConfiguration; } interface AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfiguration { /** * Object configuration used to filter crawled content. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration` Block for details. */ filterConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfigurationFilterConfiguration; } interface AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfigurationFilterConfiguration { /** * Configuration for filtering objects or content types of the data source. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration.pattern_object_filter` Block for details. */ patternObjectFilters?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilter[]; /** * Type of filtering to apply to objects or content of the data source. For example, the `PATTERN` type uses regular expression patterns to filter content. */ type: string; } interface AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilter { /** * Filters applied to your data source content. Minimum of 1 filter and maximum of 25 filters. See `data_source_configuration.share_point_configuration.crawler_configuration.filter_configuration.pattern_object_filter.filters` Block for details. */ filters?: outputs.bedrock.AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilterFilter[]; } interface AgentDataSourceDataSourceConfigurationSharePointConfigurationCrawlerConfigurationFilterConfigurationPatternObjectFilterFilter { /** * One or more exclusion regular expression patterns to exclude object types that match the pattern. */ exclusionFilters?: string[]; /** * One or more inclusion regular expression patterns to include object types that match the pattern. */ inclusionFilters?: string[]; /** * Object type or content type of the data source. */ objectType: string; } interface AgentDataSourceDataSourceConfigurationSharePointConfigurationSourceConfiguration { /** * Supported authentication type to authenticate and connect to your SharePoint site. Valid values: `OAUTH2_CLIENT_CREDENTIALS`, `OAUTH2_SHAREPOINT_APP_ONLY_CLIENT_CREDENTIALS`. */ authType: string; /** * ARN of an AWS Secrets Manager secret that stores your authentication credentials for your SharePoint site. For more information on the key-value pairs that must be included in your secret, depending on your authentication type, see SharePoint connection configuration. Pattern: `^arn:aws(|-cn|-us-gov):secretsmanager:[a-z0-9-]{1,20}:([0-9]{12}|):secret:[a-zA-Z0-9!/_+=.@-]{1,512}$`. */ credentialsSecretArn: string; /** * Domain of your SharePoint instance or site URL/URLs. */ domain: string; /** * Supported host type, whether online/cloud or server/on-premises. Valid values: `ONLINE`. */ hostType: string; /** * One or more SharePoint site URLs. */ siteUrls: string[]; /** * Identifier of your Microsoft 365 tenant. */ tenantId?: string; } interface AgentDataSourceDataSourceConfigurationWebConfiguration { /** * Configuration for web content. See `data_source_configuration.web_configuration.crawler_configuration` Block for details. */ crawlerConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationWebConfigurationCrawlerConfiguration; /** * Endpoint information to connect to your web data source. See `data_source_configuration.web_configuration.source_configuration` Block for details. */ sourceConfiguration?: outputs.bedrock.AgentDataSourceDataSourceConfigurationWebConfigurationSourceConfiguration; } interface AgentDataSourceDataSourceConfigurationWebConfigurationCrawlerConfiguration { /** * Configuration of crawl limits for the web URLs. See `crawlerLimits` Block for details. */ crawlerLimits?: outputs.bedrock.AgentDataSourceDataSourceConfigurationWebConfigurationCrawlerConfigurationCrawlerLimits; /** * List of one or more exclusion regular expression patterns to exclude object types that match the pattern. */ exclusionFilters?: string[]; /** * List of one or more inclusion regular expression patterns to include object types that match the pattern. */ inclusionFilters?: string[]; /** * Scope of what is crawled for your URLs. */ scope?: string; /** * String used to identify the crawler or bot when it accesses a web server. Default value is `bedrockbot_UUID`. */ userAgent?: string; } interface AgentDataSourceDataSourceConfigurationWebConfigurationCrawlerConfigurationCrawlerLimits { /** * Max number of web pages crawled from your source URLs, up to 25,000 pages. */ maxPages?: number; /** * Max rate at which pages are crawled, up to 300 per minute per host. */ rateLimit?: number; } interface AgentDataSourceDataSourceConfigurationWebConfigurationSourceConfiguration { /** * URL configuration of your web data source. See `urlConfiguration` Block for details. */ urlConfiguration: outputs.bedrock.AgentDataSourceDataSourceConfigurationWebConfigurationSourceConfigurationUrlConfiguration; } interface AgentDataSourceDataSourceConfigurationWebConfigurationSourceConfigurationUrlConfiguration { /** * List of one or more seed URLs to crawl. See `seedUrls` Block for details. */ seedUrls?: outputs.bedrock.AgentDataSourceDataSourceConfigurationWebConfigurationSourceConfigurationUrlConfigurationSeedUrl[]; } interface AgentDataSourceDataSourceConfigurationWebConfigurationSourceConfigurationUrlConfigurationSeedUrl { /** * Seed or starting point URL. Must match the pattern `^https?://[A-Za-z0-9][^\s]*$`. */ url?: string; } interface AgentDataSourceServerSideEncryptionConfiguration { /** * ARN of the AWS KMS key used to encrypt the resource. */ kmsKeyArn?: string; } interface AgentDataSourceTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentDataSourceVectorIngestionConfiguration { /** * Details about how to chunk the documents in the data source. A chunk refers to an excerpt from a data source that is returned when the knowledge base that it belongs to is queried. See `chunkingConfiguration` Block for details. */ chunkingConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationChunkingConfiguration; /** * Configuration for custom transformation of data source documents. See `customTransformationConfiguration` Block for details. */ customTransformationConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationCustomTransformationConfiguration; /** * Configuration for custom parsing of data source documents. See `parsingConfiguration` Block for details. */ parsingConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationParsingConfiguration; } interface AgentDataSourceVectorIngestionConfigurationChunkingConfiguration { /** * Option for chunking your source data, either in fixed-sized chunks or as one chunk. Valid values: `FIXED_SIZE`, `HIERARCHICAL`, `SEMANTIC`, `NONE`. */ chunkingStrategy: string; /** * Configurations for when you choose fixed-size chunking. Requires `chunkingStrategy` as `FIXED_SIZE`. See `fixedSizeChunkingConfiguration` Block for details. */ fixedSizeChunkingConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationChunkingConfigurationFixedSizeChunkingConfiguration; /** * Configurations for when you choose hierarchical chunking. Requires `chunkingStrategy` as `HIERARCHICAL`. See `hierarchicalChunkingConfiguration` Block for details. */ hierarchicalChunkingConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationChunkingConfigurationHierarchicalChunkingConfiguration; /** * Configurations for when you choose semantic chunking. Requires `chunkingStrategy` as `SEMANTIC`. See `semanticChunkingConfiguration` Block for details. */ semanticChunkingConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationChunkingConfigurationSemanticChunkingConfiguration; } interface AgentDataSourceVectorIngestionConfigurationChunkingConfigurationFixedSizeChunkingConfiguration { /** * Maximum number of tokens to include in a chunk. */ maxTokens: number; /** * Percentage of overlap between adjacent chunks of a data source. */ overlapPercentage: number; } interface AgentDataSourceVectorIngestionConfigurationChunkingConfigurationHierarchicalChunkingConfiguration { /** * Token settings for each layer. Must contain two `levelConfiguration` blocks. See `levelConfiguration` Block for details. */ levelConfigurations?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationChunkingConfigurationHierarchicalChunkingConfigurationLevelConfiguration[]; /** * Number of tokens to repeat across chunks in the same layer. */ overlapTokens: number; } interface AgentDataSourceVectorIngestionConfigurationChunkingConfigurationHierarchicalChunkingConfigurationLevelConfiguration { /** * Maximum number of tokens that a chunk can contain in this layer. */ maxTokens: number; } interface AgentDataSourceVectorIngestionConfigurationChunkingConfigurationSemanticChunkingConfiguration { /** * Dissimilarity threshold for splitting chunks. */ breakpointPercentileThreshold: number; /** * Buffer size. */ bufferSize: number; /** * Maximum number of tokens a chunk can contain. */ maxToken: number; } interface AgentDataSourceVectorIngestionConfigurationCustomTransformationConfiguration { /** * Intermediate storage for custom transformation. See `intermediateStorage` Block for details. */ intermediateStorage?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationIntermediateStorage; /** * Custom processing step for documents moving through the data source ingestion pipeline. See `transformation` Block for details. */ transformation?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationTransformation; } interface AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationIntermediateStorage { /** * Configuration block for intermediate S3 storage. See `s3Location` Block for details. */ s3Location?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationIntermediateStorageS3Location; } interface AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationIntermediateStorageS3Location { /** * S3 URI for intermediate storage. */ uri: string; } interface AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationTransformation { /** * When the service applies the transformation. Currently only `POST_CHUNKING` is supported. */ stepToApply: string; /** * Lambda function that processes documents. See `transformationFunction` Block for details. */ transformationFunction?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationTransformationTransformationFunction; } interface AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationTransformationTransformationFunction { /** * Configuration of the Lambda function. See `transformationLambdaConfiguration` Block for details. */ transformationLambdaConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationTransformationTransformationFunctionTransformationLambdaConfiguration; } interface AgentDataSourceVectorIngestionConfigurationCustomTransformationConfigurationTransformationTransformationFunctionTransformationLambdaConfiguration { /** * ARN of the Lambda to use for custom transformation. */ lambdaArn: string; } interface AgentDataSourceVectorIngestionConfigurationParsingConfiguration { /** * Settings for using Amazon Bedrock Data Automation to parse documents. See `bedrockDataAutomationConfiguration` Block for details. */ bedrockDataAutomationConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationParsingConfigurationBedrockDataAutomationConfiguration; /** * Settings for a foundation model used to parse documents in a data source. See `bedrockFoundationModelConfiguration` Block for details. */ bedrockFoundationModelConfiguration?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationParsingConfigurationBedrockFoundationModelConfiguration; /** * Parsing strategy to use. Valid values: `BEDROCK_FOUNDATION_MODEL`, `BEDROCK_DATA_AUTOMATION`. */ parsingStrategy: string; } interface AgentDataSourceVectorIngestionConfigurationParsingConfigurationBedrockDataAutomationConfiguration { /** * Whether to enable parsing of multimodal data, including both text and images. Valid value: `MULTIMODAL`. */ parsingModality?: string; } interface AgentDataSourceVectorIngestionConfigurationParsingConfigurationBedrockFoundationModelConfiguration { /** * ARN of the model used to parse documents. */ modelArn: string; /** * Whether to enable parsing of multimodal data, including both text and images. Valid values: `MULTIMODAL`. */ parsingModality?: string; /** * Instructions for interpreting the contents of the document. See `parsingPrompt` Block for details. */ parsingPrompt?: outputs.bedrock.AgentDataSourceVectorIngestionConfigurationParsingConfigurationBedrockFoundationModelConfigurationParsingPrompt; } interface AgentDataSourceVectorIngestionConfigurationParsingConfigurationBedrockFoundationModelConfigurationParsingPrompt { /** * Instructions for interpreting the contents of the document. */ parsingPromptString: string; } interface AgentFlowDefinition { /** * List of connection definitions in the flow. See `definition.connection` Block for details. */ connections?: outputs.bedrock.AgentFlowDefinitionConnection[]; /** * List of node definitions in the flow. See `definition.node` Block for details. */ nodes?: outputs.bedrock.AgentFlowDefinitionNode[]; } interface AgentFlowDefinitionConnection { /** * Configurations for the node. See `definition.node.configuration` Block for details. */ configuration?: outputs.bedrock.AgentFlowDefinitionConnectionConfiguration; /** * Name for the flow. * * The following arguments are optional: */ name: string; /** * Node that the connection starts at. */ source: string; /** * Node that the connection ends at. */ target: string; /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionConnectionConfiguration { /** * Configuration of a connection originating from a Condition node. See `definition.connection.configuration.conditional` Block for details. */ conditional?: outputs.bedrock.AgentFlowDefinitionConnectionConfigurationConditional; /** * Configuration of a connection originating from a node that isn't a Condition node. See `definition.connection.configuration.data` Block for details. */ data?: outputs.bedrock.AgentFlowDefinitionConnectionConfigurationData; } interface AgentFlowDefinitionConnectionConfigurationConditional { /** * List of conditions. See `definition.node.configuration.condition.condition` Block for details. */ condition: string; } interface AgentFlowDefinitionConnectionConfigurationData { /** * Name of the output in the source node that the connection begins from. */ sourceOutput: string; /** * Name of the input in the target node that the connection ends at. */ targetInput: string; } interface AgentFlowDefinitionNode { /** * Configurations for the node. See `definition.node.configuration` Block for details. */ configuration?: outputs.bedrock.AgentFlowDefinitionNodeConfiguration; /** * Configurations for an input flow node in your flow. The node `inputs` can't be specified for this node. This block has no arguments. */ inputs?: outputs.bedrock.AgentFlowDefinitionNodeInput[]; /** * Name for the flow. * * The following arguments are optional: */ name: string; /** * Configurations for an output flow node in your flow. The node `outputs` can't be specified for this node. This block has no arguments. */ outputs?: outputs.bedrock.AgentFlowDefinitionNodeOutput[]; /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionNodeConfiguration { /** * Configurations for an agent node in your flow. Invokes an alias of an agent and returns the response. See `definition.node.configuration.agent` Block for details. */ agent?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationAgent; /** * Configurations for a collector node in your flow. Collects an iteration of inputs and consolidates them into an array of outputs. This block has no arguments. */ collector?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationCollector; /** * List of conditions. See `definition.node.configuration.condition.condition` Block for details. */ condition?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationCondition; /** * Configurations for an inline code node in your flow. See `definition.node.configuration.inline_code` Block for details. */ inlineCode?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationInlineCode; /** * Configurations for an input flow node in your flow. The node `inputs` can't be specified for this node. This block has no arguments. */ input?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationInput; /** * Configurations for an iterator node in your flow. Takes an input that is an array and iteratively sends each item of the array as an output to the following node. The size of the array is also returned in the output. The output flow node at the end of the flow iteration returns a response for each member of the array. To return only one response, you can include a collector node downstream from the iterator node. This block has no arguments. */ iterator?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationIterator; /** * Configurations for a knowledge base node in your flow. Queries a knowledge base and returns the retrieved results or generated response. See `definition.node.configuration.knowledge_base` Block for details. */ knowledgeBase?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationKnowledgeBase; /** * Configurations for a Lambda function node in your flow. Invokes a Lambda function. See `definition.node.configuration.lambda_function` Block for details. */ lambdaFunction?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationLambdaFunction; /** * Configurations for a Lex node in your flow. Invokes an Amazon Lex bot to identify the intent of the input and return the intent as the output. See `definition.node.configuration.lex` Block for details. */ lex?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationLex; /** * Configurations for an output flow node in your flow. The node `outputs` can't be specified for this node. This block has no arguments. */ output?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationOutput; /** * Configurations for a prompt node in your flow. Runs a prompt and generates the model response as the output. You can use a prompt from Prompt management or you can configure one in this node. See `definition.node.configuration.prompt` Block for details. */ prompt?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPrompt; /** * Configurations for a Retrieval node in your flow. Retrieves data from an Amazon S3 location and returns it as the output. See `definition.node.configuration.retrieval` Block for details. */ retrieval?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationRetrieval; /** * Configurations for a Storage node in your flow. Stores an input in an Amazon S3 location. See `definition.node.configuration.storage` Block for details. */ storage?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationStorage; } interface AgentFlowDefinitionNodeConfigurationAgent { /** * ARN of the alias of the agent to invoke. */ agentAliasArn: string; } interface AgentFlowDefinitionNodeConfigurationCollector { } interface AgentFlowDefinitionNodeConfigurationCondition { /** * List of conditions. See `definition.node.configuration.condition.condition` Block for details. */ conditions?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationConditionCondition[]; } interface AgentFlowDefinitionNodeConfigurationConditionCondition { /** * Expression that formats the input for the node. For an explanation of how to create expressions, see [Expressions in Prompt flows in Amazon Bedrock](https://docs.aws.amazon.com/bedrock/latest/userguide/flows-expressions.html). */ expression?: string; /** * Name for the flow. * * The following arguments are optional: */ name: string; } interface AgentFlowDefinitionNodeConfigurationInlineCode { /** * Code that's executed in your inline code node. */ code: string; /** * Programming language used by your inline code node. */ language: string; } interface AgentFlowDefinitionNodeConfigurationInput { } interface AgentFlowDefinitionNodeConfigurationIterator { } interface AgentFlowDefinitionNodeConfigurationKnowledgeBase { /** * Configuration of a guardrail for prompt generation. See `definition.node.configuration.prompt.guardrail_configuration` Block for details. */ guardrailConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationKnowledgeBaseGuardrailConfiguration; /** * Inference configurations for the prompt. See `definition.node.configuration.prompt.source_configuration.inline.inference_configuration` Block for details. */ inferenceConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationKnowledgeBaseInferenceConfiguration; /** * Unique identifier of the knowledge base to query. */ knowledgeBaseId: string; /** * Unique identifier of the model or [inference profile](https://docs.aws.amazon.com/bedrock/latest/userguide/cross-region-inference.html) to run inference with. */ modelId: string; /** * Maximum number of results to retrieve from the knowledge base. Valid values are between 1 and 100. */ numberOfResults?: number; } interface AgentFlowDefinitionNodeConfigurationKnowledgeBaseGuardrailConfiguration { /** * Unique identifier of the guardrail. */ guardrailIdentifier: string; /** * Version of the guardrail. */ guardrailVersion: string; } interface AgentFlowDefinitionNodeConfigurationKnowledgeBaseInferenceConfiguration { /** * Message for the prompt. */ text?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationKnowledgeBaseInferenceConfigurationText; } interface AgentFlowDefinitionNodeConfigurationKnowledgeBaseInferenceConfigurationText { /** * Maximum number of tokens to return in the response. */ maxTokens?: number; /** * List of strings that define sequences after which the model stops generating. */ stopSequences?: string[]; /** * Controls the randomness of the response. Choose a lower value for more predictable outputs and a higher value for more surprising outputs. */ temperature?: number; /** * Percentage of most-likely candidates that the model considers for the next token. */ topP?: number; } interface AgentFlowDefinitionNodeConfigurationLambdaFunction { /** * ARN of the Lambda function to invoke. */ lambdaArn: string; } interface AgentFlowDefinitionNodeConfigurationLex { /** * ARN of the Amazon Lex bot alias to invoke. */ botAliasArn: string; /** * Region to invoke the Amazon Lex bot in. */ localeId: string; } interface AgentFlowDefinitionNodeConfigurationOutput { } interface AgentFlowDefinitionNodeConfigurationPrompt { /** * Configuration of a guardrail for prompt generation. See `definition.node.configuration.prompt.guardrail_configuration` Block for details. */ guardrailConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptGuardrailConfiguration; /** * Configuration of the prompt source, either inline or from Prompt management. See `definition.node.configuration.prompt.source_configuration` Block for details. */ sourceConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfiguration; } interface AgentFlowDefinitionNodeConfigurationPromptGuardrailConfiguration { /** * Unique identifier of the guardrail. */ guardrailIdentifier: string; /** * Version of the guardrail. */ guardrailVersion: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfiguration { /** * Configurations for a prompt that is defined inline. See `definition.node.configuration.prompt.source_configuration.inline` Block for details. */ inline?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInline; /** * Configurations for a prompt from Prompt management. See `definition.node.configuration.prompt.source_configuration.resource` Block for details. */ resource?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationResource; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInline { /** * Additional fields to be included in the model request for the Prompt node. */ additionalModelRequestFields?: string; /** * Inference configurations for the prompt. See `definition.node.configuration.prompt.source_configuration.inline.inference_configuration` Block for details. */ inferenceConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineInferenceConfiguration; /** * Unique identifier of the model or [inference profile](https://docs.aws.amazon.com/bedrock/latest/userguide/cross-region-inference.html) to run inference with. */ modelId: string; /** * Prompt and variables in the prompt that can be replaced with values at runtime. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration` Block for details. */ templateConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfiguration; /** * Type of prompt template. Valid values: `TEXT`, `CHAT`. */ templateType: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineInferenceConfiguration { /** * Message for the prompt. */ text?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineInferenceConfigurationText; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineInferenceConfigurationText { /** * Maximum number of tokens to return in the response. */ maxTokens?: number; /** * List of strings that define sequences after which the model stops generating. */ stopSequences?: string[]; /** * Controls the randomness of the response. Choose a lower value for more predictable outputs and a higher value for more surprising outputs. */ temperature?: number; /** * Percentage of most-likely candidates that the model considers for the next token. */ topP?: number; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfiguration { /** * Configurations to use the prompt in a conversational format. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat` Block for details. */ chat?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChat; /** * Message for the prompt. */ text?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationText; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChat { /** * Variables in the prompt template. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.text.input_variable` Block for details. */ inputVariables?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatInputVariable[]; /** * Messages in the chat for the prompt. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.message` Block for details. */ messages: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatMessage[]; /** * System prompts that provide context to the model or describe how it should behave. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.system` Block for details. */ systems?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatSystem[]; /** * Configuration information for the tools that the model can use when generating a response. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.tool_configuration` Block for details. */ toolConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfiguration; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatInputVariable { /** * Name for the flow. * * The following arguments are optional: */ name: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatMessage { /** * Content for the message you pass to, or receive from, a model. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.message.content` Block for details. */ content?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatMessageContent; /** * Role that the message belongs to. */ role: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatMessageContent { /** * Cache checkpoint within a template configuration. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.text.cache_point` Block for details. */ cachePoint?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatMessageContentCachePoint; /** * Message for the prompt. */ text?: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatMessageContentCachePoint { /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatSystem { /** * Cache checkpoint within a template configuration. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.text.cache_point` Block for details. */ cachePoint?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatSystemCachePoint; /** * Message for the prompt. */ text?: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatSystemCachePoint { /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfiguration { /** * Which tools the model should request when invoked. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.tool_configuration.tool_choice` Block for details. */ toolChoice?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoice; /** * Specific tool that the model must request. No text is generated but the results of tool use are sent back to the model to help generate a response. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.tool_configuration.tool_choice.tool` Block for details. */ tools?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationTool[]; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationTool { /** * Cache checkpoint within a template configuration. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.text.cache_point` Block for details. */ cachePoint?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolCachePoint; /** * Specification for the tool. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.tool_configuration.tool.tool_spec` Block for details. */ toolSpec?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolToolSpec; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolCachePoint { /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoice { /** * Tools, at least one of which must be requested by the model. No text is generated but the results of tool use are sent back to the model to help generate a response. This block has no arguments. */ any?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoiceAny; /** * Tools. The model automatically decides whether to call a tool or to generate text instead. This block has no arguments. */ auto?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoiceAuto; /** * Specific tool that the model must request. No text is generated but the results of tool use are sent back to the model to help generate a response. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.tool_configuration.tool_choice.tool` Block for details. */ tool?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoiceTool; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoiceAny { } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoiceAuto { } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolChoiceTool { /** * Name for the flow. * * The following arguments are optional: */ name: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolToolSpec { /** * Description for the flow. */ description?: string; /** * Input schema of the tool. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.chat.tool_configuration.tool.tool_spec.input_schema` Block for details. */ inputSchema?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolToolSpecInputSchema; /** * Name for the flow. * * The following arguments are optional: */ name: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationChatToolConfigurationToolToolSpecInputSchema { /** * JSON object defining the input schema for the tool. */ json?: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationText { /** * Cache checkpoint within a template configuration. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.text.cache_point` Block for details. */ cachePoint?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationTextCachePoint; /** * Variables in the prompt template. See `definition.node.configuration.prompt.source_configuration.inline.template_configuration.text.input_variable` Block for details. */ inputVariables?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationTextInputVariable[]; /** * Message for the prompt. */ text: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationTextCachePoint { /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationInlineTemplateConfigurationTextInputVariable { /** * Name for the flow. * * The following arguments are optional: */ name: string; } interface AgentFlowDefinitionNodeConfigurationPromptSourceConfigurationResource { /** * ARN of the prompt from Prompt management. */ promptArn: string; } interface AgentFlowDefinitionNodeConfigurationRetrieval { /** * Configurations for the service to use for storing the input into the node. See `definition.node.configuration.storage.service_configuration` Block for details. */ serviceConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationRetrievalServiceConfiguration; } interface AgentFlowDefinitionNodeConfigurationRetrievalServiceConfiguration { /** * Configurations for the Amazon S3 location in which to store the input into the node. See `definition.node.configuration.storage.service_configuration.s3` Block for details. */ s3?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationRetrievalServiceConfigurationS3; } interface AgentFlowDefinitionNodeConfigurationRetrievalServiceConfigurationS3 { /** * Name of the Amazon S3 bucket in which to store the input into the node. */ bucketName: string; } interface AgentFlowDefinitionNodeConfigurationStorage { /** * Configurations for the service to use for storing the input into the node. See `definition.node.configuration.storage.service_configuration` Block for details. */ serviceConfiguration?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationStorageServiceConfiguration; } interface AgentFlowDefinitionNodeConfigurationStorageServiceConfiguration { /** * Configurations for the Amazon S3 location in which to store the input into the node. See `definition.node.configuration.storage.service_configuration.s3` Block for details. */ s3?: outputs.bedrock.AgentFlowDefinitionNodeConfigurationStorageServiceConfigurationS3; } interface AgentFlowDefinitionNodeConfigurationStorageServiceConfigurationS3 { /** * Name of the Amazon S3 bucket in which to store the input into the node. */ bucketName: string; } interface AgentFlowDefinitionNodeInput { /** * How input data flows between iterations in a DoWhile loop. */ category?: string; /** * Expression that formats the input for the node. For an explanation of how to create expressions, see [Expressions in Prompt flows in Amazon Bedrock](https://docs.aws.amazon.com/bedrock/latest/userguide/flows-expressions.html). */ expression: string; /** * Name for the flow. * * The following arguments are optional: */ name: string; /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowDefinitionNodeOutput { /** * Name for the flow. * * The following arguments are optional: */ name: string; /** * Data type of the output. If the output doesn't match this type at runtime, a validation error is thrown. */ type: string; } interface AgentFlowTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentKnowledgeBaseKnowledgeBaseConfiguration { /** * Settings for an Amazon Kendra knowledge base. See `kendraKnowledgeBaseConfiguration` Block for details. */ kendraKnowledgeBaseConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationKendraKnowledgeBaseConfiguration; /** * Settings for a managed knowledge base where Amazon Bedrock manages the vector store. See `managedKnowledgeBaseConfiguration` Block for details. */ managedKnowledgeBaseConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfiguration; /** * Configurations for a knowledge base connected to an SQL database. See `sqlKnowledgeBaseConfiguration` Block for details. */ sqlKnowledgeBaseConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfiguration; /** * Type of data that the data source is converted into for the knowledge base. Valid Values: `VECTOR`, `KENDRA`, `SQL`, `MANAGED`. */ type: string; /** * Details about the model that's used to convert the data source into vector embeddings. See `vectorKnowledgeBaseConfiguration` Block for details. */ vectorKnowledgeBaseConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationKendraKnowledgeBaseConfiguration { /** * ARN of the Amazon Kendra index. */ kendraIndexArn: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfiguration { /** * ARN of the embedding model. Required when `embeddingModelType` is `CUSTOM`. */ embeddingModelArn?: string; /** * Configuration for the embedding model. Required when `embeddingModelType` is `CUSTOM`. See `embeddingModelConfiguration` Block for details. */ embeddingModelConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfiguration; /** * Type of embedding model. Valid values: `MANAGED`, `CUSTOM`. When `MANAGED`, no model selection or configuration is required. When `CUSTOM`, `embeddingModelArn` and `embeddingModelConfiguration` are required. Defaults to `MANAGED`. */ embeddingModelType: string; /** * Server-side encryption configuration for the managed knowledge base. See `serverSideEncryptionConfiguration` Block for details. */ serverSideEncryptionConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationServerSideEncryptionConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfiguration { /** * Vector configuration details for the Bedrock embeddings model. See `bedrockEmbeddingModelConfiguration` Block for details. */ bedrockEmbeddingModelConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfiguration { /** * Configuration for processing audio content in multimodal knowledge bases. See `audio` Block for details. */ audio?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudio; /** * Dimension details for the vector configuration used on the Bedrock embeddings model. */ dimensions?: number; /** * Data type for the vectors when using a model to convert text into vector embeddings. The model must support the specified data type for vector embeddings. Valid values are `FLOAT32` and `BINARY`. */ embeddingDataType?: string; /** * Configuration for processing video content in multimodal knowledge bases. See `video` Block for details. */ video?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideo; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudio { /** * Configuration for segmenting audio content during processing. See `segmentationConfiguration` Block for details. */ segmentationConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudioSegmentationConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudioSegmentationConfiguration { /** * Duration in seconds for each audio or video segment. */ fixedLengthDuration: number; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideo { /** * Configuration for segmenting video content during processing. See `segmentationConfiguration` Block for details. */ segmentationConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideoSegmentationConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideoSegmentationConfiguration { /** * Duration in seconds for each audio or video segment. */ fixedLengthDuration: number; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationManagedKnowledgeBaseConfigurationServerSideEncryptionConfiguration { /** * ARN of the KMS key used to encrypt the managed knowledge base. * * > **NOTE:** `storageConfiguration` is not required when `knowledge_base_configuration.type` is `MANAGED`. Amazon Bedrock manages the vector store automatically for managed knowledge bases. */ kmsKeyArn?: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfiguration { /** * Configurations for a knowledge base connected to an Amazon Redshift database. See `knowledge_base_configuration.sql_knowledge_base_configuration.redshift_configuration` Block for details. */ redshiftConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfiguration; /** * Type of SQL database to connect to the knowledge base. Valid values: `REDSHIFT`. */ type: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfiguration { /** * Configurations for an Amazon Redshift query engine. See `queryEngineConfiguration` Block for details. */ queryEngineConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfiguration; /** * Configurations for generating queries. See `queryGenerationConfiguration` Block for details. */ queryGenerationConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfiguration; /** * Configurations for Amazon Redshift database storage. See `knowledge_base_configuration.sql_knowledge_base_configuration.redshift_configuration.storage_configuration` Block for details. */ storageConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationStorageConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfiguration { /** * Configurations for a provisioned Amazon Redshift query engine. See `provisionedConfiguration` Block for details. */ provisionedConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationProvisionedConfiguration; /** * Configurations for a serverless Amazon Redshift query engine. See `serverlessConfiguration` Block for details. */ serverlessConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationServerlessConfiguration; /** * Type of query engine. Valid values: `SERVERLESS`, `PROVISIONED`. */ type: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationProvisionedConfiguration { /** * Configurations for authentication to Amazon Redshift. See `knowledge_base_configuration.sql_knowledge_base_configuration.redshift_configuration.query_engine_configuration.provisioned_configuration.auth_configuration` Block for details. */ authConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationProvisionedConfigurationAuthConfiguration; /** * ID of the Amazon Redshift cluster. */ clusterIdentifier: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationProvisionedConfigurationAuthConfiguration { /** * Database username for authentication to an Amazon Redshift provisioned data warehouse. */ databaseUser?: string; /** * Type of authentication to use. Valid values: `IAM`, `USERNAME_PASSWORD`. */ type: string; /** * ARN of a Secrets Manager secret for authentication. */ usernamePasswordSecretArn?: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationServerlessConfiguration { /** * Configurations for authentication to a Redshift Serverless. See `knowledge_base_configuration.sql_knowledge_base_configuration.redshift_configuration.query_engine_configuration.serverless_configuration.auth_configuration` Block for details. */ authConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationServerlessConfigurationAuthConfiguration; /** * ARN of the Amazon Redshift workgroup. */ workgroupArn: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryEngineConfigurationServerlessConfigurationAuthConfiguration { /** * Type of authentication to use. Valid values: `IAM`, `USERNAME_PASSWORD`. */ type: string; /** * ARN of a Secrets Manager secret for authentication. */ usernamePasswordSecretArn?: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfiguration { /** * Time after which query generation will time out. */ executionTimeoutSeconds?: number; /** * Configurations for context to use during query generation. See `generationContext` Block for details. */ generationContext?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContext; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContext { /** * Information about example queries to help the query engine generate appropriate SQL queries. See `curatedQuery` Block for details. */ curatedQueries?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContextCuratedQuery[]; /** * Information about a table in the database. See `table` Block for details. */ tables?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContextTable[]; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContextCuratedQuery { /** * Example natural language query. */ naturalLanguage: string; /** * SQL equivalent of `naturalLanguage`. */ sql: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContextTable { /** * Information about a column in the table. See `column` Block for details. */ columns?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContextTableColumn[]; /** * Description of the table that helps the query engine understand the contents of the table. */ description?: string; /** * Whether to include or exclude the table during query generation. Valid values `INCLUDE`, `EXCLUDE`. */ inclusion?: string; /** * Name of the table for which the other fields in this object apply. */ name: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationQueryGenerationConfigurationGenerationContextTableColumn { /** * Description of the column that helps the query engine understand the contents of the column. */ description?: string; /** * Whether to include or exclude the column during query generation. Valid values `INCLUDE`, `EXCLUDE`. */ inclusion?: string; /** * Name of the column for which the other fields in this object apply. */ name?: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationStorageConfiguration { /** * Configurations for storage in AWS Glue Data Catalog. See `awsDataCatalogConfiguration` Block for details. */ awsDataCatalogConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationStorageConfigurationAwsDataCatalogConfiguration; /** * Configurations for storage in Amazon Redshift. See `knowledge_base_configuration.sql_knowledge_base_configuration.redshift_configuration.storage_configuration.redshift_configuration` Block for details. */ redshiftConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationStorageConfigurationRedshiftConfiguration; /** * Vector store service in which the knowledge base is stored. Valid Values: `MONGO_DB_ATLAS`, `OPENSEARCH_SERVERLESS`, `OPENSEARCH_MANAGED_CLUSTER`, `PINECONE`, `REDIS_ENTERPRISE_CLOUD`, `RDS`, `S3_VECTORS`, `NEPTUNE_ANALYTICS`. */ type: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationStorageConfigurationAwsDataCatalogConfiguration { /** * List of names of the tables to use. */ tableNames: string[]; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationSqlKnowledgeBaseConfigurationRedshiftConfigurationStorageConfigurationRedshiftConfiguration { /** * Name of the Amazon Redshift database. */ databaseName: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfiguration { /** * ARN of the model used to create vector embeddings for the knowledge base. */ embeddingModelArn: string; /** * Embeddings model configuration details for the vector model used in the knowledge base. See `embeddingModelConfiguration` Block for details. */ embeddingModelConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfiguration; /** * Supplemental data storage configuration for images extracted from multimodal documents. See `supplementalDataStorageConfiguration` Block for details. */ supplementalDataStorageConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationSupplementalDataStorageConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfiguration { /** * Vector configuration details for the Bedrock embeddings model. See `bedrockEmbeddingModelConfiguration` Block for details. */ bedrockEmbeddingModelConfiguration?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfiguration { /** * Configuration for processing audio content in multimodal knowledge bases. See `audio` Block for details. */ audio?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudio; /** * Dimension details for the vector configuration used on the Bedrock embeddings model. */ dimensions?: number; /** * Data type for the vectors when using a model to convert text into vector embeddings. The model must support the specified data type for vector embeddings. Valid values are `FLOAT32` and `BINARY`. */ embeddingDataType?: string; /** * Configuration for processing video content in multimodal knowledge bases. See `video` Block for details. */ video?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideo; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudio { /** * Configuration for segmenting audio content during processing. See `segmentationConfiguration` Block for details. */ segmentationConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudioSegmentationConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationAudioSegmentationConfiguration { /** * Duration in seconds for each audio or video segment. */ fixedLengthDuration: number; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideo { /** * Configuration for segmenting video content during processing. See `segmentationConfiguration` Block for details. */ segmentationConfiguration: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideoSegmentationConfiguration; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationEmbeddingModelConfigurationBedrockEmbeddingModelConfigurationVideoSegmentationConfiguration { /** * Duration in seconds for each audio or video segment. */ fixedLengthDuration: number; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationSupplementalDataStorageConfiguration { /** * Storage location specification for images extracted from multimodal documents in your data source. See `storageLocation` Block for details. */ storageLocations: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationSupplementalDataStorageConfigurationStorageLocation[]; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationSupplementalDataStorageConfigurationStorageLocation { /** * Information about the Amazon S3 location for the extracted images. See `s3Location` Block for details. */ s3Location?: outputs.bedrock.AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationSupplementalDataStorageConfigurationStorageLocationS3Location; /** * Storage service used for this location. `S3` is the only valid value. */ type: string; } interface AgentKnowledgeBaseKnowledgeBaseConfigurationVectorKnowledgeBaseConfigurationSupplementalDataStorageConfigurationStorageLocationS3Location { /** * URI of the location. */ uri: string; } interface AgentKnowledgeBaseStorageConfiguration { /** * Storage configuration of the knowledge base in MongoDB Atlas. See `mongoDbAtlasConfiguration` Block for details. */ mongoDbAtlasConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationMongoDbAtlasConfiguration; /** * Storage configuration of the knowledge base in Amazon Neptune Analytics. See `neptuneAnalyticsConfiguration` Block for details. */ neptuneAnalyticsConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationNeptuneAnalyticsConfiguration; /** * Storage configuration of the knowledge base in Amazon OpenSearch Service Managed Cluster. See `opensearchManagedClusterConfiguration` Block for details. */ opensearchManagedClusterConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationOpensearchManagedClusterConfiguration; /** * Storage configuration of the knowledge base in Amazon OpenSearch Service Serverless. See `opensearchServerlessConfiguration` Block for details. */ opensearchServerlessConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationOpensearchServerlessConfiguration; /** * Storage configuration of the knowledge base in Pinecone. See `pineconeConfiguration` Block for details. */ pineconeConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationPineconeConfiguration; /** * Details about the storage configuration of the knowledge base in Amazon RDS. For more information, see [Create a vector index in Amazon RDS](https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-base-setup.html). See `rdsConfiguration` Block for details. */ rdsConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationRdsConfiguration; /** * Storage configuration of the knowledge base in Redis Enterprise Cloud. See `redisEnterpriseCloudConfiguration` Block for details. */ redisEnterpriseCloudConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationRedisEnterpriseCloudConfiguration; /** * Storage configuration of the knowledge base in Amazon S3 Vectors. See `s3VectorsConfiguration` Block for details. */ s3VectorsConfiguration?: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationS3VectorsConfiguration; /** * Vector store service in which the knowledge base is stored. Valid Values: `MONGO_DB_ATLAS`, `OPENSEARCH_SERVERLESS`, `OPENSEARCH_MANAGED_CLUSTER`, `PINECONE`, `REDIS_ENTERPRISE_CLOUD`, `RDS`, `S3_VECTORS`, `NEPTUNE_ANALYTICS`. */ type: string; } interface AgentKnowledgeBaseStorageConfigurationMongoDbAtlasConfiguration { /** * Name of the collection in the MongoDB Atlas database. */ collectionName: string; /** * ARN of the secret that you created in AWS Secrets Manager that is linked to your MongoDB Atlas database. */ credentialsSecretArn: string; /** * Name of the database in the MongoDB Atlas database. */ databaseName: string; /** * Endpoint URL of the MongoDB Atlas database. */ endpoint: string; /** * Name of the service that hosts the MongoDB Atlas database. */ endpointServiceName?: string; /** * Names of the fields to which to map information about the vector store. See `storage_configuration.mongo_db_atlas_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationMongoDbAtlasConfigurationFieldMapping; /** * Name of the vector index. */ textIndexName?: string; /** * Name of the vector index. */ vectorIndexName: string; } interface AgentKnowledgeBaseStorageConfigurationMongoDbAtlasConfigurationFieldMapping { /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField: string; /** * Name of the field in which Amazon Bedrock stores the vector embeddings for your data sources. */ vectorField: string; } interface AgentKnowledgeBaseStorageConfigurationNeptuneAnalyticsConfiguration { /** * Names of the fields to which to map information about the vector store. See `storage_configuration.neptune_analytics_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationNeptuneAnalyticsConfigurationFieldMapping; /** * ARN of the Neptune Analytics vector store. */ graphArn: string; } interface AgentKnowledgeBaseStorageConfigurationNeptuneAnalyticsConfigurationFieldMapping { /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField: string; } interface AgentKnowledgeBaseStorageConfigurationOpensearchManagedClusterConfiguration { /** * ARN of the OpenSearch domain. */ domainArn: string; /** * Endpoint URL of the OpenSearch domain. */ domainEndpoint: string; /** * Names of the fields to which to map information about the vector store. See `storage_configuration.opensearch_managed_cluster_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationOpensearchManagedClusterConfigurationFieldMapping; /** * Name of the vector store. */ vectorIndexName: string; } interface AgentKnowledgeBaseStorageConfigurationOpensearchManagedClusterConfigurationFieldMapping { /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField: string; /** * Name of the field in which Amazon Bedrock stores the vector embeddings for your data sources. */ vectorField: string; } interface AgentKnowledgeBaseStorageConfigurationOpensearchServerlessConfiguration { /** * ARN of the OpenSearch Service vector store. */ collectionArn: string; /** * Names of the fields to which to map information about the vector store. See `storage_configuration.opensearch_serverless_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationOpensearchServerlessConfigurationFieldMapping; /** * Name of the vector store. */ vectorIndexName: string; } interface AgentKnowledgeBaseStorageConfigurationOpensearchServerlessConfigurationFieldMapping { /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField: string; /** * Name of the field in which Amazon Bedrock stores the vector embeddings for your data sources. */ vectorField: string; } interface AgentKnowledgeBaseStorageConfigurationPineconeConfiguration { /** * Endpoint URL for your index management page. */ connectionString: string; /** * ARN of the secret that you created in AWS Secrets Manager that is linked to your Pinecone API key. */ credentialsSecretArn: string; /** * Names of the fields to which to map information about the vector store. See `storage_configuration.pinecone_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationPineconeConfigurationFieldMapping; /** * Namespace to be used to write new data to your database. */ namespace?: string; } interface AgentKnowledgeBaseStorageConfigurationPineconeConfigurationFieldMapping { /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField: string; } interface AgentKnowledgeBaseStorageConfigurationRdsConfiguration { /** * ARN of the secret that you created in AWS Secrets Manager that is linked to your Amazon RDS database. */ credentialsSecretArn: string; /** * Name of your Amazon RDS database. */ databaseName: string; /** * Names of the fields to which to map information about the vector store. See `storage_configuration.rds_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationRdsConfigurationFieldMapping; /** * ARN of the vector store. */ resourceArn: string; /** * Name of the table in the database. */ tableName: string; } interface AgentKnowledgeBaseStorageConfigurationRdsConfigurationFieldMapping { /** * Name for the universal metadata field where Amazon Bedrock will store any custom metadata from your data source. */ customMetadataField?: string; /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField: string; /** * Name of the field in which Amazon Bedrock stores the ID for each entry. */ primaryKeyField: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField: string; /** * Name of the field in which Amazon Bedrock stores the vector embeddings for your data sources. */ vectorField: string; } interface AgentKnowledgeBaseStorageConfigurationRedisEnterpriseCloudConfiguration { /** * ARN of the secret that you created in AWS Secrets Manager that is linked to your Redis Enterprise Cloud database. */ credentialsSecretArn: string; /** * Endpoint URL of the Redis Enterprise Cloud database. */ endpoint: string; /** * Names of the fields to which to map information about the vector store. See `storage_configuration.redis_enterprise_cloud_configuration.field_mapping` Block for details. */ fieldMapping: outputs.bedrock.AgentKnowledgeBaseStorageConfigurationRedisEnterpriseCloudConfigurationFieldMapping; /** * Name of the vector index. */ vectorIndexName: string; } interface AgentKnowledgeBaseStorageConfigurationRedisEnterpriseCloudConfigurationFieldMapping { /** * Name of the field in which Amazon Bedrock stores metadata about the vector store. */ metadataField?: string; /** * Name of the field in which Amazon Bedrock stores the raw text from your data. The text is split according to the chunking strategy you choose. */ textField?: string; /** * Name of the field in which Amazon Bedrock stores the vector embeddings for your data sources. */ vectorField?: string; } interface AgentKnowledgeBaseStorageConfigurationS3VectorsConfiguration { /** * ARN of the S3 Vectors index. Conflicts with `indexName` and `vectorBucketArn`. */ indexArn?: string; /** * Name of the S3 Vectors index. Must be specified with `vectorBucketArn`. Conflicts with `indexArn`. */ indexName?: string; /** * ARN of the S3 Vectors vector bucket. Must be specified with `indexName`. Conflicts with `indexArn`. */ vectorBucketArn?: string; } interface AgentKnowledgeBaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentPromptVariant { /** * Model-specific inference configurations that aren’t in the inferenceConfiguration field. To see model-specific inference parameters, see [Inference request parameters and response fields for foundation models](https://docs.aws.amazon.com/bedrock/latest/userguide/model-parameters.html). */ additionalModelRequestFields?: string; /** * Generative AI resource with which to use the prompt. If this is not supplied, then a `modelId` must be defined. See `genAiResource` Block for more information. */ genAiResource?: outputs.bedrock.AgentPromptVariantGenAiResource; /** * Inference configurations for the prompt variant. See `inferenceConfiguration` Block for more information. */ inferenceConfiguration?: outputs.bedrock.AgentPromptVariantInferenceConfiguration; /** * List of objects, each containing a key-value pair that defines a metadata tag and value to attach to a prompt variant. See `metadata` Block for more information. */ metadatas?: outputs.bedrock.AgentPromptVariantMetadata[]; /** * Unique identifier of the model or [inference profile](https://docs.aws.amazon.com/bedrock/latest/userguide/cross-region-inference.html) with which to run inference on the prompt. If this is not supplied, then a `genAiResource` must be defined. */ modelId?: string; /** * Name of the tool. */ name: string; /** * Configurations for the prompt template. See `templateConfiguration` Block for more information. */ templateConfiguration?: outputs.bedrock.AgentPromptVariantTemplateConfiguration; /** * Type of prompt template to use. Valid values: `CHAT`, `TEXT`. */ templateType: string; } interface AgentPromptVariantGenAiResource { /** * Amazon Bedrock agent with which to use the prompt. See `agent` Block for more information. */ agent?: outputs.bedrock.AgentPromptVariantGenAiResourceAgent; } interface AgentPromptVariantGenAiResourceAgent { /** * ARN of the agent with which to use the prompt. */ agentIdentifier: string; } interface AgentPromptVariantInferenceConfiguration { /** * Inference configurations for the prompt variant. See `variant.inference_configuration.text` Block for more information. */ text?: outputs.bedrock.AgentPromptVariantInferenceConfigurationText; } interface AgentPromptVariantInferenceConfigurationText { /** * Maximum number of tokens to return in the response. */ maxTokens?: number; /** * List of strings that define sequences after which the model will stop generating. */ stopSequences?: string[]; /** * Controls the randomness of the response. Choose a lower value for more predictable outputs and a higher value for more surprising outputs. */ temperature?: number; /** * Percentage of most-likely candidates that the model considers for the next token. */ topP?: number; } interface AgentPromptVariantMetadata { /** * Key of a metadata tag for a prompt variant. */ key: string; /** * Value of a metadata tag for a prompt variant. */ value: string; } interface AgentPromptVariantTemplateConfiguration { /** * Configurations to use the prompt in a conversational format. See `chat` Block for more information. */ chat?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChat; /** * Configurations for the text in a message for a prompt. See `variant.template_configuration.text` Block for more information. */ text?: outputs.bedrock.AgentPromptVariantTemplateConfigurationText; } interface AgentPromptVariantTemplateConfigurationChat { /** * List of variables in the prompt template. See `inputVariable` Block for more information. */ inputVariables?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatInputVariable[]; /** * List of messages in the chat for the prompt. See `message` Block for more information. */ messages: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatMessage[]; /** * List of system prompts to provide context to the model or to describe how it should behave. See `system` Block for more information. */ systems?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatSystem[]; /** * Configuration information for the tools that the model can use when generating a response. See `toolConfiguration` Block for more information. */ toolConfiguration?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfiguration; } interface AgentPromptVariantTemplateConfigurationChatInputVariable { /** * Name of the variable. */ name: string; } interface AgentPromptVariantTemplateConfigurationChatMessage { /** * Content for the message you pass to, or receive from a model. See `content` Block for more information. */ content?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatMessageContent; /** * Role that the message belongs to. */ role: string; } interface AgentPromptVariantTemplateConfigurationChatMessageContent { /** * Cache checkpoint within a message. See `cachePoint` Block for more information. */ cachePoint?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatMessageContentCachePoint; /** * Text in the message. */ text?: string; } interface AgentPromptVariantTemplateConfigurationChatMessageContentCachePoint { /** * Cache point type. Valid values: `default`. */ type: string; } interface AgentPromptVariantTemplateConfigurationChatSystem { /** * Cache checkpoint within the system prompt. See `cachePoint` Block for more information. */ cachePoint?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatSystemCachePoint; /** * Text in the system prompt. */ text?: string; } interface AgentPromptVariantTemplateConfigurationChatSystemCachePoint { /** * Cache point type. Valid values: `default`. */ type: string; } interface AgentPromptVariantTemplateConfigurationChatToolConfiguration { /** * Configuration for which tools the model should request when invoked. See `toolChoice` Block for more information. */ toolChoice?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoice; /** * List of tools to pass to a model. See `variant.template_configuration.chat.tool_configuration.tool` Block for more information. */ tools?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationTool[]; } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationTool { cachePoint?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolCachePoint; /** * Specification for the tool. See `toolSpec` Block for more information. */ toolSpec?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolToolSpec; } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolCachePoint { /** * Cache point type. Valid values: `default`. */ type: string; } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoice { /** * Tools, at least one of which must be requested by the model. No text is generated but the results of tool use are sent back to the model to help generate a response. This object has no fields. */ any?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoiceAny; /** * Tools from which the model automatically decides whether to call a tool or to generate text instead. This object has no fields. */ auto?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoiceAuto; /** * Specific tool that the model must request. No text is generated but the results of tool use are sent back to the model to help generate a response. See `variant.template_configuration.chat.tool_configuration.tool_choice.tool` Block for more information. */ tool?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoiceTool; } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoiceAny { } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoiceAuto { } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolChoiceTool { /** * Name of the prompt. * * The following arguments are optional: */ name: string; } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolToolSpec { /** * Description of the tool. */ description?: string; /** * Input schema of the tool. See `inputSchema` Block for more information. */ inputSchema?: outputs.bedrock.AgentPromptVariantTemplateConfigurationChatToolConfigurationToolToolSpecInputSchema; /** * Name of the tool. */ name: string; } interface AgentPromptVariantTemplateConfigurationChatToolConfigurationToolToolSpecInputSchema { /** * JSON object defining the input schema for the tool. */ json?: string; } interface AgentPromptVariantTemplateConfigurationText { cachePoint?: outputs.bedrock.AgentPromptVariantTemplateConfigurationTextCachePoint; inputVariables?: outputs.bedrock.AgentPromptVariantTemplateConfigurationTextInputVariable[]; text: string; } interface AgentPromptVariantTemplateConfigurationTextCachePoint { /** * Cache point type. Valid values: `default`. */ type: string; } interface AgentPromptVariantTemplateConfigurationTextInputVariable { /** * Name of the variable. */ name: string; } interface AgentcoreAgentRuntimeAgentRuntimeArtifact { /** * Code configuration block for the agent runtime artifact, including the source code location and execution settings. Exactly one of `codeConfiguration` or `containerConfiguration` must be specified. See `codeConfiguration` below. */ codeConfiguration?: outputs.bedrock.AgentcoreAgentRuntimeAgentRuntimeArtifactCodeConfiguration; /** * Container configuration block for the agent artifact. Exactly one of `codeConfiguration` or `containerConfiguration` must be specified. See `containerConfiguration` below. */ containerConfiguration?: outputs.bedrock.AgentcoreAgentRuntimeAgentRuntimeArtifactContainerConfiguration; } interface AgentcoreAgentRuntimeAgentRuntimeArtifactCodeConfiguration { /** * Configuration block for the source code location and configuration details. See `code` below. */ code?: outputs.bedrock.AgentcoreAgentRuntimeAgentRuntimeArtifactCodeConfigurationCode; /** * Array specifying the entry point for code execution, indicating the function or method to invoke when the code runs. The array must contain 1 or 2 elements. Examples: `["main.py"]`, `["opentelemetry-instrument", "main.py"]`. */ entryPoints: string[]; /** * Runtime environment used to execute the code. Valid values: `PYTHON_3_10`, `PYTHON_3_11`, `PYTHON_3_12`, `PYTHON_3_13`. */ runtime: string; } interface AgentcoreAgentRuntimeAgentRuntimeArtifactCodeConfigurationCode { /** * Configuration block for the Amazon S3 object that contains the source code for the agent runtime. See `s3` below. */ s3?: outputs.bedrock.AgentcoreAgentRuntimeAgentRuntimeArtifactCodeConfigurationCodeS3; } interface AgentcoreAgentRuntimeAgentRuntimeArtifactCodeConfigurationCodeS3 { /** * Name of the Amazon S3 bucket. */ bucket: string; /** * Key of the object containing the ZIP file of the source code for the agent runtime in the Amazon S3 bucket. */ prefix: string; /** * Version ID of the Amazon S3 object. If not specified, the latest version of the object is used. */ versionId?: string; } interface AgentcoreAgentRuntimeAgentRuntimeArtifactContainerConfiguration { /** * URI of the container image in Amazon ECR. */ containerUri: string; } interface AgentcoreAgentRuntimeAuthorizerConfiguration { /** * JWT-based authorization configuration block. See `customJwtAuthorizer` below. */ customJwtAuthorizer?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizer; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizer { /** * Set of allowed audience values for JWT token validation. */ allowedAudiences?: string[]; /** * Set of allowed client IDs for JWT token validation. */ allowedClients?: string[]; /** * Set of scopes that are allowed to access the token. */ allowedScopes?: string[]; /** * Configuration restricting which workloads may use this authorizer. See `allowedWorkloadConfiguration` below. */ allowedWorkloadConfiguration?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration; /** * Repeatable block to define a custom claim validation name, value, and operation. See `customClaim` below. */ customClaims?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerCustomClaim[]; /** * URL used to fetch OpenID Connect configuration or authorization server metadata. Must end with `.well-known/openid-configuration`. */ discoveryUrl: string; /** * Private endpoint used to reach the authorization server. See `privateEndpoint` below. */ privateEndpoint?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint; /** * Overrides for the private endpoints used to reach the authorization server. See `privateEndpointOverrides` below. */ privateEndpointOverrides?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride[]; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration { /** * Hosting environments allowed to use the authorizer. Between 1 and 10 entries. See `hostingEnvironment` below. */ hostingEnvironments?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment[]; /** * List of workload identity names allowed to use the authorizer. Between 1 and 10 entries. */ workloadIdentities?: string[]; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment { /** * ARN of the hosting environment. */ arn: string; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerCustomClaim { /** * Configuration block to define the value or values to match for and the relationship of the match. See `authorizingClaimMatchValue` below. */ authorizingClaimMatchValue: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue; /** * Name of the custom claim field to check. */ inboundTokenClaimName: string; /** * Data type of the claim value to check for. Valid values are `STRING` and `STRING_ARRAY`. */ inboundTokenClaimValueType: string; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue { /** * Relationship between the claim field value and the value or values to match for. Valid values are `EQUALS`, `CONTAINS`, and `CONTAINS_ANY`. `EQUALS` can be used only when `inboundTokenClaimValueType` is `STRING`. `CONTAINS` or `CONTAINS_ANY` can be used only when `inboundTokenClaimValueType` is `STRING_ARRAY`. */ claimMatchOperator: string; /** * Value or values to match for. See `claimMatchValue` below. */ claimMatchValue: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue { /** * String value to match for. Must be specified when `claimMatchOperator` is `EQUALS` or `CONTAINS`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueString?: string; /** * List of strings to check for a match. Must be specified when `claimMatchOperator` is `CONTAINS_ANY`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueStringLists?: string[]; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` below. */ managedVpcResource?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride { /** * Domain the override applies to. */ domain: string; /** * Private endpoint configuration. See `privateEndpoint` below. */ privateEndpoint: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` below. */ managedVpcResource?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreAgentRuntimeAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreAgentRuntimeEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreAgentRuntimeFilesystemConfiguration { /** * Amazon EFS access point to mount as shared file storage. Exactly one of `sessionStorage`, `s3FilesAccessPoint`, or `efsAccessPoint` must be specified. See `efsAccessPoint` below. */ efsAccessPoint?: outputs.bedrock.AgentcoreAgentRuntimeFilesystemConfigurationEfsAccessPoint; /** * Amazon S3 Files access point to mount as shared file storage. Exactly one of `sessionStorage`, `s3FilesAccessPoint`, or `efsAccessPoint` must be specified. See `s3FilesAccessPoint` below. */ s3FilesAccessPoint?: outputs.bedrock.AgentcoreAgentRuntimeFilesystemConfigurationS3FilesAccessPoint; /** * Session storage filesystem providing persistent storage across agent runtime session invocations. Exactly one of `sessionStorage`, `s3FilesAccessPoint`, or `efsAccessPoint` must be specified. See `sessionStorage` below. */ sessionStorage?: outputs.bedrock.AgentcoreAgentRuntimeFilesystemConfigurationSessionStorage; } interface AgentcoreAgentRuntimeFilesystemConfigurationEfsAccessPoint { /** * ARN of the Amazon EFS access point to mount into the agent runtime. */ accessPointArn: string; /** * Mount path for the EFS access point inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreAgentRuntimeFilesystemConfigurationS3FilesAccessPoint { /** * ARN of the Amazon S3 Files access point to mount into the agent runtime. */ accessPointArn: string; /** * Mount path for the S3 Files access point inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreAgentRuntimeFilesystemConfigurationSessionStorage { /** * Mount path for the session storage filesystem inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreAgentRuntimeLifecycleConfiguration { /** * Timeout in seconds for idle runtime sessions. */ idleRuntimeSessionTimeout: number; /** * Maximum lifetime for the instance in seconds. */ maxLifetime: number; } interface AgentcoreAgentRuntimeNetworkConfiguration { /** * Network mode for the agent runtime. Valid values: `PUBLIC`, `VPC`. */ networkMode: string; /** * Network mode configuration. See `networkModeConfig` below. */ networkModeConfig?: outputs.bedrock.AgentcoreAgentRuntimeNetworkConfigurationNetworkModeConfig; } interface AgentcoreAgentRuntimeNetworkConfigurationNetworkModeConfig { /** * Whether a service-managed Amazon S3 gateway endpoint is provisioned in the VPC for the agent runtime. This value is managed by the service. Agent runtimes created on or after the May 5, 2026 rollout do not include a service-managed Amazon S3 gateway. */ requireServiceS3Endpoint: boolean; /** * Security groups associated with the VPC configuration. */ securityGroups: string[]; /** * Subnets associated with the VPC configuration. */ subnets: string[]; } interface AgentcoreAgentRuntimeProtocolConfiguration { /** * Server protocol for the agent runtime. Valid values: `HTTP`, `MCP`, `A2A`, `AGUI`. */ serverProtocol?: string; } interface AgentcoreAgentRuntimeRequestHeaderConfiguration { /** * List of HTTP request headers that are allowed to be passed through to the runtime. */ requestHeaderAllowlists?: string[]; } interface AgentcoreAgentRuntimeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreAgentRuntimeWorkloadIdentityDetail { /** * ARN of the workload identity. */ workloadIdentityArn: string; } interface AgentcoreApiKeyCredentialProviderApiKeySecretArn { /** * ARN of the secret in AWS Secrets Manager. */ secretArn: string; } interface AgentcoreApiKeyCredentialProviderApiKeySecretConfig { /** * JSON key used to extract the secret value from the AWS Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the secret value. */ secretId: string; } interface AgentcoreBrowserBrowserSigning { /** * Whether browser signing is enabled. When enabled, the browser cryptographically signs HTTP requests to identify itself as an AI agent to bot control vendors. */ enabled: boolean; } interface AgentcoreBrowserCertificate { /** * Location from which to retrieve the certificate. See `certificate.location` below. */ location: outputs.bedrock.AgentcoreBrowserCertificateLocation; } interface AgentcoreBrowserCertificateLocation { /** * AWS Secrets Manager location of the certificate. See `secretsManager` below. */ secretsManager?: outputs.bedrock.AgentcoreBrowserCertificateLocationSecretsManager; } interface AgentcoreBrowserCertificateLocationSecretsManager { /** * ARN of the AWS Secrets Manager secret containing the certificate. */ secretArn: string; } interface AgentcoreBrowserEnterprisePolicy { /** * Location of the enterprise policy file. See `location` below. */ location: outputs.bedrock.AgentcoreBrowserEnterprisePolicyLocation; /** * Type of browser enterprise policy. Valid values: `MANAGED`, `RECOMMENDED`. */ type?: string; } interface AgentcoreBrowserEnterprisePolicyLocation { /** * S3 location of the enterprise policy file. See `s3` below. */ s3?: outputs.bedrock.AgentcoreBrowserEnterprisePolicyLocationS3; } interface AgentcoreBrowserEnterprisePolicyLocationS3 { /** * Name of the S3 bucket. */ bucket: string; /** * Prefix for objects in the S3 bucket. */ prefix: string; /** * Version ID of the S3 object. If not specified, the latest version is used. */ versionId?: string; } interface AgentcoreBrowserNetworkConfiguration { /** * Network mode for the browser. Valid values: `PUBLIC`, `VPC`. */ networkMode: string; /** * VPC configuration when `networkMode` is `VPC`. See `vpcConfig` below. */ vpcConfig?: outputs.bedrock.AgentcoreBrowserNetworkConfigurationVpcConfig; } interface AgentcoreBrowserNetworkConfigurationVpcConfig { /** * Set of security group IDs for the VPC configuration. */ securityGroups: string[]; /** * Set of subnet IDs for the VPC configuration. */ subnets: string[]; } interface AgentcoreBrowserProfileTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface AgentcoreBrowserRecording { /** * Whether to enable recording for browser sessions. Defaults to `false`. */ enabled?: boolean; /** * S3 location where browser session recordings are stored. See `s3Location` below. */ s3Location?: outputs.bedrock.AgentcoreBrowserRecordingS3Location; } interface AgentcoreBrowserRecordingS3Location { /** * Name of the S3 bucket where recordings are stored. */ bucket: string; /** * S3 key prefix for recording files. */ prefix: string; } interface AgentcoreBrowserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface AgentcoreCodeInterpreterCertificate { /** * Location from which to retrieve the certificate. See `certificate.location` below. */ location: outputs.bedrock.AgentcoreCodeInterpreterCertificateLocation; } interface AgentcoreCodeInterpreterCertificateLocation { /** * AWS Secrets Manager location of the certificate. See `secretsManager` below. */ secretsManager?: outputs.bedrock.AgentcoreCodeInterpreterCertificateLocationSecretsManager; } interface AgentcoreCodeInterpreterCertificateLocationSecretsManager { /** * ARN of the AWS Secrets Manager secret containing the certificate. */ secretArn: string; } interface AgentcoreCodeInterpreterNetworkConfiguration { /** * Network mode for the code interpreter. Valid values: `PUBLIC`, `SANDBOX`, `VPC`. */ networkMode: string; /** * VPC configuration. See `vpcConfig` below. */ vpcConfig?: outputs.bedrock.AgentcoreCodeInterpreterNetworkConfigurationVpcConfig; } interface AgentcoreCodeInterpreterNetworkConfigurationVpcConfig { /** * Security groups associated with the VPC configuration. */ securityGroups: string[]; /** * Subnets associated with the VPC configuration. */ subnets: string[]; } interface AgentcoreCodeInterpreterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface AgentcoreEvaluatorEvaluatorConfig { /** * Configuration that runs a Lambda function you provide to score the agent. See `codeBased` below. */ codeBased?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigCodeBased; /** * Configuration that uses a Bedrock model to score the agent. See `llmAsAJudge` below. */ llmAsAJudge?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudge; } interface AgentcoreEvaluatorEvaluatorConfigCodeBased { /** * Lambda function configuration. See `lambdaConfig` below. */ lambdaConfig?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigCodeBasedLambdaConfig; } interface AgentcoreEvaluatorEvaluatorConfigCodeBasedLambdaConfig { /** * ARN of the Lambda function that runs the evaluation. */ lambdaArn: string; /** * Time in seconds to wait for the Lambda function before timing out. Defaults to 60. Range 1–300. */ lambdaTimeoutInSeconds: number; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudge { /** * Instructions that tell the model how to score the agent. */ instructions: string; /** * Which Bedrock model to use. See `modelConfig` below. */ modelConfig: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeModelConfig; /** * Scale used to score the agent. See `ratingScale` below. */ ratingScale: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeRatingScale; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeModelConfig { /** * Amazon Bedrock model configuration. See `bedrockEvaluatorModelConfig` below. */ bedrockEvaluatorModelConfig?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeModelConfigBedrockEvaluatorModelConfig; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeModelConfigBedrockEvaluatorModelConfig { /** * JSON-encoded model-specific request fields, for settings not covered by `inferenceConfig`. */ additionalModelRequestFields?: string; /** * Settings that control how the model generates its response. See `inferenceConfig` below. */ inferenceConfig?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeModelConfigBedrockEvaluatorModelConfigInferenceConfig; /** * Identifier of the Amazon Bedrock model to use for evaluation. */ modelId: string; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeModelConfigBedrockEvaluatorModelConfigInferenceConfig { /** * Maximum number of tokens to generate in the model response. Must be at least 1. */ maxTokens?: number; /** * List of sequences that cause the model to stop generating tokens. */ stopSequences?: string[]; /** * Temperature value that controls randomness. Range 0–1. */ temperature?: number; /** * Top-p sampling parameter. Range 0–1. */ topP?: number; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeRatingScale { /** * One or more categorical rating scale definitions. See `categorical` below. */ categoricals?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeRatingScaleCategorical[]; /** * One or more numerical rating scale definitions. See `numerical` below. */ numericals?: outputs.bedrock.AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeRatingScaleNumerical[]; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeRatingScaleCategorical { /** * Description that explains what this categorical rating represents. */ definition: string; /** * Label for this categorical rating option. Length 1–100. */ label: string; } interface AgentcoreEvaluatorEvaluatorConfigLlmAsAJudgeRatingScaleNumerical { /** * Description that explains what this numerical rating represents. */ definition: string; /** * Label for this numerical rating option. Length 1–100. */ label: string; /** * Numerical value for this rating option. Must be at least 0. */ value: number; } interface AgentcoreEvaluatorTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreGatewayAuthorizerConfiguration { /** * JWT-based authorization configuration block. See `customJwtAuthorizer` below. */ customJwtAuthorizer?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizer; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizer { /** * Set of allowed audience values for JWT token validation. */ allowedAudiences?: string[]; /** * Set of allowed client IDs for JWT token validation. */ allowedClients?: string[]; /** * Set of scopes that are allowed to access the token. */ allowedScopes?: string[]; /** * Configuration restricting which workloads may use this authorizer. See `allowedWorkloadConfiguration` below. */ allowedWorkloadConfiguration?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration; /** * Repeatable block to define a custom claim validation name, value, and operation. See `customClaim` below. */ customClaims?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerCustomClaim[]; /** * URL used to fetch OpenID Connect configuration or authorization server metadata. Must end with `.well-known/openid-configuration`. */ discoveryUrl: string; /** * Private endpoint used to reach the authorization server. See `privateEndpoint` below. */ privateEndpoint?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint; /** * Overrides for the private endpoints used to reach the authorization server. See `privateEndpointOverrides` below. */ privateEndpointOverrides?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride[]; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration { /** * Hosting environments allowed to use the authorizer. Between 1 and 10 entries. See `hostingEnvironment` below. */ hostingEnvironments?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment[]; /** * List of workload identity names allowed to use the authorizer. Between 1 and 10 entries. */ workloadIdentities?: string[]; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment { /** * ARN of the hosting environment. */ arn: string; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerCustomClaim { /** * Configuration block to define the value or values to match for and the relationship of the match. See `authorizingClaimMatchValue` below. */ authorizingClaimMatchValue: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue; /** * Name of the custom claim field to check. */ inboundTokenClaimName: string; /** * Data type of the claim value to check for. Valid values are `STRING` and `STRING_ARRAY`. */ inboundTokenClaimValueType: string; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue { /** * Relationship between the claim field value and the value or values to match for. Valid values are `EQUALS`, `CONTAINS`, and `CONTAINS_ANY`. `EQUALS` can be used only when `inboundTokenClaimValueType` is `STRING`. `CONTAINS` or `CONTAINS_ANY` can be used only when `inboundTokenClaimValueType` is `STRING_ARRAY`. */ claimMatchOperator: string; /** * Value or values to match for. See `claimMatchValue` below. */ claimMatchValue: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue { /** * String value to match for. Must be specified when `claimMatchOperator` is `EQUALS` or `CONTAINS`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueString?: string; /** * List of strings to check for a match. Must be specified when `claimMatchOperator` is `CONTAINS_ANY`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueStringLists?: string[]; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` below. */ managedVpcResource?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride { /** * Domain the override applies to. */ domain: string; /** * Private endpoint configuration. See `privateEndpoint` below. */ privateEndpoint: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` below. */ managedVpcResource?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreGatewayAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreGatewayInterceptorConfiguration { /** * Input configuration for the interceptor. See `inputConfiguration` below. */ inputConfiguration?: outputs.bedrock.AgentcoreGatewayInterceptorConfigurationInputConfiguration; /** * Set of interception points. Valid values: `REQUEST`, `RESPONSE`. */ interceptionPoints: string[]; /** * Interceptor infrastructure configuration. See `interceptor` below. */ interceptor?: outputs.bedrock.AgentcoreGatewayInterceptorConfigurationInterceptor; } interface AgentcoreGatewayInterceptorConfigurationInputConfiguration { /** * Whether to pass request headers to the interceptor. */ passRequestHeaders: boolean; } interface AgentcoreGatewayInterceptorConfigurationInterceptor { /** * Lambda function configuration for the interceptor. See `lambda` below. */ lambda?: outputs.bedrock.AgentcoreGatewayInterceptorConfigurationInterceptorLambda; } interface AgentcoreGatewayInterceptorConfigurationInterceptorLambda { /** * ARN of the Lambda function to invoke for the interceptor. */ arn: string; } interface AgentcoreGatewayPolicyEngineConfiguration { /** * ARN of the policy engine. The policy engine contains Cedar policies that define fine-grained authorization rules specifying who can perform what actions on which resources as agents interact through the gateway. */ arn: string; /** * Enforcement mode for the policy engine. Valid values: `LOG_ONLY`, `ENFORCE`. In `LOG_ONLY` mode, the policy engine evaluates actions and records traces but does not enforce decisions. In `ENFORCE` mode, the policy engine evaluates actions and enforces allow/deny decisions. */ mode: string; } interface AgentcoreGatewayProtocolConfiguration { /** * Model Context Protocol (MCP) configuration block. See `mcp` below. */ mcp?: outputs.bedrock.AgentcoreGatewayProtocolConfigurationMcp; } interface AgentcoreGatewayProtocolConfigurationMcp { /** * Instructions for the MCP protocol configuration. */ instructions?: string; /** * Search type for MCP. Valid values: `SEMANTIC`. */ searchType?: string; /** * Configuration block for session settings of the MCP gateway. See `sessionConfiguration` below. */ sessionConfiguration?: outputs.bedrock.AgentcoreGatewayProtocolConfigurationMcpSessionConfiguration; /** * Configuration block for streaming settings of the MCP gateway. See `streamingConfiguration` below. */ streamingConfiguration?: outputs.bedrock.AgentcoreGatewayProtocolConfigurationMcpStreamingConfiguration; /** * Set of supported MCP protocol versions. */ supportedVersions?: string[]; } interface AgentcoreGatewayProtocolConfigurationMcpSessionConfiguration { /** * Integer value for session timeout in seconds. Must be between 900 and 28800. */ sessionTimeoutInSeconds?: number; } interface AgentcoreGatewayProtocolConfigurationMcpStreamingConfiguration { /** * Boolean indicating whether response streaming is enabled for the gateway. */ enableResponseStreaming?: boolean; } interface AgentcoreGatewayRuleAction { /** * Reference to the configuration bundle for this variant. */ configurationBundle?: outputs.bedrock.AgentcoreGatewayRuleActionConfigurationBundle; /** * Route requests to a gateway target when the rule's conditions match. See routeToTarget below. */ routeToTarget?: outputs.bedrock.AgentcoreGatewayRuleActionRouteToTarget; } interface AgentcoreGatewayRuleActionConfigurationBundle { /** * Statically override the configuration bundle used for the matched request. */ staticOverride?: outputs.bedrock.AgentcoreGatewayRuleActionConfigurationBundleStaticOverride; /** * Distribute the request across two configuration bundle versions by weight. */ weightedOverride?: outputs.bedrock.AgentcoreGatewayRuleActionConfigurationBundleWeightedOverride; } interface AgentcoreGatewayRuleActionConfigurationBundleStaticOverride { /** * ARN of the configuration bundle to apply. */ bundleArn: string; /** * Version (UUID) of the configuration bundle to apply. */ bundleVersion: string; } interface AgentcoreGatewayRuleActionConfigurationBundleWeightedOverride { /** * Exactly two `trafficSplit` blocks describing the two variants. */ trafficSplits?: outputs.bedrock.AgentcoreGatewayRuleActionConfigurationBundleWeightedOverrideTrafficSplit[]; } interface AgentcoreGatewayRuleActionConfigurationBundleWeightedOverrideTrafficSplit { /** * Reference to the configuration bundle for this variant. */ configurationBundle?: outputs.bedrock.AgentcoreGatewayRuleActionConfigurationBundleWeightedOverrideTrafficSplitConfigurationBundle; /** * Description of the rule. Between 1 and 256 characters. */ description?: string; /** * Up to 25 key/value metadata pairs describing this variant. */ metadata?: { [key: string]: string; }; /** * Name of this variant. Between 1 and 64 characters; alphanumeric with internal hyphens. */ name: string; /** * Percentage of traffic routed to this variant, between 1 and 99. */ weight: number; } interface AgentcoreGatewayRuleActionConfigurationBundleWeightedOverrideTrafficSplitConfigurationBundle { /** * ARN of the configuration bundle to apply. */ bundleArn: string; /** * Version (UUID) of the configuration bundle to apply. */ bundleVersion: string; } interface AgentcoreGatewayRuleActionRouteToTarget { /** * Route all matching requests to a single named gateway target. */ staticRoute?: outputs.bedrock.AgentcoreGatewayRuleActionRouteToTargetStaticRoute; /** * Distribute requests across two named targets by weight. */ weightedRoute?: outputs.bedrock.AgentcoreGatewayRuleActionRouteToTargetWeightedRoute; } interface AgentcoreGatewayRuleActionRouteToTargetStaticRoute { /** * Name of the gateway target this variant points to. */ targetName: string; } interface AgentcoreGatewayRuleActionRouteToTargetWeightedRoute { /** * Exactly two `trafficSplit` blocks describing the two variants. */ trafficSplits?: outputs.bedrock.AgentcoreGatewayRuleActionRouteToTargetWeightedRouteTrafficSplit[]; } interface AgentcoreGatewayRuleActionRouteToTargetWeightedRouteTrafficSplit { /** * Description of the rule. Between 1 and 256 characters. */ description?: string; /** * Up to 25 key/value metadata pairs describing this variant. */ metadata?: { [key: string]: string; }; /** * Name of this variant. Between 1 and 64 characters; alphanumeric with internal hyphens. */ name: string; /** * Name of the gateway target this variant points to. */ targetName: string; /** * Percentage of traffic routed to this variant, between 1 and 99. */ weight: number; } interface AgentcoreGatewayRuleCondition { /** * Match when the request path matches any of the supplied glob patterns (e.g. `/api/*`). */ matchPaths?: outputs.bedrock.AgentcoreGatewayRuleConditionMatchPaths; /** * Match when the caller's IAM identity matches any of the supplied principal entries. */ matchPrincipals?: outputs.bedrock.AgentcoreGatewayRuleConditionMatchPrincipals; } interface AgentcoreGatewayRuleConditionMatchPaths { /** * Between 1 and 100 principal entry blocks. */ anyOfs: string[]; } interface AgentcoreGatewayRuleConditionMatchPrincipals { /** * Between 1 and 100 principal entry blocks. */ anyOfs?: outputs.bedrock.AgentcoreGatewayRuleConditionMatchPrincipalsAnyOf[]; } interface AgentcoreGatewayRuleConditionMatchPrincipalsAnyOf { /** * Match an IAM user, role, or assumed-role ARN. Exactly one `iamPrincipal` block is required per entry. */ iamPrincipal: outputs.bedrock.AgentcoreGatewayRuleConditionMatchPrincipalsAnyOfIamPrincipal; } interface AgentcoreGatewayRuleConditionMatchPrincipalsAnyOfIamPrincipal { /** * IAM principal ARN. Wildcards are allowed with the `StringLike` operator. */ arn: string; /** * Match operator, one of `StringEquals` or `StringLike`. Defaults to `StringEquals`. */ operator: string; } interface AgentcoreGatewayRuleSystem { /** * Name of the system that manages the rule. */ managedBy: string; } interface AgentcoreGatewayRuleTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreGatewayTargetCredentialProviderConfiguration { /** * API key-based authentication configuration. See `apiKey` Block below. */ apiKey?: outputs.bedrock.AgentcoreGatewayTargetCredentialProviderConfigurationApiKey; /** * Caller IAM credentials-based authentication configuration. See `callerIamCredentials` Block below. */ callerIamCredentials?: outputs.bedrock.AgentcoreGatewayTargetCredentialProviderConfigurationCallerIamCredentials; /** * Use the gateway's IAM role for authentication. See `gatewayIamRole` Block below. */ gatewayIamRole?: outputs.bedrock.AgentcoreGatewayTargetCredentialProviderConfigurationGatewayIamRole; /** * JWT passthrough-based authentication configuration. This is an empty configuration block. */ jwtPassthrough?: outputs.bedrock.AgentcoreGatewayTargetCredentialProviderConfigurationJwtPassthrough; /** * OAuth-based authentication configuration. See `oauth` Block below. */ oauth?: outputs.bedrock.AgentcoreGatewayTargetCredentialProviderConfigurationOauth; } interface AgentcoreGatewayTargetCredentialProviderConfigurationApiKey { /** * Location where the API key credential is provided. Valid values: `HEADER`, `QUERY_PARAMETER`. */ credentialLocation?: string; /** * Name of the parameter containing the API key credential. */ credentialParameterName?: string; /** * Prefix to add to the API key credential value. */ credentialPrefix?: string; /** * ARN of the OIDC provider for API key authentication. */ providerArn: string; } interface AgentcoreGatewayTargetCredentialProviderConfigurationCallerIamCredentials { /** * AWS region for the credentials. */ region?: string; /** * Service name for the credentials. */ service: string; } interface AgentcoreGatewayTargetCredentialProviderConfigurationGatewayIamRole { /** * AWS Region used for SigV4 signing of upstream requests. Defaults to the gateway's Region when omitted. Only meaningful when `service` is set. */ region?: string; /** * Target AWS service name used for SigV4 signing of upstream requests. Required when calling SigV4-protected endpoints such as another Bedrock AgentCore Runtime (use `bedrock-agentcore`). Omit for non-SigV4 IAM-role-based authentication, in which case the block can be empty (`gatewayIamRole {}`). */ service?: string; } interface AgentcoreGatewayTargetCredentialProviderConfigurationJwtPassthrough { } interface AgentcoreGatewayTargetCredentialProviderConfigurationOauth { /** * Map of custom parameters to include in OAuth requests. */ customParameters?: { [key: string]: string; }; /** * URL where the end user's browser is redirected after obtaining the authorization code. Required when `grantType` is `AUTHORIZATION_CODE`. */ defaultReturnUrl?: string; /** * OAuth grant type. Valid values: `CLIENT_CREDENTIALS` (machine-to-machine authentication), `AUTHORIZATION_CODE` (user-delegated access). */ grantType?: string; /** * ARN of the Oauth credential provider for OAuth authentication. */ providerArn: string; /** * Set of OAuth scopes to request. */ scopes: string[]; } interface AgentcoreGatewayTargetMetadataConfiguration { /** * Set of URL query parameters that are allowed to be propagated from incoming gateway URL to the target. Maximum of 10 parameters. */ allowedQueryParameters?: string[]; /** * Set of HTTP headers that are allowed to be propagated from incoming client requests to the target. Maximum of 10 headers. */ allowedRequestHeaders?: string[]; /** * Set of HTTP headers that are allowed to be propagated from the target response back to the client. Maximum of 10 headers. * * > **Note:** Header names must contain only alphanumeric characters, hyphens, and underscores. A large number of standard HTTP headers are restricted and cannot be configured for propagation, including authentication, content negotiation, caching, security, CORS, and connection management headers. Headers starting with `X-Amzn-` are prohibited except for `X-Amzn-Bedrock-AgentCore-Runtime-Custom-*` headers. These restrictions are enforced by schema validation. For the full list of restricted headers, see the [AWS documentation](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-headers.html). */ allowedResponseHeaders?: string[]; } interface AgentcoreGatewayTargetPrivateEndpoint { /** * AWS creates and manages the VPC Lattice resource gateway and resource configuration on your behalf using a service-linked role. See `managedVpcResource` Block below. */ managedVpcResource?: outputs.bedrock.AgentcoreGatewayTargetPrivateEndpointManagedVpcResource; /** * Use an existing VPC Lattice resource configuration that you manage yourself. Useful for cross-account setups or advanced Lattice configurations. See `selfManagedLatticeResource` Block below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreGatewayTargetPrivateEndpointSelfManagedLatticeResource; } interface AgentcoreGatewayTargetPrivateEndpointManagedVpcResource { /** * IP address type for the resource configuration endpoint. Valid values: `IPV4`, `IPV6`. */ endpointIpAddressType: string; /** * Intermediate domain (e.g. a VPCE or ALB DNS name) to use instead of the actual target domain. Useful when the MCP server uses a private TLS certificate — place an ALB with a public ACM cert in front and set this to the ALB DNS name. */ routingDomain?: string; /** * Set of security group IDs (up to 5) to associate with the Lattice resource gateway. Defaults to the VPC default security group. */ securityGroupIds?: string[]; /** * Set of subnet IDs inside the VPC where Lattice ENIs are placed. */ subnetIds: string[]; /** * Map of tags to apply to the managed Lattice resource gateway. */ tags?: { [key: string]: string; }; /** * ID of the VPC that contains the private resource. */ vpcIdentifier: string; } interface AgentcoreGatewayTargetPrivateEndpointSelfManagedLatticeResource { /** * ARN or ID of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreGatewayTargetTargetConfiguration { /** * HTTP target configuration for routing requests directly to an AgentCore Runtime agent. See `http` Block below. */ http?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttp; /** * Inference target configuration for routing requests to a large language model (LLM) provider, either through a built-in connector or an explicitly configured provider. See `inference` Block below. */ inference?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInference; /** * Model Context Protocol (MCP) configuration. See `mcp` Block below. */ mcp?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcp; } interface AgentcoreGatewayTargetTargetConfigurationHttp { /** * AgentCore Runtime target configuration. See `agentcoreRuntime` Block below. */ agentcoreRuntime?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntime; /** * Passthrough target configuration that forwards requests to an external HTTPS endpoint. See `passthrough` Block below. * * > **Note:** HTTP targets can only be attached to gateways that do not have a `protocolType` set. They are not supported on MCP-protocol gateways. */ passthrough?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpPassthrough; } interface AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntime { /** * ARN of the AgentCore Runtime agent that the gateway routes requests to. */ arn: string; /** * Runtime qualifier identifying a specific endpoint version. Defaults to `DEFAULT` when not set. */ qualifier?: string; /** * API schema configuration that defines the structure of the runtime target's API. See `schema` Block below. */ schema?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchema; } interface AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchema { /** * Configuration for the API schema. Supports exactly one of `inlinePayload` or `s3` (see `s3` Block). For HTTP targets, the `inlinePayload` block is documented under its full path (for example, `target_configuration.http.agentcore_runtime.schema.source.inline_payload` Block). */ source: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchemaSource; } interface AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchemaSource { inlinePayload?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchemaSourceInlinePayload; s3?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchemaSourceS3; } interface AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchemaSourceInlinePayload { /** * Inline schema payload content. */ payload: string; } interface AgentcoreGatewayTargetTargetConfigurationHttpAgentcoreRuntimeSchemaSourceS3 { /** * Account ID of the S3 bucket owner. */ bucketOwnerAccountId?: string; /** * S3 URI where the schema is stored. */ uri?: string; } interface AgentcoreGatewayTargetTargetConfigurationHttpPassthrough { /** * HTTPS endpoint that the gateway forwards requests to for this passthrough target. Must start with `https://`. */ endpoint: string; /** * Application protocol the passthrough target implements. Valid values: `MCP`, `A2A`, `INFERENCE`, `CUSTOM`. */ protocolType: string; /** * API schema configuration that defines the structure of the passthrough target's API. See `schema` Block below. */ schema?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchema; /** * Controls precedence when a client request supplies a query parameter whose name matches a configured static query parameter. Valid values: `CLIENT_OVERRIDE`, `STATIC_OVERRIDE`. */ staticQueryParameterConflictResolution?: string; /** * Map of static query parameters that the gateway always appends to the outbound URL when forwarding requests to the target. */ staticQueryParameters?: { [key: string]: string; }; /** * Session stickiness configuration routing requests within the same session to the same target. See `stickinessConfiguration` below. */ stickinessConfiguration?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpPassthroughStickinessConfiguration; } interface AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchema { /** * Configuration for the API schema. Supports exactly one of `inlinePayload` or `s3` (see `s3` Block). For HTTP targets, the `inlinePayload` block is documented under its full path (for example, `target_configuration.http.agentcore_runtime.schema.source.inline_payload` Block). */ source: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchemaSource; } interface AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchemaSource { inlinePayload?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchemaSourceInlinePayload; s3?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchemaSourceS3; } interface AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchemaSourceInlinePayload { /** * Inline schema payload content. */ payload: string; } interface AgentcoreGatewayTargetTargetConfigurationHttpPassthroughSchemaSourceS3 { /** * Account ID of the S3 bucket owner. */ bucketOwnerAccountId?: string; /** * S3 URI where the schema is stored. */ uri?: string; } interface AgentcoreGatewayTargetTargetConfigurationHttpPassthroughStickinessConfiguration { /** * Additional headers to include in session affinity routing. */ compositeIdentifiers?: string[]; /** * Expression identifying where to extract the session identifier from the request (for example, `$context.header.x-session-id`). */ identifier: string; /** * Session stickiness timeout, in seconds. Valid values range from 1 to 86400. */ timeout?: number; } interface AgentcoreGatewayTargetTargetConfigurationInference { /** * Connector-based inference configuration that routes requests to an LLM provider through a built-in connector with predefined provider rules. See `target_configuration.inference.connector` Block below. */ connector?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceConnector; /** * Provider-based inference configuration that explicitly defines the endpoint, model mapping, and operations used to route requests to an LLM provider. See `provider` Block below. */ provider?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceProvider; } interface AgentcoreGatewayTargetTargetConfigurationInferenceConnector { /** * Source configuration identifying which connector to use. See `target_configuration.mcp.connector.source` Block below. */ source: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceConnectorSource; } interface AgentcoreGatewayTargetTargetConfigurationInferenceConnectorSource { /** * Identifier for the connector integration (for example, `bedrock-knowledge-bases`). */ connectorId: string; } interface AgentcoreGatewayTargetTargetConfigurationInferenceProvider { /** * HTTPS endpoint of the inference provider that the gateway forwards requests to. */ endpoint: string; /** * Configuration that translates client-facing model IDs to the model IDs expected by the provider. See `modelMapping` Block below. */ modelMapping?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceProviderModelMapping; /** * List of per-operation configurations that map request paths to the models supported for each operation. See `operation` below. */ operations?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceProviderOperation[]; } interface AgentcoreGatewayTargetTargetConfigurationInferenceProviderModelMapping { /** * Provider prefix configuration used for model ID translation. See `providerPrefix` Block below. */ providerPrefix?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceProviderModelMappingProviderPrefix; } interface AgentcoreGatewayTargetTargetConfigurationInferenceProviderModelMappingProviderPrefix { /** * Single character that separates the provider prefix from the model name (for example, `.`). Defaults to `.`. */ separator?: string; /** * Whether clients can omit the provider prefix from model IDs. If `true`, the gateway accepts model IDs without the prefix and restores the full prefixed form before forwarding to the provider. Defaults to `false`. */ strip: boolean; } interface AgentcoreGatewayTargetTargetConfigurationInferenceProviderOperation { /** * List of models supported for this operation. See `model` Block below. */ models?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationInferenceProviderOperationModel[]; /** * Request path for this operation (for example, `/v1/messages` or `/v1/responses`). */ path: string; /** * Provider path to forward requests to, if it differs from the request path. For example, `/anthropic/v1/messages` when the provider expects a different path than the client-facing `/v1/messages`. */ providerPath?: string; } interface AgentcoreGatewayTargetTargetConfigurationInferenceProviderOperationModel { model: string; } interface AgentcoreGatewayTargetTargetConfigurationMcp { /** * API Gateway target configuration. See `apiGateway` Block below. */ apiGateway?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpApiGateway; /** * Connector integration target configuration. Connectors provide pre-built integrations with AWS services and third-party tools. See `target_configuration.mcp.connector` Block below. */ connector?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpConnector; /** * Lambda function target configuration. See `lambda` Block below. */ lambda?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambda; /** * MCP server target configuration. See `mcpServer` Block below. */ mcpServer?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpMcpServer; /** * OpenAPI schema-based target configuration. Supports exactly one of `inlinePayload` (see `target_configuration.mcp.open_api_schema.inline_payload` Block) or `s3` (see `s3` Block). */ openApiSchema?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpOpenApiSchema; /** * Smithy model-based target configuration. Supports exactly one of `inlinePayload` (see `target_configuration.mcp.smithy_model.inline_payload` Block) or `s3` (see `s3` Block). */ smithyModel?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpSmithyModel; } interface AgentcoreGatewayTargetTargetConfigurationMcpApiGateway { /** * Configuration for API Gateway tools. See `apiGatewayToolConfiguration` Block below. */ apiGatewayToolConfiguration?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpApiGatewayApiGatewayToolConfiguration; /** * ID of the API Gateway REST API to invoke. */ restApiId: string; /** * Stage name of the REST API to add as a target. */ stage: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpApiGatewayApiGatewayToolConfiguration { /** * Repeatable block of path and method patterns to expose as tools. See `toolFilter` Block below. */ toolFilters?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpApiGatewayApiGatewayToolConfigurationToolFilter[]; /** * Repeatable block of explicit tool definitions with optional custom names and descriptions. See `toolOverride` Block below. */ toolOverrides?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpApiGatewayApiGatewayToolConfigurationToolOverride[]; } interface AgentcoreGatewayTargetTargetConfigurationMcpApiGatewayApiGatewayToolConfigurationToolFilter { /** * Resource path to match in the REST API. Supports exact paths (for example, `/pets`) or wildcard paths (for example, `/pets/*` to match all paths under `/pets`). Must match existing paths in the REST API. */ filterPath: string; /** * List of HTTP methods to filter for. Valid values: `GET`, `DELETE`, `HEAD`, `OPTIONS`, `PATCH`, `PUT` and `POST`. */ methods: string[]; } interface AgentcoreGatewayTargetTargetConfigurationMcpApiGatewayApiGatewayToolConfigurationToolOverride { /** * Description of the tool. Provides information about the purpose and usage of the tool. If not provided, uses the description from the API's OpenAPI specification. */ description?: string; /** * HTTP method to expose for the specified path. Valid values: `GET`, `DELETE`, `HEAD`, `OPTIONS`, `PATCH`, `PUT` and `POST`. */ method: string; /** * Name of tool. Identifies the tool in the Model Context Protocol. */ name: string; /** * Resource path in the REST API (e.g., `/pets`). Must explicitly match an existing path in the REST API. */ path: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpConnector { /** * Per-tool configurations for the connector. See `configuration` Block below. */ configurations: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpConnectorConfiguration[]; /** * List of tool names to enable from this connector. If omitted, all tools provided by the connector are enabled. */ enableds?: string[]; /** * Source configuration identifying which connector to use. See `target_configuration.mcp.connector.source` Block below. */ source: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpConnectorSource; } interface AgentcoreGatewayTargetTargetConfigurationMcpConnectorConfiguration { /** * Agent-facing description override for this tool. */ description?: string; /** * Tool or operation name (for example, `retrieve` or `webSearch`). */ name: string; /** * Parameter overrides to control parameter visibility and descriptions. See `parameterOverride` Block below. */ parameterOverrides?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpConnectorConfigurationParameterOverride[]; /** * JSON-encoded parameters to set as fixed or default values when provisioning this tool. Free-form JSON whose schema is defined by the connector. */ parameterValues?: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpConnectorConfigurationParameterOverride { /** * Description of the gateway target. */ description?: string; path: string; /** * Whether this parameter is visible to the agent. If not specified, uses the service default. */ visible?: boolean; } interface AgentcoreGatewayTargetTargetConfigurationMcpConnectorSource { /** * Identifier for the connector integration (for example, `bedrock-knowledge-bases`). */ connectorId: string; /** * Version of the connector to use (for example, `1.2.0`). */ version: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambda { /** * ARN of the Lambda function to invoke. */ lambdaArn: string; /** * Schema definition for the tool. See `toolSchema` Block below. */ toolSchema: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchema; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchema { /** * Inline tool definition. See `target_configuration.mcp.lambda.tool_schema.inline_payload` Block below. */ inlinePayloads?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayload[]; /** * S3-based tool definition. See `s3` Block below. */ s3?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaS3; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayload { /** * Description of what the tool does. */ description: string; /** * Schema for the tool's input. See `inputSchema` Block below. */ inputSchema: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchema; /** * Name of the tool. */ name: string; /** * Schema for the tool's output. See `outputSchema` Block below. */ outputSchema?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchema; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchema { /** * Description of the schema element. */ description?: string; /** * Schema definition for array items. Can only be used when `type` is `array`. See `target_configuration.mcp.lambda.tool_schema.inline_payload.input_schema.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaItems; /** * Set of property definitions for object types. Can only be used when `type` is `object`. See `target_configuration.mcp.lambda.tool_schema.inline_payload.input_schema.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaProperty[]; /** * Data type of the schema. Valid values: `string`, `number`, `integer`, `boolean`, `array`, `object`. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaItems { /** * Description of the array items. */ description?: string; /** * Nested items definition for arrays of arrays. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaItemsItems; /** * Set of property definitions for arrays of objects. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaItemsProperty[]; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaItemsItems { /** * Description of the array items. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaItemsProperty { /** * Description of the property. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * Name of the property. */ name: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaProperty { /** * Description of the property. */ description?: string; /** * Items definition for array properties. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyItems; /** * Name of the property. */ name: string; /** * Set of nested property definitions for object properties. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyProperty[]; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyItems { /** * Description of the array items. */ description?: string; /** * Nested items definition for arrays of arrays. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyItemsItems; /** * Set of property definitions for arrays of objects. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyItemsProperty[]; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyItemsItems { /** * Description of the array items. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyItemsProperty { /** * Description of the property. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * Name of the property. */ name: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadInputSchemaPropertyProperty { /** * Description of the property. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * Name of the property. */ name: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchema { /** * Description of the schema element. */ description?: string; /** * Schema definition for array items. Can only be used when `type` is `array`. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaItems; /** * Set of property definitions for object types. Can only be used when `type` is `object`. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaProperty[]; /** * Data type of the schema. Valid values: `string`, `number`, `integer`, `boolean`, `array`, `object`. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaItems { /** * Description of the array items. */ description?: string; /** * Nested items definition for arrays of arrays. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaItemsItems; /** * Set of property definitions for arrays of objects. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaItemsProperty[]; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaItemsItems { /** * Description of the array items. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaItemsProperty { /** * Description of the property. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * Name of the property. */ name: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaProperty { /** * Description of the property. */ description?: string; /** * Items definition for array properties. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyItems; /** * Name of the property. */ name: string; /** * Set of nested property definitions for object properties. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyProperty[]; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyItems { /** * Description of the array items. */ description?: string; /** * Nested items definition for arrays of arrays. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.items` Block below. */ items?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyItemsItems; /** * Set of property definitions for arrays of objects. See `target_configuration.mcp.lambda.tool_schema.inline_payload.output_schema.property.items.property` Block below. */ properties?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyItemsProperty[]; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyItemsItems { /** * Description of the array items. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Data type of the array items. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyItemsProperty { /** * Description of the property. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * Name of the property. */ name: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaInlinePayloadOutputSchemaPropertyProperty { /** * Description of the property. */ description?: string; /** * JSON-encoded schema definition for array items. Used for complex nested structures. Cannot be used with `propertiesJson`. */ itemsJson?: string; /** * Name of the property. */ name: string; /** * JSON-encoded schema definition for object properties. Used for complex nested structures. Cannot be used with `itemsJson`. */ propertiesJson?: string; /** * Whether this property is required. Defaults to `false`. */ required: boolean; /** * Data type of the property. */ type: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpLambdaToolSchemaS3 { /** * Account ID of the S3 bucket owner. */ bucketOwnerAccountId?: string; /** * S3 URI where the schema is stored. */ uri?: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpMcpServer { /** * Endpoint for the MCP server target configuration. */ endpoint: string; /** * Listing mode for the MCP server target. Valid values are `DEFAULT` and `DYNAMIC`. MCP resources for `DEFAULT` targets are cached at the control plane for faster access, while resources for `DYNAMIC` targets are retrieved dynamically when listing tools. */ listingMode: string; /** * Tool schema configuration for the MCP server target. Supported only when the credential provider is configured with an authorization code grant type. When set, dynamic tool discovery and synchronization are disabled. See `mcpToolSchema` Block below. */ mcpToolSchema?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpMcpServerMcpToolSchema; /** * Priority for resolving MCP server targets with shared resource URIs. Lower values take precedence. Defaults to `1000` when not set. */ resourcePriority: number; } interface AgentcoreGatewayTargetTargetConfigurationMcpMcpServerMcpToolSchema { /** * Inline tool schema payload. The `inlinePayload` block requires a `payload` (string) containing the MCP tool schema definition. */ inlinePayload?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpMcpServerMcpToolSchemaInlinePayload; /** * S3 location of the tool schema. See `s3` Block below. */ s3?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpMcpServerMcpToolSchemaS3; } interface AgentcoreGatewayTargetTargetConfigurationMcpMcpServerMcpToolSchemaInlinePayload { /** * Inline schema payload content. */ payload: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpMcpServerMcpToolSchemaS3 { /** * Account ID of the S3 bucket owner. */ bucketOwnerAccountId?: string; /** * S3 URI where the schema is stored. */ uri: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpOpenApiSchema { inlinePayload?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpOpenApiSchemaInlinePayload; s3?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpOpenApiSchemaS3; } interface AgentcoreGatewayTargetTargetConfigurationMcpOpenApiSchemaInlinePayload { /** * Inline schema payload content. */ payload: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpOpenApiSchemaS3 { /** * Account ID of the S3 bucket owner. */ bucketOwnerAccountId?: string; /** * S3 URI where the schema is stored. */ uri?: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpSmithyModel { inlinePayload?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpSmithyModelInlinePayload; s3?: outputs.bedrock.AgentcoreGatewayTargetTargetConfigurationMcpSmithyModelS3; } interface AgentcoreGatewayTargetTargetConfigurationMcpSmithyModelInlinePayload { /** * Inline schema payload content. */ payload: string; } interface AgentcoreGatewayTargetTargetConfigurationMcpSmithyModelS3 { /** * Account ID of the S3 bucket owner. */ bucketOwnerAccountId?: string; /** * S3 URI where the schema is stored. */ uri?: string; } interface AgentcoreGatewayTargetTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreGatewayTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreGatewayWorkloadIdentityDetail { /** * ARN of the workload identity. */ workloadIdentityArn: string; } interface AgentcoreHarnessAuthorizerConfiguration { /** * JWT-based authorization configuration block. See `customJwtAuthorizer` Block below. */ customJwtAuthorizer?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizer; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizer { /** * Set of allowed audience values for JWT token validation. */ allowedAudiences?: string[]; /** * Set of allowed client IDs for JWT token validation. */ allowedClients?: string[]; /** * Set of scopes that are allowed to access the token. */ allowedScopes?: string[]; /** * Configuration restricting which workloads may use this authorizer. See `allowedWorkloadConfiguration` Block below. */ allowedWorkloadConfiguration?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration; /** * Repeatable block to define a custom claim validation name, value, and operation. See `customClaim` Block below. */ customClaims?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerCustomClaim[]; /** * URL used to fetch OpenID Connect configuration or authorization server metadata. Must end with `.well-known/openid-configuration`. */ discoveryUrl: string; /** * Private endpoint used to reach the authorization server. See `privateEndpoint` Block below. */ privateEndpoint?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint; /** * Overrides for the private endpoints used to reach the authorization server. See `privateEndpointOverrides` Block below. */ privateEndpointOverrides?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride[]; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration { /** * Hosting environments allowed to use the authorizer. Between 1 and 10 entries. See `hostingEnvironment` Block below. */ hostingEnvironments?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment[]; /** * List of workload identity names allowed to use the authorizer. Between 1 and 10 entries. */ workloadIdentities?: string[]; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment { /** * ARN of the hosting environment. */ arn: string; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerCustomClaim { /** * Configuration block to define the value or values to match for and the relationship of the match. See `authorizingClaimMatchValue` Block below. */ authorizingClaimMatchValue: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue; /** * Name of the custom claim field to check. */ inboundTokenClaimName: string; /** * Data type of the claim value to check for. Valid values are `STRING` and `STRING_ARRAY`. */ inboundTokenClaimValueType: string; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue { /** * Relationship between the claim field value and the value or values to match for. Valid values are `EQUALS`, `CONTAINS`, and `CONTAINS_ANY`. `EQUALS` can be used only when `inboundTokenClaimValueType` is `STRING`. `CONTAINS` or `CONTAINS_ANY` can be used only when `inboundTokenClaimValueType` is `STRING_ARRAY`. */ claimMatchOperator: string; /** * Value or values to match for. See `claimMatchValue` Block below. */ claimMatchValue: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue { /** * String value to match for. Must be specified when `claimMatchOperator` is `EQUALS` or `CONTAINS`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueString?: string; /** * List of strings to check for a match. Must be specified when `claimMatchOperator` is `CONTAINS_ANY`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueStringLists?: string[]; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` Block below. */ managedVpcResource?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` Block below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride { /** * Domain the override applies to. */ domain: string; /** * Private endpoint configuration. See `privateEndpoint` Block below. */ privateEndpoint: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` Block below. */ managedVpcResource?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` Block below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreHarnessAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreHarnessEnvironment { /** * AgentCore runtime environment configuration. See `environment.agentcore_runtime_environment` Block below. */ agentcoreRuntimeEnvironments?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironment[]; } interface AgentcoreHarnessEnvironmentActual { /** * AgentCore runtime environment configuration. See `environment_actual.agentcore_runtime_environment` Block below. */ agentcoreRuntimeEnvironments: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironment[]; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironment { /** * ARN of the agent runtime the service provisions for the harness. */ agentRuntimeArn: string; /** * ID of the agent runtime the service provisions for the harness. */ agentRuntimeId: string; /** * Name of the agent runtime the service derives for the harness. */ agentRuntimeName: string; /** * Filesystem configurations. See `environment_actual.agentcore_runtime_environment.filesystem_configuration` Block below. */ filesystemConfigurations: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfiguration[]; /** * Lifecycle configuration. See `environment_actual.agentcore_runtime_environment.lifecycle_configuration` Block below. */ lifecycleConfigurations: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentLifecycleConfiguration[]; /** * Network configuration. See `environment_actual.agentcore_runtime_environment.network_configuration` Block below. */ networkConfigurations: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentNetworkConfiguration[]; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfiguration { /** * Amazon EFS access point mounted as shared file storage. See `environment_actual.agentcore_runtime_environment.filesystem_configuration.efs_access_point` Block below. */ efsAccessPoints: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfigurationEfsAccessPoint[]; /** * Amazon S3 Files access point mounted as shared file storage. See `environment_actual.agentcore_runtime_environment.filesystem_configuration.s3_files_access_point` Block below. */ s3FilesAccessPoints: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfigurationS3FilesAccessPoint[]; /** * Session storage filesystem. See `environment_actual.agentcore_runtime_environment.filesystem_configuration.session_storage` Block below. */ sessionStorages: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfigurationSessionStorage[]; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfigurationEfsAccessPoint { /** * ARN of the Amazon EFS access point to mount into the agent runtime. */ accessPointArn: string; /** * Mount path for the EFS access point inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfigurationS3FilesAccessPoint { /** * ARN of the Amazon S3 Files access point to mount into the agent runtime. */ accessPointArn: string; /** * Mount path for the S3 Files access point inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentFilesystemConfigurationSessionStorage { /** * Mount path for the session storage filesystem inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentLifecycleConfiguration { /** * Timeout in seconds for idle sessions. */ idleRuntimeSessionTimeout: number; /** * Maximum lifetime of the instance in seconds. */ maxLifetime: number; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentNetworkConfiguration { /** * Network mode. */ networkMode: string; /** * VPC configuration. See `environment_actual.agentcore_runtime_environment.network_configuration.network_mode_config` Block below. */ networkModeConfigs: outputs.bedrock.AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentNetworkConfigurationNetworkModeConfig[]; } interface AgentcoreHarnessEnvironmentActualAgentcoreRuntimeEnvironmentNetworkConfigurationNetworkModeConfig { /** * Whether an S3 endpoint is required for the service in the VPC. */ requireServiceS3Endpoint: boolean; /** * Security groups for the VPC. */ securityGroups: string[]; /** * Subnets for the VPC. */ subnets: string[]; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironment { /** * ARN of the agent runtime the service provisions for the harness. */ agentRuntimeArn: string; /** * ID of the agent runtime the service provisions for the harness. */ agentRuntimeId: string; /** * Name of the agent runtime the service derives for the harness. */ agentRuntimeName: string; /** * Filesystem configurations. See `environment_actual.agentcore_runtime_environment.filesystem_configuration` Block below. */ filesystemConfigurations?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfiguration[]; /** * Lifecycle configuration. See `environment_actual.agentcore_runtime_environment.lifecycle_configuration` Block below. */ lifecycleConfigurations: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentLifecycleConfiguration[]; /** * Network configuration. See `environment_actual.agentcore_runtime_environment.network_configuration` Block below. */ networkConfigurations?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentNetworkConfiguration[]; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfiguration { /** * Amazon EFS access point mounted as shared file storage. See `environment_actual.agentcore_runtime_environment.filesystem_configuration.efs_access_point` Block below. */ efsAccessPoints?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfigurationEfsAccessPoint[]; /** * Amazon S3 Files access point mounted as shared file storage. See `environment_actual.agentcore_runtime_environment.filesystem_configuration.s3_files_access_point` Block below. */ s3FilesAccessPoints?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfigurationS3FilesAccessPoint[]; /** * Session storage filesystem. See `environment_actual.agentcore_runtime_environment.filesystem_configuration.session_storage` Block below. */ sessionStorages?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfigurationSessionStorage[]; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfigurationEfsAccessPoint { /** * ARN of the Amazon EFS access point to mount into the agent runtime. */ accessPointArn: string; /** * Mount path for the EFS access point inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfigurationS3FilesAccessPoint { /** * ARN of the Amazon S3 Files access point to mount into the agent runtime. */ accessPointArn: string; /** * Mount path for the S3 Files access point inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentFilesystemConfigurationSessionStorage { /** * Mount path for the session storage filesystem inside the agent runtime. Must be under `/mnt` with exactly one subdirectory level (for example, `/mnt/data`). */ mountPath: string; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentLifecycleConfiguration { /** * Timeout in seconds for idle sessions. */ idleRuntimeSessionTimeout: number; /** * Maximum lifetime of the instance in seconds. */ maxLifetime: number; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentNetworkConfiguration { /** * Network mode. */ networkMode: string; /** * VPC configuration. See `environment_actual.agentcore_runtime_environment.network_configuration.network_mode_config` Block below. */ networkModeConfigs?: outputs.bedrock.AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentNetworkConfigurationNetworkModeConfig[]; } interface AgentcoreHarnessEnvironmentAgentcoreRuntimeEnvironmentNetworkConfigurationNetworkModeConfig { /** * Whether an S3 endpoint is required for the service in the VPC. */ requireServiceS3Endpoint: boolean; /** * Security groups for the VPC. */ securityGroups: string[]; /** * Subnets for the VPC. */ subnets: string[]; } interface AgentcoreHarnessEnvironmentArtifact { /** * Container configuration. See `containerConfiguration` Block below. */ containerConfiguration?: outputs.bedrock.AgentcoreHarnessEnvironmentArtifactContainerConfiguration; } interface AgentcoreHarnessEnvironmentArtifactContainerConfiguration { /** * URI of the container image. */ containerUri: string; } interface AgentcoreHarnessMemory { /** * AgentCore memory configuration. Use this to connect to an existing AgentCore memory resource. See `memory.agentcore_memory_configuration` Block below. */ agentcoreMemoryConfiguration?: outputs.bedrock.AgentcoreHarnessMemoryAgentcoreMemoryConfiguration; /** * Explicitly disable memory for this harness. See `memory.disabled` Block below. */ disabled?: outputs.bedrock.AgentcoreHarnessMemoryDisabled; /** * Managed memory configuration. Creates and manages a memory resource automatically. See `memory.managed_memory_configuration` Block below. */ managedMemoryConfiguration?: outputs.bedrock.AgentcoreHarnessMemoryManagedMemoryConfiguration; } interface AgentcoreHarnessMemoryActual { /** * AgentCore memory configuration. See `memory_actual.agentcore_memory_configuration` Block below. */ agentcoreMemoryConfigurations: outputs.bedrock.AgentcoreHarnessMemoryActualAgentcoreMemoryConfiguration[]; /** * Present when memory is explicitly disabled. See `memory_actual.disabled` Block below. */ disableds: outputs.bedrock.AgentcoreHarnessMemoryActualDisabled[]; /** * Managed memory configuration. See `memory_actual.managed_memory_configuration` Block below. */ managedMemoryConfigurations: outputs.bedrock.AgentcoreHarnessMemoryActualManagedMemoryConfiguration[]; } interface AgentcoreHarnessMemoryActualAgentcoreMemoryConfiguration { /** * Actor ID for memory sessions. */ actorId: string; /** * ARN of the managed memory resource. */ arn: string; /** * Number of messages to retrieve from memory. */ messagesCount: number; /** * Retrieval configuration parameters. See `memory_actual.agentcore_memory_configuration.retrieval_config` Block below. */ retrievalConfigs: outputs.bedrock.AgentcoreHarnessMemoryActualAgentcoreMemoryConfigurationRetrievalConfig[]; } interface AgentcoreHarnessMemoryActualAgentcoreMemoryConfigurationRetrievalConfig { /** * Namespace path template for retrieval settings. */ mapBlockKey: string; /** * Relevance score threshold. Valid value is between `0` and `1`. */ relevanceScore: number; /** * ID of the memory strategy. */ strategyId: string; /** * Number of top results to retrieve. */ topK: number; } interface AgentcoreHarnessMemoryActualDisabled { } interface AgentcoreHarnessMemoryActualManagedMemoryConfiguration { /** * ARN of the managed memory resource. */ arn: string; /** * ARN of the customer-managed KMS key used to encrypt the memory. */ encryptionKeyArn: string; /** * Event retention in days. */ eventExpiryDuration: number; /** * Set of strategy types enabled. */ strategies: string[]; } interface AgentcoreHarnessMemoryAgentcoreMemoryConfiguration { /** * Actor ID for memory sessions. */ actorId?: string; /** * ARN of the managed memory resource. */ arn: string; /** * Number of messages to retrieve from memory. */ messagesCount?: number; /** * Retrieval configuration parameters. See `memory_actual.agentcore_memory_configuration.retrieval_config` Block below. */ retrievalConfig?: outputs.bedrock.AgentcoreHarnessMemoryAgentcoreMemoryConfigurationRetrievalConfig; } interface AgentcoreHarnessMemoryAgentcoreMemoryConfigurationRetrievalConfig { /** * Namespace path template for retrieval settings. */ mapBlockKey: string; /** * Relevance score threshold. Valid value is between `0` and `1`. */ relevanceScore?: number; /** * ID of the memory strategy. */ strategyId?: string; /** * Number of top results to retrieve. */ topK?: number; } interface AgentcoreHarnessMemoryDisabled { } interface AgentcoreHarnessMemoryManagedMemoryConfiguration { /** * ARN of the managed memory resource. */ arn: string; /** * ARN of the customer-managed KMS key used to encrypt the memory. */ encryptionKeyArn?: string; /** * Event retention in days. */ eventExpiryDuration: number; /** * Set of strategy types enabled. */ strategies: string[]; } interface AgentcoreHarnessModel { /** * Amazon Bedrock model configuration. See `bedrockModelConfig` Block below. */ bedrockModelConfig?: outputs.bedrock.AgentcoreHarnessModelBedrockModelConfig; /** * Gemini model configuration. See `geminiModelConfig` Block below. */ geminiModelConfig?: outputs.bedrock.AgentcoreHarnessModelGeminiModelConfig; /** * LiteLLM model configuration. See `litellmModelConfig` Block below. */ litellmModelConfig?: outputs.bedrock.AgentcoreHarnessModelLitellmModelConfig; /** * OpenAI model configuration. See `openaiModelConfig` Block below. */ openaiModelConfig?: outputs.bedrock.AgentcoreHarnessModelOpenaiModelConfig; } interface AgentcoreHarnessModelBedrockModelConfig { /** * JSON string containing provider-specific parameters to pass through to the Bedrock model provider unchanged. */ additionalParams?: string; /** * API format for the model. Valid values are `converseStream`, `responses`, and `chatCompletions`. */ apiFormat: string; /** * Maximum number of tokens to generate. */ maxTokens?: number; /** * Bedrock model ID (e.g., `anthropic.claude-sonnet-4-20250514`). */ modelId: string; /** * Temperature for sampling. Must be between 0 and 2. */ temperature?: number; /** * Top-p (nucleus) sampling parameter. Must be between 0 and 1. */ topP?: number; } interface AgentcoreHarnessModelGeminiModelConfig { /** * JSON string containing provider-specific parameters to pass through to the Gemini model provider unchanged. */ additionalParams?: string; /** * ARN of the secret containing the API key. */ apiKeyArn: string; /** * Maximum number of tokens to generate. */ maxTokens?: number; /** * Gemini model ID. */ modelId: string; /** * Temperature for sampling. */ temperature?: number; /** * Top-k sampling parameter. */ topK?: number; /** * Top-p sampling parameter. */ topP?: number; } interface AgentcoreHarnessModelLitellmModelConfig { /** * JSON string containing provider-specific parameters to pass through to the LiteLLM model provider unchanged. */ additionalParams?: string; /** * Base URL of the LiteLLM-compatible API endpoint. */ apiBase?: string; /** * ARN of the secret containing the API key. */ apiKeyArn?: string; /** * Maximum number of tokens to generate. */ maxTokens?: number; /** * LiteLLM model ID. */ modelId: string; /** * Temperature for sampling. Must be between 0 and 2. */ temperature?: number; /** * Top-p sampling parameter. Must be between 0 and 1. */ topP?: number; } interface AgentcoreHarnessModelOpenaiModelConfig { /** * JSON string containing provider-specific parameters to pass through to the OpenAI model provider unchanged. */ additionalParams?: string; /** * API format for the model. Valid values are `responses` and `chatCompletions`. */ apiFormat: string; /** * ARN of the secret containing the API key. */ apiKeyArn: string; /** * Maximum number of tokens to generate. */ maxTokens?: number; /** * OpenAI model ID. */ modelId: string; /** * Temperature for sampling. */ temperature?: number; /** * Top-p sampling parameter. */ topP?: number; } interface AgentcoreHarnessSkill { /** * AWS Skills baked into the harness's underlying runtime. See `awsSkills` Block below. */ awsSkills?: outputs.bedrock.AgentcoreHarnessSkillAwsSkills; /** * Git repository source for the skill. See `git` Block below. */ git?: outputs.bedrock.AgentcoreHarnessSkillGit; /** * Path to the skill. */ path?: string; /** * S3 source for the skill. See `s3` Block below. */ s3?: outputs.bedrock.AgentcoreHarnessSkillS3; } interface AgentcoreHarnessSkillAwsSkills { /** * List of glob patterns to filter allowed skills (e.g., `["core-skills/*"]`). */ paths?: string[]; } interface AgentcoreHarnessSkillGit { /** * Authentication configuration for private repositories. See `auth` Block below. */ auth?: outputs.bedrock.AgentcoreHarnessSkillGitAuth; /** * Subdirectory within the repository containing the skill. */ path?: string; /** * HTTPS URL of the git repository. */ url: string; } interface AgentcoreHarnessSkillGitAuth { /** * ARN of the credential in AgentCore Identity containing the password or personal access token. */ credentialArn: string; /** * Username for authentication. Defaults to `oauth2` if not specified. */ username?: string; } interface AgentcoreHarnessSkillS3 { /** * S3 URI of the skill source. Must begin with `s3://`. */ uri: string; } interface AgentcoreHarnessSystemPrompt { /** * Text content of the system prompt. */ text?: string; } interface AgentcoreHarnessTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreHarnessTool { /** * Tool-specific configuration. See `tool.config` Block below. */ config?: outputs.bedrock.AgentcoreHarnessToolConfig; /** * Name of the tool. */ name?: string; /** * Type of tool. Valid values: `remoteMcp`, `agentcoreBrowser`, `agentcoreGateway`, `inlineFunction`, `agentcoreCodeInterpreter`. */ type: string; } interface AgentcoreHarnessToolConfig { /** * AgentCore browser configuration. See `agentcoreBrowser` Block below. */ agentcoreBrowser?: outputs.bedrock.AgentcoreHarnessToolConfigAgentcoreBrowser; /** * AgentCore code interpreter configuration. See `agentcoreCodeInterpreter` Block below. */ agentcoreCodeInterpreter?: outputs.bedrock.AgentcoreHarnessToolConfigAgentcoreCodeInterpreter; /** * AgentCore gateway configuration. See `agentcoreGateway` Block below. */ agentcoreGateway?: outputs.bedrock.AgentcoreHarnessToolConfigAgentcoreGateway; /** * Inline function configuration. See `inlineFunction` Block below. */ inlineFunction?: outputs.bedrock.AgentcoreHarnessToolConfigInlineFunction; /** * Remote MCP server configuration. See `remoteMcp` Block below. */ remoteMcp?: outputs.bedrock.AgentcoreHarnessToolConfigRemoteMcp; } interface AgentcoreHarnessToolConfigAgentcoreBrowser { /** * ARN of the AgentCore browser resource. */ browserArn?: string; } interface AgentcoreHarnessToolConfigAgentcoreCodeInterpreter { /** * ARN of the AgentCore code interpreter resource. */ codeInterpreterArn?: string; } interface AgentcoreHarnessToolConfigAgentcoreGateway { /** * ARN of the AgentCore gateway resource. */ gatewayArn: string; /** * Outbound authentication configuration. See `outboundAuth` Block below. */ outboundAuth?: outputs.bedrock.AgentcoreHarnessToolConfigAgentcoreGatewayOutboundAuth; } interface AgentcoreHarnessToolConfigAgentcoreGatewayOutboundAuth { /** * Set to `true` to use AWS IAM authentication. */ awsIam?: boolean; /** * Set to `true` to disable authentication. */ none?: boolean; /** * OAuth credential provider configuration. See `oauth` Block below. */ oauth?: outputs.bedrock.AgentcoreHarnessToolConfigAgentcoreGatewayOutboundAuthOauth; } interface AgentcoreHarnessToolConfigAgentcoreGatewayOutboundAuthOauth { /** * Map of custom parameters. */ customParameters?: { [key: string]: string; }; /** * Default return URL for OAuth flow. */ defaultReturnUrl?: string; /** * OAuth grant type. */ grantType?: string; /** * ARN of the OAuth credential provider. */ providerArn: string; /** * List of OAuth scopes. */ scopes: string[]; } interface AgentcoreHarnessToolConfigInlineFunction { /** * Description of the inline function. */ description: string; /** * JSON string defining the input schema for the function. */ inputSchema: string; } interface AgentcoreHarnessToolConfigRemoteMcp { /** * Map of HTTP headers to include in requests to the MCP server. */ headers?: { [key: string]: string; }; /** * URL of the remote MCP server. */ url: string; } interface AgentcoreHarnessTruncation { /** * Strategy-specific configuration. See `truncation.config` Block below. */ configs: outputs.bedrock.AgentcoreHarnessTruncationConfig[]; /** * Truncation strategy. Valid values: `slidingWindow`, `summarization`, `none`. */ strategy: string; } interface AgentcoreHarnessTruncationConfig { /** * Sliding window truncation configuration. See `slidingWindow` Block below. */ slidingWindows: outputs.bedrock.AgentcoreHarnessTruncationConfigSlidingWindow[]; /** * Summarization truncation configuration. See `summarization` Block below. */ summarizations: outputs.bedrock.AgentcoreHarnessTruncationConfigSummarization[]; } interface AgentcoreHarnessTruncationConfigSlidingWindow { /** * Number of recent messages to keep in the conversation window. */ messagesCount: number; } interface AgentcoreHarnessTruncationConfigSummarization { /** * Number of recent messages to preserve without summarization. */ preserveRecentMessages: number; /** * Custom system prompt for the summarization model. */ summarizationSystemPrompt: string; /** * Ratio of the conversation to summarize (0 to 1). */ summaryRatio: number; } interface AgentcoreMemoryIndexedKey { /** * Metadata key name to index. */ key: string; /** * Data type of the indexed key. Valid values are `STRING`, `STRINGLIST`, and `NUMBER`. */ type: string; } interface AgentcoreMemoryStrategyConfiguration { /** * Consolidation configuration for the memory strategy. See `consolidation` Block below. Cannot be used with `type` set to `SELF_MANAGED`. Once added, this block cannot be removed without recreating the resource. */ consolidation?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationConsolidation; /** * Extraction configuration for the memory strategy. See `extraction` Block below. Cannot be used with `type` set to `SUMMARY_OVERRIDE` or `SELF_MANAGED`. Once added, this block cannot be removed without recreating the resource. */ extraction?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationExtraction; /** * Reflection configuration for the memory strategy. See `reflection` Block below. Can only be used, and is required, with `type` set to `EPISODIC_OVERRIDE`. Once added, this block cannot be removed without recreating the resource. */ reflection?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationReflection; /** * Self-managed processing configuration. Required when `type` is `SELF_MANAGED` and only valid for that type. See `selfManagedConfiguration` Block below. */ selfManagedConfiguration?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfiguration; /** * Type of custom override. Valid values: `SEMANTIC_OVERRIDE`, `SUMMARY_OVERRIDE`, `USER_PREFERENCE_OVERRIDE`, `EPISODIC_OVERRIDE`, `SELF_MANAGED`. Changing this forces a new resource. */ type: string; } interface AgentcoreMemoryStrategyConfigurationConsolidation { /** * Additional text to append to the model prompt for consolidation processing. */ appendToPrompt: string; /** * ID of the foundation model to use for consolidation processing. */ modelId: string; } interface AgentcoreMemoryStrategyConfigurationExtraction { /** * Additional text to append to the model prompt for extraction processing. */ appendToPrompt: string; /** * ID of the foundation model to use for extraction processing. */ modelId: string; } interface AgentcoreMemoryStrategyConfigurationReflection { /** * Additional text to append to the model prompt for reflection processing. */ appendToPrompt: string; /** * ID of the foundation model to use for reflection processing. */ modelId: string; /** * Namespace templates for episodic reflection. Can be less nested than the episodic namespaces. */ namespaceTemplates: string[]; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfiguration { /** * Number of historical messages to include in processing context. Valid range: `0` to `50`. Defaults to `4`. */ historicalContextWindowSize: number; /** * Configuration used to invoke the self-managed memory processing pipeline. See `invocationConfiguration` Block below. */ invocationConfiguration: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationInvocationConfiguration; /** * Conditions that trigger memory processing. See `triggerConditions` Block below. When omitted, the service supplies the documented defaults for all three trigger types. */ triggerConditions?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditions; /** * Actual deployed trigger conditions. */ triggerConditionsActuals: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActual[]; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationInvocationConfiguration { /** * S3 bucket name for event payload delivery. */ payloadDeliveryBucketName: string; /** * ARN of the SNS topic for job notifications. */ topicArn: string; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditions { /** * Message-based condition. See `messageBasedTrigger` Block below. */ messageBasedTrigger?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsMessageBasedTrigger; /** * Idle-time condition. See `timeBasedTrigger` Block below. */ timeBasedTrigger?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsTimeBasedTrigger; /** * Token-based condition. See `tokenBasedTrigger` Block below. */ tokenBasedTrigger?: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsTokenBasedTrigger; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActual { /** * Message-based condition. */ messageBasedTriggers: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActualMessageBasedTrigger[]; /** * Idle-time condition. */ timeBasedTriggers: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActualTimeBasedTrigger[]; /** * Token-based condition. */ tokenBasedTriggers: outputs.bedrock.AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActualTokenBasedTrigger[]; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActualMessageBasedTrigger { /** * Number of messages that trigger memory processing. Accepts values from `1` to `50`. */ messageCount: number; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActualTimeBasedTrigger { /** * Idle session timeout (seconds) that triggers memory processing. Accepts values from `10` to `3000`. */ idleSessionTimeout: number; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsActualTokenBasedTrigger { /** * Number of tokens that trigger memory processing. Accepts values from `100` to `500000`. */ tokenCount: number; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsMessageBasedTrigger { /** * Number of messages that trigger memory processing. Accepts values from `1` to `50`. */ messageCount: number; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsTimeBasedTrigger { /** * Idle session timeout (seconds) that triggers memory processing. Accepts values from `10` to `3000`. */ idleSessionTimeout: number; } interface AgentcoreMemoryStrategyConfigurationSelfManagedConfigurationTriggerConditionsTokenBasedTrigger { /** * Number of tokens that trigger memory processing. Accepts values from `100` to `500000`. */ tokenCount: number; } interface AgentcoreMemoryStrategyMemoryRecordSchema { /** * List of metadata field definitions for records generated by this strategy. See `metadataSchema` Block below. */ metadataSchemas?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchema[]; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchema { /** * Configuration for extracting this metadata value from conversational content. Applicable only when `extractionType` is `LLM_INFERRED`. See `extractionConfig` Block below. */ extractionConfig?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfig; /** * Whether the metadata value is extracted by the LLM or passed through deterministically from the event. Valid values: `LLM_INFERRED`, `STRICTLY_CONSISTENT`. */ extractionType: string; /** * Metadata field name. Must match an indexed key to be queryable via metadata filters. */ key: string; /** * Metadata value type. Valid values: `STRING`, `STRINGLIST`, `NUMBER`. */ type: string; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfig { /** * Model-based extraction configuration. See `llmExtractionConfig` Block below. */ llmExtractionConfig?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfig; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfig { /** * Description of what this metadata field represents. */ definition: string; /** * Instructions for extraction. Supports built-in operators like `LATEST_VALUE` or custom natural-language instructions. */ llmExtractionInstruction: string; /** * Validation rules to constrain extracted values. See `validation` Block below. */ validation?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidation; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidation { /** * Validation for `NUMBER` fields. See `numberValidation` Block below. */ numberValidation?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidationNumberValidation; /** * Validation for `STRINGLIST` fields. See `stringListValidation` Block below. */ stringListValidation?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidationStringListValidation; /** * Validation for `STRING` fields. See `stringValidation` Block below. */ stringValidation?: outputs.bedrock.AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidationStringValidation; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidationNumberValidation { /** * Maximum allowed value. */ maxValue?: number; /** * Minimum allowed value. */ minValue?: number; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidationStringListValidation { /** * Allowed values for items in this `STRINGLIST` field. */ allowedValues?: string[]; /** * Maximum number of items in the string list. */ maxItems?: number; } interface AgentcoreMemoryStrategyMemoryRecordSchemaMetadataSchemaExtractionConfigLlmExtractionConfigValidationStringValidation { /** * Allowed values for this `STRING` field. */ allowedValues: string[]; } interface AgentcoreMemoryStrategyReflectionConfiguration { /** * Namespace templates over which to create reflections. Can be less nested than episode namespaces. */ namespaceTemplates: string[]; } interface AgentcoreMemoryStrategyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreMemoryStreamDeliveryResources { /** * List of stream delivery resource configurations. See `resource` Block below. */ resource?: outputs.bedrock.AgentcoreMemoryStreamDeliveryResourcesResource; } interface AgentcoreMemoryStreamDeliveryResourcesResource { /** * Kinesis Data Stream configuration. See `kinesis` Block below. */ kinesis?: outputs.bedrock.AgentcoreMemoryStreamDeliveryResourcesResourceKinesis; } interface AgentcoreMemoryStreamDeliveryResourcesResourceKinesis { /** * Content configurations for stream delivery. See `contentConfiguration` Block below. */ contentConfiguration: outputs.bedrock.AgentcoreMemoryStreamDeliveryResourcesResourceKinesisContentConfiguration; /** * ARN of the Kinesis Data Stream. */ dataStreamArn: string; } interface AgentcoreMemoryStreamDeliveryResourcesResourceKinesisContentConfiguration { /** * Level of detail for streamed content. Valid values are `METADATA_ONLY` and `FULL_CONTENT`. Defaults to `METADATA_ONLY`. */ level: string; /** * Type of content to stream. Valid value is `MEMORY_RECORDS`. */ type: string; } interface AgentcoreMemoryTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreOauth2CredentialProviderClientSecretArn { /** * ARN of the secret in AWS Secrets Manager. */ secretArn: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfig { /** * Atlassian OAuth provider configuration. See `atlassianOauth2ProviderConfig` Block below. */ atlassianOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfig; /** * Custom OAuth2 provider configuration. See `customOauth2ProviderConfig` Block below. */ customOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfig; /** * GitHub OAuth provider configuration. See `githubOauth2ProviderConfig` Block below. */ githubOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfig; /** * Google OAuth provider configuration. See `googleOauth2ProviderConfig` Block below. */ googleOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfig; /** * Configuration for an included (vendor-supported) OAuth2 provider, used for the additional supported vendors. See `includedOauth2ProviderConfig` Block below. */ includedOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfig; /** * LinkedIn OAuth provider configuration. See `linkedinOauth2ProviderConfig` Block below. */ linkedinOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfig; /** * Microsoft OAuth provider configuration. See `microsoftOauth2ProviderConfig` Block below. */ microsoftOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfig; /** * Salesforce OAuth provider configuration. See `salesforceOauth2ProviderConfig` Block below. */ salesforceOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfig; /** * Slack OAuth provider configuration. See `slackOauth2ProviderConfig` Block below. */ slackOauth2ProviderConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfig; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfigOauthDiscovery[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigAtlassianOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfig { /** * Client authentication method used with the token endpoint. Valid values: `CLIENT_SECRET_BASIC`, `CLIENT_SECRET_POST`, `AWS_IAM_ID_TOKEN_JWT`. */ clientAuthenticationMethod?: string; /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration. See `oauth2_provider_config.custom_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscovery: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOauthDiscovery; /** * On-behalf-of token exchange configuration, enabling RFC 8693 token exchange or RFC 7523 JWT authorization grant flows. See `onBehalfOfTokenExchangeConfig` Block below. */ onBehalfOfTokenExchangeConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOnBehalfOfTokenExchangeConfig; /** * Default private endpoint for the custom OAuth2 provider, enabling secure connectivity through a VPC Lattice resource configuration. See `privateEndpoint` Block below. */ privateEndpoint?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpoint; /** * Private endpoint overrides for the custom OAuth2 provider configuration. See `privateEndpointOverride` Block below. */ privateEndpointOverrides?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverride[]; /** * Private key JWT client authentication configuration used when signing client assertions. See `privateKeyJwtConfig` Block below. */ privateKeyJwtConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateKeyJwtConfig; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadata?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl?: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes?: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods?: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOnBehalfOfTokenExchangeConfig { /** * Grant type for the on-behalf-of token exchange. Valid values: `TOKEN_EXCHANGE`, `JWT_AUTHORIZATION_GRANT`. */ grantType: string; /** * Configuration specific to the `TOKEN_EXCHANGE` grant type (RFC 8693). See `tokenExchangeGrantTypeConfig` Block below. */ tokenExchangeGrantTypeConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOnBehalfOfTokenExchangeConfigTokenExchangeGrantTypeConfig; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigOnBehalfOfTokenExchangeConfigTokenExchangeGrantTypeConfig { /** * Content type for the actor token in the token exchange. Valid values: `NONE`, `M2M`, `AWS_IAM_ID_TOKEN_JWT`. */ actorTokenContent: string; /** * Set of scopes for the actor token. Only valid when `actorTokenContent` is `M2M`. */ actorTokenScopes?: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpoint { /** * Service-managed VPC resource configuration. See `managedVpcResource` Block below. */ managedVpcResource?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` Block below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointSelfManagedLatticeResource; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values: `IPV4`, `DUALSTACK`. */ endpointIpAddressType: string; /** * Routing domain for the managed VPC resource. */ routingDomain?: string; /** * Set of up to 5 security group IDs for the managed VPC resource. */ securityGroupIds?: string[]; /** * Set of subnet IDs for the managed VPC resource. */ subnetIds: string[]; /** * Key-value map of tags for the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC. */ vpcIdentifier: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverride { /** * Domain the private endpoint override applies to. */ domain: string; /** * Private endpoint configuration for the domain. See `privateEndpoint` Block above. */ privateEndpoint: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverridePrivateEndpoint; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverridePrivateEndpoint { /** * Service-managed VPC resource configuration. See `managedVpcResource` Block below. */ managedVpcResource?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverridePrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` Block below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values: `IPV4`, `DUALSTACK`. */ endpointIpAddressType: string; /** * Routing domain for the managed VPC resource. */ routingDomain?: string; /** * Set of up to 5 security group IDs for the managed VPC resource. */ securityGroupIds?: string[]; /** * Set of subnet IDs for the managed VPC resource. */ subnetIds: string[]; /** * Key-value map of tags for the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC. */ vpcIdentifier: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateKeyJwtConfig { /** * Key-value map of additional claims to include in the JWT header. */ additionalHeaderClaims?: { [key: string]: string; }; /** * Key-value map of additional claims to include in the JWT payload. */ additionalPayloadClaims?: { [key: string]: string; }; /** * Source of the private key used to sign the JWT. See `privateKeySource` Block below. */ privateKeySource?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateKeyJwtConfigPrivateKeySource; /** * Algorithm used to sign the JWT. */ signingAlgorithm?: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateKeyJwtConfigPrivateKeySource { /** * AWS KMS key source configuration for the signing key. See `kmsKeySource` Block below. */ kmsKeySource?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateKeyJwtConfigPrivateKeySourceKmsKeySource; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigCustomOauth2ProviderConfigPrivateKeyJwtConfigPrivateKeySourceKmsKeySource { /** * ARN of the AWS KMS key used to sign the JWT. */ kmsKeyArn: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfigOauthDiscovery[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGithubOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfigOauthDiscovery[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigGoogleOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfig { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint?: string; /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth2 authorization server issuer identifier. */ issuer?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfigOauthDiscovery[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint?: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigIncludedOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfigOauthDiscovery[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigLinkedinOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfigOauthDiscovery[]; /** * Microsoft Entra (Azure AD) tenant ID. Conflicts with `tenantIdWo`. */ tenantId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only Microsoft Entra (Azure AD) tenant ID. Conflicts with `tenantId`. Must be used together with `tenantIdWoVersion`. */ tenantIdWo?: string; /** * Version paired with the write-only tenant ID. Increment this value to trigger an update to `tenantIdWo`. */ tenantIdWoVersion?: number; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigMicrosoftOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfigOauthDiscovery[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSalesforceOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfig { /** * Version used together with the write-only credentials. Required when `clientIdWo` and `clientSecretWo` are set. Changing this value triggers an update to `clientIdWo` and `clientSecretWo`. */ clientCredentialsWoVersion?: number; /** * OAuth2 client ID. Conflicts with `clientIdWo`. Must be used together with `clientSecret`. */ clientId?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client ID. Conflicts with `clientId`. If set, requires `clientSecretWo` and `clientCredentialsWoVersion` to be set. */ clientIdWo?: string; /** * OAuth2 client secret. Conflicts with `clientSecretWo`. Must be used together with `clientId`. */ clientSecret?: string; /** * Reference to an AWS Secrets Manager secret that stores the client secret. Required when `clientSecretSource` is `EXTERNAL`. See `clientSecretConfig` Block below. */ clientSecretConfig?: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfigClientSecretConfig; /** * Source type of the client secret. Valid values: `MANAGED` (the service manages the secret) or `EXTERNAL` (you manage the secret in AWS Secrets Manager). Use `EXTERNAL` together with `clientSecretConfig`. */ clientSecretSource?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Write-only OAuth2 client secret. Conflicts with `clientSecret`. If set, requires `clientIdWo` and `clientCredentialsWoVersion` to be set. */ clientSecretWo?: string; /** * OAuth discovery configuration resolved by the service. See `oauth2_provider_config.slack_oauth2_provider_config.oauth_discovery` Block below. */ oauthDiscoveries: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfigOauthDiscovery[]; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfigClientSecretConfig { /** * JSON key used to extract the client secret value from the Secrets Manager secret. */ jsonKey: string; /** * ID of the AWS Secrets Manager secret that stores the client secret value. */ secretId: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfigOauthDiscovery { /** * OAuth2 authorization server metadata resolved by the service. See `authorizationServerMetadata` Block below. */ authorizationServerMetadatas: outputs.bedrock.AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata[]; /** * OpenID Connect discovery URL resolved by the service. */ discoveryUrl: string; } interface AgentcoreOauth2CredentialProviderOauth2ProviderConfigSlackOauth2ProviderConfigOauthDiscoveryAuthorizationServerMetadata { /** * OAuth2 authorization endpoint URL. */ authorizationEndpoint: string; /** * OAuth2 authorization server issuer identifier. */ issuer: string; /** * Set of OAuth2 response types supported by the authorization server. */ responseTypes: string[]; /** * OAuth2 token endpoint URL. */ tokenEndpoint: string; /** * List of authentication methods supported by the token endpoint. */ tokenEndpointAuthMethods: string[]; } interface AgentcoreOauth2CredentialProviderTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreOnlineEvaluationConfigDataSourceConfig { /** * CloudWatch logs configuration for reading agent traces. See `cloudwatchLogs` Block below. */ cloudwatchLogs?: outputs.bedrock.AgentcoreOnlineEvaluationConfigDataSourceConfigCloudwatchLogs; } interface AgentcoreOnlineEvaluationConfigDataSourceConfigCloudwatchLogs { /** * List of CloudWatch log group names to monitor for agent traces. Maximum 5. */ logGroupNames: string[]; /** * List of service names to filter traces within the specified log groups. */ serviceNames: string[]; } interface AgentcoreOnlineEvaluationConfigEvaluator { /** * Unique identifier of the evaluator. Can reference builtin evaluators (e.g., `Builtin.Helpfulness`, `Builtin.GoalSuccessRate`) or custom evaluator IDs. */ evaluatorId: string; } interface AgentcoreOnlineEvaluationConfigOutputConfig { /** * CloudWatch configuration for evaluation results. See `cloudwatchConfig` Block below. */ cloudwatchConfigs: outputs.bedrock.AgentcoreOnlineEvaluationConfigOutputConfigCloudwatchConfig[]; } interface AgentcoreOnlineEvaluationConfigOutputConfigCloudwatchConfig { /** * Name of the CloudWatch log group where evaluation results are written. */ logGroupName: string; } interface AgentcoreOnlineEvaluationConfigRule { /** * List of filters determining which agent traces to evaluate. Maximum 5. See `filter` Block below. */ filters?: outputs.bedrock.AgentcoreOnlineEvaluationConfigRuleFilter[]; /** * Sampling configuration determining what percentage of agent traces to evaluate. See `samplingConfig` Block below. */ samplingConfig: outputs.bedrock.AgentcoreOnlineEvaluationConfigRuleSamplingConfig; /** * Session configuration defining timeout settings for detecting when agent sessions are complete. See `sessionConfig` Block below. */ sessionConfig?: outputs.bedrock.AgentcoreOnlineEvaluationConfigRuleSessionConfig; } interface AgentcoreOnlineEvaluationConfigRuleFilter { /** * Key or field name to filter on within the agent trace data. */ key: string; /** * Comparison operator. Valid values: `Equals`, `NotEquals`, `GreaterThan`, `LessThan`, `GreaterThanOrEqual`, `LessThanOrEqual`, `Contains`, `NotContains`. */ operator: string; /** * Value to compare against. See `value` Block below. */ value: outputs.bedrock.AgentcoreOnlineEvaluationConfigRuleFilterValue; } interface AgentcoreOnlineEvaluationConfigRuleFilterValue { /** * Boolean value for true/false filtering. */ booleanValue?: boolean; /** * Numeric value for numerical filtering. */ doubleValue?: number; /** * String value for text-based filtering. */ stringValue?: string; } interface AgentcoreOnlineEvaluationConfigRuleSamplingConfig { /** * Percentage of agent traces to sample for evaluation, from 0.01 to 100. */ samplingPercentage: number; } interface AgentcoreOnlineEvaluationConfigRuleSessionConfig { /** * Minutes of inactivity after which a session is considered complete. Between 1 and 60. */ sessionTimeoutMinutes: number; } interface AgentcoreOnlineEvaluationConfigTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcorePolicyDefinition { /** * Inline Cedar policy. See `cedar` Block for details. */ cedar: outputs.bedrock.AgentcorePolicyDefinitionCedar; } interface AgentcorePolicyDefinitionCedar { /** * Cedar policy statement. */ statement: string; } interface AgentcorePolicyEngineTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcorePolicyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreRegistryApprovalConfiguration { /** * Whether registry records are auto-approved. When set to `true`, records are automatically approved upon creation. When set to `false` (the default), records require explicit approval. */ autoApproval: boolean; } interface AgentcoreRegistryAuthorizerConfiguration { /** * JWT-based authorization configuration block. See `customJwtAuthorizer` below. */ customJwtAuthorizer?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizer; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizer { /** * Set of allowed audience values for JWT token validation. */ allowedAudiences?: string[]; /** * Set of allowed client IDs for JWT token validation. */ allowedClients?: string[]; /** * Set of scopes that are allowed to access the token. */ allowedScopes?: string[]; /** * Configuration restricting which workloads may use this authorizer. See `allowedWorkloadConfiguration` below. */ allowedWorkloadConfiguration?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration; /** * Repeatable block to define a custom claim validation name, value, and operation. See `customClaim` below. */ customClaims?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerCustomClaim[]; /** * URL used to fetch OpenID Connect configuration or authorization server metadata. Must end with `.well-known/openid-configuration`. */ discoveryUrl: string; /** * Private endpoint used to reach the authorization server. See `privateEndpoint` below. */ privateEndpoint?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint; /** * Overrides for the private endpoints used to reach the authorization server. See `privateEndpointOverrides` below. */ privateEndpointOverrides?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride[]; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfiguration { /** * Hosting environments allowed to use the authorizer. Between 1 and 10 entries. See `hostingEnvironment` below. */ hostingEnvironments?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment[]; /** * List of workload identity names allowed to use the authorizer. Between 1 and 10 entries. */ workloadIdentities?: string[]; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerAllowedWorkloadConfigurationHostingEnvironment { /** * ARN of the hosting environment. */ arn: string; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerCustomClaim { /** * Configuration block to define the value or values to match for and the relationship of the match. See `authorizingClaimMatchValue` below. */ authorizingClaimMatchValue: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue; /** * Name of the custom claim field to check. */ inboundTokenClaimName: string; /** * Data type of the claim value to check for. Valid values are `STRING` and `STRING_ARRAY`. */ inboundTokenClaimValueType: string; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValue { /** * Relationship between the claim field value and the value or values to match for. Valid values are `EQUALS`, `CONTAINS`, and `CONTAINS_ANY`. `EQUALS` can be used only when `inboundTokenClaimValueType` is `STRING`. `CONTAINS` or `CONTAINS_ANY` can be used only when `inboundTokenClaimValueType` is `STRING_ARRAY`. */ claimMatchOperator: string; /** * Value or values to match for. See `claimMatchValue` below. */ claimMatchValue: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerCustomClaimAuthorizingClaimMatchValueClaimMatchValue { /** * String value to match for. Must be specified when `claimMatchOperator` is `EQUALS` or `CONTAINS`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueString?: string; /** * List of strings to check for a match. Must be specified when `claimMatchOperator` is `CONTAINS_ANY`. Exactly one of `matchValueString` or `matchValueStringList` must be specified. */ matchValueStringLists?: string[]; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` below. */ managedVpcResource?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverride { /** * Domain the override applies to. */ domain: string; /** * Private endpoint configuration. See `privateEndpoint` below. */ privateEndpoint: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpoint { /** * Managed VPC resource configuration. See `managedVpcResource` below. */ managedVpcResource?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource; /** * Self-managed VPC Lattice resource configuration. See `selfManagedLatticeResource` below. */ selfManagedLatticeResource?: outputs.bedrock.AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointManagedVpcResource { /** * IP address type for the endpoint. Valid values are `IPV4` and `IPV6`. */ endpointIpAddressType: string; /** * Routing domain for the endpoint. */ routingDomain?: string; /** * IDs of the security groups for the endpoint. */ securityGroupIds?: string[]; /** * IDs of the subnets for the endpoint. */ subnetIds: string[]; /** * Tags to assign to the managed VPC resource. */ tags?: { [key: string]: string; }; /** * Identifier of the VPC for the endpoint. */ vpcIdentifier: string; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointOverridePrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreRegistryAuthorizerConfigurationCustomJwtAuthorizerPrivateEndpointSelfManagedLatticeResource { /** * Identifier of the VPC Lattice resource configuration. */ resourceConfigurationIdentifier?: string; } interface AgentcoreRegistryTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AgentcoreTokenVaultCmkKmsConfiguration { /** * Type of KMS key. Valid values: `CustomerManagedKey`, `ServiceManagedKey`. */ keyType: string; /** * ARN of the KMS key. */ kmsKeyArn?: string; } interface CustomModelOutputDataConfig { /** * S3 URI where the output data is stored. */ s3Uri: string; } interface CustomModelTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface CustomModelTrainingDataConfig { /** * S3 URI where the training data is stored. */ s3Uri: string; } interface CustomModelTrainingMetric { /** * Loss metric associated with the customization job. */ trainingLoss: number; } interface CustomModelValidationDataConfig { /** * Information about the validators. See `validator` below. */ validators: outputs.bedrock.CustomModelValidationDataConfigValidator[]; } interface CustomModelValidationDataConfigValidator { /** * S3 URI where the validation data is stored. */ s3Uri: string; } interface CustomModelValidationMetric { /** * Validation loss associated with the validator. */ validationLoss: number; } interface CustomModelVpcConfig { /** * VPC configuration security group IDs. */ securityGroupIds: string[]; /** * VPC configuration subnets. */ subnetIds: string[]; } interface EvaluationJobEvaluationConfig { /** * Configuration for an automated evaluation job that computes metrics. See `automated` Block below. */ automated?: outputs.bedrock.EvaluationJobEvaluationConfigAutomated; /** * Configuration for an evaluation job that uses human workers. See `human` Block below. */ human?: outputs.bedrock.EvaluationJobEvaluationConfigHuman; } interface EvaluationJobEvaluationConfigAutomated { /** * Configuration for custom metrics to compute for the evaluation job. See `customMetricConfig` Block below. */ customMetricConfig?: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfig; /** * One or more configurations for the prompt datasets and metrics to use. See `evaluation_config.automated.dataset_metric_config` Block below. */ datasetMetricConfigs: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedDatasetMetricConfig[]; /** * Configuration for the evaluator (judge) model. Required for automated jobs that use an LLM-as-judge metric, or that evaluate a knowledge base. See `evaluatorModelConfig` Block below. */ evaluatorModelConfig?: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedEvaluatorModelConfig; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfig { /** * One or more custom metric definitions. See `evaluation_config.automated.custom_metric_config.custom_metric` Block below. */ customMetrics: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetric[]; /** * Configuration for the evaluator model used to compute the custom metrics. See `evaluatorModelConfig` Block above. */ evaluatorModelConfig: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfigEvaluatorModelConfig; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetric { /** * Definition of the custom metric. See `customMetricDefinition` Block below. */ customMetricDefinition: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetricCustomMetricDefinition; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetricCustomMetricDefinition { /** * Prompt that instructs the evaluator model how to rate the model or RAG source under evaluation. */ instructions: string; /** * Name for the custom metric. Must be unique in your AWS Region. */ name: string; /** * One or more items defining the rating scale for the custom metric. See `ratingScale` Block below. */ ratingScales?: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetricCustomMetricDefinitionRatingScale[]; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetricCustomMetricDefinitionRatingScale { /** * Definition for one rating in the custom metric rating scale. */ definition: string; /** * Value for one rating in the custom metric rating scale. See `value` Block below. */ value: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetricCustomMetricDefinitionRatingScaleValue; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfigCustomMetricCustomMetricDefinitionRatingScaleValue { /** * Floating point number representing the rating value. */ floatValue?: number; /** * String representing the rating value. */ stringValue?: string; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfigEvaluatorModelConfig { /** * Evaluator model. See `bedrockEvaluatorModel` Block below. */ bedrockEvaluatorModel: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedCustomMetricConfigEvaluatorModelConfigBedrockEvaluatorModel; } interface EvaluationJobEvaluationConfigAutomatedCustomMetricConfigEvaluatorModelConfigBedrockEvaluatorModel { /** * Identifier of the Amazon Bedrock model, or inference profile, used to compute the metrics. */ modelIdentifier: string; } interface EvaluationJobEvaluationConfigAutomatedDatasetMetricConfig { /** * Prompt dataset to use. See `dataset` Block below. */ dataset: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedDatasetMetricConfigDataset; /** * Names of the metrics to use for the evaluation job. */ metricNames: string[]; /** * Type of task to evaluate. Common values are `Summarization`, `Classification`, `QuestionAndAnswer`, `Generation`, and `Custom`. */ taskType: string; } interface EvaluationJobEvaluationConfigAutomatedDatasetMetricConfigDataset { /** * Location of a custom prompt dataset. See `datasetLocation` Block below. */ datasetLocation?: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedDatasetMetricConfigDatasetDatasetLocation; /** * Name of a built-in prompt dataset, for example `Builtin.Bold`, or a label for a custom prompt dataset. */ name: string; } interface EvaluationJobEvaluationConfigAutomatedDatasetMetricConfigDatasetDatasetLocation { /** * S3 URI of the custom prompt dataset. */ s3Uri: string; } interface EvaluationJobEvaluationConfigAutomatedEvaluatorModelConfig { /** * Evaluator model. See `bedrockEvaluatorModel` Block below. */ bedrockEvaluatorModel: outputs.bedrock.EvaluationJobEvaluationConfigAutomatedEvaluatorModelConfigBedrockEvaluatorModel; } interface EvaluationJobEvaluationConfigAutomatedEvaluatorModelConfigBedrockEvaluatorModel { /** * Identifier of the Amazon Bedrock model, or inference profile, used to compute the metrics. */ modelIdentifier: string; } interface EvaluationJobEvaluationConfigHuman { /** * One or more custom metrics for your human workers to use. See `evaluation_config.human.custom_metric` Block below. */ customMetrics?: outputs.bedrock.EvaluationJobEvaluationConfigHumanCustomMetric[]; /** * One or more configurations for the prompt datasets and metrics to use. See `evaluation_config.human.dataset_metric_config` Block below. */ datasetMetricConfigs: outputs.bedrock.EvaluationJobEvaluationConfigHumanDatasetMetricConfig[]; /** * Configuration for the human workflow. See `humanWorkflowConfig` Block below. */ humanWorkflowConfig?: outputs.bedrock.EvaluationJobEvaluationConfigHumanHumanWorkflowConfig; } interface EvaluationJobEvaluationConfigHumanCustomMetric { /** * Description of the metric. */ description?: string; /** * Name of the metric. */ name: string; /** * How the metric is rated. Valid values: `ThumbsUpDown`, `IndividualLikertScale`, `ComparisonLikertScale`, `ComparisonChoice`, `ComparisonRank`. */ ratingMethod: string; } interface EvaluationJobEvaluationConfigHumanDatasetMetricConfig { /** * Prompt dataset to use. See `dataset` Block below. */ dataset: outputs.bedrock.EvaluationJobEvaluationConfigHumanDatasetMetricConfigDataset; /** * Names of the metrics to use for the evaluation job. */ metricNames: string[]; /** * Type of task to evaluate. Common values are `Summarization`, `Classification`, `QuestionAndAnswer`, `Generation`, and `Custom`. */ taskType: string; } interface EvaluationJobEvaluationConfigHumanDatasetMetricConfigDataset { /** * Location of a custom prompt dataset. See `datasetLocation` Block below. */ datasetLocation?: outputs.bedrock.EvaluationJobEvaluationConfigHumanDatasetMetricConfigDatasetDatasetLocation; /** * Name of a built-in prompt dataset, for example `Builtin.Bold`, or a label for a custom prompt dataset. */ name: string; } interface EvaluationJobEvaluationConfigHumanDatasetMetricConfigDatasetDatasetLocation { /** * S3 URI of the custom prompt dataset. */ s3Uri: string; } interface EvaluationJobEvaluationConfigHumanHumanWorkflowConfig { /** * ARN of the Amazon SageMaker AI flow definition. */ flowDefinitionArn: string; /** * Instructions for the flow definition. */ instructions?: string; } interface EvaluationJobInferenceConfig { /** * One or more inference models. Automated jobs support a single model; jobs that use human workers support up to two models. See `model` Block below. */ models?: outputs.bedrock.EvaluationJobInferenceConfigModel[]; /** * Inference configuration for a knowledge base evaluation job. See `ragConfig` Block below. */ ragConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfig; } interface EvaluationJobInferenceConfigModel { /** * Amazon Bedrock model. See `bedrockModel` Block below. */ bedrockModel?: outputs.bedrock.EvaluationJobInferenceConfigModelBedrockModel; /** * Model where you provide your own precomputed inference response data. See `precomputedInferenceSource` Block below. */ precomputedInferenceSource?: outputs.bedrock.EvaluationJobInferenceConfigModelPrecomputedInferenceSource; } interface EvaluationJobInferenceConfigModelBedrockModel { /** * JSON-formatted string of inference parameters for the model. */ inferenceParams?: string; /** * Identifier of the Amazon Bedrock model, or inference profile, used for inference. */ modelIdentifier: string; /** * Model's performance settings. See `performanceConfig` Block below. */ performanceConfig?: outputs.bedrock.EvaluationJobInferenceConfigModelBedrockModelPerformanceConfig; } interface EvaluationJobInferenceConfigModelBedrockModelPerformanceConfig { /** * Whether to use the latency-optimized or standard version of the model. Valid values: `standard`, `optimized`. */ latency?: string; } interface EvaluationJobInferenceConfigModelPrecomputedInferenceSource { /** * Label that identifies the precomputed inference source. */ inferenceSourceIdentifier: string; } interface EvaluationJobInferenceConfigRagConfig { /** * Amazon Bedrock knowledge base. See `knowledgeBaseConfig` Block below. */ knowledgeBaseConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfig; /** * RAG source where you provide your own precomputed inference response data. See `precomputedRagSourceConfig` Block below. */ precomputedRagSourceConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigPrecomputedRagSourceConfig; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfig { /** * Configuration for retrieval with response generation. See `retrieveAndGenerateConfig` Block below. */ retrieveAndGenerateConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveAndGenerateConfig; /** * Configuration for retrieval only. See `retrieveConfig` Block below. */ retrieveConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveConfig; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveAndGenerateConfig { /** * Identifier of the knowledge base. */ knowledgeBaseId: string; /** * ARN of the foundation model, or inference profile, used to generate responses. */ modelArn: string; /** * Knowledge base retrieval configuration. See `retrievalConfiguration` Block below. */ retrievalConfiguration?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveAndGenerateConfigRetrievalConfiguration; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveAndGenerateConfigRetrievalConfiguration { /** * Vector search configuration. See `vectorSearchConfiguration` Block below. */ vectorSearchConfiguration: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveAndGenerateConfigRetrievalConfigurationVectorSearchConfiguration; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveAndGenerateConfigRetrievalConfigurationVectorSearchConfiguration { /** * Number of text chunks to retrieve. */ numberOfResults?: number; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveConfig { /** * Identifier of the knowledge base. */ knowledgeBaseId: string; /** * Knowledge base retrieval configuration. See `knowledgeBaseRetrievalConfiguration` Block below. */ knowledgeBaseRetrievalConfiguration?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveConfigKnowledgeBaseRetrievalConfiguration; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveConfigKnowledgeBaseRetrievalConfiguration { /** * Vector search configuration. See `vectorSearchConfiguration` Block above. */ vectorSearchConfiguration: outputs.bedrock.EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveConfigKnowledgeBaseRetrievalConfigurationVectorSearchConfiguration; } interface EvaluationJobInferenceConfigRagConfigKnowledgeBaseConfigRetrieveConfigKnowledgeBaseRetrievalConfigurationVectorSearchConfiguration { /** * Number of text chunks to retrieve. */ numberOfResults?: number; } interface EvaluationJobInferenceConfigRagConfigPrecomputedRagSourceConfig { /** * Configuration for retrieval with response generation. See `retrieveAndGenerateSourceConfig` Block below. */ retrieveAndGenerateSourceConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigPrecomputedRagSourceConfigRetrieveAndGenerateSourceConfig; /** * Configuration for retrieval only. See `retrieveSourceConfig` Block below. */ retrieveSourceConfig?: outputs.bedrock.EvaluationJobInferenceConfigRagConfigPrecomputedRagSourceConfigRetrieveSourceConfig; } interface EvaluationJobInferenceConfigRagConfigPrecomputedRagSourceConfigRetrieveAndGenerateSourceConfig { /** * Label that identifies the precomputed RAG source. */ ragSourceIdentifier: string; } interface EvaluationJobInferenceConfigRagConfigPrecomputedRagSourceConfigRetrieveSourceConfig { /** * Label that identifies the precomputed RAG source. */ ragSourceIdentifier: string; } interface EvaluationJobOutputDataConfig { /** * S3 URI where the results of the evaluation job are stored. */ s3Uri: string; } interface EvaluationJobTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface GetAgentAgentVersionsAgentVersionSummary { /** * Name of agent to which the version belongs. */ agentName: string; /** * Status of the agent to which the version belongs. */ agentStatus: string; /** * Version of the agent. */ agentVersion: string; /** * Time at which the version was created. */ createdAt: string; /** * Description of the version of the agent. */ description: string; /** * Details about the guardrail associated with the agent. See `guardrailConfiguration` Block */ guardrailConfigurations?: outputs.bedrock.GetAgentAgentVersionsAgentVersionSummaryGuardrailConfiguration[]; /** * Time at which the version was last updated. */ updatedAt: string; } interface GetAgentAgentVersionsAgentVersionSummaryGuardrailConfiguration { /** * Unique identifier of the guardrail. */ guardrailIdentifier: string; /** * Version of the guardrail. */ guardrailVersion: string; } interface GetCustomModelOutputDataConfig { /** * S3 URI where the validation data is stored. */ s3Uri: string; } interface GetCustomModelTrainingDataConfig { /** * S3 URI where the validation data is stored. */ s3Uri: string; } interface GetCustomModelTrainingMetric { /** * Loss metric associated with the customization job. */ trainingLoss: number; } interface GetCustomModelValidationDataConfig { /** * Information about the validators. */ validators: outputs.bedrock.GetCustomModelValidationDataConfigValidator[]; } interface GetCustomModelValidationDataConfigValidator { /** * S3 URI where the validation data is stored. */ s3Uri: string; } interface GetCustomModelValidationMetric { /** * Validation loss associated with the validator. */ validationLoss: number; } interface GetCustomModelsModelSummary { /** * Creation time of the model. */ creationTime: string; /** * ARN of the custom model. */ modelArn: string; /** * Name of the custom model. */ modelName: string; } interface GetInferenceProfileModel { /** * ARN of the model. */ modelArn: string; } interface GetInferenceProfilesInferenceProfileSummary { /** * Time at which the inference profile was created. */ createdAt: string; /** * Description of the inference profile. */ description: string; /** * ARN of the inference profile. */ inferenceProfileArn: string; /** * Unique identifier of the inference profile. */ inferenceProfileId: string; /** * Name of the inference profile. */ inferenceProfileName: string; /** * List of information about each model in the inference profile. See `models` Block. */ models: outputs.bedrock.GetInferenceProfilesInferenceProfileSummaryModel[]; /** * Status of the inference profile. `ACTIVE` means that the inference profile is available to use. */ status: string; /** * Filters for inference profiles that match the type you specify. Valid values are: `SYSTEM_DEFINED`, `APPLICATION`. */ type: string; /** * Time at which the inference profile was last updated. */ updatedAt: string; } interface GetInferenceProfilesInferenceProfileSummaryModel { /** * ARN of the model. */ modelArn: string; } interface GuardrailContentPolicyConfig { /** * Set of content filter configs in content policy. See `content_policy_config.filters_config` Block for more information. */ filtersConfigs?: outputs.bedrock.GuardrailContentPolicyConfigFiltersConfig[]; /** * Configuration block for the content policy tier. See `content_policy_config.tier_config` Block for more information. */ tierConfigs: outputs.bedrock.GuardrailContentPolicyConfigTierConfig[]; } interface GuardrailContentPolicyConfigFiltersConfig { /** * Action to take when harmful content is detected. Valid values: `BLOCK`, `NONE`. */ inputAction?: string; /** * Toggles guardrail evaluation on input. */ inputEnabled?: boolean; /** * List of selected input modalities. Valid values: `IMAGE`, `TEXT`. */ inputModalities?: string[]; /** * Strength for filters. Valid values: `NONE`, `LOW`, `MEDIUM`, `HIGH`. */ inputStrength: string; /** * Action to take when harmful content is detected. Valid values: `BLOCK`, `NONE`. */ outputAction?: string; /** * Toggles guardrail evaluation on output. */ outputEnabled?: boolean; /** * List of selected output modalities. Valid values: `IMAGE`, `TEXT`. */ outputModalities?: string[]; /** * Strength for filters. Valid values: `NONE`, `LOW`, `MEDIUM`, `HIGH`. */ outputStrength: string; /** * Type of contextual grounding filter. */ type: string; } interface GuardrailContentPolicyConfigTierConfig { /** * Name of the topic policy tier. Valid values include STANDARD or CLASSIC. */ tierName: string; } interface GuardrailContextualGroundingPolicyConfig { /** * One or more blocks defining contextual grounding filter configs. See `contextual_grounding_policy_config.filters_config` Block for more information. */ filtersConfigs?: outputs.bedrock.GuardrailContextualGroundingPolicyConfigFiltersConfig[]; } interface GuardrailContextualGroundingPolicyConfigFiltersConfig { /** * Threshold for this filter. */ threshold: number; /** * Type of contextual grounding filter. */ type: string; } interface GuardrailCrossRegionConfig { /** * Guardrail profile ARN. */ guardrailProfileIdentifier: string; } interface GuardrailSensitiveInformationPolicyConfig { /** * List of entities. See `piiEntitiesConfig` Block for more information. */ piiEntitiesConfigs?: outputs.bedrock.GuardrailSensitiveInformationPolicyConfigPiiEntitiesConfig[]; /** * List of regex. See `regexesConfig` Block for more information. */ regexesConfigs?: outputs.bedrock.GuardrailSensitiveInformationPolicyConfigRegexesConfig[]; } interface GuardrailSensitiveInformationPolicyConfigPiiEntitiesConfig { /** * Options for sensitive information action. Valid values: `BLOCK`, `ANONYMIZE`, `NONE`. */ action: string; /** * Action to take when harmful content is detected in the input. Valid values: `BLOCK`, `ANONYMIZE`, `NONE`. */ inputAction: string; /** * Whether to enable guardrail evaluation on the input. When disabled, you aren't charged for the evaluation. */ inputEnabled: boolean; /** * Action to take when harmful content is detected in the output. Valid values: `BLOCK`, `ANONYMIZE`, `NONE`. */ outputAction: string; /** * Whether to enable guardrail evaluation on the output. When disabled, you aren't charged for the evaluation. */ outputEnabled: boolean; /** * Currently supported PII entities. */ type: string; } interface GuardrailSensitiveInformationPolicyConfigRegexesConfig { /** * Options for sensitive information action. Valid values: `BLOCK`, `ANONYMIZE`, `NONE`. */ action: string; /** * Regex description. */ description: string; /** * Action to take when harmful content is detected in the input. Valid values: `BLOCK`, `ANONYMIZE`, `NONE`. */ inputAction: string; /** * Whether to enable guardrail evaluation on the input. When disabled, you aren't charged for the evaluation. */ inputEnabled: boolean; /** * Regex name. */ name: string; /** * Action to take when harmful content is detected in the output. Valid values: `BLOCK`, `ANONYMIZE`, `NONE`. */ outputAction: string; /** * Whether to enable guardrail evaluation on the output. When disabled, you aren't charged for the evaluation. */ outputEnabled: boolean; /** * Regex pattern. */ pattern: string; } interface GuardrailTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GuardrailTopicPolicyConfig { /** * Configuration block for the topic policy tier. See `topic_policy_config.tier_config` Block for more information. */ tierConfigs: outputs.bedrock.GuardrailTopicPolicyConfigTierConfig[]; /** * List of topic configs in topic policy. See `topicsConfig` Block for more information. */ topicsConfigs?: outputs.bedrock.GuardrailTopicPolicyConfigTopicsConfig[]; } interface GuardrailTopicPolicyConfigTierConfig { /** * Name of the topic policy tier. Valid values include STANDARD or CLASSIC. */ tierName: string; } interface GuardrailTopicPolicyConfigTopicsConfig { /** * Definition of topic in topic policy. */ definition: string; /** * List of text examples. */ examples: string[]; /** * Name of topic in topic policy. */ name: string; /** * Type of topic in a policy. */ type: string; } interface GuardrailVersionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface GuardrailWordPolicyConfig { /** * Config for the list of managed words. See `managedWordListsConfig` Block for more information. */ managedWordListsConfigs?: outputs.bedrock.GuardrailWordPolicyConfigManagedWordListsConfig[]; /** * List of custom word configs. See `wordsConfig` Block for more information. */ wordsConfigs?: outputs.bedrock.GuardrailWordPolicyConfigWordsConfig[]; } interface GuardrailWordPolicyConfigManagedWordListsConfig { /** * Action to take when harmful content is detected in the input. Valid values: `BLOCK`, `NONE`. */ inputAction?: string; /** * Whether to enable guardrail evaluation on the input. When disabled, you aren't charged for the evaluation. */ inputEnabled?: boolean; /** * Action to take when harmful content is detected in the output. Valid values: `BLOCK`, `NONE`. */ outputAction?: string; /** * Whether to enable guardrail evaluation on the output. When disabled, you aren't charged for the evaluation. */ outputEnabled?: boolean; /** * Options for managed words. */ type: string; } interface GuardrailWordPolicyConfigWordsConfig { /** * Action to take when harmful content is detected in the input. Valid values: `BLOCK`, `NONE`. */ inputAction?: string; /** * Whether to enable guardrail evaluation on the input. When disabled, you aren't charged for the evaluation. */ inputEnabled?: boolean; /** * Action to take when harmful content is detected in the output. Valid values: `BLOCK`, `NONE`. */ outputAction?: string; /** * Whether to enable guardrail evaluation on the output. When disabled, you aren't charged for the evaluation. */ outputEnabled?: boolean; /** * Custom word text. */ text: string; } interface InferenceProfileModel { /** * ARN of the model. */ modelArn: string; } interface InferenceProfileModelSource { /** * ARN of the model. */ copyFrom: string; } interface InferenceProfileTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ProvisionedModelThroughputTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } } export declare namespace bedrockfoundation { interface GetModelAgreementOffersOffer { /** * Offer ID for a model offer. */ offerId: string; /** * Offer token. */ offerToken: string; /** * Details about the terms of the offer. See `termDetails`. */ termDetails: outputs.bedrockfoundation.GetModelAgreementOffersOfferTermDetail[]; } interface GetModelAgreementOffersOfferTermDetail { /** * Details about the legal terms. See `legalTerm`. */ legalTerms: outputs.bedrockfoundation.GetModelAgreementOffersOfferTermDetailLegalTerm[]; /** * Details about the support terms. See `supportTerm`. */ supportTerms: outputs.bedrockfoundation.GetModelAgreementOffersOfferTermDetailSupportTerm[]; /** * Details about the pricing terms. See `usageBasedPricingTerm`. */ usageBasedPricingTerms: outputs.bedrockfoundation.GetModelAgreementOffersOfferTermDetailUsageBasedPricingTerm[]; /** * Details about the validity terms. See `validityTerm`. */ validityTerms: outputs.bedrockfoundation.GetModelAgreementOffersOfferTermDetailValidityTerm[]; } interface GetModelAgreementOffersOfferTermDetailLegalTerm { /** * URL to the legal term document. */ url: string; } interface GetModelAgreementOffersOfferTermDetailSupportTerm { /** * Refund policy description. */ refundPolicyDescription: string; } interface GetModelAgreementOffersOfferTermDetailUsageBasedPricingTerm { /** * Details about a usage price for each dimension. See `rateCard`. */ rateCards: outputs.bedrockfoundation.GetModelAgreementOffersOfferTermDetailUsageBasedPricingTermRateCard[]; } interface GetModelAgreementOffersOfferTermDetailUsageBasedPricingTermRateCard { /** * Description of the price rate. */ description: string; /** * Dimension for the price rate. */ dimension: string; /** * Single-dimensional rate information. */ price: string; /** * Unit associated with the price. */ unit: string; } interface GetModelAgreementOffersOfferTermDetailValidityTerm { /** * Duration of the agreement. */ agreementDuration: string; } interface GetModelsModelSummary { /** * Customizations that the model supports. */ customizationsSupporteds: string[]; /** * Inference types that the model supports. */ inferenceTypesSupporteds: string[]; /** * Input modalities that the model supports. */ inputModalities: string[]; /** * Model ARN. */ modelArn: string; /** * Model identifier. */ modelId: string; /** * Model name. */ modelName: string; /** * Output modalities that the model supports. */ outputModalities: string[]; /** * Model provider name. */ providerName: string; /** * Whether the model supports streaming. */ responseStreamingSupported: boolean; } interface ModelAgreementTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace bedrockmodel { interface InvocationJobInputDataConfig { /** * Location of the S3 input data. See `s3InputDataConfig` Block below. */ s3InputDataConfig: outputs.bedrockmodel.InvocationJobInputDataConfigS3InputDataConfig; } interface InvocationJobInputDataConfigS3InputDataConfig { /** * ID of the AWS account that owns the S3 bucket containing the input data. */ s3BucketOwner: string; /** * Format of the input data. Valid values: `JSONL`. */ s3InputFormat: string; /** * S3 location of the input data. */ s3Uri: string; } interface InvocationJobOutputDataConfig { /** * Location of the S3 output data. See `s3OutputDataConfig` Block below. */ s3OutputDataConfig: outputs.bedrockmodel.InvocationJobOutputDataConfigS3OutputDataConfig; } interface InvocationJobOutputDataConfigS3OutputDataConfig { /** * ID of the AWS account that owns the S3 bucket containing the output data. */ s3BucketOwner: string; /** * ARN of the KMS key that encrypts the S3 location of the output data. */ s3EncryptionKeyId: string; /** * S3 location where the results of the batch inference job are stored. */ s3Uri: string; } interface InvocationJobTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface InvocationJobVpcConfig { /** * IDs of the security groups in the VPC to use. */ securityGroupIds: string[]; /** * IDs of the subnets in the VPC to use. */ subnetIds: string[]; } interface InvocationLoggingConfigurationLoggingConfig { /** * CloudWatch logging configuration. See `cloudwatchConfig` Block for details. */ cloudwatchConfig?: outputs.bedrockmodel.InvocationLoggingConfigurationLoggingConfigCloudwatchConfig; /** * Set to include embeddings data in the log delivery. Defaults to `true`. */ embeddingDataDeliveryEnabled: boolean; /** * Set to include image data in the log delivery. Defaults to `true`. */ imageDataDeliveryEnabled: boolean; /** * S3 configuration for storing log data. See `s3Config` Block for details. */ s3Config?: outputs.bedrockmodel.InvocationLoggingConfigurationLoggingConfigS3Config; /** * Set to include text data in the log delivery. Defaults to `true`. */ textDataDeliveryEnabled: boolean; /** * Set to include text data in the log delivery. Defaults to `true`. */ videoDataDeliveryEnabled: boolean; } interface InvocationLoggingConfigurationLoggingConfigCloudwatchConfig { /** * S3 configuration for delivering a large amount of data. See `largeDataDeliveryS3Config` Block for details. */ largeDataDeliveryS3Config?: outputs.bedrockmodel.InvocationLoggingConfigurationLoggingConfigCloudwatchConfigLargeDataDeliveryS3Config; /** * Log group name. */ logGroupName: string; /** * Role ARN. */ roleArn: string; } interface InvocationLoggingConfigurationLoggingConfigCloudwatchConfigLargeDataDeliveryS3Config { /** * S3 bucket name. */ bucketName: string; /** * S3 prefix. */ keyPrefix?: string; } interface InvocationLoggingConfigurationLoggingConfigS3Config { /** * S3 bucket name. */ bucketName: string; /** * S3 prefix. */ keyPrefix?: string; } } export declare namespace billing { interface GetViewsBillingView { /** * ARN of the billing view. */ arn: string; /** * Type of the billing view. */ billingViewType: string; /** * Description of the billing view. */ description: string; /** * Name of the billing view. */ name: string; /** * Account ID of the billing view owner. */ ownerAccountId: string; } interface ViewDataFilterExpression { /** * Dimension to use for the expression. See `dimensions` below for details. */ dimensions?: outputs.billing.ViewDataFilterExpressionDimensions; /** * Tags to use for the expression. See `tags` below for details. */ tags?: outputs.billing.ViewDataFilterExpressionTag[]; /** * Time range to use for the expression. See `timeRange` below for details. */ timeRange?: outputs.billing.ViewDataFilterExpressionTimeRange; } interface ViewDataFilterExpressionDimensions { /** * Key of the dimension. Valid values are `LINKED_ACCOUNT`. */ key: string; /** * List of metadata values that you can use to filter and group your results. */ values: string[]; } interface ViewDataFilterExpressionTag { /** * Key of the tag. */ key: string; /** * List of values for the tag. */ values: string[]; } interface ViewDataFilterExpressionTimeRange { /** * Inclusive start date of the time range. */ beginDateInclusive: string; /** * Inclusive end date of the time range. */ endDateInclusive: string; } interface ViewTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace budgets { interface BudgetActionActionThreshold { /** * Type of threshold for a notification. Valid values are `PERCENTAGE` or `ABSOLUTE_VALUE`. */ actionThresholdType: string; /** * Threshold of a notification. */ actionThresholdValue: number; } interface BudgetActionDefinition { /** * AWS Identity and Access Management (IAM) action definition details. See `iamActionDefinition` Block. */ iamActionDefinition?: outputs.budgets.BudgetActionDefinitionIamActionDefinition; /** * Service control policies (SCPs) action definition details. See `scpActionDefinition` Block. */ scpActionDefinition?: outputs.budgets.BudgetActionDefinitionScpActionDefinition; /** * AWS Systems Manager (SSM) action definition details. See `ssmActionDefinition` Block. */ ssmActionDefinition?: outputs.budgets.BudgetActionDefinitionSsmActionDefinition; } interface BudgetActionDefinitionIamActionDefinition { /** * List of groups to be attached. There must be at least one group. */ groups?: string[]; /** * ARN of the policy to be attached. */ policyArn: string; /** * List of roles to be attached. There must be at least one role. */ roles?: string[]; /** * List of users to be attached. There must be at least one user. */ users?: string[]; } interface BudgetActionDefinitionScpActionDefinition { /** * Policy ID attached. */ policyId: string; /** * List of target IDs. */ targetIds: string[]; } interface BudgetActionDefinitionSsmActionDefinition { /** * Action subType. Valid values are `STOP_EC2_INSTANCES` or `STOP_RDS_INSTANCES`. */ actionSubType: string; /** * EC2 and RDS instance IDs. */ instanceIds: string[]; /** * Region to run the SSM document. */ region: string; } interface BudgetActionSubscriber { /** * Address that AWS sends budget notifications to, either an SNS topic or an email. */ address: string; /** * Type of notification that AWS sends to a subscriber. Valid values are `SNS` or `EMAIL`. */ subscriptionType: string; } interface BudgetAutoAdjustData { /** * Whether your budget auto-adjusts based on historical or forecasted data. Valid values: `FORECAST`, `HISTORICAL`. */ autoAdjustType: string; /** * Configuration block of Historical Options. Required for `autoAdjustType` of `HISTORICAL`. Defines the historical data that your auto-adjusting budget is based on. */ historicalOptions?: outputs.budgets.BudgetAutoAdjustDataHistoricalOptions; /** * Last time that your budget was auto-adjusted. */ lastAutoAdjustTime: string; } interface BudgetAutoAdjustDataHistoricalOptions { /** * Number of budget periods included in the moving-average calculation that determines your auto-adjusted budget amount. */ budgetAdjustmentPeriod: number; /** * Integer that describes how many budget periods in your BudgetAdjustmentPeriod are included in the calculation of your current budget limit. If the first budget period in your BudgetAdjustmentPeriod has no cost data, then that budget period isn’t included in the average that determines your budget limit. You can’t set your own LookBackAvailablePeriods. The value is automatically calculated from the `budgetAdjustmentPeriod` and your historical cost data. */ lookbackAvailablePeriods: number; } interface BudgetCostFilter { /** * Name of the cost filter. Valid values are `AZ`, `BillingEntity`, `CostCategory`, `InstanceType`, `InvoicingEntity`, `LegalEntityName`, `LinkedAccount`, `Operation`, `PurchaseType`, `Region`, `Service`, `TagKeyValue`, `UsageType`, and `UsageTypeGroup`. */ name: string; /** * List of values used for filtering. */ values: string[]; } interface BudgetCostTypes { /** * Whether to include credits in the cost budget. Defaults to `true`. */ includeCredit?: boolean; /** * Whether a budget includes discounts. Defaults to `true`. */ includeDiscount?: boolean; /** * Whether to include other subscription costs in the cost budget. Defaults to `true`. */ includeOtherSubscription?: boolean; /** * Whether to include recurring costs in the cost budget. Defaults to `true`. */ includeRecurring?: boolean; /** * Whether to include refunds in the cost budget. Defaults to `true`. */ includeRefund?: boolean; /** * Whether to include subscriptions in the cost budget. Defaults to `true`. */ includeSubscription?: boolean; /** * Whether to include support costs in the cost budget. Defaults to `true`. */ includeSupport?: boolean; /** * Whether to include tax in the cost budget. Defaults to `true`. */ includeTax?: boolean; /** * Whether to include upfront costs in the cost budget. Defaults to `true`. */ includeUpfront?: boolean; /** * Whether a budget uses the amortized rate. Defaults to `false`. */ useAmortized?: boolean; /** * Whether to use blended costs in the cost budget. Defaults to `false`. */ useBlended?: boolean; } interface BudgetFilterExpression { /** * List of filter expressions to combine with AND logic. Each `and` block is one operand and must itself contain exactly one root. */ ands?: outputs.budgets.BudgetFilterExpressionAnd[]; /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionDimensions; /** * Single filter expression to negate. Must contain exactly one root. */ not?: outputs.budgets.BudgetFilterExpressionNot; /** * List of filter expressions to combine with OR logic. Each `or` block is one operand and must itself contain exactly one root. */ ors?: outputs.budgets.BudgetFilterExpressionOr[]; /** * Tags block. */ tags?: outputs.budgets.BudgetFilterExpressionTags; } interface BudgetFilterExpressionAnd { /** * List of filter expressions to combine with AND logic. Each `and` block is one operand and must itself contain exactly one root. */ ands?: outputs.budgets.BudgetFilterExpressionAndAnd[]; /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionAndCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionAndDimensions; /** * Single filter expression to negate. Must contain exactly one root. */ not?: outputs.budgets.BudgetFilterExpressionAndNot; /** * List of filter expressions to combine with OR logic. Each `or` block is one operand and must itself contain exactly one root. */ ors?: outputs.budgets.BudgetFilterExpressionAndOr[]; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionAndTags; } interface BudgetFilterExpressionAndAnd { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionAndAndCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionAndAndDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionAndAndTags; } interface BudgetFilterExpressionAndAndCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndAndDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionAndAndTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionAndNot { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionAndNotCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionAndNotDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionAndNotTags; } interface BudgetFilterExpressionAndNotCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndNotDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionAndNotTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndOr { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionAndOrCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionAndOrDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionAndOrTags; } interface BudgetFilterExpressionAndOrCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndOrDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionAndOrTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionAndTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionNot { /** * List of filter expressions to combine with AND logic. Each `and` block is one operand and must itself contain exactly one root. */ ands?: outputs.budgets.BudgetFilterExpressionNotAnd[]; /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionNotCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionNotDimensions; /** * Single filter expression to negate. Must contain exactly one root. */ not?: outputs.budgets.BudgetFilterExpressionNotNot; /** * List of filter expressions to combine with OR logic. Each `or` block is one operand and must itself contain exactly one root. */ ors?: outputs.budgets.BudgetFilterExpressionNotOr[]; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionNotTags; } interface BudgetFilterExpressionNotAnd { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionNotAndCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionNotAndDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionNotAndTags; } interface BudgetFilterExpressionNotAndCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotAndDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionNotAndTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionNotNot { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionNotNotCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionNotNotDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionNotNotTags; } interface BudgetFilterExpressionNotNotCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotNotDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionNotNotTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotOr { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionNotOrCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionNotOrDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionNotOrTags; } interface BudgetFilterExpressionNotOrCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotOrDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionNotOrTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionNotTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOr { /** * List of filter expressions to combine with AND logic. Each `and` block is one operand and must itself contain exactly one root. */ ands?: outputs.budgets.BudgetFilterExpressionOrAnd[]; /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionOrCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionOrDimensions; /** * Single filter expression to negate. Must contain exactly one root. */ not?: outputs.budgets.BudgetFilterExpressionOrNot; /** * List of filter expressions to combine with OR logic. Each `or` block is one operand and must itself contain exactly one root. */ ors?: outputs.budgets.BudgetFilterExpressionOrOr[]; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionOrTags; } interface BudgetFilterExpressionOrAnd { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionOrAndCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionOrAndDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionOrAndTags; } interface BudgetFilterExpressionOrAndCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrAndDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionOrAndTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionOrNot { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionOrNotCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionOrNotDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionOrNotTags; } interface BudgetFilterExpressionOrNotCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrNotDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionOrNotTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrOr { /** * Cost Categories block. */ costCategories?: outputs.budgets.BudgetFilterExpressionOrOrCostCategories; /** * Dimensions block. */ dimensions?: outputs.budgets.BudgetFilterExpressionOrOrDimensions; /** * Map of tags assigned to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.budgets.BudgetFilterExpressionOrOrTags; } interface BudgetFilterExpressionOrOrCostCategories { /** * Cost category key to filter on. */ key?: string; /** * Match options for the cost category filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of cost category values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrOrDimensions { /** * Dimension to filter on. Valid values include `AZ`, `INSTANCE_TYPE`, `LINKED_ACCOUNT`, `OPERATION`, `PURCHASE_TYPE`, `REGION`, `SERVICE`, `USAGE_TYPE`, `USAGE_TYPE_GROUP`, `RECORD_TYPE`, `OPERATING_SYSTEM`, `TENANCY`, `SCOPE`, `PLATFORM`, `SUBSCRIPTION_ID`, `LEGAL_ENTITY_NAME`, `DEPLOYMENT_OPTION`, `DATABASE_ENGINE`, `CACHE_ENGINE`, `INSTANCE_TYPE_FAMILY`, `BILLING_ENTITY`, `RESERVATION_ID`, `RESOURCE_ID`, `RIGHTSIZING_TYPE`, `SAVINGS_PLANS_TYPE`, `SAVINGS_PLAN_ARN`, `PAYMENT_OPTION`, and `AGREEMENT_END_DATE_TIME_AFTER`, `AGREEMENT_END_DATE_TIME_BEFORE`. */ key: string; /** * Match options for the dimension filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of values to match against the dimension. At least one value is required. */ values: string[]; } interface BudgetFilterExpressionOrOrTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionOrTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetFilterExpressionTags { /** * Tag key to filter on. */ key?: string; /** * Match options for the tag filter. Valid values are `EQUALS`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `GREATER_THAN_OR_EQUAL`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. Note: `ABSENT` is not supported due to AWS API contradictions (it requires values to be absent but also cannot have values set). */ matchOptions?: string[]; /** * List of tag values to match. At least one value is required. */ values?: string[]; } interface BudgetNotification { /** * Comparison operator to use to evaluate the condition. Can be `LESS_THAN`, `EQUAL_TO` or `GREATER_THAN`. */ comparisonOperator: string; /** * What kind of budget value to notify on. Can be `ACTUAL` or `FORECASTED`. */ notificationType: string; /** * E-Mail addresses to notify. Either this or `subscriberSnsTopicArns` is required. */ subscriberEmailAddresses?: string[]; /** * SNS topics to notify. Either this or `subscriberEmailAddresses` is required. */ subscriberSnsTopicArns?: string[]; /** * Threshold when the notification should be sent. */ threshold: number; /** * What kind of threshold is defined. Can be `PERCENTAGE` OR `ABSOLUTE_VALUE`. */ thresholdType: string; } interface BudgetPlannedLimit { /** * Amount of cost or usage being measured for a budget. */ amount: string; /** * Start time of the budget limit. Format: `2017-01-01_12:00`. See [PlannedBudgetLimits](https://docs.aws.amazon.com/aws-cost-management/latest/APIReference/API_budgets_Budget.html#awscostmanagement-Type-budgets_Budget-PlannedBudgetLimits) documentation. */ startTime: string; /** * Unit of measurement used for the budget forecast, actual spend, or budget threshold, such as dollars or GB. See [Spend](http://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/data-type-spend.html) documentation. */ unit: string; } interface GetBudgetAutoAdjustData { /** * String that defines whether the budget auto-adjusts based on historical or forecasted data. Valid values: `FORECAST`, `HISTORICAL`. */ autoAdjustType: string; /** * Historical data that the auto-adjusting budget is based on. See `historicalOptions` Block for details. */ historicalOptions: outputs.budgets.GetBudgetAutoAdjustDataHistoricalOption[]; /** * Last time that the budget was auto-adjusted. */ lastAutoAdjustTime: string; } interface GetBudgetAutoAdjustDataHistoricalOption { /** * Number of budget periods included in the moving-average calculation that determines the auto-adjusted budget amount. */ budgetAdjustmentPeriod: number; /** * Number of budget periods in the `budgetAdjustmentPeriod` included in the calculation of the current budget limit. */ lookbackAvailablePeriods: number; } interface GetBudgetBudgetLimit { /** * Amount of cost or usage measured for the budget. */ amount: string; /** * Unit of measurement used for the budget, such as dollars or GB. */ unit: string; } interface GetBudgetCalculatedSpend { /** * Amount of cost, usage, RI units, or Savings Plans units used. See `actualSpend` Block for details. */ actualSpends: outputs.budgets.GetBudgetCalculatedSpendActualSpend[]; } interface GetBudgetCalculatedSpendActualSpend { /** * Amount of cost or usage measured for the budget. */ amount: string; /** * Unit of measurement used for the budget, such as dollars or GB. */ unit: string; } interface GetBudgetCostFilter { /** * Name of the budget. Unique within an account. * * The following arguments are optional: */ name: string; /** * Values of the cost filter. */ values: string[]; } interface GetBudgetCostType { /** * Whether to include credits in the cost budget. */ includeCredit: boolean; /** * Whether to include discounts in the cost budget. */ includeDiscount: boolean; /** * Whether to include other subscription costs in the cost budget. */ includeOtherSubscription: boolean; /** * Whether to include recurring costs in the cost budget. */ includeRecurring: boolean; /** * Whether to include refunds in the cost budget. */ includeRefund: boolean; /** * Whether to include subscriptions in the cost budget. */ includeSubscription: boolean; /** * Whether to include support costs in the cost budget. */ includeSupport: boolean; /** * Whether to include tax in the cost budget. */ includeTax: boolean; /** * Whether to include upfront costs in the cost budget. */ includeUpfront: boolean; /** * Whether the budget uses the amortized rate. */ useAmortized: boolean; /** * Whether to use blended costs in the cost budget. */ useBlended: boolean; } interface GetBudgetNotification { /** * Comparison operator used to evaluate the condition. Valid values: `LESS_THAN`, `EQUAL_TO`, `GREATER_THAN`. */ comparisonOperator: string; /** * Type of budget value to notify on. Valid values: `ACTUAL`, `FORECASTED`. */ notificationType: string; /** * Email addresses to notify. */ subscriberEmailAddresses: string[]; /** * SNS topics to notify. */ subscriberSnsTopicArns: string[]; /** * Threshold at which the notification is sent. */ threshold: number; /** * Type of threshold. Valid values: `PERCENTAGE`, `ABSOLUTE_VALUE`. */ thresholdType: string; } interface GetBudgetPlannedLimit { /** * Amount of cost or usage measured for the budget. */ amount: string; /** * Start time of the budget limit. Format: `2017-01-01_12:00`. */ startTime: string; /** * Unit of measurement used for the budget, such as dollars or GB. */ unit: string; } } export declare namespace cfg { interface ConfigurationAggregatorAccountAggregationSource { /** * List of 12-digit account IDs of the account(s) being aggregated. */ accountIds: string[]; /** * If true, aggregate existing AWS Config regions and future regions. */ allRegions?: boolean; /** * List of source regions being aggregated. * * Either `regions` or `allRegions` (as true) must be specified. */ regions?: string[]; } interface ConfigurationAggregatorOrganizationAggregationSource { /** * If true, aggregate existing AWS Config regions and future regions. */ allRegions?: boolean; /** * List of source regions being aggregated. */ regions?: string[]; /** * ARN of the IAM role used to retrieve AWS Organization details associated with the aggregator account. * * Either `regions` or `allRegions` (as true) must be specified. */ roleArn: string; } interface ConformancePackInputParameter { /** * The input key. */ parameterName: string; /** * The input value. */ parameterValue: string; } interface DeliveryChannelSnapshotDeliveryProperties { /** * The frequency with which AWS Config recurringly delivers configuration snapshotsE.g., `One_Hour` or `Three_Hours`. Valid values are listed [here](https://docs.aws.amazon.com/config/latest/APIReference/API_ConfigSnapshotDeliveryProperties.html#API_ConfigSnapshotDeliveryProperties_Contents). */ deliveryFrequency?: string; } interface OrganizationConformancePackInputParameter { /** * The input key. */ parameterName: string; /** * The input value. */ parameterValue: string; } interface RecorderRecordingGroup { /** * Specifies whether AWS Config records configuration changes for every supported type of regional resource (which includes any new type that will become supported in the future). Conflicts with `resourceTypes`. Defaults to `true`. */ allSupported?: boolean; /** * An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.To use this option, you must set the useOnly field of RecordingStrategy to `EXCLUSION_BY_RESOURCE_TYPES` Requires `allSupported = false`. Conflicts with `resourceTypes`. */ exclusionByResourceTypes: outputs.cfg.RecorderRecordingGroupExclusionByResourceType[]; /** * Specifies whether AWS Config includes all supported types of _global resources_ with the resources that it records. Requires `allSupported = true`. Conflicts with `resourceTypes`. */ includeGlobalResourceTypes?: boolean; /** * Recording Strategy. Detailed below. */ recordingStrategies: outputs.cfg.RecorderRecordingGroupRecordingStrategy[]; /** * A list that specifies the types of AWS resources for which AWS Config records configuration changes (for example, `AWS::EC2::Instance` or `AWS::CloudTrail::Trail`). See [relevant part of AWS Docs](http://docs.aws.amazon.com/config/latest/APIReference/API_ResourceIdentifier.html#config-Type-ResourceIdentifier-resourceType) for available types. In order to use this attribute, `allSupported` must be set to false. */ resourceTypes?: string[]; } interface RecorderRecordingGroupExclusionByResourceType { /** * A list that specifies the types of AWS resources for which AWS Config excludes records configuration changes. See [relevant part of AWS Docs](http://docs.aws.amazon.com/config/latest/APIReference/API_ResourceIdentifier.html#config-Type-ResourceIdentifier-resourceType) for available types. */ resourceTypes?: string[]; } interface RecorderRecordingGroupRecordingStrategy { useOnly?: string; } interface RecorderRecordingMode { /** * Default recording frequency. `CONTINUOUS` or `DAILY`. */ recordingFrequency?: string; /** * Recording mode overrides. Detailed below. */ recordingModeOverride?: outputs.cfg.RecorderRecordingModeRecordingModeOverride; } interface RecorderRecordingModeRecordingModeOverride { /** * A description you provide of the override. */ description?: string; /** * The recording frequency for the resources in the override block. `CONTINUOUS` or `DAILY`. */ recordingFrequency: string; /** * A list that specifies the types of AWS resources for which the override applies to. See [restrictions in the AWS Docs](https://docs.aws.amazon.com/config/latest/APIReference/API_RecordingModeOverride.html) */ resourceTypes: string[]; } interface RemediationConfigurationExecutionControls { /** * Configuration block for SSM controls. See below. */ ssmControls?: outputs.cfg.RemediationConfigurationExecutionControlsSsmControls; } interface RemediationConfigurationExecutionControlsSsmControls { /** * Maximum percentage of remediation actions allowed to run in parallel on the non-compliant resources for that specific rule. The default value is 10%. */ concurrentExecutionRatePercentage?: number; /** * Percentage of errors that are allowed before SSM stops running automations on non-compliant resources for that specific rule. The default is 50%. */ errorPercentage?: number; } interface RemediationConfigurationParameter { /** * Name of the attribute. */ name: string; /** * Value is dynamic and changes at run-time. */ resourceValue?: string; /** * Value is static and does not change at run-time. */ staticValue?: string; /** * List of static values. */ staticValues: string[]; } interface RuleEvaluationMode { /** * The mode of an evaluation. */ mode: string; } interface RuleScope { /** * The IDs of the only AWS resource that you want to trigger an evaluation for the rule. If you specify a resource ID, you must specify one resource type for `complianceResourceTypes`. */ complianceResourceId?: string; /** * A list of resource types of only those AWS resources that you want to trigger an evaluation for the ruleE.g., `AWS::EC2::Instance`. You can only specify one type if you also specify a resource ID for `complianceResourceId`. See [relevant part of AWS Docs](http://docs.aws.amazon.com/config/latest/APIReference/API_ResourceIdentifier.html#config-Type-ResourceIdentifier-resourceType) for available types. */ complianceResourceTypes?: string[]; /** * The tag key that is applied to only those AWS resources that you want you want to trigger an evaluation for the rule. */ tagKey?: string; /** * The tag value applied to only those AWS resources that you want to trigger an evaluation for the rule. */ tagValue?: string; } interface RuleSource { /** * Provides the runtime system, policy definition, and whether debug logging is enabled. Required when owner is set to `CUSTOM_POLICY`. See Custom Policy Details Below. */ customPolicyDetails?: outputs.cfg.RuleSourceCustomPolicyDetails; /** * Indicates whether AWS or the customer owns and manages the AWS Config rule. Valid values are `AWS`, `CUSTOM_LAMBDA` or `CUSTOM_POLICY`. For more information about managed rules, see the [AWS Config Managed Rules documentation](https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config_use-managed-rules.html). For more information about custom rules, see the [AWS Config Custom Rules documentation](https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config_develop-rules.html). Custom Lambda Functions require permissions to allow the AWS Config service to invoke them, e.g., via the `aws.lambda.Permission` resource. */ owner: string; /** * Provides the source and type of the event that causes AWS Config to evaluate your AWS resources. Only valid if `owner` is `CUSTOM_LAMBDA` or `CUSTOM_POLICY`. See Source Detail Below. */ sourceDetails?: outputs.cfg.RuleSourceSourceDetail[]; /** * For AWS Config managed rules, a predefined identifier, e.g `IAM_PASSWORD_POLICY`. For custom Lambda rules, the identifier is the ARN of the Lambda Function, such as `arn:aws:lambda:us-east-1:123456789012:function:custom_rule_name` or the `arn` attribute of the `aws.lambda.Function` resource. */ sourceIdentifier?: string; } interface RuleSourceCustomPolicyDetails { /** * The boolean expression for enabling debug logging for your Config Custom Policy rule. The default value is `false`. */ enableDebugLogDelivery?: boolean; /** * The runtime system for your Config Custom Policy rule. Guard is a policy-as-code language that allows you to write policies that are enforced by Config Custom Policy rules. For more information about Guard, see the [Guard GitHub Repository](https://github.com/aws-cloudformation/cloudformation-guard). */ policyRuntime: string; /** * The policy definition containing the logic for your Config Custom Policy rule. */ policyText: string; } interface RuleSourceSourceDetail { /** * The source of the event, such as an AWS service, that triggers AWS Config to evaluate your AWSresources. This defaults to `aws.config` and is the only valid value. */ eventSource?: string; /** * The frequency that you want AWS Config to run evaluations for a rule that istriggered periodically. If specified, requires `messageType` to be `ScheduledNotification`. */ maximumExecutionFrequency?: string; /** * The type of notification that triggers AWS Config to run an evaluation for a rule. You canspecify the following notification types: * * `ConfigurationItemChangeNotification` - Triggers an evaluation when AWS Config delivers a configuration item as a result of a resource change. * * `OversizedConfigurationItemChangeNotification` - Triggers an evaluation when AWS Config delivers an oversized configuration item. AWS Config may generate this notification type when a resource changes and the notification exceeds the maximum size allowed by Amazon SNS. * * `ScheduledNotification` - Triggers a periodic evaluation at the frequency specified for `maximumExecutionFrequency`. * * `ConfigurationSnapshotDeliveryCompleted` - Triggers a periodic evaluation when AWS Config delivers a configuration snapshot. */ messageType?: string; } } export declare namespace chatbot { interface SlackChannelConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface TeamsChannelConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace chime { interface SdkvoiceGlobalSettingsVoiceConnector { /** * The S3 bucket that stores the Voice Connector's call detail records. */ cdrBucket?: string; } interface SdkvoiceSipMediaApplicationEndpoints { /** * Valid ARN of the Lambda function, version, or alias. The function must be created in the same AWS Region as the SIP media application. */ lambdaArn: string; } interface SdkvoiceSipRuleTargetApplication { /** * The AWS Region of the target application. */ awsRegion: string; /** * Priority of the SIP media application in the target list. */ priority: number; /** * The SIP media application ID. */ sipMediaApplicationId: string; } interface SdkvoiceVoiceProfileDomainServerSideEncryptionConfiguration { /** * ARN for KMS Key. * * The following arguments are optional: */ kmsKeyArn: string; } interface VoiceConnectorGroupConnector { /** * The priority associated with the Amazon Chime Voice Connector, with 1 being the highest priority. Higher priority Amazon Chime Voice Connectors are attempted first. */ priority: number; /** * The Amazon Chime Voice Connector ID. */ voiceConnectorId: string; } interface VoiceConnectorOriginationRoute { /** * The FQDN or IP address to contact for origination traffic. */ host: string; /** * The designated origination route port. Defaults to `5060`. */ port?: number; /** * The priority associated with the host, with 1 being the highest priority. Higher priority hosts are attempted first. */ priority: number; /** * The protocol to use for the origination route. Encryption-enabled Amazon Chime Voice Connectors use TCP protocol by default. */ protocol: string; /** * The weight associated with the host. If hosts are equal in priority, calls are redistributed among them based on their relative weight. */ weight: number; } interface VoiceConnectorStreamingMediaInsightsConfiguration { /** * The media insights configuration that will be invoked by the Voice Connector. */ configurationArn?: string; /** * When `true`, the media insights configuration is not enabled. Defaults to `false`. */ disabled?: boolean; } interface VoiceConnectorTerminationCredentialsCredential { /** * RFC2617 compliant password associated with the SIP credentials. */ password: string; /** * RFC2617 compliant username associated with the SIP credentials. */ username: string; } } export declare namespace chimesdkmediapipelines { interface MediaInsightsPipelineConfigurationElement { /** * Configuration for Amazon Transcribe Call Analytics processor. */ amazonTranscribeCallAnalyticsProcessorConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementAmazonTranscribeCallAnalyticsProcessorConfiguration; /** * Configuration for Amazon Transcribe processor. */ amazonTranscribeProcessorConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementAmazonTranscribeProcessorConfiguration; /** * Configuration for Kinesis Data Stream sink. */ kinesisDataStreamSinkConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementKinesisDataStreamSinkConfiguration; /** * Configuration for Lambda Function sink. */ lambdaFunctionSinkConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementLambdaFunctionSinkConfiguration; /** * Configuration for S3 recording sink. */ s3RecordingSinkConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementS3RecordingSinkConfiguration; /** * Configuration for SNS Topic sink. */ snsTopicSinkConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementSnsTopicSinkConfiguration; /** * Configuration for SQS Queue sink. */ sqsQueueSinkConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementSqsQueueSinkConfiguration; /** * Element type. */ type: string; /** * Configuration for Voice analytics processor. */ voiceAnalyticsProcessorConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementVoiceAnalyticsProcessorConfiguration; } interface MediaInsightsPipelineConfigurationElementAmazonTranscribeCallAnalyticsProcessorConfiguration { /** * Filter for category events to be delivered to insights target. */ callAnalyticsStreamCategories?: string[]; /** * Labels all personally identifiable information (PII) identified in Utterance events. */ contentIdentificationType?: string; /** * Redacts all personally identifiable information (PII) identified in Utterance events. */ contentRedactionType?: string; /** * Enables partial result stabilization in Utterance events. */ enablePartialResultsStabilization?: boolean; /** * Filters partial Utterance events from delivery to the insights target. */ filterPartialResults?: boolean; /** * Language code for the transcription model. */ languageCode: string; /** * Name of custom language model for transcription. */ languageModelName?: string; /** * Level of stability to use when partial results stabilization is enabled. */ partialResultsStability?: string; /** * Types of personally identifiable information (PII) to redact from an Utterance event. */ piiEntityTypes?: string; /** * Settings for post call analytics. */ postCallAnalyticsSettings?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationElementAmazonTranscribeCallAnalyticsProcessorConfigurationPostCallAnalyticsSettings; /** * Method for applying a vocabulary filter to Utterance events. */ vocabularyFilterMethod?: string; /** * Name of the custom vocabulary filter to use when processing Utterance events. */ vocabularyFilterName?: string; /** * Name of the custom vocabulary to use when processing Utterance events. */ vocabularyName?: string; } interface MediaInsightsPipelineConfigurationElementAmazonTranscribeCallAnalyticsProcessorConfigurationPostCallAnalyticsSettings { /** * Should output be redacted. */ contentRedactionOutput?: string; /** * ARN of the role used by AWS Transcribe to upload your post call analysis. */ dataAccessRoleArn: string; /** * ID of the KMS key used to encrypt the output. */ outputEncryptionKmsKeyId?: string; /** * The Amazon S3 location where you want your Call Analytics post-call transcription output stored. */ outputLocation: string; } interface MediaInsightsPipelineConfigurationElementAmazonTranscribeProcessorConfiguration { /** * Labels all personally identifiable information (PII) identified in Transcript events. */ contentIdentificationType?: string; /** * Redacts all personally identifiable information (PII) identified in Transcript events. */ contentRedactionType?: string; /** * Enables partial result stabilization in Transcript events. */ enablePartialResultsStabilization?: boolean; /** * Filters partial Utterance events from delivery to the insights target. */ filterPartialResults?: boolean; /** * Language code for the transcription model. */ languageCode: string; /** * Name of custom language model for transcription. */ languageModelName?: string; /** * Level of stability to use when partial results stabilization is enabled. */ partialResultsStability?: string; /** * Types of personally identifiable information (PII) to redact from a Transcript event. */ piiEntityTypes?: string; /** * Enables speaker partitioning (diarization) in your Transcript events. */ showSpeakerLabel?: boolean; /** * Method for applying a vocabulary filter to Transcript events. */ vocabularyFilterMethod?: string; /** * Name of the custom vocabulary filter to use when processing Transcript events. */ vocabularyFilterName?: string; /** * Name of the custom vocabulary to use when processing Transcript events. */ vocabularyName?: string; } interface MediaInsightsPipelineConfigurationElementKinesisDataStreamSinkConfiguration { /** * Kinesis Data Stream to deliver results. */ insightsTarget: string; } interface MediaInsightsPipelineConfigurationElementLambdaFunctionSinkConfiguration { /** * Lambda Function to deliver results. */ insightsTarget: string; } interface MediaInsightsPipelineConfigurationElementS3RecordingSinkConfiguration { /** * S3 URI to deliver recordings. */ destination?: string; } interface MediaInsightsPipelineConfigurationElementSnsTopicSinkConfiguration { /** * SNS topic to deliver results. */ insightsTarget: string; } interface MediaInsightsPipelineConfigurationElementSqsQueueSinkConfiguration { /** * SQS queue to deliver results. */ insightsTarget: string; } interface MediaInsightsPipelineConfigurationElementVoiceAnalyticsProcessorConfiguration { /** * Enable speaker search. */ speakerSearchStatus: string; /** * Enable voice tone analysis. */ voiceToneAnalysisStatus: string; } interface MediaInsightsPipelineConfigurationRealTimeAlertConfiguration { /** * Disables real time alert rules. */ disabled: boolean; /** * Collection of real time alert rules */ rules: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRule[]; } interface MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRule { /** * Configuration for an issue detection rule. */ issueDetectionConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRuleIssueDetectionConfiguration; /** * Configuration for a keyword match rule. */ keywordMatchConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRuleKeywordMatchConfiguration; /** * Configuration for a sentiment rule. */ sentimentConfiguration?: outputs.chimesdkmediapipelines.MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRuleSentimentConfiguration; /** * Rule type. */ type: string; } interface MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRuleIssueDetectionConfiguration { /** * Rule name. */ ruleName: string; } interface MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRuleKeywordMatchConfiguration { /** * Collection of keywords to match. */ keywords: string[]; /** * Negate the rule. */ negate: boolean; /** * Rule name. */ ruleName: string; } interface MediaInsightsPipelineConfigurationRealTimeAlertConfigurationRuleSentimentConfiguration { /** * Rule name. */ ruleName: string; /** * Sentiment type to match. */ sentimentType: string; /** * Analysis interval. */ timePeriod: number; } } export declare namespace cleanrooms { interface CollaborationDataEncryptionMetadata { /** * Whether encrypted tables can contain cleartext data. This is a boolean field. */ allowClearText: boolean; /** * Whether Fingerprint columns can contain duplicate entries. This is a boolean field. */ allowDuplicates: boolean; /** * Whether Fingerprint columns can be joined on any other Fingerprint column with a different name. This is a boolean field. */ allowJoinsOnColumnsWithDifferentNames: boolean; /** * Whether NULL values are to be copied as NULL to encrypted tables (true) or cryptographically processed (false). */ preserveNulls: boolean; } interface CollaborationMember { /** * Account ID for the invited member. */ accountId: string; /** * Display name for the invited member. */ displayName: string; /** * List of abilities for the invited member. Valid values [may be found here](https://docs.aws.amazon.com/clean-rooms/latest/apireference/API_CreateCollaboration.html#API-CreateCollaboration-request-creatorMemberAbilities). */ memberAbilities: string[]; /** * For each member included in the collaboration an additional computed attribute of status is added. These values [may be found here](https://docs.aws.amazon.com/clean-rooms/latest/apireference/API_MemberSummary.html#API-Type-MemberSummary-status). */ status: string; } interface ConfiguredTableTableReference { databaseName: string; tableName: string; } interface MembershipDefaultResultConfiguration { outputConfiguration: outputs.cleanrooms.MembershipDefaultResultConfigurationOutputConfiguration; /** * The ARN of the IAM role which will be used to create the membership. * - `output_configuration.s3.bucket` - (Required) - The name of the S3 bucket where the query results will be stored. * - `output_configuration.s3.result_format` - (Required) - The format of the query results. Valid values are `PARQUET` and `CSV`. * - `output_configuration.s3.key_prefix` - (Optional) - The prefix used for the query results. */ roleArn?: string; } interface MembershipDefaultResultConfigurationOutputConfiguration { s3: outputs.cleanrooms.MembershipDefaultResultConfigurationOutputConfigurationS3; } interface MembershipDefaultResultConfigurationOutputConfigurationS3 { bucket: string; keyPrefix?: string; resultFormat: string; } interface MembershipPaymentConfiguration { queryCompute: outputs.cleanrooms.MembershipPaymentConfigurationQueryCompute; } interface MembershipPaymentConfigurationQueryCompute { /** * Indicates whether the collaboration member has accepted to pay for query compute costs. */ isResponsible: boolean; } } export declare namespace cloudformation { interface CloudFormationTypeLoggingConfig { /** * Name of the CloudWatch Log Group where CloudFormation sends error logging information when invoking the type's handlers. */ logGroupName: string; /** * ARN of the IAM Role CloudFormation assumes when sending error logging information to CloudWatch Logs. */ logRoleArn: string; } interface GetCloudFormationTypeLoggingConfig { /** * Name of the CloudWatch Log Group where CloudFormation sends error logging information when invoking the type's handlers. */ logGroupName: string; /** * ARN of the IAM Role CloudFormation assumes when sending error logging information to CloudWatch Logs. */ logRoleArn: string; } interface StackInstancesDeploymentTargets { /** * Limit deployment targets to individual accounts or include additional accounts with provided OUs. Valid values: `INTERSECTION`, `DIFFERENCE`, `UNION`, `NONE`. */ accountFilterType?: string; /** * List of accounts to deploy stack set updates. */ accounts?: string[]; /** * S3 URL of the file containing the list of accounts. */ accountsUrl?: string; /** * Organization root ID or organizational unit (OU) IDs to which stack sets deploy. */ organizationalUnitIds?: string[]; } interface StackInstancesOperationPreferences { /** * How the concurrency level behaves during the operation execution. Valid values are `STRICT_FAILURE_TOLERANCE` and `SOFT_FAILURE_TOLERANCE`. */ concurrencyMode?: string; /** * Number of accounts, per region, for which this operation can fail before CloudFormation stops the operation in that region. */ failureToleranceCount?: number; /** * Percentage of accounts, per region, for which this stack operation can fail before CloudFormation stops the operation in that region. */ failureTolerancePercentage?: number; /** * Maximum number of accounts in which to perform this operation at one time. */ maxConcurrentCount?: number; /** * Maximum percentage of accounts in which to perform this operation at one time. */ maxConcurrentPercentage?: number; /** * Concurrency type of deploying stack sets operations in regions, could be in parallel or one region at a time. Valid values are `SEQUENTIAL` and `PARALLEL`. */ regionConcurrencyType?: string; /** * Order of the regions where you want to perform the stack operation. */ regionOrders?: string[]; } interface StackInstancesStackInstanceSummary { /** * Account ID in which the instance is deployed. */ accountId: string; /** * Detailed status of the stack instance. Values include `PENDING`, `RUNNING`, `SUCCEEDED`, `FAILED`, `CANCELLED`, `INOPERABLE`, `SKIPPED_SUSPENDED_ACCOUNT`, `FAILED_IMPORT`. */ detailedStatus: string; /** * Status of the stack instance's actual configuration compared to the expected template and parameter configuration of the stack set to which it belongs. Values include `DRIFTED`, `IN_SYNC`, `UNKNOWN`, `NOT_CHECKED`. */ driftStatus: string; /** * Organization root ID or organizational unit (OU) IDs that you specified for `deploymentTargets`. */ organizationalUnitId: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * ID of the stack instance. */ stackId: string; /** * Name or unique ID of the stack set that the stack instance is associated with. */ stackSetId: string; /** * Status of the stack instance, in terms of its synchronization with its associated stack set. Values include `CURRENT`, `OUTDATED`, `INOPERABLE`. */ status: string; /** * Explanation for the specific status code assigned to this stack instance. */ statusReason: string; } interface StackSetAutoDeployment { /** * A list of StackSet ARNs that this StackSet depends on for auto-deployment operations. When auto-deployment is triggered, operations will be sequenced to ensure all dependencies complete successfully before this StackSet's operation begins. */ dependsOnStackSets?: string[]; /** * Whether or not auto-deployment is enabled. */ enabled?: boolean; /** * Whether or not to retain stacks when the account is removed. */ retainStacksOnAccountRemoval?: boolean; } interface StackSetInstanceDeploymentTargets { /** * Limit deployment targets to individual accounts or include additional accounts with provided OUs. Valid values: `INTERSECTION`, `DIFFERENCE`, `UNION`, `NONE`. */ accountFilterType?: string; /** * List of accounts to deploy stack set updates. */ accounts?: string[]; /** * S3 URL of the file containing the list of accounts. */ accountsUrl?: string; /** * Organization root ID or organizational unit (OU) IDs to which StackSets deploys. */ organizationalUnitIds?: string[]; } interface StackSetInstanceOperationPreferences { /** * Specifies how the concurrency level behaves during the operation execution. Valid values are `STRICT_FAILURE_TOLERANCE` and `SOFT_FAILURE_TOLERANCE`. */ concurrencyMode?: string; /** * Number of accounts, per Region, for which this operation can fail before AWS CloudFormation stops the operation in that Region. */ failureToleranceCount?: number; /** * Percentage of accounts, per Region, for which this stack operation can fail before AWS CloudFormation stops the operation in that Region. */ failureTolerancePercentage?: number; /** * Maximum number of accounts in which to perform this operation at one time. */ maxConcurrentCount?: number; /** * Maximum percentage of accounts in which to perform this operation at one time. */ maxConcurrentPercentage?: number; /** * Concurrency type of deploying StackSets operations in Regions, could be in parallel or one Region at a time. Valid values are `SEQUENTIAL` and `PARALLEL`. */ regionConcurrencyType?: string; /** * Order of the Regions in where you want to perform the stack operation. */ regionOrders?: string[]; } interface StackSetInstanceStackInstanceSummary { /** * Target AWS Account ID to create a Stack based on the StackSet. Defaults to current account. */ accountId: string; /** * Organizational unit ID in which the stack is deployed. */ organizationalUnitId: string; /** * Stack identifier. */ stackId: string; } interface StackSetManagedExecution { /** * When set to true, StackSets performs non-conflicting operations concurrently and queues conflicting operations. After conflicting operations finish, StackSets starts queued operations in request order. Default is false. */ active?: boolean; } interface StackSetOperationPreferences { /** * The number of accounts, per Region, for which this operation can fail before AWS CloudFormation stops the operation in that Region. */ failureToleranceCount?: number; /** * The percentage of accounts, per Region, for which this stack operation can fail before AWS CloudFormation stops the operation in that Region. */ failureTolerancePercentage?: number; /** * The maximum number of accounts in which to perform this operation at one time. */ maxConcurrentCount?: number; /** * The maximum percentage of accounts in which to perform this operation at one time. */ maxConcurrentPercentage?: number; /** * The concurrency type of deploying StackSets operations in Regions, could be in parallel or one Region at a time. */ regionConcurrencyType?: string; /** * The order of the Regions in where you want to perform the stack operation. */ regionOrders?: string[]; } } export declare namespace cloudfront { interface AnycastIpListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface CachePolicyParametersInCacheKeyAndForwardedToOrigin { /** * Whether any cookies in viewer requests are included in the cache key and automatically included in requests that CloudFront sends to the origin. See Cookies Config for more information. */ cookiesConfig: outputs.cloudfront.CachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfig; /** * Flag determines whether the Accept-Encoding HTTP header is included in the cache key and in requests that CloudFront sends to the origin. */ enableAcceptEncodingBrotli?: boolean; /** * Whether the Accept-Encoding HTTP header is included in the cache key and in requests sent to the origin by CloudFront. */ enableAcceptEncodingGzip?: boolean; /** * Whether any HTTP headers are included in the cache key and automatically included in requests that CloudFront sends to the origin. See Headers Config for more information. */ headersConfig: outputs.cloudfront.CachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfig; /** * Whether any URL query strings in viewer requests are included in the cache key. It also automatically includes these query strings in requests that CloudFront sends to the origin. Please refer to the Query String Config for more information. */ queryStringsConfig: outputs.cloudfront.CachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfig; } interface CachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfig { /** * Whether any cookies in viewer requests are included in the cache key and automatically included in requests that CloudFront sends to the origin. Valid values for `cookieBehavior` are `none`, `whitelist`, `allExcept`, and `all`. */ cookieBehavior: string; /** * Object that contains a list of cookie names. See Items for more information. */ cookies?: outputs.cloudfront.CachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfigCookies; } interface CachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfigCookies { /** * List of item names, such as cookies, headers, or query strings. */ items?: string[]; } interface CachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfig { /** * Whether any HTTP headers are included in the cache key and automatically included in requests that CloudFront sends to the origin. Valid values for `headerBehavior` are `none` and `whitelist`. */ headerBehavior?: string; /** * Object contains a list of header names. See Items for more information. */ headers?: outputs.cloudfront.CachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfigHeaders; } interface CachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfigHeaders { /** * List of item names, such as cookies, headers, or query strings. */ items?: string[]; } interface CachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfig { /** * Whether URL query strings in viewer requests are included in the cache key and automatically included in requests that CloudFront sends to the origin. Valid values for `queryStringBehavior` are `none`, `whitelist`, `allExcept`, and `all`. */ queryStringBehavior: string; /** * Configuration parameter that contains a list of query string names. See Items for more information. */ queryStrings?: outputs.cloudfront.CachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfigQueryStrings; } interface CachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfigQueryStrings { /** * List of item names, such as cookies, headers, or query strings. */ items?: string[]; } interface ConnectionFunctionConnectionFunctionConfig { /** * Comment to describe the function. */ comment: string; /** * Key value store associations. See `keyValueStoreAssociation` below. */ keyValueStoreAssociation?: outputs.cloudfront.ConnectionFunctionConnectionFunctionConfigKeyValueStoreAssociation; /** * Runtime environment for the function. Valid values are `cloudfront-js-1.0` and `cloudfront-js-2.0`. */ runtime: string; } interface ConnectionFunctionConnectionFunctionConfigKeyValueStoreAssociation { /** * ARN of the key value store. */ keyValueStoreArn: string; } interface ConnectionGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Default is 90 minutes. */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Default is 90 minutes. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Default is 90 minutes. */ update?: string; } interface ContinuousDeploymentPolicyStagingDistributionDnsNames { /** * A list of CloudFront domain names for the staging distribution. */ items?: string[]; /** * Number of CloudFront domain names in the staging distribution. */ quantity: number; } interface ContinuousDeploymentPolicyTrafficConfig { /** * Determines which HTTP requests are sent to the staging distribution. See `singleHeaderConfig`. */ singleHeaderConfig?: outputs.cloudfront.ContinuousDeploymentPolicyTrafficConfigSingleHeaderConfig; /** * Contains the percentage of traffic to send to the staging distribution. See `singleWeightConfig`. */ singleWeightConfig?: outputs.cloudfront.ContinuousDeploymentPolicyTrafficConfigSingleWeightConfig; /** * Type of traffic configuration. Valid values are `SingleWeight` and `SingleHeader`. */ type: string; } interface ContinuousDeploymentPolicyTrafficConfigSingleHeaderConfig { /** * Request header name to send to the staging distribution. The header must contain the prefix `aws-cf-cd-`. */ header: string; /** * Request header value. */ value: string; } interface ContinuousDeploymentPolicyTrafficConfigSingleWeightConfig { /** * Session stickiness provides the ability to define multiple requests from a single viewer as a single session. This prevents the potentially inconsistent experience of sending some of a given user's requests to the staging distribution, while others are sent to the primary distribution. Define the session duration using TTL values. See `sessionStickinessConfig`. */ sessionStickinessConfig?: outputs.cloudfront.ContinuousDeploymentPolicyTrafficConfigSingleWeightConfigSessionStickinessConfig; /** * The percentage of traffic to send to a staging distribution, expressed as a decimal number between `0` and `.15`. */ weight: number; } interface ContinuousDeploymentPolicyTrafficConfigSingleWeightConfigSessionStickinessConfig { /** * The amount of time in seconds after which sessions will cease if no requests are received. Valid values are `300` - `3600` (5–60 minutes). The value must be less than or equal to `maximumTtl`. */ idleTtl: number; /** * The maximum amount of time in seconds to consider requests from the viewer as being part of the same session. Valid values are `300` - `3600` (5–60 minutes). The value must be greater than or equal to `idleTtl`. */ maximumTtl: number; } interface DistributionCacheTagConfig { /** * Name of the HTTP header to extract cache tags. The header value must contain comma-separated tag values. */ headerName: string; } interface DistributionConnectionFunctionAssociation { /** * Identifier for the distribution. For example: `EDFDVBD632BHDS5`. */ id: string; } interface DistributionCustomErrorResponse { /** * Minimum amount of time you want HTTP error codes to stay in CloudFront caches before CloudFront queries your origin to see whether the object has been updated. */ errorCachingMinTtl?: number; /** * 4xx or 5xx HTTP status code that you want to customize. */ errorCode: number; /** * HTTP status code that you want CloudFront to return with the custom error page to the viewer. */ responseCode?: number; /** * Path of the custom error page (for example, `/custom_404.html`). */ responsePagePath?: string; } interface DistributionDefaultCacheBehavior { /** * Controls which HTTP methods CloudFront processes and forwards to your Amazon S3 bucket or your custom origin. */ allowedMethods: string[]; /** * Unique identifier of the cache policy that is attached to the cache behavior. If configuring the `defaultCacheBehavior` either `cachePolicyId` or `forwardedValues` must be set. */ cachePolicyId?: string; /** * Controls whether CloudFront caches the response to requests using the specified HTTP methods. */ cachedMethods: string[]; /** * Whether you want CloudFront to automatically compress content for web requests that include `Accept-Encoding: gzip` in the request header (default: `false`). */ compress?: boolean; /** * Default amount of time (in seconds) that an object is in a CloudFront cache before CloudFront forwards another request in the absence of an `Cache-Control max-age` or `Expires` header. The TTL defined in Cache Policy overrides this configuration. */ defaultTtl: number; /** * Field level encryption configuration ID. */ fieldLevelEncryptionId?: string; /** * The forwarded values configuration that specifies how CloudFront handles query strings, cookies and headers (maximum one). */ forwardedValues?: outputs.cloudfront.DistributionDefaultCacheBehaviorForwardedValues; /** * A config block that triggers a cloudfront function with specific actions (maximum 2). */ functionAssociations?: outputs.cloudfront.DistributionDefaultCacheBehaviorFunctionAssociation[]; /** * A config block that sets the grpc config. */ grpcConfig: outputs.cloudfront.DistributionDefaultCacheBehaviorGrpcConfig; /** * A config block that triggers a lambda function with specific actions (maximum 4). */ lambdaFunctionAssociations?: outputs.cloudfront.DistributionDefaultCacheBehaviorLambdaFunctionAssociation[]; /** * Maximum amount of time (in seconds) that an object is in a CloudFront cache before CloudFront forwards another request to your origin to determine whether the object has been updated. Only effective in the presence of `Cache-Control max-age`, `Cache-Control s-maxage`, and `Expires` headers. The TTL defined in Cache Policy overrides this configuration. */ maxTtl: number; /** * Minimum amount of time that you want objects to stay in CloudFront caches before CloudFront queries your origin to see whether the object has been updated. Defaults to 0 seconds. The TTL defined in Cache Policy overrides this configuration. */ minTtl?: number; /** * Unique identifier of the origin request policy that is attached to the behavior. */ originRequestPolicyId?: string; /** * ARN of the real-time log configuration that is attached to this cache behavior. */ realtimeLogConfigArn?: string; /** * Identifier for a response headers policy. */ responseHeadersPolicyId?: string; /** * Indicates whether you want to distribute media files in Microsoft Smooth Streaming format using the origin that is associated with this cache behavior. */ smoothStreaming?: boolean; /** * Value of ID for the origin that you want CloudFront to route requests to when a request matches the path pattern either for a cache behavior or for the default cache behavior. */ targetOriginId: string; /** * List of nested attributes for active trusted key groups, if the distribution is set up to serve private content with signed URLs. */ trustedKeyGroups: string[]; /** * List of nested attributes for active trusted signers, if the distribution is set up to serve private content with signed URLs. */ trustedSigners: string[]; /** * Use this element to specify the protocol that users can use to access the files in the origin specified by TargetOriginId when a request matches the path pattern in PathPattern. One of `allow-all`, `https-only`, or `redirect-to-https`. */ viewerProtocolPolicy: string; } interface DistributionDefaultCacheBehaviorForwardedValues { /** * The forwarded values cookies that specifies how CloudFront handles cookies (maximum one). */ cookies: outputs.cloudfront.DistributionDefaultCacheBehaviorForwardedValuesCookies; /** * Headers, if any, that you want CloudFront to vary upon for this cache behavior. Specify `*` to include all headers. */ headers: string[]; /** * Indicates whether you want CloudFront to forward query strings to the origin that is associated with this cache behavior. */ queryString: boolean; /** * When specified, along with a value of `true` for `queryString`, all query strings are forwarded, however only the query string keys listed in this argument are cached. When omitted with a value of `true` for `queryString`, all query string keys are cached. */ queryStringCacheKeys: string[]; } interface DistributionDefaultCacheBehaviorForwardedValuesCookies { /** * Whether you want CloudFront to forward cookies to the origin that is associated with this cache behavior. You can specify `all`, `none` or `whitelist`. If `whitelist`, you must include the subsequent `whitelistedNames`. */ forward: string; /** * If you have specified `whitelist` to `forward`, the whitelisted cookies that you want CloudFront to forward to your origin. */ whitelistedNames: string[]; } interface DistributionDefaultCacheBehaviorFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request` or `viewer-response`. */ eventType: string; /** * ARN of the CloudFront function. */ functionArn: string; } interface DistributionDefaultCacheBehaviorGrpcConfig { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; } interface DistributionDefaultCacheBehaviorLambdaFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request`, `origin-request`, `viewer-response`, `origin-response`. */ eventType: string; /** * When set to true it exposes the request body to the lambda function. Defaults to false. Valid values: `true`, `false`. */ includeBody?: boolean; /** * ARN of the Lambda function. */ lambdaArn: string; } interface DistributionLoggingConfig { /** * Amazon S3 bucket for V1 logging where access logs are stored, for example, `myawslogbucket.s3.amazonaws.com`. V1 logging is enabled when this argument is specified. The bucket must have correct ACL attached with "FULL_CONTROL" permission for "awslogsdelivery" account (Canonical ID: "c4c1ede66af53448b93c283ce9448c4ba468c9432aa01d700d3878632f77d2d0") for log transfer to work. */ bucket?: string; /** * Whether to include cookies in access logs (default: `false`). This argument applies to both V1 and V2 logging. */ includeCookies?: boolean; /** * Prefix added to the access log file names for V1 logging, for example, `myprefix/`. This argument is effective only when V1 logging is enabled. */ prefix?: string; } interface DistributionOrderedCacheBehavior { /** * Controls which HTTP methods CloudFront processes and forwards to your Amazon S3 bucket or your custom origin. */ allowedMethods: string[]; /** * Unique identifier of the cache policy that is attached to the cache behavior. If configuring the `defaultCacheBehavior` either `cachePolicyId` or `forwardedValues` must be set. */ cachePolicyId?: string; /** * Controls whether CloudFront caches the response to requests using the specified HTTP methods. */ cachedMethods: string[]; /** * Whether you want CloudFront to automatically compress content for web requests that include `Accept-Encoding: gzip` in the request header (default: `false`). */ compress?: boolean; /** * Default amount of time (in seconds) that an object is in a CloudFront cache before CloudFront forwards another request in the absence of an `Cache-Control max-age` or `Expires` header. The TTL defined in Cache Policy overrides this configuration. */ defaultTtl: number; /** * Field level encryption configuration ID. */ fieldLevelEncryptionId?: string; /** * The forwarded values configuration that specifies how CloudFront handles query strings, cookies and headers (maximum one). */ forwardedValues?: outputs.cloudfront.DistributionOrderedCacheBehaviorForwardedValues; /** * A config block that triggers a cloudfront function with specific actions (maximum 2). */ functionAssociations?: outputs.cloudfront.DistributionOrderedCacheBehaviorFunctionAssociation[]; /** * A config block that sets the grpc config. */ grpcConfig: outputs.cloudfront.DistributionOrderedCacheBehaviorGrpcConfig; /** * A config block that triggers a lambda function with specific actions (maximum 4). */ lambdaFunctionAssociations?: outputs.cloudfront.DistributionOrderedCacheBehaviorLambdaFunctionAssociation[]; /** * Maximum amount of time (in seconds) that an object is in a CloudFront cache before CloudFront forwards another request to your origin to determine whether the object has been updated. Only effective in the presence of `Cache-Control max-age`, `Cache-Control s-maxage`, and `Expires` headers. The TTL defined in Cache Policy overrides this configuration. */ maxTtl: number; /** * Minimum amount of time that you want objects to stay in CloudFront caches before CloudFront queries your origin to see whether the object has been updated. Defaults to 0 seconds. The TTL defined in Cache Policy overrides this configuration. */ minTtl?: number; /** * Unique identifier of the origin request policy that is attached to the behavior. */ originRequestPolicyId?: string; /** * Pattern (for example, `images/*.jpg`) that specifies which requests you want this cache behavior to apply to. */ pathPattern: string; /** * ARN of the real-time log configuration that is attached to this cache behavior. */ realtimeLogConfigArn?: string; /** * Identifier for a response headers policy. */ responseHeadersPolicyId?: string; /** * Indicates whether you want to distribute media files in Microsoft Smooth Streaming format using the origin that is associated with this cache behavior. */ smoothStreaming?: boolean; /** * Value of ID for the origin that you want CloudFront to route requests to when a request matches the path pattern either for a cache behavior or for the default cache behavior. */ targetOriginId: string; /** * List of nested attributes for active trusted key groups, if the distribution is set up to serve private content with signed URLs. */ trustedKeyGroups?: string[]; /** * List of nested attributes for active trusted signers, if the distribution is set up to serve private content with signed URLs. */ trustedSigners?: string[]; /** * Use this element to specify the protocol that users can use to access the files in the origin specified by TargetOriginId when a request matches the path pattern in PathPattern. One of `allow-all`, `https-only`, or `redirect-to-https`. */ viewerProtocolPolicy: string; } interface DistributionOrderedCacheBehaviorForwardedValues { /** * The forwarded values cookies that specifies how CloudFront handles cookies (maximum one). */ cookies: outputs.cloudfront.DistributionOrderedCacheBehaviorForwardedValuesCookies; /** * Headers, if any, that you want CloudFront to vary upon for this cache behavior. Specify `*` to include all headers. */ headers: string[]; /** * Indicates whether you want CloudFront to forward query strings to the origin that is associated with this cache behavior. */ queryString: boolean; /** * When specified, along with a value of `true` for `queryString`, all query strings are forwarded, however only the query string keys listed in this argument are cached. When omitted with a value of `true` for `queryString`, all query string keys are cached. */ queryStringCacheKeys: string[]; } interface DistributionOrderedCacheBehaviorForwardedValuesCookies { /** * Whether you want CloudFront to forward cookies to the origin that is associated with this cache behavior. You can specify `all`, `none` or `whitelist`. If `whitelist`, you must include the subsequent `whitelistedNames`. */ forward: string; /** * If you have specified `whitelist` to `forward`, the whitelisted cookies that you want CloudFront to forward to your origin. */ whitelistedNames?: string[]; } interface DistributionOrderedCacheBehaviorFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request` or `viewer-response`. */ eventType: string; /** * ARN of the CloudFront function. */ functionArn: string; } interface DistributionOrderedCacheBehaviorGrpcConfig { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; } interface DistributionOrderedCacheBehaviorLambdaFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request`, `origin-request`, `viewer-response`, `origin-response`. */ eventType: string; /** * When set to true it exposes the request body to the lambda function. Defaults to false. Valid values: `true`, `false`. */ includeBody?: boolean; /** * ARN of the Lambda function. */ lambdaArn: string; } interface DistributionOrigin { /** * Number of times that CloudFront attempts to connect to the origin. Must be between 1-3. Defaults to 3. */ connectionAttempts?: number; /** * Number of seconds that CloudFront waits when trying to establish a connection to the origin. Must be between 1-10. Defaults to 10. */ connectionTimeout?: number; /** * One or more sub-resources with `name` and `value` parameters that specify header data that will be sent to the origin (multiples allowed). */ customHeaders?: outputs.cloudfront.DistributionOriginCustomHeader[]; /** * The CloudFront custom origin configuration information. If an S3 origin is required, use `originAccessControlId` or `s3OriginConfig` instead. */ customOriginConfig?: outputs.cloudfront.DistributionOriginCustomOriginConfig; /** * Domain name corresponding to the distribution. For example: `d604721fxaaqy9.cloudfront.net`. */ domainName: string; /** * Unique identifier of a CloudFront origin access control for this origin. */ originAccessControlId?: string; originId: string; /** * Optional element that causes CloudFront to request your content from a directory in your Amazon S3 bucket or your custom origin. */ originPath?: string; /** * CloudFront Origin Shield configuration information. Using Origin Shield can help reduce the load on your origin. For more information, see [Using Origin Shield](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/origin-shield.html) in the Amazon CloudFront Developer Guide. */ originShield?: outputs.cloudfront.DistributionOriginOriginShield; /** * Time (in seconds) that a request from CloudFront to the origin can stay open and wait for a response. Must be integer greater than or equal to the value of `originReadTimeout`. If omitted or explicitly set to `0`, no maximum value is enforced. */ responseCompletionTimeout: number; /** * CloudFront S3 origin configuration information. If a custom origin is required, use `customOriginConfig` instead. */ s3OriginConfig?: outputs.cloudfront.DistributionOriginS3OriginConfig; /** * The VPC origin configuration. */ vpcOriginConfig?: outputs.cloudfront.DistributionOriginVpcOriginConfig; } interface DistributionOriginCustomHeader { name: string; value: string; } interface DistributionOriginCustomOriginConfig { /** * HTTP port the custom origin listens on. */ httpPort: number; /** * HTTPS port the custom origin listens on. */ httpsPort: number; /** * IP protocol CloudFront uses when connecting to your origin. Valid values: `ipv4`, `ipv6`, `dualstack`. */ ipAddressType?: string; originKeepaliveTimeout?: number; /** * The origin mTLS configuration for mutual TLS authentication between CloudFront and your origin. */ originMtlsConfig?: outputs.cloudfront.DistributionOriginCustomOriginConfigOriginMtlsConfig; /** * Origin protocol policy to apply to your origin. One of `http-only`, `https-only`, or `match-viewer`. */ originProtocolPolicy: string; originReadTimeout?: number; /** * List of SSL/TLS protocols that CloudFront can use when connecting to your origin over HTTPS. Valid values: `SSLv3`, `TLSv1`, `TLSv1.1`, `TLSv1.2`. For more information, see [Minimum Origin SSL Protocol](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/distribution-web-values-specify.html#DownloadDistValuesOriginSSLProtocols) in the Amazon CloudFront Developer Guide. */ originSslProtocols: string[]; } interface DistributionOriginCustomOriginConfigOriginMtlsConfig { /** * ARN of the ACM certificate to use for mutual TLS authentication with the origin. The certificate must have Extended Key Usage set to TLS Client Authentication. */ clientCertificateArn: string; } interface DistributionOriginGroup { /** * The failover criteria for when to failover to the secondary origin. */ failoverCriteria: outputs.cloudfront.DistributionOriginGroupFailoverCriteria; /** * Ordered member configuration blocks assigned to the origin group, where the first member is the primary origin. You must specify two members. */ members: outputs.cloudfront.DistributionOriginGroupMember[]; originId: string; } interface DistributionOriginGroupFailoverCriteria { /** * List of HTTP status codes for the origin group. */ statusCodes: number[]; } interface DistributionOriginGroupMember { originId: string; } interface DistributionOriginOriginShield { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; /** * AWS Region for Origin Shield. To specify a region, use the region code, not the region name. For example, specify the US East (Ohio) region as `us-east-2`. */ originShieldRegion?: string; } interface DistributionOriginS3OriginConfig { /** * The CloudFront origin access identity to associate with the origin. */ originAccessIdentity: string; } interface DistributionOriginVpcOriginConfig { originKeepaliveTimeout?: number; originReadTimeout?: number; /** * The AWS account ID that owns the VPC origin. Required when referencing a VPC origin from a different AWS account for cross-account VPC origin access. */ ownerAccountId?: string; /** * The VPC origin ID. */ vpcOriginId: string; } interface DistributionRestrictions { geoRestriction: outputs.cloudfront.DistributionRestrictionsGeoRestriction; } interface DistributionRestrictionsGeoRestriction { /** * [ISO 3166-1-alpha-2 codes](http://www.iso.org/iso/country_codes/iso_3166_code_lists/country_names_and_code_elements.htm) for which you want CloudFront either to distribute your content (`whitelist`) or not distribute your content (`blacklist`). If the type is specified as `none` an empty array can be used. */ locations: string[]; /** * Method that you want to use to restrict distribution of your content by country: `none`, `whitelist`, or `blacklist`. */ restrictionType: string; } interface DistributionTenantCustomizations { /** * Certificate configuration for the tenant (maximum one). */ certificate?: outputs.cloudfront.DistributionTenantCustomizationsCertificate; /** * Geographic restrictions configuration for the tenant (maximum one). */ geoRestriction?: outputs.cloudfront.DistributionTenantCustomizationsGeoRestriction; /** * Web ACL configuration for the tenant (maximum one). */ webAcl?: outputs.cloudfront.DistributionTenantCustomizationsWebAcl; } interface DistributionTenantCustomizationsCertificate { /** * ARN of the distribution tenant. */ arn?: string; } interface DistributionTenantCustomizationsGeoRestriction { /** * Set of ISO 3166-1-alpha-2 country codes for the restriction. Required if `restrictionType` is `whitelist` or `blacklist`. */ locations: string[]; /** * Method to restrict distribution by country: `none`, `whitelist`, or `blacklist`. */ restrictionType?: string; } interface DistributionTenantCustomizationsWebAcl { /** * Action to take for the web ACL. Valid values: `allow`, `block`. */ action?: string; /** * ARN of the distribution tenant. */ arn?: string; } interface DistributionTenantDomain { /** * Set of domains associated with the distribution tenant. */ domain: string; /** * Current status of the distribution tenant. */ status: string; } interface DistributionTenantManagedCertificateRequest { /** * Certificate transparency logging preference. Valid values: `enabled`, `disabled`. */ certificateTransparencyLoggingPreference?: string; /** * Primary domain name for the certificate. */ primaryDomainName?: string; /** * Host for validation token. Valid values: `cloudfront`, `self-hosted`. */ validationTokenHost?: string; } interface DistributionTenantParameter { /** * Name of the distribution tenant. */ name: string; /** * Value of the parameter. */ value: string; } interface DistributionTenantTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DistributionTrustedKeyGroup { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; /** * List of nested attributes for each trusted signer */ items: outputs.cloudfront.DistributionTrustedKeyGroupItem[]; } interface DistributionTrustedKeyGroupItem { /** * ID of the key group that contains the public keys. */ keyGroupId: string; /** * Set of active CloudFront key pairs associated with the signer account */ keyPairIds: string[]; } interface DistributionTrustedSigner { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; /** * List of nested attributes for each trusted signer */ items: outputs.cloudfront.DistributionTrustedSignerItem[]; } interface DistributionTrustedSignerItem { /** * AWS account ID or `self` */ awsAccountNumber: string; /** * Set of active CloudFront key pairs associated with the signer account */ keyPairIds: string[]; } interface DistributionViewerCertificate { /** * ARN of the [AWS Certificate Manager](https://aws.amazon.com/certificate-manager/) certificate that you wish to use with this distribution. Specify this, `cloudfrontDefaultCertificate`, or `iamCertificateId`. The ACM certificate must be in US-EAST-1. */ acmCertificateArn?: string; /** * `true` if you want viewers to use HTTPS to request your objects and you're using the CloudFront domain name for your distribution. Specify this, `acmCertificateArn`, or `iamCertificateId`. */ cloudfrontDefaultCertificate?: boolean; /** * IAM certificate identifier of the custom viewer certificate for this distribution if you are using a custom domain. Specify this, `acmCertificateArn`, or `cloudfrontDefaultCertificate`. */ iamCertificateId?: string; /** * Minimum version of the SSL protocol that you want CloudFront to use for HTTPS connections. Can only be set if `cloudfrontDefaultCertificate = false`. See all possible values in [this](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/secure-connections-supported-viewer-protocols-ciphers.html) table under "Security policy." Some examples include: `TLSv1.2_2019` and `TLSv1.2_2021`. Default: `TLSv1`. **NOTE**: If you are using a custom certificate (specified with `acmCertificateArn` or `iamCertificateId`), and have specified `sni-only` in `sslSupportMethod`, `TLSv1` or later must be specified. If you have specified `vip` in `sslSupportMethod`, only `SSLv3` or `TLSv1` can be specified. If you have specified `cloudfrontDefaultCertificate`, `TLSv1` must be specified. */ minimumProtocolVersion?: string; /** * How you want CloudFront to serve HTTPS requests. One of `vip`, `sni-only`, or `static-ip`. Required if you specify `acmCertificateArn` or `iamCertificateId`. **NOTE:** `vip` causes CloudFront to use a dedicated IP address and may incur extra charges. */ sslSupportMethod?: string; } interface DistributionViewerMtlsConfig { /** * The mode for viewer mTLS. Valid values: `required`, `optional`. */ mode?: string; /** * The trust store configuration for viewer mTLS (maximum one). */ trustStoreConfig?: outputs.cloudfront.DistributionViewerMtlsConfigTrustStoreConfig; } interface DistributionViewerMtlsConfigTrustStoreConfig { /** * Whether to advertise the trust store CA names to clients. Defaults to `false`. */ advertiseTrustStoreCaNames?: boolean; /** * Whether to ignore certificate expiry for viewer mTLS. Defaults to `false`. */ ignoreCertificateExpiry?: boolean; /** * Identifier of the trust store to use for viewer mTLS. */ trustStoreId: string; } interface FieldLevelEncryptionConfigContentTypeProfileConfig { /** * Object that contains an attribute `items` that contains the list of configurations for a field-level encryption content type-profile. See Content Type Profile. */ contentTypeProfiles: outputs.cloudfront.FieldLevelEncryptionConfigContentTypeProfileConfigContentTypeProfiles; /** * specifies what to do when an unknown content type is provided for the profile. If true, content is forwarded without being encrypted when the content type is unknown. If false (the default), an error is returned when the content type is unknown. */ forwardWhenContentTypeIsUnknown: boolean; } interface FieldLevelEncryptionConfigContentTypeProfileConfigContentTypeProfiles { items: outputs.cloudfront.FieldLevelEncryptionConfigContentTypeProfileConfigContentTypeProfilesItem[]; } interface FieldLevelEncryptionConfigContentTypeProfileConfigContentTypeProfilesItem { /** * he content type for a field-level encryption content type-profile mapping. Valid value is `application/x-www-form-urlencoded`. */ contentType: string; /** * The format for a field-level encryption content type-profile mapping. Valid value is `URLEncoded`. */ format: string; profileId?: string; } interface FieldLevelEncryptionConfigQueryArgProfileConfig { /** * Flag to set if you want a request to be forwarded to the origin even if the profile specified by the field-level encryption query argument, fle-profile, is unknown. */ forwardWhenQueryArgProfileIsUnknown: boolean; /** * Object that contains an attribute `items` that contains the list ofrofiles specified for query argument-profile mapping for field-level encryption. see Query Arg Profile. */ queryArgProfiles?: outputs.cloudfront.FieldLevelEncryptionConfigQueryArgProfileConfigQueryArgProfiles; } interface FieldLevelEncryptionConfigQueryArgProfileConfigQueryArgProfiles { items?: outputs.cloudfront.FieldLevelEncryptionConfigQueryArgProfileConfigQueryArgProfilesItem[]; } interface FieldLevelEncryptionConfigQueryArgProfileConfigQueryArgProfilesItem { profileId: string; /** * Query argument for field-level encryption query argument-profile mapping. */ queryArg: string; } interface FieldLevelEncryptionProfileEncryptionEntities { items?: outputs.cloudfront.FieldLevelEncryptionProfileEncryptionEntitiesItem[]; } interface FieldLevelEncryptionProfileEncryptionEntitiesItem { /** * Object that contains an attribute `items` that contains the list of field patterns in a field-level encryption content type profile specify the fields that you want to be encrypted. */ fieldPatterns: outputs.cloudfront.FieldLevelEncryptionProfileEncryptionEntitiesItemFieldPatterns; /** * The provider associated with the public key being used for encryption. */ providerId: string; /** * The public key associated with a set of field-level encryption patterns, to be used when encrypting the fields that match the patterns. */ publicKeyId: string; } interface FieldLevelEncryptionProfileEncryptionEntitiesItemFieldPatterns { items?: string[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOrigin { /** * Object that determines whether any cookies in viewer requests (and if so, which cookies) are included in the cache key and automatically included in requests that CloudFront sends to the origin. See Cookies Config for more information. */ cookiesConfigs: outputs.cloudfront.GetCachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfig[]; /** * A flag that can affect whether the Accept-Encoding HTTP header is included in the cache key and included in requests that CloudFront sends to the origin. */ enableAcceptEncodingBrotli: boolean; /** * A flag that can affect whether the Accept-Encoding HTTP header is included in the cache key and included in requests that CloudFront sends to the origin. */ enableAcceptEncodingGzip: boolean; /** * Object that determines whether any HTTP headers (and if so, which headers) are included in the cache key and automatically included in requests that CloudFront sends to the origin. See Headers Config for more information. */ headersConfigs: outputs.cloudfront.GetCachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfig[]; /** * Object that determines whether any URL query strings in viewer requests (and if so, which query strings) are included in the cache key and automatically included in requests that CloudFront sends to the origin. See Query String Config for more information. */ queryStringsConfigs: outputs.cloudfront.GetCachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfig[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfig { /** * Determines whether any cookies in viewer requests are included in the cache key and automatically included in requests that CloudFront sends to the origin. Valid values are `none`, `whitelist`, `allExcept`, `all`. */ cookieBehavior: string; /** * Object that contains a list of cookie names. See Items for more information. */ cookies: outputs.cloudfront.GetCachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfigCookie[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOriginCookiesConfigCookie { /** * List of item names (`cookies`, `headers`, or `queryStrings`). */ items: string[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfig { /** * Determines whether any HTTP headers are included in the cache key and automatically included in requests that CloudFront sends to the origin. Valid values are `none`, `whitelist`. */ headerBehavior: string; /** * Object that contains a list of header names. See Items for more information. */ headers: outputs.cloudfront.GetCachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfigHeader[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOriginHeadersConfigHeader { /** * List of item names (`cookies`, `headers`, or `queryStrings`). */ items: string[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfig { /** * Determines whether any URL query strings in viewer requests are included in the cache key and automatically included in requests that CloudFront sends to the origin. Valid values are `none`, `whitelist`, `allExcept`, `all`. */ queryStringBehavior: string; /** * Object that contains a list of query string names. See Items for more information. */ queryStrings: outputs.cloudfront.GetCachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfigQueryString[]; } interface GetCachePolicyParametersInCacheKeyAndForwardedToOriginQueryStringsConfigQueryString { /** * List of item names (`cookies`, `headers`, or `queryStrings`). */ items: string[]; } interface GetDistributionTenantCustomization { certificates: outputs.cloudfront.GetDistributionTenantCustomizationCertificate[]; geoRestrictions: outputs.cloudfront.GetDistributionTenantCustomizationGeoRestriction[]; webAcls: outputs.cloudfront.GetDistributionTenantCustomizationWebAcl[]; } interface GetDistributionTenantCustomizationCertificate { /** * ARN for the distribution tenant. */ arn: string; } interface GetDistributionTenantCustomizationGeoRestriction { locations: string[]; restrictionType: string; } interface GetDistributionTenantCustomizationWebAcl { action: string; /** * ARN for the distribution tenant. */ arn: string; } interface GetDistributionTenantDomain { /** * An associated domain of the distribution tenant. Exactly one of `id` or `domain` must be specified. */ domain: string; /** * Current status of the distribution tenant. `Deployed` if the * distribution tenant's information is fully propagated throughout the Amazon * CloudFront system. */ status: string; } interface GetDistributionTenantManagedCertificateRequest { certificateTransparencyLoggingPreference: string; primaryDomainName: string; validationTokenHost: string; } interface GetDistributionTenantParameter { name: string; value: string; } interface GetOriginRequestPolicyCookiesConfig { cookieBehavior: string; cookies: outputs.cloudfront.GetOriginRequestPolicyCookiesConfigCookie[]; } interface GetOriginRequestPolicyCookiesConfigCookie { items: string[]; } interface GetOriginRequestPolicyHeadersConfig { headerBehavior: string; headers: outputs.cloudfront.GetOriginRequestPolicyHeadersConfigHeader[]; } interface GetOriginRequestPolicyHeadersConfigHeader { items: string[]; } interface GetOriginRequestPolicyQueryStringsConfig { queryStringBehavior: string; queryStrings: outputs.cloudfront.GetOriginRequestPolicyQueryStringsConfigQueryString[]; } interface GetOriginRequestPolicyQueryStringsConfigQueryString { items: string[]; } interface GetRealtimeLogConfigEndpoint { /** * (Required) Amazon Kinesis data stream configuration. */ kinesisStreamConfigs: outputs.cloudfront.GetRealtimeLogConfigEndpointKinesisStreamConfig[]; /** * (Required) Type of data stream where real-time log data is sent. The only valid value is `Kinesis`. */ streamType: string; } interface GetRealtimeLogConfigEndpointKinesisStreamConfig { /** * (Required) ARN of an IAM role that CloudFront can use to send real-time log data to the Kinesis data stream. * See the [AWS documentation](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/real-time-logs.html#understand-real-time-log-config-iam-role) for more information. */ roleArn: string; /** * (Required) ARN of the Kinesis data stream. */ streamArn: string; } interface GetResponseHeadersPolicyCorsConfig { /** * A Boolean value that CloudFront uses as the value for the Access-Control-Allow-Credentials HTTP response header. */ accessControlAllowCredentials: boolean; /** * Object that contains an attribute `items` that contains a list of HTTP header names that CloudFront includes as values for the Access-Control-Allow-Headers HTTP response header. */ accessControlAllowHeaders: outputs.cloudfront.GetResponseHeadersPolicyCorsConfigAccessControlAllowHeader[]; /** * Object that contains an attribute `items` that contains a list of HTTP methods that CloudFront includes as values for the Access-Control-Allow-Methods HTTP response header. Valid values: `GET` | `POST` | `OPTIONS` | `PUT` | `DELETE` | `HEAD` | `ALL` */ accessControlAllowMethods: outputs.cloudfront.GetResponseHeadersPolicyCorsConfigAccessControlAllowMethod[]; /** * Object that contains an attribute `items` that contains a list of origins that CloudFront can use as the value for the Access-Control-Allow-Origin HTTP response header. */ accessControlAllowOrigins: outputs.cloudfront.GetResponseHeadersPolicyCorsConfigAccessControlAllowOrigin[]; /** * Object that contains an attribute `items` that contains a list of HTTP headers that CloudFront includes as values for the Access-Control-Expose-Headers HTTP response header. */ accessControlExposeHeaders: outputs.cloudfront.GetResponseHeadersPolicyCorsConfigAccessControlExposeHeader[]; /** * A number that CloudFront uses as the value for the max-age directive in the Strict-Transport-Security HTTP response header. */ accessControlMaxAgeSec: number; originOverride: boolean; } interface GetResponseHeadersPolicyCorsConfigAccessControlAllowHeader { items: string[]; } interface GetResponseHeadersPolicyCorsConfigAccessControlAllowMethod { items: string[]; } interface GetResponseHeadersPolicyCorsConfigAccessControlAllowOrigin { items: string[]; } interface GetResponseHeadersPolicyCorsConfigAccessControlExposeHeader { items: string[]; } interface GetResponseHeadersPolicyCustomHeadersConfig { items: outputs.cloudfront.GetResponseHeadersPolicyCustomHeadersConfigItem[]; } interface GetResponseHeadersPolicyCustomHeadersConfigItem { /** * The HTTP header name. */ header: string; /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * Value for the HTTP response header. */ value: string; } interface GetResponseHeadersPolicyRemoveHeadersConfig { items: outputs.cloudfront.GetResponseHeadersPolicyRemoveHeadersConfigItem[]; } interface GetResponseHeadersPolicyRemoveHeadersConfigItem { /** * The HTTP header name. */ header: string; } interface GetResponseHeadersPolicySecurityHeadersConfig { /** * The policy directives and their values that CloudFront includes as values for the Content-Security-Policy HTTP response header. */ contentSecurityPolicies: outputs.cloudfront.GetResponseHeadersPolicySecurityHeadersConfigContentSecurityPolicy[]; /** * A setting that determines whether CloudFront includes the X-Content-Type-Options HTTP response header with its value set to nosniff. See Content Type Options for more information. */ contentTypeOptions: outputs.cloudfront.GetResponseHeadersPolicySecurityHeadersConfigContentTypeOption[]; /** * Setting that determines whether CloudFront includes the X-Frame-Options HTTP response header and the header’s value. See Frame Options for more information. */ frameOptions: outputs.cloudfront.GetResponseHeadersPolicySecurityHeadersConfigFrameOption[]; /** * Value of the Referrer-Policy HTTP response header. Valid Values: `no-referrer` | `no-referrer-when-downgrade` | `origin` | `origin-when-cross-origin` | `same-origin` | `strict-origin` | `strict-origin-when-cross-origin` | `unsafe-url` */ referrerPolicies: outputs.cloudfront.GetResponseHeadersPolicySecurityHeadersConfigReferrerPolicy[]; /** * Settings that determine whether CloudFront includes the Strict-Transport-Security HTTP response header and the header’s value. See Strict Transport Security for more information. */ strictTransportSecurities: outputs.cloudfront.GetResponseHeadersPolicySecurityHeadersConfigStrictTransportSecurity[]; /** * Settings that determine whether CloudFront includes the X-XSS-Protection HTTP response header and the header’s value. See XSS Protection for more information. */ xssProtections: outputs.cloudfront.GetResponseHeadersPolicySecurityHeadersConfigXssProtection[]; } interface GetResponseHeadersPolicySecurityHeadersConfigContentSecurityPolicy { /** * The policy directives and their values that CloudFront includes as values for the Content-Security-Policy HTTP response header. */ contentSecurityPolicy: string; /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; } interface GetResponseHeadersPolicySecurityHeadersConfigContentTypeOption { /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; } interface GetResponseHeadersPolicySecurityHeadersConfigFrameOption { /** * Value of the X-Frame-Options HTTP response header. Valid values: `DENY` | `SAMEORIGIN` */ frameOption: string; /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; } interface GetResponseHeadersPolicySecurityHeadersConfigReferrerPolicy { /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * Value of the Referrer-Policy HTTP response header. Valid Values: `no-referrer` | `no-referrer-when-downgrade` | `origin` | `origin-when-cross-origin` | `same-origin` | `strict-origin` | `strict-origin-when-cross-origin` | `unsafe-url` */ referrerPolicy: string; } interface GetResponseHeadersPolicySecurityHeadersConfigStrictTransportSecurity { /** * A number that CloudFront uses as the value for the max-age directive in the Strict-Transport-Security HTTP response header. */ accessControlMaxAgeSec: number; /** * Whether CloudFront includes the includeSubDomains directive in the Strict-Transport-Security HTTP response header. */ includeSubdomains: boolean; /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * Whether CloudFront includes the preload directive in the Strict-Transport-Security HTTP response header. */ preload: boolean; } interface GetResponseHeadersPolicySecurityHeadersConfigXssProtection { /** * Whether CloudFront includes the mode=block directive in the X-XSS-Protection header. */ modeBlock: boolean; /** * Whether CloudFront overrides the X-XSS-Protection HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * Boolean value that determines the value of the X-XSS-Protection HTTP response header. When this setting is true, the value of the X-XSS-Protection header is 1. When this setting is false, the value of the X-XSS-Protection header is 0. */ protection: boolean; /** * Whether CloudFront sets a reporting URI in the X-XSS-Protection header. */ reportUri: string; } interface GetResponseHeadersPolicyServerTimingHeadersConfig { /** * Whether CloudFront adds the `Server-Timing` header to HTTP responses that it sends in response to requests that match a cache behavior that's associated with this response headers policy. */ enabled: boolean; /** * Number 0–100 (inclusive) that specifies the percentage of responses that you want CloudFront to add the Server-Timing header to. */ samplingRate: number; } interface KeyValueStoreTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface KeyvaluestoreKeysExclusiveResourceKeyValuePair { /** * Key to put. */ key: string; /** * Value to put. */ value: string; } interface MonitoringSubscriptionMonitoringSubscription { /** * A subscription configuration for additional CloudWatch metrics. See below. */ realtimeMetricsSubscriptionConfig: outputs.cloudfront.MonitoringSubscriptionMonitoringSubscriptionRealtimeMetricsSubscriptionConfig; } interface MonitoringSubscriptionMonitoringSubscriptionRealtimeMetricsSubscriptionConfig { /** * A flag that indicates whether additional CloudWatch metrics are enabled for a given CloudFront distribution. Valid values are `Enabled` and `Disabled`. See below. */ realtimeMetricsSubscriptionStatus: string; } interface MultitenantDistributionActiveTrustedKeyGroup { /** * Whether any of the key groups have public keys that CloudFront can use to verify the signatures of signed URLs and signed cookies. */ enabled: boolean; /** * List of key groups. See Key Group Items below. */ items?: outputs.cloudfront.MultitenantDistributionActiveTrustedKeyGroupItem[]; } interface MultitenantDistributionActiveTrustedKeyGroupItem { /** * ID of the key group that contains the public keys. */ keyGroupId: string; /** * Set of active CloudFront key pairs associated with the signer that can be used to verify the signatures of signed URLs and signed cookies. */ keyPairIds: string[]; } interface MultitenantDistributionCacheBehavior { /** * Controls which HTTP methods CloudFront processes and forwards to your Amazon S3 bucket or your custom origin. */ allowedMethods: outputs.cloudfront.MultitenantDistributionCacheBehaviorAllowedMethods; /** * Unique identifier of the cache policy that is attached to the cache behavior. */ cachePolicyId?: string; /** * Whether you want CloudFront to automatically compress content for web requests that include `Accept-Encoding: gzip` in the request header. Default: `false`. */ compress: boolean; /** * Field level encryption configuration ID. */ fieldLevelEncryptionId: string; /** * Configuration block for CloudFront Functions associations. See Function Association below. */ functionAssociations?: outputs.cloudfront.MultitenantDistributionCacheBehaviorFunctionAssociation[]; /** * Configuration block for Lambda@Edge associations. See Lambda Function Association below. */ lambdaFunctionAssociations?: outputs.cloudfront.MultitenantDistributionCacheBehaviorLambdaFunctionAssociation[]; /** * Unique identifier of the origin request policy that is attached to the behavior. */ originRequestPolicyId?: string; /** * Pattern that specifies which requests you want this cache behavior to apply to. */ pathPattern: string; /** * ARN of the real-time log configuration that is attached to this cache behavior. */ realtimeLogConfigArn?: string; /** * Identifier for a response headers policy. */ responseHeadersPolicyId?: string; /** * Value of ID for the origin that you want CloudFront to route requests to when a request matches the path pattern either for a cache behavior or for the default cache behavior. */ targetOriginId: string; /** * List of key group IDs that CloudFront can use to validate signed URLs or signed cookies. */ trustedKeyGroups?: outputs.cloudfront.MultitenantDistributionCacheBehaviorTrustedKeyGroups; /** * Use this element to specify the protocol that users can use to access the files in the origin specified by TargetOriginId when a request matches the path pattern in PathPattern. One of `allow-all`, `https-only`, or `redirect-to-https`. */ viewerProtocolPolicy: string; } interface MultitenantDistributionCacheBehaviorAllowedMethods { /** * Controls whether CloudFront caches the response to requests using the specified HTTP methods. */ cachedMethods: string[]; items: string[]; } interface MultitenantDistributionCacheBehaviorFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request`, `origin-request`, `viewer-response`, `origin-response`. */ eventType: string; /** * ARN of the CloudFront function. */ functionArn: string; } interface MultitenantDistributionCacheBehaviorLambdaFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request`, `origin-request`, `viewer-response`, `origin-response`. */ eventType: string; /** * When set to true, the request body is exposed to the Lambda function. Default: `false`. */ includeBody: boolean; /** * ARN of the Lambda function. */ lambdaFunctionArn: string; } interface MultitenantDistributionCacheBehaviorTrustedKeyGroups { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; items?: string[]; } interface MultitenantDistributionCustomErrorResponse { /** * Minimum amount of time that you want CloudFront to cache the HTTP status code specified in ErrorCode. */ errorCachingMinTtl: number; /** * HTTP status code for which you want to specify a custom error page and/or a caching duration. */ errorCode: number; /** * HTTP status code that you want CloudFront to return to the viewer along with the custom error page. Both `responseCode` and `responsePagePath` must be specified or both must be omitted. */ responseCode?: string; /** * Path to the custom error page that you want CloudFront to return to a viewer when your origin returns the HTTP status code specified by ErrorCode. Both `responseCode` and `responsePagePath` must be specified or both must be omitted. */ responsePagePath?: string; } interface MultitenantDistributionDefaultCacheBehavior { /** * Controls which HTTP methods CloudFront processes and forwards to your Amazon S3 bucket or your custom origin. */ allowedMethods: outputs.cloudfront.MultitenantDistributionDefaultCacheBehaviorAllowedMethods; /** * Unique identifier of the cache policy that is attached to the cache behavior. */ cachePolicyId?: string; /** * Whether you want CloudFront to automatically compress content for web requests that include `Accept-Encoding: gzip` in the request header. Default: `false`. */ compress: boolean; /** * Field level encryption configuration ID. */ fieldLevelEncryptionId: string; /** * Configuration block for CloudFront Functions associations. See Function Association below. */ functionAssociations?: outputs.cloudfront.MultitenantDistributionDefaultCacheBehaviorFunctionAssociation[]; /** * Configuration block for Lambda@Edge associations. See Lambda Function Association below. */ lambdaFunctionAssociations?: outputs.cloudfront.MultitenantDistributionDefaultCacheBehaviorLambdaFunctionAssociation[]; /** * Unique identifier of the origin request policy that is attached to the behavior. */ originRequestPolicyId?: string; /** * ARN of the real-time log configuration that is attached to this cache behavior. */ realtimeLogConfigArn?: string; /** * Identifier for a response headers policy. */ responseHeadersPolicyId?: string; /** * Value of ID for the origin that you want CloudFront to route requests to when a request matches the path pattern either for a cache behavior or for the default cache behavior. */ targetOriginId: string; /** * List of key group IDs that CloudFront can use to validate signed URLs or signed cookies. */ trustedKeyGroups?: outputs.cloudfront.MultitenantDistributionDefaultCacheBehaviorTrustedKeyGroups; /** * Use this element to specify the protocol that users can use to access the files in the origin specified by TargetOriginId when a request matches the path pattern in PathPattern. One of `allow-all`, `https-only`, or `redirect-to-https`. */ viewerProtocolPolicy: string; } interface MultitenantDistributionDefaultCacheBehaviorAllowedMethods { /** * Controls whether CloudFront caches the response to requests using the specified HTTP methods. */ cachedMethods: string[]; items: string[]; } interface MultitenantDistributionDefaultCacheBehaviorFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request`, `origin-request`, `viewer-response`, `origin-response`. */ eventType: string; /** * ARN of the CloudFront function. */ functionArn: string; } interface MultitenantDistributionDefaultCacheBehaviorLambdaFunctionAssociation { /** * Specific event to trigger this function. Valid values: `viewer-request`, `origin-request`, `viewer-response`, `origin-response`. */ eventType: string; /** * When set to true, the request body is exposed to the Lambda function. Default: `false`. */ includeBody: boolean; /** * ARN of the Lambda function. */ lambdaFunctionArn: string; } interface MultitenantDistributionDefaultCacheBehaviorTrustedKeyGroups { /** * Whether the distribution is enabled to accept end user requests for content. */ enabled: boolean; items?: string[]; } interface MultitenantDistributionOrigin { /** * Number of times that CloudFront attempts to connect to the origin. Must be between 1-3. Default: 3. */ connectionAttempts: number; /** * Number of seconds that CloudFront waits when trying to establish a connection to the origin. Must be between 1-10. Default: 10. */ connectionTimeout: number; /** * One or more sub-resources with `name` and `value` parameters that specify header data that will be sent to the origin. See Custom Header below. */ customHeaders?: outputs.cloudfront.MultitenantDistributionOriginCustomHeader[]; /** * CloudFront origin access identity to associate with the origin. See Custom Origin Config below. */ customOriginConfigs?: outputs.cloudfront.MultitenantDistributionOriginCustomOriginConfig[]; /** * DNS domain name of either the S3 bucket, or web site of your custom origin. */ domainName: string; /** * Identifier for the distribution. */ id: string; /** * CloudFront origin access control identifier to associate with the origin. */ originAccessControlId?: string; /** * Optional element that causes CloudFront to request your content from a directory in your Amazon S3 bucket or your custom origin. */ originPath: string; /** * CloudFront Origin Shield configuration information. See Origin Shield below. */ originShields?: outputs.cloudfront.MultitenantDistributionOriginOriginShield[]; /** * Number of seconds that CloudFront waits for a response after forwarding a request to the origin. Must be integer greater than or equal to the value of `originReadTimeout` in Custom Origin Config. If omitted, no maximum value is enforced. */ responseCompletionTimeout: number; /** * CloudFront VPC origin configuration. See VPC Origin Config below. */ vpcOriginConfigs?: outputs.cloudfront.MultitenantDistributionOriginVpcOriginConfig[]; } interface MultitenantDistributionOriginCustomHeader { /** * Name of the header. */ headerName: string; /** * Value for the header. */ headerValue: string; } interface MultitenantDistributionOriginCustomOriginConfig { /** * HTTP port the custom origin listens on. */ httpPort: number; /** * HTTPS port the custom origin listens on. */ httpsPort: number; /** * Type of IP addresses used by your origins. Valid values are `ipv4` and `dualstack`. */ ipAddressType?: string; /** * Custom keep-alive timeout, in seconds. Default: 5. */ originKeepaliveTimeout: number; /** * Origin mTLS configuration for mutual TLS authentication between CloudFront and your origin. See Origin mTLS Config below. */ originMtlsConfig?: outputs.cloudfront.MultitenantDistributionOriginCustomOriginConfigOriginMtlsConfig; /** * Origin protocol policy to apply to your origin. Valid values are `http-only`, `https-only`, and `match-viewer`. */ originProtocolPolicy: string; /** * Custom read timeout, in seconds. Default: 30. */ originReadTimeout: number; /** * List of SSL/TLS protocols that you want CloudFront to use when communicating with your origin over HTTPS. */ originSslProtocols: string[]; } interface MultitenantDistributionOriginCustomOriginConfigOriginMtlsConfig { /** * ARN of the ACM certificate to use for mutual TLS authentication with the origin. The certificate must have Extended Key Usage set to TLS Client Authentication. */ clientCertificateArn: string; } interface MultitenantDistributionOriginGroup { /** * Failover criteria for when to failover to the secondary origin. See Failover Criteria below. */ failoverCriteria: outputs.cloudfront.MultitenantDistributionOriginGroupFailoverCriteria; /** * Identifier for the distribution. */ id: string; /** * List of origins in this origin group. Must contain exactly 2 members. See Origin Group Member below. */ members: outputs.cloudfront.MultitenantDistributionOriginGroupMember[]; } interface MultitenantDistributionOriginGroupFailoverCriteria { /** * List of HTTP status codes that trigger a failover to the secondary origin. */ statusCodes: number[]; } interface MultitenantDistributionOriginGroupMember { originId: string; } interface MultitenantDistributionOriginOriginShield { /** * Whether Origin Shield is enabled. */ enabled: boolean; /** * AWS Region for Origin Shield. Required when `enabled` is `true`. */ originShieldRegion?: string; } interface MultitenantDistributionOriginVpcOriginConfig { /** * Custom keep-alive timeout, in seconds. By default, CloudFront uses a default timeout. Default: 5. */ originKeepaliveTimeout: number; /** * Custom read timeout, in seconds. By default, CloudFront uses a default timeout. Default: 30. */ originReadTimeout: number; /** * ID of the VPC origin that you want CloudFront to route requests to. */ vpcOriginId: string; } interface MultitenantDistributionRestrictions { /** * Geographic restriction configuration. See Geo Restriction below. */ geoRestriction: outputs.cloudfront.MultitenantDistributionRestrictionsGeoRestriction; } interface MultitenantDistributionRestrictionsGeoRestriction { /** * List of ISO 3166-1-alpha-2 country codes for which you want CloudFront either to distribute your content (`whitelist`) or not distribute your content (`blacklist`). Required when `restrictionType` is `whitelist` or `blacklist`. */ items?: string[]; /** * Method to restrict distribution of your content by country. Valid values are `none`, `whitelist`, and `blacklist`. */ restrictionType: string; } interface MultitenantDistributionTenantConfig { /** * One or more parameter definitions for the tenant configuration. See Parameter Definition below. */ parameterDefinitions?: outputs.cloudfront.MultitenantDistributionTenantConfigParameterDefinition[]; } interface MultitenantDistributionTenantConfigParameterDefinition { /** * Definition of the parameter schema. See Parameter Definition Schema below. */ definitions?: outputs.cloudfront.MultitenantDistributionTenantConfigParameterDefinitionDefinition[]; /** * Name of the parameter. */ name: string; } interface MultitenantDistributionTenantConfigParameterDefinitionDefinition { /** * String schema configuration. See String Schema below. */ stringSchemas?: outputs.cloudfront.MultitenantDistributionTenantConfigParameterDefinitionDefinitionStringSchema[]; } interface MultitenantDistributionTenantConfigParameterDefinitionDefinitionStringSchema { /** * Comment describing the parameter. */ comment?: string; /** * Default value for the parameter. */ defaultValue?: string; /** * Whether the parameter is required. */ required: boolean; } interface MultitenantDistributionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface MultitenantDistributionViewerCertificate { /** * ARN of the AWS Certificate Manager certificate that you wish to use with this distribution. Required when using a custom SSL certificate. */ acmCertificateArn?: string; /** * Whether to use the CloudFront default certificate. Cannot be used with `acmCertificateArn`. */ cloudfrontDefaultCertificate: boolean; /** * Minimum version of the SSL protocol that you want CloudFront to use for HTTPS connections. Default: `TLSv1`. */ minimumProtocolVersion: string; /** * How you want CloudFront to serve HTTPS requests. Valid values are `sni-only` and `vip`. Required when `acmCertificateArn` is specified. */ sslSupportMethod: string; } interface OriginRequestPolicyCookiesConfig { cookieBehavior: string; cookies?: outputs.cloudfront.OriginRequestPolicyCookiesConfigCookies; } interface OriginRequestPolicyCookiesConfigCookies { items?: string[]; } interface OriginRequestPolicyHeadersConfig { headerBehavior?: string; headers?: outputs.cloudfront.OriginRequestPolicyHeadersConfigHeaders; } interface OriginRequestPolicyHeadersConfigHeaders { items?: string[]; } interface OriginRequestPolicyQueryStringsConfig { queryStringBehavior: string; queryStrings?: outputs.cloudfront.OriginRequestPolicyQueryStringsConfigQueryStrings; } interface OriginRequestPolicyQueryStringsConfigQueryStrings { items?: string[]; } interface RealtimeLogConfigEndpoint { /** * The Amazon Kinesis data stream configuration. */ kinesisStreamConfig: outputs.cloudfront.RealtimeLogConfigEndpointKinesisStreamConfig; /** * The type of data stream where real-time log data is sent. The only valid value is `Kinesis`. */ streamType: string; } interface RealtimeLogConfigEndpointKinesisStreamConfig { /** * The ARN of an IAM role that CloudFront can use to send real-time log data to the Kinesis data stream. * See the [AWS documentation](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/real-time-logs.html#understand-real-time-log-config-iam-role) for more information. */ roleArn: string; /** * The ARN of the Kinesis data stream. */ streamArn: string; } interface ResponseHeadersPolicyCorsConfig { /** * A Boolean value that CloudFront uses as the value for the `Access-Control-Allow-Credentials` HTTP response header. */ accessControlAllowCredentials: boolean; /** * Object that contains an attribute `items` that contains a list of HTTP header names that CloudFront includes as values for the `Access-Control-Allow-Headers` HTTP response header. */ accessControlAllowHeaders: outputs.cloudfront.ResponseHeadersPolicyCorsConfigAccessControlAllowHeaders; /** * Object that contains an attribute `items` that contains a list of HTTP methods that CloudFront includes as values for the `Access-Control-Allow-Methods` HTTP response header. Valid values: `GET` | `POST` | `OPTIONS` | `PUT` | `DELETE` | `HEAD` | `ALL` */ accessControlAllowMethods: outputs.cloudfront.ResponseHeadersPolicyCorsConfigAccessControlAllowMethods; /** * Object that contains an attribute `items` that contains a list of origins that CloudFront can use as the value for the `Access-Control-Allow-Origin` HTTP response header. */ accessControlAllowOrigins: outputs.cloudfront.ResponseHeadersPolicyCorsConfigAccessControlAllowOrigins; /** * Object that contains an attribute `items` that contains a list of HTTP headers that CloudFront includes as values for the `Access-Control-Expose-Headers` HTTP response header. */ accessControlExposeHeaders?: outputs.cloudfront.ResponseHeadersPolicyCorsConfigAccessControlExposeHeaders; /** * A number that CloudFront uses as the value for the `Access-Control-Max-Age` HTTP response header. */ accessControlMaxAgeSec?: number; /** * A Boolean value that determines how CloudFront behaves for the HTTP response header. */ originOverride: boolean; } interface ResponseHeadersPolicyCorsConfigAccessControlAllowHeaders { items?: string[]; } interface ResponseHeadersPolicyCorsConfigAccessControlAllowMethods { items?: string[]; } interface ResponseHeadersPolicyCorsConfigAccessControlAllowOrigins { items?: string[]; } interface ResponseHeadersPolicyCorsConfigAccessControlExposeHeaders { items?: string[]; } interface ResponseHeadersPolicyCustomHeadersConfig { items?: outputs.cloudfront.ResponseHeadersPolicyCustomHeadersConfigItem[]; } interface ResponseHeadersPolicyCustomHeadersConfigItem { header: string; override: boolean; /** * The value for the HTTP response header. */ value: string; } interface ResponseHeadersPolicyRemoveHeadersConfig { items?: outputs.cloudfront.ResponseHeadersPolicyRemoveHeadersConfigItem[]; } interface ResponseHeadersPolicyRemoveHeadersConfigItem { header: string; } interface ResponseHeadersPolicySecurityHeadersConfig { /** * The policy directives and their values that CloudFront includes as values for the `Content-Security-Policy` HTTP response header. See Content Security Policy for more information. */ contentSecurityPolicy?: outputs.cloudfront.ResponseHeadersPolicySecurityHeadersConfigContentSecurityPolicy; /** * Determines whether CloudFront includes the `X-Content-Type-Options` HTTP response header with its value set to `nosniff`. See Content Type Options for more information. */ contentTypeOptions?: outputs.cloudfront.ResponseHeadersPolicySecurityHeadersConfigContentTypeOptions; /** * Determines whether CloudFront includes the `X-Frame-Options` HTTP response header and the header’s value. See Frame Options for more information. */ frameOptions?: outputs.cloudfront.ResponseHeadersPolicySecurityHeadersConfigFrameOptions; /** * Determines whether CloudFront includes the `Referrer-Policy` HTTP response header and the header’s value. See Referrer Policy for more information. */ referrerPolicy?: outputs.cloudfront.ResponseHeadersPolicySecurityHeadersConfigReferrerPolicy; /** * Determines whether CloudFront includes the `Strict-Transport-Security` HTTP response header and the header’s value. See Strict Transport Security for more information. */ strictTransportSecurity?: outputs.cloudfront.ResponseHeadersPolicySecurityHeadersConfigStrictTransportSecurity; /** * Determine whether CloudFront includes the `X-XSS-Protection` HTTP response header and the header’s value. See XSS Protection for more information. */ xssProtection?: outputs.cloudfront.ResponseHeadersPolicySecurityHeadersConfigXssProtection; } interface ResponseHeadersPolicySecurityHeadersConfigContentSecurityPolicy { /** * The policy directives and their values that CloudFront includes as values for the `Content-Security-Policy` HTTP response header. */ contentSecurityPolicy: string; /** * Whether CloudFront overrides the `Content-Security-Policy` HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; } interface ResponseHeadersPolicySecurityHeadersConfigContentTypeOptions { /** * Whether CloudFront overrides the `X-Content-Type-Options` HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; } interface ResponseHeadersPolicySecurityHeadersConfigFrameOptions { /** * The value of the `X-Frame-Options` HTTP response header. Valid values: `DENY` | `SAMEORIGIN` */ frameOption: string; /** * Whether CloudFront overrides the `X-Frame-Options` HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; } interface ResponseHeadersPolicySecurityHeadersConfigReferrerPolicy { /** * Whether CloudFront overrides the `Referrer-Policy` HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * The value of the `Referrer-Policy` HTTP response header. Valid Values: `no-referrer` | `no-referrer-when-downgrade` | `origin` | `origin-when-cross-origin` | `same-origin` | `strict-origin` | `strict-origin-when-cross-origin` | `unsafe-url` */ referrerPolicy: string; } interface ResponseHeadersPolicySecurityHeadersConfigStrictTransportSecurity { /** * A number that CloudFront uses as the value for the `max-age` directive in the `Strict-Transport-Security` HTTP response header. */ accessControlMaxAgeSec: number; /** * Whether CloudFront includes the `includeSubDomains` directive in the `Strict-Transport-Security` HTTP response header. */ includeSubdomains?: boolean; /** * Whether CloudFront overrides the `Strict-Transport-Security` HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * Whether CloudFront includes the `preload` directive in the `Strict-Transport-Security` HTTP response header. */ preload?: boolean; } interface ResponseHeadersPolicySecurityHeadersConfigXssProtection { /** * Whether CloudFront includes the `mode=block` directive in the `X-XSS-Protection` header. */ modeBlock?: boolean; /** * Whether CloudFront overrides the `X-XSS-Protection` HTTP response header received from the origin with the one specified in this response headers policy. */ override: boolean; /** * A Boolean value that determines the value of the `X-XSS-Protection` HTTP response header. When this setting is `true`, the value of the `X-XSS-Protection` header is `1`. When this setting is `false`, the value of the `X-XSS-Protection` header is `0`. */ protection: boolean; /** * A reporting URI, which CloudFront uses as the value of the report directive in the `X-XSS-Protection` header. You cannot specify a `reportUri` when `modeBlock` is `true`. */ reportUri?: string; } interface ResponseHeadersPolicyServerTimingHeadersConfig { /** * A Whether CloudFront adds the `Server-Timing` header to HTTP responses that it sends in response to requests that match a cache behavior that's associated with this response headers policy. */ enabled: boolean; /** * A number 0–100 (inclusive) that specifies the percentage of responses that you want CloudFront to add the Server-Timing header to. Valid range: Minimum value of 0.0. Maximum value of 100.0. */ samplingRate: number; } interface TrustStoreCaCertificatesBundleSource { /** * Configuration block for the S3 location of the CA certificates bundle. See `caCertificatesBundleS3Location` below. */ caCertificatesBundleS3Location: outputs.cloudfront.TrustStoreCaCertificatesBundleSourceCaCertificatesBundleS3Location; } interface TrustStoreCaCertificatesBundleSourceCaCertificatesBundleS3Location { /** * S3 bucket name containing the CA certificates bundle. */ bucket: string; /** * S3 object key for the CA certificates bundle. */ key: string; /** * AWS region of the S3 bucket. */ region: string; /** * S3 object version ID for the CA certificates bundle. */ version?: string; } interface TrustStoreTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface VpcOriginTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface VpcOriginVpcOriginEndpointConfig { /** * The VPC origin ARN. */ arn: string; /** * The HTTP port for the CloudFront VPC origin endpoint configuration. */ httpPort: number; /** * The HTTPS port for the CloudFront VPC origin endpoint configuration. */ httpsPort: number; /** * The name of the CloudFront VPC origin endpoint configuration. */ name: string; /** * The origin protocol policy for the CloudFront VPC origin endpoint configuration. */ originProtocolPolicy: string; /** * A complex type that contains information about the SSL/TLS protocols that CloudFront can use when establishing an HTTPS connection with your origin. */ originSslProtocols: outputs.cloudfront.VpcOriginVpcOriginEndpointConfigOriginSslProtocols; } interface VpcOriginVpcOriginEndpointConfigOriginSslProtocols { items: string[]; quantity: number; } } export declare namespace cloudhsmv2 { interface ClusterClusterCertificate { /** * The HSM hardware certificate issued (signed) by AWS CloudHSM. */ awsHardwareCertificate: string; /** * The cluster certificate issued (signed) by the issuing certificate authority (CA) of the cluster's owner. */ clusterCertificate: string; /** * The certificate signing request (CSR). Available only in `UNINITIALIZED` state after an HSM instance is added to the cluster. */ clusterCsr: string; /** * The HSM certificate issued (signed) by the HSM hardware. */ hsmCertificate: string; /** * The HSM hardware certificate issued (signed) by the hardware manufacturer. */ manufacturerHardwareCertificate: string; } interface GetClusterClusterCertificate { /** * The HSM hardware certificate issued (signed) by AWS CloudHSM. */ awsHardwareCertificate: string; /** * The cluster certificate issued (signed) by the issuing certificate authority (CA) of the cluster's owner. */ clusterCertificate: string; /** * The certificate signing request (CSR). Available only in UNINITIALIZED state. */ clusterCsr: string; /** * The HSM certificate issued (signed) by the HSM hardware. */ hsmCertificate: string; /** * The HSM hardware certificate issued (signed) by the hardware manufacturer. * The number of available cluster certificates may vary depending on state of the cluster. */ manufacturerHardwareCertificate: string; } } export declare namespace cloudsearch { interface DomainEndpointOptions { /** * Enables or disables the requirement that all requests to the domain arrive over HTTPS. */ enforceHttps: boolean; /** * The minimum required TLS version. See the [AWS documentation](https://docs.aws.amazon.com/cloudsearch/latest/developerguide/API_DomainEndpointOptions.html) for valid values. */ tlsSecurityPolicy: string; } interface DomainIndexField { /** * The analysis scheme you want to use for a `text` field. The analysis scheme specifies the language-specific text processing options that are used during indexing. */ analysisScheme?: string; /** * The default value for the field. This value is used when no value is specified for the field in the document data. */ defaultValue?: string; /** * You can get facet information by enabling this. */ facet?: boolean; /** * You can highlight information. */ highlight?: boolean; /** * A unique name for the field. Field names must begin with a letter and be at least 1 and no more than 64 characters long. The allowed characters are: `a`-`z` (lower-case letters), `0`-`9`, and `_` (underscore). The name `score` is reserved and cannot be used as a field name. */ name: string; /** * You can enable returning the value of all searchable fields. */ return?: boolean; /** * You can set whether this index should be searchable or not. */ search?: boolean; /** * You can enable the property to be sortable. */ sort?: boolean; /** * A comma-separated list of source fields to map to the field. Specifying a source field copies data from one field to another, enabling you to use the same source data in different ways by configuring different options for the fields. */ sourceFields?: string; /** * The field type. Valid values: `date`, `date-array`, `double`, `double-array`, `int`, `int-array`, `literal`, `literal-array`, `text`, `text-array`. */ type: string; } interface DomainScalingParameters { /** * The instance type that you want to preconfigure for your domain. See the [AWS documentation](https://docs.aws.amazon.com/cloudsearch/latest/developerguide/API_ScalingParameters.html) for valid values. */ desiredInstanceType: string; /** * The number of partitions you want to preconfigure for your domain. Only valid when you select `search.2xlarge` as the instance type. */ desiredPartitionCount: number; /** * The number of replicas you want to preconfigure for each index partition. */ desiredReplicationCount: number; } } export declare namespace cloudtrail { interface EventDataStoreAdvancedEventSelector { /** * Specifies the selector statements in an advanced event selector. Fields documented below. */ fieldSelectors: outputs.cloudtrail.EventDataStoreAdvancedEventSelectorFieldSelector[]; /** * Specifies the name of the advanced event selector. */ name: string; } interface EventDataStoreAdvancedEventSelectorFieldSelector { /** * A list of values that includes events that match the last few characters of the event record field specified as the value of `field`. */ endsWiths: string[]; /** * A list of values that includes events that match the exact value of the event record field specified as the value of `field`. This is the only valid operator that you can use with the `readOnly`, `eventCategory`, and `resources.type` fields. */ equals: string[]; /** * Specifies a field in an event record on which to filter events to be logged. You can specify only the following values: `readOnly`, `eventSource`, `eventName`, `eventCategory`, `resources.type`, `resources.ARN`. */ field: string; /** * A list of values that excludes events that match the last few characters of the event record field specified as the value of `field`. */ notEndsWiths: string[]; /** * A list of values that excludes events that match the exact value of the event record field specified as the value of `field`. */ notEquals: string[]; /** * A list of values that excludes events that match the first few characters of the event record field specified as the value of `field`. */ notStartsWiths: string[]; /** * A list of values that includes events that match the first few characters of the event record field specified as the value of `field`. */ startsWiths: string[]; } interface TrailAdvancedEventSelector { /** * Specifies the selector statements in an advanced event selector. Fields documented below. */ fieldSelectors: outputs.cloudtrail.TrailAdvancedEventSelectorFieldSelector[]; /** * Name of the trail. */ name?: string; } interface TrailAdvancedEventSelectorFieldSelector { /** * A list of values that includes events that match the last few characters of the event record field specified as the value of `field`. */ endsWiths?: string[]; /** * A list of values that includes events that match the exact value of the event record field specified as the value of `field`. This is the only valid operator that you can use with the `readOnly`, `eventCategory`, and `resources.type` fields. */ equals?: string[]; /** * Field in an event record on which to filter events to be logged. You can specify only the following values: `readOnly`, `eventSource`, `eventName`, `eventCategory`, `resources.type`, `resources.ARN`. */ field: string; /** * A list of values that excludes events that match the last few characters of the event record field specified as the value of `field`. */ notEndsWiths?: string[]; /** * A list of values that excludes events that match the exact value of the event record field specified as the value of `field`. */ notEquals?: string[]; /** * A list of values that excludes events that match the first few characters of the event record field specified as the value of `field`. */ notStartsWiths?: string[]; /** * A list of values that includes events that match the first few characters of the event record field specified as the value of `field`. */ startsWiths?: string[]; } interface TrailEventSelector { /** * Configuration block for data events. See details below. */ dataResources?: outputs.cloudtrail.TrailEventSelectorDataResource[]; /** * A set of event sources to exclude. Valid values include: `kms.amazonaws.com` and `rdsdata.amazonaws.com`. `includeManagementEvents` must be set to`true` to allow this. */ excludeManagementEventSources?: string[]; /** * Whether to include management events for your trail. Defaults to `true`. */ includeManagementEvents?: boolean; /** * Type of events to log. Valid values are `ReadOnly`, `WriteOnly`, `All`. Default value is `All`. */ readWriteType?: string; } interface TrailEventSelectorDataResource { /** * Resource type in which you want to log data events. You can specify only the following value: "AWS::S3::Object", "AWS::Lambda::Function" and "AWS::DynamoDB::Table". */ type: string; /** * List of ARN strings or partial ARN strings to specify selectors for data audit events over data resources. ARN list is specific to single-valued `type`. For example, `arn:aws:s3:::/` for all objects in a bucket, `arn:aws:s3:::/key` for specific objects, `arn:aws:lambda` for all lambda events within an account, `arn:aws:lambda:::function:` for a specific Lambda function, `arn:aws:dynamodb` for all DDB events for all tables within an account, or `arn:aws:dynamodb:::table/` for a specific DynamoDB table. */ values: string[]; } interface TrailInsightSelector { /** * Type of insights to log on a trail. Valid values are: `ApiCallRateInsight` and `ApiErrorRateInsight`. */ insightType: string; } } export declare namespace cloudwatch { interface AlarmMuteRuleMuteTargets { /** * List of alarm names to mute. */ alarmNames: string[]; } interface AlarmMuteRuleRule { /** * Schedule for the mute rule. See `schedule` block below for details. */ schedule?: outputs.cloudwatch.AlarmMuteRuleRuleSchedule; } interface AlarmMuteRuleRuleSchedule { /** * Duration of the mute period in [ISO 8601 duration format](https://en.wikipedia.org/wiki/ISO_8601#Durations) (e.g., `PT4H` for 4 hours). */ duration: string; /** * Schedule expression. Supports `cron()` and `at()` formats. For example, `cron(0 2 * * *)` for daily at 2:00 AM or `at(2026-01-01T00:00)` for a one-time mute. See [Defining alarm mute rules](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/alarm-mute-rules.html#defining-alarm-mute-rules) for details. */ expression: string; /** * Timezone for the schedule expression (e.g., `Asia/Tokyo`). Defaults to UTC. */ timezone: string; } interface CompositeAlarmActionsSuppressor { /** * Can be an AlarmName or an ARN from an existing alarm. */ alarm: string; /** * The maximum time in seconds that the composite alarm waits after suppressor alarm goes out of the `ALARM` state. After this time, the composite alarm performs its actions. */ extensionPeriod: number; /** * The maximum time in seconds that the composite alarm waits for the suppressor alarm to go into the `ALARM` state. After this time, the composite alarm performs its actions. */ waitPeriod: number; } interface EventBusDeadLetterConfig { /** * The ARN of the SQS queue specified as the target for the dead-letter queue. */ arn?: string; } interface EventBusLogConfig { /** * Whether EventBridge include detailed event information in the records it generates. Valid values are `NONE` and `FULL`. */ includeDetail?: string; /** * Level of logging detail to include. Valid values are `OFF`, `ERROR`, `INFO`, and `TRACE`. */ level?: string; } interface EventConnectionAuthParameters { /** * Parameters used for API_KEY authorization. An API key to include in the header for each authentication request. A maximum of 1 are allowed. Conflicts with `basic` and `oauth`. Documented below. */ apiKey?: outputs.cloudwatch.EventConnectionAuthParametersApiKey; /** * Parameters used for BASIC authorization. A maximum of 1 are allowed. Conflicts with `apiKey` and `oauth`. Documented below. */ basic?: outputs.cloudwatch.EventConnectionAuthParametersBasic; /** * Parameters used for `oauth` with private API. Documented below. */ connectivityParameters?: outputs.cloudwatch.EventConnectionAuthParametersConnectivityParameters; /** * Invocation Http Parameters are additional credentials used to sign each Invocation of the ApiDestination created from this Connection. If the ApiDestination Rule Target has additional HttpParameters, the values will be merged together, with the Connection Invocation Http Parameters taking precedence. Secret values are stored and managed by AWS Secrets Manager. A maximum of 1 are allowed. Documented below. */ invocationHttpParameters?: outputs.cloudwatch.EventConnectionAuthParametersInvocationHttpParameters; /** * Parameters used for OAUTH_CLIENT_CREDENTIALS authorization. A maximum of 1 are allowed. Conflicts with `basic` and `apiKey`. Documented below. */ oauth?: outputs.cloudwatch.EventConnectionAuthParametersOauth; } interface EventConnectionAuthParametersApiKey { /** * Header Name. */ key: string; /** * Header Value. Created and stored in AWS Secrets Manager. */ value: string; } interface EventConnectionAuthParametersBasic { /** * A password for the authorization. Created and stored in AWS Secrets Manager. */ password: string; /** * A username for the authorization. */ username: string; } interface EventConnectionAuthParametersConnectivityParameters { /** * The parameters for EventBridge to use when invoking the authentication endpoint. Documented below. */ resourceParameters: outputs.cloudwatch.EventConnectionAuthParametersConnectivityParametersResourceParameters; } interface EventConnectionAuthParametersConnectivityParametersResourceParameters { resourceAssociationArn: string; /** * ARN of the Amazon VPC Lattice resource configuration for the resource endpoint. */ resourceConfigurationArn: string; } interface EventConnectionAuthParametersInvocationHttpParameters { /** * Contains additional body string parameters for the connection. You can include up to 100 additional body string parameters per request. Each additional parameter counts towards the event payload size, which cannot exceed 64 KB. Each parameter can contain the following: */ bodies?: outputs.cloudwatch.EventConnectionAuthParametersInvocationHttpParametersBody[]; /** * Contains additional header parameters for the connection. You can include up to 100 additional body string parameters per request. Each additional parameter counts towards the event payload size, which cannot exceed 64 KB. Each parameter can contain the following: */ headers?: outputs.cloudwatch.EventConnectionAuthParametersInvocationHttpParametersHeader[]; /** * Contains additional query string parameters for the connection. You can include up to 100 additional body string parameters per request. Each additional parameter counts towards the event payload size, which cannot exceed 64 KB. Each parameter can contain the following: */ queryStrings?: outputs.cloudwatch.EventConnectionAuthParametersInvocationHttpParametersQueryString[]; } interface EventConnectionAuthParametersInvocationHttpParametersBody { /** * Specified whether the value is secret. */ isValueSecret?: boolean; /** * The key for the parameter. */ key?: string; /** * The value associated with the key. Created and stored in AWS Secrets Manager if is secret. */ value?: string; } interface EventConnectionAuthParametersInvocationHttpParametersHeader { /** * Specified whether the value is secret. */ isValueSecret?: boolean; /** * The key for the parameter. */ key?: string; /** * The value associated with the key. Created and stored in AWS Secrets Manager if is secret. */ value?: string; } interface EventConnectionAuthParametersInvocationHttpParametersQueryString { /** * Specified whether the value is secret. */ isValueSecret?: boolean; /** * The key for the parameter. */ key?: string; /** * The value associated with the key. Created and stored in AWS Secrets Manager if is secret. */ value?: string; } interface EventConnectionAuthParametersOauth { /** * The URL to the authorization endpoint. */ authorizationEndpoint: string; /** * Contains the client parameters for OAuth authorization. Contains the following two parameters. */ clientParameters?: outputs.cloudwatch.EventConnectionAuthParametersOauthClientParameters; /** * A password for the authorization. Created and stored in AWS Secrets Manager. */ httpMethod: string; /** * OAuth Http Parameters are additional credentials used to sign the request to the authorization endpoint to exchange the OAuth Client information for an access token. Secret values are stored and managed by AWS Secrets Manager. A maximum of 1 are allowed. Documented below. */ oauthHttpParameters: outputs.cloudwatch.EventConnectionAuthParametersOauthOauthHttpParameters; } interface EventConnectionAuthParametersOauthClientParameters { /** * The client ID for the credentials to use for authorization. Created and stored in AWS Secrets Manager. */ clientId: string; /** * The client secret for the credentials to use for authorization. Created and stored in AWS Secrets Manager. */ clientSecret: string; } interface EventConnectionAuthParametersOauthOauthHttpParameters { /** * Contains additional body string parameters for the connection. You can include up to 100 additional body string parameters per request. Each additional parameter counts towards the event payload size, which cannot exceed 64 KB. Each parameter can contain the following: */ bodies?: outputs.cloudwatch.EventConnectionAuthParametersOauthOauthHttpParametersBody[]; /** * Contains additional header parameters for the connection. You can include up to 100 additional body string parameters per request. Each additional parameter counts towards the event payload size, which cannot exceed 64 KB. Each parameter can contain the following: */ headers?: outputs.cloudwatch.EventConnectionAuthParametersOauthOauthHttpParametersHeader[]; /** * Contains additional query string parameters for the connection. You can include up to 100 additional body string parameters per request. Each additional parameter counts towards the event payload size, which cannot exceed 64 KB. Each parameter can contain the following: */ queryStrings?: outputs.cloudwatch.EventConnectionAuthParametersOauthOauthHttpParametersQueryString[]; } interface EventConnectionAuthParametersOauthOauthHttpParametersBody { /** * Specified whether the value is secret. */ isValueSecret?: boolean; /** * The key for the parameter. */ key?: string; /** * The value associated with the key. Created and stored in AWS Secrets Manager if is secret. */ value?: string; } interface EventConnectionAuthParametersOauthOauthHttpParametersHeader { /** * Specified whether the value is secret. */ isValueSecret?: boolean; /** * The key for the parameter. */ key?: string; /** * The value associated with the key. Created and stored in AWS Secrets Manager if is secret. */ value?: string; } interface EventConnectionAuthParametersOauthOauthHttpParametersQueryString { /** * Specified whether the value is secret. */ isValueSecret?: boolean; /** * The key for the parameter. */ key?: string; /** * The value associated with the key. Created and stored in AWS Secrets Manager if is secret. */ value?: string; } interface EventConnectionInvocationConnectivityParameters { /** * The parameters for EventBridge to use when invoking the resource endpoint. Documented below. */ resourceParameters: outputs.cloudwatch.EventConnectionInvocationConnectivityParametersResourceParameters; } interface EventConnectionInvocationConnectivityParametersResourceParameters { resourceAssociationArn: string; /** * ARN of the Amazon VPC Lattice resource configuration for the resource endpoint. */ resourceConfigurationArn: string; } interface EventEndpointEventBus { /** * The ARN of the event bus the endpoint is associated with. */ eventBusArn: string; } interface EventEndpointReplicationConfig { /** * The state of event replication. Valid values: `ENABLED`, `DISABLED`. The default state is `ENABLED`, which means you must supply a `roleArn`. If you don't have a `roleArn` or you don't want event replication enabled, set `state` to `DISABLED`. */ state?: string; } interface EventEndpointRoutingConfig { /** * Parameters used for failover. This includes what triggers failover and what happens when it's triggered. Documented below. */ failoverConfig: outputs.cloudwatch.EventEndpointRoutingConfigFailoverConfig; } interface EventEndpointRoutingConfigFailoverConfig { /** * Parameters used for the primary Region. Documented below. */ primary: outputs.cloudwatch.EventEndpointRoutingConfigFailoverConfigPrimary; /** * Parameters used for the secondary Region, the Region that events are routed to when failover is triggered or event replication is enabled. Documented below. */ secondary: outputs.cloudwatch.EventEndpointRoutingConfigFailoverConfigSecondary; } interface EventEndpointRoutingConfigFailoverConfigPrimary { /** * The ARN of the health check used by the endpoint to determine whether failover is triggered. */ healthCheck?: string; } interface EventEndpointRoutingConfigFailoverConfigSecondary { /** * The name of the secondary Region. */ route?: string; } interface EventPermissionCondition { /** * Key for the condition. Valid values: `aws:PrincipalOrgID`. */ key: string; /** * Type of condition. Value values: `StringEquals`. */ type: string; /** * Value for the key. */ value: string; } interface EventTargetAppsyncTarget { /** * Contains the GraphQL mutation to be parsed and executed. */ graphqlOperation?: string; } interface EventTargetBatchTarget { /** * The size of the array, if this is an array batch job. Valid values are integers between 2 and 10,000. */ arraySize?: number; /** * The number of times to attempt to retry, if the job fails. Valid values are 1 to 10. */ jobAttempts?: number; /** * The ARN or name of the job definition to use if the event target is an AWS Batch job. This job definition must already exist. */ jobDefinition: string; /** * The name to use for this execution of the job, if the target is an AWS Batch job. */ jobName: string; } interface EventTargetDeadLetterConfig { /** * ARN of the SQS queue specified as the target for the dead-letter queue. */ arn?: string; } interface EventTargetEcsTarget { /** * The capacity provider strategy to use for the task. If a `capacityProviderStrategy` specified, the `launchType` parameter must be omitted. If no `capacityProviderStrategy` or `launchType` is specified, the default capacity provider strategy for the cluster is used. Can be one or more. See below. */ capacityProviderStrategies?: outputs.cloudwatch.EventTargetEcsTargetCapacityProviderStrategy[]; /** * Specifies whether to enable Amazon ECS managed tags for the task. */ enableEcsManagedTags?: boolean; /** * Whether or not to enable the execute command functionality for the containers in this task. If true, this enables execute command functionality on all containers in the task. */ enableExecuteCommand?: boolean; /** * Specifies an ECS task group for the task. The maximum length is 255 characters. */ group?: string; /** * Specifies the launch type on which your task is running. The launch type that you specify here must match one of the launch type (compatibilities) of the target task. Valid values include: `EC2`, `EXTERNAL`, or `FARGATE`. */ launchType?: string; /** * Use this if the ECS task uses the awsvpc network mode. This specifies the VPC subnets and security groups associated with the task, and whether a public IP address is to be used. Required if `launchType` is `FARGATE` because the awsvpc mode is required for Fargate tasks. */ networkConfiguration?: outputs.cloudwatch.EventTargetEcsTargetNetworkConfiguration; /** * An array of placement strategy objects to use for the task. You can specify a maximum of five strategy rules per task. */ orderedPlacementStrategies?: outputs.cloudwatch.EventTargetEcsTargetOrderedPlacementStrategy[]; /** * An array of placement constraint objects to use for the task. You can specify up to 10 constraints per task (including constraints in the task definition and those specified at runtime). See Below. */ placementConstraints?: outputs.cloudwatch.EventTargetEcsTargetPlacementConstraint[]; /** * Specifies the platform version for the task. Specify only the numeric portion of the platform version, such as `1.1.0`. This is used only if LaunchType is FARGATE. For more information about valid platform versions, see [AWS Fargate Platform Versions](http://docs.aws.amazon.com/AmazonECS/latest/developerguide/platform_versions.html). */ platformVersion?: string; /** * Specifies whether to propagate the tags from the task definition to the task. If no value is specified, the tags are not propagated. Tags can only be propagated to the task during task creation. The only valid value is: `TASK_DEFINITION`. */ propagateTags?: string; /** * A map of tags to assign to ecs resources. */ tags?: { [key: string]: string; }; /** * The number of tasks to create based on the TaskDefinition. Defaults to `1`. */ taskCount?: number; /** * The ARN of the task definition to use if the event target is an Amazon ECS cluster. */ taskDefinitionArn: string; } interface EventTargetEcsTargetCapacityProviderStrategy { /** * The base value designates how many tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. Defaults to `0`. */ base?: number; /** * Short name of the capacity provider. */ capacityProvider: string; /** * The weight value designates the relative percentage of the total number of tasks launched that should use the specified capacity provider. The weight value is taken into consideration after the base value, if defined, is satisfied. */ weight?: number; } interface EventTargetEcsTargetNetworkConfiguration { /** * Assign a public IP address to the ENI (Fargate launch type only). Valid values are `true` or `false`. Defaults to `false`. * * For more information, see [Task Networking](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-networking.html) */ assignPublicIp?: boolean; /** * The security groups associated with the task or service. If you do not specify a security group, the default security group for the VPC is used. */ securityGroups?: string[]; /** * The subnets associated with the task or service. */ subnets: string[]; } interface EventTargetEcsTargetOrderedPlacementStrategy { /** * The field to apply the placement strategy against. For the `spread` placement strategy, valid values are `instanceId` (or `host`, which has the same effect), or any platform or custom attribute that is applied to a container instance, such as `attribute:ecs.availability-zone`. For the `binpack` placement strategy, valid values are `cpu` and `memory`. For the `random` placement strategy, this field is not used. For more information, see [Amazon ECS task placement strategies](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-placement-strategies.html). */ field?: string; /** * Type of placement strategy. The only valid values at this time are `binpack`, `random` and `spread`. */ type: string; } interface EventTargetEcsTargetPlacementConstraint { /** * Cluster Query Language expression to apply to the constraint. Does not need to be specified for the `distinctInstance` type. For more information, see [Cluster Query Language in the Amazon EC2 Container Service Developer Guide](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/cluster-query-language.html). */ expression?: string; /** * Type of constraint. The only valid values at this time are `memberOf` and `distinctInstance`. */ type: string; } interface EventTargetHttpTarget { /** * Enables you to specify HTTP headers to add to the request. */ headerParameters?: { [key: string]: string; }; /** * The list of values that correspond sequentially to any path variables in your endpoint ARN (for example `arn:aws:execute-api:us-east-1:123456:myapi/*/POST/pets/*`). */ pathParameterValues?: string[]; /** * Represents keys/values of query string parameters that are appended to the invoked endpoint. */ queryStringParameters?: { [key: string]: string; }; } interface EventTargetInputTransformer { /** * Key value pairs specified in the form of JSONPath (for example, time = $.time) * * You can have as many as 100 key-value pairs. * * You must use JSON dot notation, not bracket notation. * * The keys can't start with "AWS". */ inputPaths?: { [key: string]: string; }; /** * Template to customize data sent to the target. Must be valid JSON. To send a string value, the string value must include double quotes. */ inputTemplate: string; } interface EventTargetKinesisTarget { /** * The JSON path to be extracted from the event and used as the partition key. */ partitionKeyPath?: string; } interface EventTargetRedshiftTarget { /** * The name of the database. */ database: string; /** * The database user name. */ dbUser?: string; /** * The name or ARN of the secret that enables access to the database. */ secretsManagerArn?: string; /** * The SQL statement text to run. */ sql?: string; /** * The name of the SQL statement. */ statementName?: string; /** * Indicates whether to send an event back to EventBridge after the SQL statement runs. */ withEvent?: boolean; } interface EventTargetRetryPolicy { /** * The age in seconds to continue to make retry attempts. */ maximumEventAgeInSeconds?: number; /** * maximum number of retry attempts to make before the request fails */ maximumRetryAttempts?: number; } interface EventTargetRunCommandTarget { /** * Can be either `tag:tag-key` or `InstanceIds`. */ key: string; /** * If Key is `tag:tag-key`, Values is a list of tag values. If Key is `InstanceIds`, Values is a list of Amazon EC2 instance IDs. */ values: string[]; } interface EventTargetSagemakerPipelineTarget { /** * List of Parameter names and values for SageMaker AI Model Building Pipeline execution. */ pipelineParameterLists?: outputs.cloudwatch.EventTargetSagemakerPipelineTargetPipelineParameterList[]; } interface EventTargetSagemakerPipelineTargetPipelineParameterList { /** * Name of parameter to start execution of a SageMaker AI Model Building Pipeline. */ name: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. */ value: string; } interface EventTargetSqsTarget { /** * The FIFO message group ID to use as the target. */ messageGroupId?: string; } interface GetContributorManagedInsightRulesManagedRule { /** * ARN of an Amazon Web Services resource that has managed Contributor Insights rules. */ resourceArn: string; /** * Describes the state of a managed rule. If the rule is enabled, it contains information about the Contributor Insights rule that contains information about the related Amazon Web Services resource. See `ruleState reference` below for details. */ ruleStates: outputs.cloudwatch.GetContributorManagedInsightRulesManagedRuleRuleState[]; /** * Template name for the managed rule. Used to enable managed rules using `PutManagedInsightRules`. */ templateName: string; } interface GetContributorManagedInsightRulesManagedRuleRuleState { /** * Name of the Contributor Insights rule that contains data for the specified Amazon Web Services resource. */ ruleName: string; /** * Indicates whether the rule is enabled or disabled. */ state: string; } interface GetEventBusDeadLetterConfig { /** * The ARN of the SQS queue specified as the target for the dead-letter queue. */ arn: string; } interface GetEventBusLogConfig { /** * Whether EventBridge include detailed event information in the records it generates. */ includeDetail: string; /** * Level of logging detail to include. */ level: string; } interface GetEventBusesEventBus { /** * The ARN of the event bus. */ arn: string; /** * The time the event bus was created. */ creationTime: string; /** * The event bus description. */ description: string; /** * The time the event bus was last modified. */ lastModifiedTime: string; /** * The name of the event bus. */ name: string; /** * The permissions policy of the event bus, describing which other AWS accounts can write events to this event bus. */ policy: string; } interface GetLogDataProtectionPolicyDocumentConfiguration { /** * Configures custom regular expressions to detect sensitive data. Read more in [Custom data identifiers](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CWL-custom-data-identifiers.html). */ customDataIdentifiers?: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentConfigurationCustomDataIdentifier[]; } interface GetLogDataProtectionPolicyDocumentConfigurationCustomDataIdentifier { /** * Name of the custom data idenfitier */ name: string; /** * Regular expression to match sensitive data */ regex: string; } interface GetLogDataProtectionPolicyDocumentStatement { /** * Set of at least 1 sensitive data identifiers that you want to mask. Read more in [Types of data that you can protect](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/protect-sensitive-log-data-types.html). */ dataIdentifiers: string[]; /** * Configures the data protection operation applied by this statement. */ operation: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperation; /** * Name of this statement. */ sid?: string; } interface GetLogDataProtectionPolicyDocumentStatementOperation { /** * Configures the detection of sensitive data. */ audit?: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationAudit; /** * Configures the masking of sensitive data. * * > Every policy statement must specify exactly one operation. */ deidentify?: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationDeidentify; } interface GetLogDataProtectionPolicyDocumentStatementOperationAudit { /** * Configures destinations to send audit findings to. */ findingsDestination: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestination; } interface GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestination { /** * Configures CloudWatch Logs as a findings destination. */ cloudwatchLogs?: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestinationCloudwatchLogs; /** * Configures Kinesis Firehose as a findings destination. */ firehose?: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestinationFirehose; /** * Configures S3 as a findings destination. */ s3?: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestinationS3; } interface GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestinationCloudwatchLogs { /** * Name of the CloudWatch Log Group to send findings to. */ logGroup: string; } interface GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestinationFirehose { /** * Name of the Kinesis Firehose Delivery Stream to send findings to. */ deliveryStream: string; } interface GetLogDataProtectionPolicyDocumentStatementOperationAuditFindingsDestinationS3 { /** * Name of the S3 Bucket to send findings to. */ bucket: string; } interface GetLogDataProtectionPolicyDocumentStatementOperationDeidentify { /** * An empty object that configures masking. */ maskConfig: outputs.cloudwatch.GetLogDataProtectionPolicyDocumentStatementOperationDeidentifyMaskConfig; } interface GetLogDataProtectionPolicyDocumentStatementOperationDeidentifyMaskConfig { } interface InternetMonitorHealthEventsConfig { /** * The health event threshold percentage set for availability scores. */ availabilityScoreThreshold?: number; /** * The health event threshold percentage set for performance scores. */ performanceScoreThreshold?: number; } interface InternetMonitorInternetMeasurementsLogDelivery { s3Config?: outputs.cloudwatch.InternetMonitorInternetMeasurementsLogDeliveryS3Config; } interface InternetMonitorInternetMeasurementsLogDeliveryS3Config { bucketName: string; bucketPrefix?: string; logDeliveryStatus?: string; } interface LogDeliveryDestinationDeliveryDestinationConfiguration { /** * The ARN of the AWS destination that this delivery destination represents. Required when `deliveryDestinationConfiguration` is specified. */ destinationResourceArn?: string; } interface LogDeliveryS3DeliveryConfiguration { /** * This parameter causes the S3 objects that contain delivered logs to use a prefix structure that allows for integration with Apache Hive. */ enableHiveCompatiblePath: boolean; /** * This string allows re-configuring the S3 object prefix to contain either static or variable sections. The valid variables to use in the suffix path will vary by each log source. **Note:** AWS automatically prepends account and service-specific prefixes (e.g., `AWSLogs/{account-id}/CloudFront/` for CloudFront sources) to the configured value. Specify only your custom suffix path without these AWS-managed prefixes. */ suffixPath: string; } interface LogMetricFilterMetricTransformation { /** * The value to emit when a filter pattern does not match a log event. Conflicts with `dimensions`. */ defaultValue?: string; /** * Map of fields to use as dimensions for the metric. Up to 3 dimensions are allowed. Conflicts with `defaultValue`. */ dimensions?: { [key: string]: string; }; /** * The name of the CloudWatch metric to which the monitored log information should be published (e.g., `ErrorCount`) */ name: string; /** * The destination namespace of the CloudWatch metric. */ namespace: string; /** * The unit to assign to the metric. If you omit this, the unit is set as `None`. */ unit?: string; /** * What to publish to the metric. For example, if you're counting the occurrences of a particular term like "Error", the value will be "1" for each occurrence. If you're counting the bytes transferred the published value will be the value in the log event. */ value: string; } interface LogS3TableIntegrationSourceDataSource { /** * Name of the data source. Use `"*"` to match all sources. */ name: string; /** * Type of the data source. Use `"*"` to match all types. */ type: string; } interface LogS3TableIntegrationSourceTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface LogTransformerTransformerConfig { /** * Adds new key-value pairs to the log event. See `addKeys` below for details. */ addKeys?: outputs.cloudwatch.LogTransformerTransformerConfigAddKeys; /** * Copies values within a log event. See `copyValue` below for details. */ copyValue?: outputs.cloudwatch.LogTransformerTransformerConfigCopyValue; /** * Parses comma-separated values (CSV) from the log events into columns. See `csv` below for details. */ csvs?: outputs.cloudwatch.LogTransformerTransformerConfigCsv[]; /** * Converts a datetime string into a format that you specify. See `dateTimeConverter` below for details. */ dateTimeConverters?: outputs.cloudwatch.LogTransformerTransformerConfigDateTimeConverter[]; /** * Deletes entry from a log event. See `deleteKeys` below for details. */ deleteKeys?: outputs.cloudwatch.LogTransformerTransformerConfigDeleteKey[]; /** * Parses and structures unstructured data by using pattern matching. See `grok` below for details. */ grok?: outputs.cloudwatch.LogTransformerTransformerConfigGrok; /** * Converts list of objects that contain key fields into a map of target keys. See `listToMap` below for details. */ listToMaps?: outputs.cloudwatch.LogTransformerTransformerConfigListToMap[]; /** * Converts a string to lowercase. See `lowerCaseString` below for details. */ lowerCaseStrings?: outputs.cloudwatch.LogTransformerTransformerConfigLowerCaseString[]; /** * Moves a key from one field to another. See `moveKeys` below for details. */ moveKeys?: outputs.cloudwatch.LogTransformerTransformerConfigMoveKey[]; /** * Parses CloudFront vended logs, extracts fields, and converts them into JSON format. See `parseCloudfront` below for details. */ parseCloudfront?: outputs.cloudwatch.LogTransformerTransformerConfigParseCloudfront; /** * Parses log events that are in JSON format. See `parseJson` below for details. */ parseJsons?: outputs.cloudwatch.LogTransformerTransformerConfigParseJson[]; /** * Parses a specified field in the original log event into key-value pairs. See `parseKeyValue` below for details. */ parseKeyValues?: outputs.cloudwatch.LogTransformerTransformerConfigParseKeyValue[]; /** * Parses RDS for PostgreSQL vended logs, extracts fields, and and convert them into a JSON format. See `parsePostgres` below for details. */ parsePostgres?: outputs.cloudwatch.LogTransformerTransformerConfigParsePostgres; /** * Parses Route 53 vended logs, extracts fields, and converts them into JSON format. See `parseRoute53` below for details. */ parseRoute53?: outputs.cloudwatch.LogTransformerTransformerConfigParseRoute53; /** * Parses logs events and converts them into Open Cybersecurity Schema Framework (OCSF) events. See `parseToOcsf` below for details. */ parseToOcsf?: outputs.cloudwatch.LogTransformerTransformerConfigParseToOcsf; /** * Parses Amazon VPC vended logs, extracts fields, and converts them into JSON format. See `parseVpc` below for details. */ parseVpc?: outputs.cloudwatch.LogTransformerTransformerConfigParseVpc; /** * Parses AWS WAF vended logs, extracts fields, and converts them into JSON format. See `parseWaf` below for details. */ parseWaf?: outputs.cloudwatch.LogTransformerTransformerConfigParseWaf; /** * Renames keys in a log event. See `renameKeys` below for details. */ renameKeys?: outputs.cloudwatch.LogTransformerTransformerConfigRenameKey[]; /** * Splits a field into an array of strings using a delimiting character. See `splitString` below for details. */ splitStrings?: outputs.cloudwatch.LogTransformerTransformerConfigSplitString[]; /** * Matches a key’s value against a regular expression and replaces all matches with a replacement string. See `substituteString` below for details. */ substituteStrings?: outputs.cloudwatch.LogTransformerTransformerConfigSubstituteString[]; /** * Removes leading and trailing whitespace from a string. See `trimString` below for details. */ trimStrings?: outputs.cloudwatch.LogTransformerTransformerConfigTrimString[]; /** * Converts a value type associated with the specified key to the specified type. See `typeConverter` below for details. */ typeConverters?: outputs.cloudwatch.LogTransformerTransformerConfigTypeConverter[]; /** * Converts a string to uppercase. See `upperCaseString` below for details. */ upperCaseStrings?: outputs.cloudwatch.LogTransformerTransformerConfigUpperCaseString[]; } interface LogTransformerTransformerConfigAddKeys { /** * Objects containing the information about the keys to add to the log event. You must include at least one entry, and five at most. See `addKeys` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigAddKeysEntry[]; } interface LogTransformerTransformerConfigAddKeysEntry { /** * Specifies the key with the value that will be converted to a different type. */ key: string; /** * Specifies whether to overwrite the value if the destination key already exists. Defaults to `false`. * * `renameTo` - (Required) Specifies the new name of the key. */ overwriteIfExists: boolean; /** * Specifies the value of the new entry to be added to the log event. */ value: string; } interface LogTransformerTransformerConfigCopyValue { /** * Objects containing the information about the values to copy to the log event. You must include at least one entry, and five at most. See `copyValue` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigCopyValueEntry[]; } interface LogTransformerTransformerConfigCopyValueEntry { /** * Specifies whether to overwrite the value if the destination key already exists. Defaults to `false`. * * `renameTo` - (Required) Specifies the new name of the key. */ overwriteIfExists: boolean; /** * Specifies the key to modify. */ source: string; /** * Specifies the key to move to. */ target: string; } interface LogTransformerTransformerConfigCsv { /** * Specifies the names to use for the columns in the transformed log event. If not specified, default column names (`[column_1, column2 ...]`) are used. */ columns: string[]; /** * Specifies the character used to separate each column in the original comma-separated value log event. Defaults to the comma `,` character. */ delimiter: string; /** * Specifies the character used as a text qualifier for a single column of data. Defaults to the double quotation mark `"` character. */ quoteCharacter: string; /** * Specifies the path to the field in the log event that has the comma separated values to be parsed. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigDateTimeConverter { /** * Specifies the locale of the source field. Defaults to `locale.ROOT`. */ locale: string; /** * Specifies the list of patterns to match against the `source` field. */ matchPatterns: string[]; /** * Specifies the key to apply the date conversion to. */ source: string; /** * Specifies the time zone of the source field. Defaults to `UTC`. */ sourceTimezone: string; /** * Specifies the JSON field to store the result in. */ target: string; /** * Specifies the datetime format to use for the converted data in the target field. Defaults to `yyyy-MM-dd'T'HH:mm:ss.SSS'Z`. */ targetFormat: string; /** * Specifies the time zone of the target field. Defaults to `UTC`. */ targetTimezone: string; } interface LogTransformerTransformerConfigDeleteKey { /** * Specifies the keys to be deleted. */ withKeys: string[]; } interface LogTransformerTransformerConfigGrok { /** * Specifies the grok pattern to match against the log event. */ match: string; /** * Specifies the path to the field in the log event that has the comma separated values to be parsed. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigListToMap { /** * Specifies whether the list will be flattened into single items. Defaults to `false`. */ flatten: boolean; /** * Required if `flatten` is set to true. Specifies the element to keep. Allowed values are `first` and `last`. */ flattenedElement: string; /** * Specifies the key of the field to be extracted as keys in the generated map. */ key: string; /** * Specifies the key in the log event that has a list of objects that will be converted to a map. */ source: string; /** * Specifies the key of the field that will hold the generated map. */ target: string; /** * Specifies the values that will be extracted from the source objects and put into the values of the generated map. If omitted, original objects in the source list will be put into the values of the generated map. */ valueKey: string; } interface LogTransformerTransformerConfigLowerCaseString { /** * Specifies the keys of the fields to convert to lowercase. */ withKeys: string[]; } interface LogTransformerTransformerConfigMoveKey { /** * Objects containing the information about the keys to move to the log event. You must include at least one entry, and five at most. See `moveKeys` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigMoveKeyEntry[]; } interface LogTransformerTransformerConfigMoveKeyEntry { /** * Specifies whether to overwrite the value if the destination key already exists. Defaults to `false`. * * `renameTo` - (Required) Specifies the new name of the key. */ overwriteIfExists: boolean; /** * Specifies the key to modify. */ source: string; /** * Specifies the key to move to. */ target: string; } interface LogTransformerTransformerConfigParseCloudfront { /** * Specifies the source field to be parsed. The only allowed value is `@message`. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigParseJson { /** * Specifies the location to put the parsed key value pair into. If omitted, it will be placed under the root node. */ destination: string; /** * Specifies the path to the field in the log event that will be parsed. Defaults to `@message`. */ source: string; } interface LogTransformerTransformerConfigParseKeyValue { /** * Specifies the destination field to put the extracted key-value pairs into. */ destination: string; /** * Specifies the field delimiter string that is used between key-value pairs in the original log events. Defaults to the ampersand `&` character. */ fieldDelimiter: string; /** * Specifies a prefix that will be added to all transformed keys. */ keyPrefix: string; /** * Specifies the delimiter string to use between the key and value in each pair in the transformed log event. Defaults to the equal `=` character. */ keyValueDelimiter: string; /** * Specifies a value to insert into the value field in the result if a key-value pair is not successfully split. */ nonMatchValue: string; /** * Specifies whether to overwrite the value if the destination key already exists. Defaults to `false`. */ overwriteIfExists: boolean; /** * Specifies the path to the field in the log event that will be parsed. Defaults to `@message`. */ source: string; } interface LogTransformerTransformerConfigParsePostgres { /** * Specifies the source field to be parsed. The only allowed value is `@message`. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigParseRoute53 { /** * Specifies the source field to be parsed. The only allowed value is `@message`. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigParseToOcsf { eventSource: string; /** * Specifies the version of the OCSF schema to use for the transformed log events. The only allowed value is `V1.1`. */ ocsfVersion: string; /** * Specifies the source field to be parsed. The only allowed value is `@message`. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigParseVpc { /** * Specifies the source field to be parsed. The only allowed value is `@message`. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigParseWaf { /** * Specifies the source field to be parsed. The only allowed value is `@message`. If omitted, the whole log message is processed. */ source: string; } interface LogTransformerTransformerConfigRenameKey { /** * Objects containing the information about the keys to rename. You must include at least one entry, and five at most. See `renameKeys` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigRenameKeyEntry[]; } interface LogTransformerTransformerConfigRenameKeyEntry { /** * Specifies the key with the value that will be converted to a different type. */ key: string; /** * Specifies whether to overwrite the value if the destination key already exists. Defaults to `false`. * * `renameTo` - (Required) Specifies the new name of the key. */ overwriteIfExists: boolean; renameTo: string; } interface LogTransformerTransformerConfigSplitString { /** * Objects containing the information about the fields to split. You must include at least one entry, and ten at most. See `splitString` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigSplitStringEntry[]; } interface LogTransformerTransformerConfigSplitStringEntry { /** * Specifies the separator characters to split the string entry on. */ delimiter: string; /** * Specifies the key to modify. */ source: string; } interface LogTransformerTransformerConfigSubstituteString { /** * Objects containing the information about the fields to substitute. You must include at least one entry, and ten at most. See `substituteString` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigSubstituteStringEntry[]; } interface LogTransformerTransformerConfigSubstituteStringEntry { /** * Specifies the regular expression string to be replaced. */ from: string; /** * Specifies the key to modify. */ source: string; /** * Specifies the string to be substituted for each match of `from`. */ to: string; } interface LogTransformerTransformerConfigTrimString { /** * Specifies the keys of the fields to trim. */ withKeys: string[]; } interface LogTransformerTransformerConfigTypeConverter { /** * Objects containing the information about the fields to change the type of. You must include at least one entry, and five at most. See `typeConverter` `entry` below for details. */ entries: outputs.cloudwatch.LogTransformerTransformerConfigTypeConverterEntry[]; } interface LogTransformerTransformerConfigTypeConverterEntry { /** * Specifies the key with the value that will be converted to a different type. */ key: string; /** * Specifies the type to convert the field value to. Allowed values are: `integer`, `double`, `string` and `boolean`. */ type: string; } interface LogTransformerTransformerConfigUpperCaseString { /** * Specifies the keys of the fields to convert to uppercase. */ withKeys: string[]; } interface MetricAlarmEvaluationCriteria { /** * The PromQL criteria for the alarm evaluation. */ promqlCriteria: outputs.cloudwatch.MetricAlarmEvaluationCriteriaPromqlCriteria; } interface MetricAlarmEvaluationCriteriaPromqlCriteria { /** * The duration, in seconds, that a contributor must be continuously breaching before it transitions to the ALARM state. Valid range: 0-86400. */ pendingPeriod?: number; /** * The PromQL query that the alarm evaluates. The query must return a result of vector type. Each entry in the vector result represents an alarm contributor. */ query: string; /** * The duration, in seconds, that a contributor must continuously not be breaching before it transitions back to the OK state. Valid range: 0-86400. */ recoveryPeriod?: number; } interface MetricAlarmMetricQuery { /** * The ID of the account where the metrics are located, if this is a cross-account alarm. */ accountId?: string; /** * A Metrics Insights query or a metric math expression to be evaluated on the returned data. * For details about Metrics Insights queries, see [Metrics Insights query components and syntax](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/cloudwatch-metrics-insights-querylanguage) in the AWS documentation. * For details about metric math expressions, see [Metric Math Syntax and Functions](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/using-metric-math.html#metric-math-syntax) in the AWS documentation. */ expression?: string; /** * A short name used to tie this object to the results in the response. If you are performing math expressions on this set of data, this name represents that data and can serve as a variable in the mathematical expression. The valid characters are letters, numbers, and underscore. The first character must be a lowercase letter. */ id: string; /** * A human-readable label for this metric or expression. This is especially useful if this is an expression, so that you know what the value represents. */ label?: string; /** * The metric to be returned, along with statistics, period, and units. Use this parameter only if this object is retrieving a metric and not performing a math expression on returned data. */ metric?: outputs.cloudwatch.MetricAlarmMetricQueryMetric; /** * Granularity in seconds of returned data points. * For metrics with regular resolution, valid values are any multiple of `60`. * For high-resolution metrics, valid values are `1`, `5`, `10`, `20`, `30`, or any multiple of `60`. */ period?: number; /** * Specify exactly one `metricQuery` to be `true` to use that `metricQuery` result as the alarm. * * > **NOTE:** You must specify either `metric` or `expression`. Not both. */ returnData?: boolean; } interface MetricAlarmMetricQueryMetric { /** * The dimensions for this metric. For the list of available dimensions see the AWS documentation [here](http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/CW_Support_For_AWS.html). */ dimensions?: { [key: string]: string; }; /** * The name for this metric. * See docs for [supported metrics](https://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/CW_Support_For_AWS.html). */ metricName: string; /** * The namespace for this metric. See docs for the [list of namespaces](https://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/aws-namespaces.html). * See docs for [supported metrics](https://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/CW_Support_For_AWS.html). */ namespace?: string; /** * Granularity in seconds of returned data points. * For metrics with regular resolution, valid values are any multiple of `60`. * For high-resolution metrics, valid values are `1`, `5`, `10`, `20`, `30`, or any multiple of `60`. */ period: number; /** * The statistic to apply to this metric. * See docs for [supported statistics](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Statistics-definitions.html). */ stat: string; /** * The unit for this metric. */ unit?: string; } interface MetricAlarmWarmUpConfiguration { /** * Whether to wait for the full warm-up period before evaluation begins, even if metric data arrives earlier. When `false`, the warm-up period ends early as soon as the alarm has enough data to fill its evaluation window. Defaults to `false`. * * > **Note:** The warm-up period applies once, when the alarm is created. Changing the warm-up configuration after the warm-up period ends does not start a new warm-up period. See [Alarm warm-up periods](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/alarm-warm-up.html) in the Amazon CloudWatch User Guide. */ onlyStartEvaluatingAfterWarmUpPeriodEnds?: boolean; /** * Length of the warm-up period, in minutes. Valid values are `1` to `2880`. */ warmUpPeriodDurationInMinutes: number; } interface MetricStreamExcludeFilter { /** * An array that defines the metrics you want to exclude for this metric namespace */ metricNames?: string[]; /** * Name of the metric namespace in the filter. */ namespace: string; } interface MetricStreamIncludeFilter { /** * An array that defines the metrics you want to include for this metric namespace */ metricNames?: string[]; /** * Name of the metric namespace in the filter. */ namespace: string; } interface MetricStreamStatisticsConfiguration { /** * The additional statistics to stream for the metrics listed in `includeMetrics`. */ additionalStatistics: string[]; /** * An array that defines the metrics that are to have additional statistics streamed. See details below. */ includeMetrics: outputs.cloudwatch.MetricStreamStatisticsConfigurationIncludeMetric[]; } interface MetricStreamStatisticsConfigurationIncludeMetric { /** * The name of the metric. */ metricName: string; namespace: string; } interface OtelEnrichmentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace codeartifact { interface RepositoryExternalConnections { /** * The name of the external connection associated with a repository. */ externalConnectionName: string; packageFormat: string; status: string; } interface RepositoryUpstream { /** * The name of an upstream repository. */ repositoryName: string; } } export declare namespace codebuild { interface FleetComputeConfiguration { /** * Amount of disk space of the instance type included in the fleet. */ disk: number; /** * EC2 instance type to be launched in the fleet. Specify only if `computeType` is set to `CUSTOM_INSTANCE_TYPE`. See [Supported instance families](https://docs.aws.amazon.com/codebuild/latest/userguide/build-env-ref-compute-types.html#environment-reserved-capacity.instance-types). */ instanceType: string; /** * Machine type of the instance type included in the fleet. Valid values: `GENERAL`, `NVME`. Specify only if `computeType` is set to `ATTRIBUTE_BASED_COMPUTE`. */ machineType: string; /** * Amount of memory of the instance type included in the fleet. Specify only if `computeType` is set to `ATTRIBUTE_BASED_COMPUTE`. */ memory: number; /** * Number of vCPUs of the instance type included in the fleet. Specify only if `computeType` is set to `ATTRIBUTE_BASED_COMPUTE`. */ vcpu: number; } interface FleetScalingConfiguration { desiredCapacity: number; /** * Maximum number of instances in the fleet when auto-scaling. */ maxCapacity?: number; /** * Scaling type for a compute fleet. Valid value: `TARGET_TRACKING_SCALING`. */ scalingType?: string; /** * Configuration block. Detailed below. */ targetTrackingScalingConfigs?: outputs.codebuild.FleetScalingConfigurationTargetTrackingScalingConfig[]; } interface FleetScalingConfigurationTargetTrackingScalingConfig { /** * Metric type to determine auto-scaling. Valid value: `FLEET_UTILIZATION_RATE`. */ metricType?: string; /** * Value of metricType when to start scaling. */ targetValue?: number; } interface FleetStatus { /** * Additional information about a compute fleet. */ context: string; /** * Message associated with the status of a compute fleet. */ message: string; /** * Status code of the compute fleet. */ statusCode: string; } interface FleetVpcConfig { /** * A list of one or more security groups IDs in your Amazon VPC. */ securityGroupIds: string[]; /** * A list of one or more subnet IDs in your Amazon VPC. */ subnets: string[]; /** * The ID of the Amazon VPC. */ vpcId: string; } interface GetFleetComputeConfiguration { /** * Amount of disk space of the instance type included in the fleet. */ disk: number; /** * EC2 instance type in the fleet. */ instanceType: string; /** * Machine type of the instance type included in the fleet. */ machineType: string; /** * Amount of memory of the instance type included in the fleet. */ memory: number; /** * Number of vCPUs of the instance type included in the fleet. */ vcpu: number; } interface GetFleetScalingConfiguration { /** * The desired number of instances in the fleet when auto-scaling. */ desiredCapacity: number; /** * The maximum number of instances in the fleet when auto-scaling. */ maxCapacity: number; /** * The scaling type for a compute fleet. */ scalingType: string; /** * Nested attribute containing information about thresholds when new instance is auto-scaled into the compute fleet. */ targetTrackingScalingConfigs: outputs.codebuild.GetFleetScalingConfigurationTargetTrackingScalingConfig[]; } interface GetFleetScalingConfigurationTargetTrackingScalingConfig { /** * The metric type to determine auto-scaling. */ metricType: string; /** * The value of metricType when to start scaling. */ targetValue: number; } interface GetFleetStatus { /** * Additional information about a compute fleet. */ context: string; /** * Message associated with the status of a compute fleet. */ message: string; /** * Status code of the compute fleet. */ statusCode: string; } interface GetFleetVpcConfig { /** * A list of one or more security groups IDs in your Amazon VPC. */ securityGroupIds: string[]; /** * A list of one or more subnet IDs in your Amazon VPC. */ subnets: string[]; /** * The ID of the Amazon VPC. */ vpcId: string; } interface ProjectArtifacts { /** * Artifact identifier. Must be the same specified inside the AWS CodeBuild build * specification. */ artifactIdentifier?: string; /** * Specifies the bucket owner's access for objects that another account uploads to * their Amazon S3 bucket. By default, only the account that uploads the objects to the bucket has access to these * objects. This property allows you to give the bucket owner access to these objects. Valid values are `NONE`, * `READ_ONLY`, and `FULL`. your CodeBuild service role must have the `s3:PutBucketAcl` permission. This permission * allows CodeBuild to modify the access control list for the bucket. */ bucketOwnerAccess?: string; /** * Whether to disable encrypting output artifacts. If `type` is set to `NO_ARTIFACTS`, * this value is ignored. Defaults to `false`. */ encryptionDisabled?: boolean; /** * Information about the build output artifact location. If `type` is set to `CODEPIPELINE` or * `NO_ARTIFACTS`, this value is ignored. If `type` is set to `S3`, this is the name of the output bucket. */ location?: string; /** * Name of the project. If `type` is set to `S3`, this is the name of the output artifact object */ name?: string; /** * Namespace to use in storing build artifacts. If `type` is set to `S3`, then valid values * are `BUILD_ID`, `NONE`. */ namespaceType?: string; /** * Whether a name specified in the build specification overrides the artifact name. */ overrideArtifactName?: boolean; /** * Type of build output artifact to create. If `type` is set to `S3`, valid values are `NONE`, * `ZIP` */ packaging?: string; /** * If `type` is set to `S3`, this is the path to the output artifact. */ path?: string; /** * Build output artifact's type. Valid values: `CODEPIPELINE`, `NO_ARTIFACTS`, `S3`. */ type: string; } interface ProjectBuildBatchConfig { /** * Specifies if the build artifacts for the batch build should be combined into a single * artifact location. */ combineArtifacts?: boolean; /** * Configuration block specifying the restrictions for the batch build. Detailed below. */ restrictions?: outputs.codebuild.ProjectBuildBatchConfigRestrictions; /** * Specifies the service role ARN for the batch build project. */ serviceRole: string; /** * Specifies the maximum amount of time, in minutes, that the batch build must be * completed in. */ timeoutInMins?: number; } interface ProjectBuildBatchConfigRestrictions { /** * An array of strings that specify the compute types that are allowed for the batch * build. * See [Build environment compute types](https://docs.aws.amazon.com/codebuild/latest/userguide/build-env-ref-compute-types.html) * in the AWS CodeBuild User Guide for these values. */ computeTypesAlloweds?: string[]; /** * Specifies the maximum number of builds allowed. */ maximumBuildsAllowed?: number; } interface ProjectCache { /** * Namespace that determines the scope in which a cache is shared across multiple projects. */ cacheNamespace?: string; /** * Location where the AWS CodeBuild project stores cached resources. For * type `S3`, the value must be a valid S3 bucket name/prefix. */ location?: string; /** * Specifies settings that AWS CodeBuild uses to store and reuse build * dependencies. Valid values: `LOCAL_SOURCE_CACHE`, `LOCAL_DOCKER_LAYER_CACHE`, `LOCAL_CUSTOM_CACHE`. */ modes?: string[]; /** * Type of storage that will be used for the AWS CodeBuild project cache. Valid values: `NO_CACHE`, * `LOCAL`, `S3`. Defaults to `NO_CACHE`. */ type?: string; } interface ProjectEnvironment { /** * ARN of the S3 bucket, path prefix and object key that contains the PEM-encoded certificate. */ certificate?: string; /** * Information about the compute resources the build project will use. Valid values: * `BUILD_GENERAL1_SMALL`, `BUILD_GENERAL1_MEDIUM`, `BUILD_GENERAL1_LARGE`, `BUILD_GENERAL1_XLARGE`, `BUILD_GENERAL1_2XLARGE`, `BUILD_LAMBDA_1GB`, * `BUILD_LAMBDA_2GB`, `BUILD_LAMBDA_4GB`, `BUILD_LAMBDA_8GB`, `BUILD_LAMBDA_10GB`. For additional information, see * the [CodeBuild User Guide](https://docs.aws.amazon.com/codebuild/latest/userguide/build-env-ref-compute-types.html). */ computeType: string; /** * Configuration block. Detailed below. */ dockerServer?: outputs.codebuild.ProjectEnvironmentDockerServer; /** * Configuration block. Detailed below. */ environmentVariables?: outputs.codebuild.ProjectEnvironmentEnvironmentVariable[]; /** * Configuration block. Detailed below. */ fleet?: outputs.codebuild.ProjectEnvironmentFleet; /** * Host operating system kernel used for on-demand builds in the build project. This setting * controls the kernel of the underlying build host. It does not change the build environment operating system, which is * determined by the image you specify. Valid values: `LINUX_KERNEL_4` (runs on an Amazon Linux 2 host, kernel 4.x), * `LINUX_KERNEL_6` (runs on an Amazon Linux 2023 host, kernel 6.x), `LINUX_KERNEL_LATEST` (runs on the latest supported * host kernel). Applies to the `LINUX_CONTAINER`, `ARM_CONTAINER`, `LINUX_EC2`, and `ARM_EC2` environment types; not * applicable to Windows, Lambda, or Mac environment types. If not specified, CodeBuild selects a default. */ hostKernel: string; /** * Docker image to use for this build project. Valid values * include [Docker images provided by CodeBuild](https://docs.aws.amazon.com/codebuild/latest/userguide/build-env-ref-available.html) ( * e.g `aws/codebuild/amazonlinux2-x86_64-standard:4.0`), [Docker Hub images](https://hub.docker.com/) (e.g., * `pulumi/pulumi:latest`), and full Docker repository URIs such as those for ECR (e.g., * `137112412989.dkr.ecr.us-west-2.amazonaws.com/amazonlinux:latest`). */ image: string; /** * Type of credentials AWS CodeBuild uses to pull images in your build. Valid * values: `CODEBUILD`, `SERVICE_ROLE`. When you use a cross-account or private registry image, you must use SERVICE_ROLE * credentials. When you use an AWS CodeBuild curated image, you must use CodeBuild credentials. Defaults to `CODEBUILD`. */ imagePullCredentialsType?: string; /** * Whether to enable running the Docker daemon inside a Docker container. Defaults to * `false`. */ privilegedMode?: boolean; /** * Configuration block. Detailed below. */ registryCredential?: outputs.codebuild.ProjectEnvironmentRegistryCredential; /** * Type of build environment to use for related builds. Valid values: `WINDOWS_CONTAINER` (deprecated), `LINUX_CONTAINER`, * `LINUX_GPU_CONTAINER`, `ARM_CONTAINER`, `WINDOWS_SERVER_2019_CONTAINER`, `WINDOWS_SERVER_2022_CONTAINER`, * `LINUX_LAMBDA_CONTAINER`, `ARM_LAMBDA_CONTAINER`, `LINUX_EC2`, `ARM_EC2`, `WINDOWS_EC2`, `MAC_ARM`. For additional information, see * the [CodeBuild User Guide](https://docs.aws.amazon.com/codebuild/latest/userguide/build-env-ref-compute-types.html). */ type: string; } interface ProjectEnvironmentDockerServer { /** * Compute type for the Docker server. Valid values: `BUILD_GENERAL1_SMALL`, `BUILD_GENERAL1_MEDIUM`, `BUILD_GENERAL1_LARGE`, `BUILD_GENERAL1_XLARGE`, and `BUILD_GENERAL1_2XLARGE`. */ computeType: string; /** * List of security group IDs to assign to the Docker server. */ securityGroupIds?: string[]; } interface ProjectEnvironmentEnvironmentVariable { /** * Environment variable's name or key. */ name: string; /** * Type of environment variable. Valid values: `PARAMETER_STORE`, `PLAINTEXT`, `SECRETS_MANAGER`. */ type?: string; /** * Environment variable's value. */ value: string; } interface ProjectEnvironmentFleet { /** * Compute fleet ARN for the build project. */ fleetArn?: string; } interface ProjectEnvironmentRegistryCredential { /** * ARN or name of credentials created using AWS Secrets Manager. */ credential: string; /** * Service that created the credentials to access a private Docker registry. Valid * value: `SECRETS_MANAGER` (AWS Secrets Manager). */ credentialProvider: string; } interface ProjectFileSystemLocation { /** * The name used to access a file system created by Amazon EFS. CodeBuild creates an * environment variable by appending the identifier in all capital letters to CODEBUILD\_. For example, if you specify * my-efs for identifier, a new environment variable is create named CODEBUILD_MY-EFS. */ identifier?: string; /** * A string that specifies the location of the file system created by Amazon EFS. Its format is * `efs-dns-name:/directory-path`. */ location?: string; /** * The mount options for a file system created by AWS EFS. */ mountOptions?: string; /** * The location in the container where you mount the file system. */ mountPoint?: string; /** * The type of the file system. The one supported type is `EFS`. */ type?: string; } interface ProjectLogsConfig { /** * Configuration block. Detailed below. */ cloudwatchLogs?: outputs.codebuild.ProjectLogsConfigCloudwatchLogs; /** * Configuration block. Detailed below. */ s3Logs?: outputs.codebuild.ProjectLogsConfigS3Logs; } interface ProjectLogsConfigCloudwatchLogs { /** * Group name of the logs in CloudWatch Logs. */ groupName?: string; /** * Current status of logs in CloudWatch Logs for a build project. Valid values: `ENABLED`, * `DISABLED`. Defaults to `ENABLED`. */ status?: string; /** * Prefix of the log stream name of the logs in CloudWatch Logs. */ streamName?: string; } interface ProjectLogsConfigS3Logs { /** * Specifies the bucket owner's access for objects that another account uploads to * their Amazon S3 bucket. By default, only the account that uploads the objects to the bucket has access to these * objects. This property allows you to give the bucket owner access to these objects. Valid values are `NONE`, * `READ_ONLY`, and `FULL`. your CodeBuild service role must have the `s3:PutBucketAcl` permission. This permission * allows CodeBuild to modify the access control list for the bucket. */ bucketOwnerAccess?: string; /** * Whether to disable encrypting S3 logs. Defaults to `false`. */ encryptionDisabled?: boolean; /** * Name of the S3 bucket and the path prefix for S3 logs. Must be set if status is `ENABLED`, * otherwise it must be empty. */ location?: string; /** * Current status of logs in S3 for a build project. Valid values: `ENABLED`, `DISABLED`. Defaults * to `DISABLED`. */ status?: string; } interface ProjectSecondaryArtifact { /** * Artifact identifier. Must be the same specified inside the AWS CodeBuild build * specification. */ artifactIdentifier: string; /** * Specifies the bucket owner's access for objects that another account uploads to * their Amazon S3 bucket. By default, only the account that uploads the objects to the bucket has access to these * objects. This property allows you to give the bucket owner access to these objects. Valid values are `NONE`, * `READ_ONLY`, and `FULL`. The CodeBuild service role must have the `s3:PutBucketAcl` permission. This permission allows * CodeBuild to modify the access control list for the bucket. */ bucketOwnerAccess?: string; /** * Whether to disable encrypting output artifacts. If `type` is set to `NO_ARTIFACTS`, * this value is ignored. Defaults to `false`. */ encryptionDisabled?: boolean; /** * Information about the build output artifact location. If `type` is set to `CODEPIPELINE` or * `NO_ARTIFACTS`, this value is ignored if specified. If `type` is set to `S3`, this is the name of the output bucket. * If `path` is not specified, `location` can specify the path of the output artifact in the output bucket. */ location?: string; /** * Name of the project. If `type` is set to `CODEPIPELINE` or `NO_ARTIFACTS`, this value is ignored * if specified. If `type` is set to `S3`, this is the name of the output artifact object. */ name?: string; /** * Namespace to use in storing build artifacts. If `type` is set to `CODEPIPELINE` or * `NO_ARTIFACTS`, this value is ignored if specified. If `type` is set to `S3`, valid values are `BUILD_ID` or `NONE`. */ namespaceType?: string; /** * Whether a name specified in the build specification overrides the artifact name. */ overrideArtifactName?: boolean; /** * Type of build output artifact to create. If `type` is set to `CODEPIPELINE` or * `NO_ARTIFACTS`, this value is ignored if specified. If `type` is set to `S3`, valid values are `NONE` or `ZIP`. */ packaging?: string; /** * Along with `namespaceType` and `name`, the pattern that AWS CodeBuild uses to name and store the * output artifact. If `type` is set to `CODEPIPELINE` or `NO_ARTIFACTS`, this value is ignored if specified. If `type` * is set to `S3`, this is the path to the output artifact. */ path?: string; /** * Build output artifact's type. Valid values `CODEPIPELINE`, `NO_ARTIFACTS`, and `S3`. */ type: string; } interface ProjectSecondarySource { /** * Information about the strategy CodeBuild should use when authenticating with the source code host. * Detailed below. */ auth?: outputs.codebuild.ProjectSecondarySourceAuth; /** * Configuration block that contains information that defines how the build project * reports the build status to the source provider. This option is only used when the source provider is GitHub, GitHub * Enterprise, GitLab, GitLab Self Managed, or Bitbucket. `buildStatusConfig` blocks are documented below. */ buildStatusConfig?: outputs.codebuild.ProjectSecondarySourceBuildStatusConfig; /** * The build spec declaration to use for this build project's related builds. This must be set * when `type` is `NO_SOURCE`. It can either be a path to a file residing in the repository to be built or a local file * path leveraging the `file()` built-in. */ buildspec?: string; /** * Truncate git history to this many commits. Use `0` for a `Full` checkout which you need * to run commands like `git branch --show-current`. * See [AWS CodePipeline User Guide: Tutorial: Use full clone with a GitHub pipeline source](https://docs.aws.amazon.com/codepipeline/latest/userguide/tutorials-github-gitclone.html) * for details. */ gitCloneDepth?: number; /** * Configuration block. Detailed below. */ gitSubmodulesConfig?: outputs.codebuild.ProjectSecondarySourceGitSubmodulesConfig; /** * Ignore SSL warnings when connecting to source control. */ insecureSsl?: boolean; /** * Location of the source code from git or s3. */ location?: string; /** * Whether to report the status of a build's start and finish to your source provider. * This option is valid only when your source provider is GitHub, GitHub Enterprise, GitLab, GitLab Self Managed, or * Bitbucket. */ reportBuildStatus?: boolean; /** * An identifier for this project source. The identifier can only contain alphanumeric * characters and underscores, and must be less than 128 characters in length. */ sourceIdentifier: string; /** * Type of repository that contains the source code to be built. Valid values: `BITBUCKET`, * `CODECOMMIT`, `CODEPIPELINE`, `GITHUB`, `GITHUB_ENTERPRISE`, `GITLAB`, `GITLAB_SELF_MANAGED`, `NO_SOURCE`, `S3`. */ type: string; } interface ProjectSecondarySourceAuth { /** * The ARN of the resource to use for authentication. For type `CODECONNECTIONS` this should be * an AWS CodeStar Connection. For type `SECRETS_MANAGER` this should be an AWS Secrets Manager secret. */ resource: string; /** * The type of authentication AWS CodeBuild should perform. Valid values are `CODECONNECTIONS` and * `SECRETS_MANAGER`. */ type: string; } interface ProjectSecondarySourceBuildStatusConfig { /** * Specifies the context of the build status CodeBuild sends to the source provider. The usage of * this parameter depends on the source provider. */ context?: string; /** * Specifies the target url of the build status CodeBuild sends to the source provider. The * usage of this parameter depends on the source provider. */ targetUrl?: string; } interface ProjectSecondarySourceGitSubmodulesConfig { /** * Whether to fetch Git submodules for the AWS CodeBuild build project. */ fetchSubmodules: boolean; } interface ProjectSecondarySourceVersion { /** * An identifier for a source in the build project. */ sourceIdentifier: string; /** * The source version for the corresponding source identifier. * See [AWS docs](https://docs.aws.amazon.com/codebuild/latest/APIReference/API_ProjectSourceVersion.html#CodeBuild-Type-ProjectSourceVersion-sourceVersion) * for more details. */ sourceVersion: string; } interface ProjectSource { /** * Information about the strategy CodeBuild should use when authenticating with the source code host. * Detailed below. */ auth?: outputs.codebuild.ProjectSourceAuth; /** * Configuration block that contains information that defines how the build project * reports the build status to the source provider. This option is only used when the source provider is GitHub, GitHub * Enterprise, GitLab, GitLab Self Managed, or Bitbucket. `buildStatusConfig` blocks are documented below. */ buildStatusConfig?: outputs.codebuild.ProjectSourceBuildStatusConfig; /** * Build specification to use for this build project's related builds. This must be set when * `type` is `NO_SOURCE`. Also, if a non-default buildspec file name or file path aside from the root is used, it must be * specified. */ buildspec?: string; /** * Truncate git history to this many commits. Use `0` for a `Full` checkout which you need * to run commands like `git branch --show-current`. * See [AWS CodePipeline User Guide: Tutorial: Use full clone with a GitHub pipeline source](https://docs.aws.amazon.com/codepipeline/latest/userguide/tutorials-github-gitclone.html) * for details. */ gitCloneDepth?: number; /** * Configuration block. Detailed below. */ gitSubmodulesConfig?: outputs.codebuild.ProjectSourceGitSubmodulesConfig; /** * Ignore SSL warnings when connecting to source control. */ insecureSsl?: boolean; /** * Location of the source code from git or s3. */ location?: string; /** * Whether to report the status of a build's start and finish to your source provider. * This option is valid only when your source provider is GitHub, GitHub Enterprise, GitLab, GitLab Self Managed, or * Bitbucket. */ reportBuildStatus?: boolean; /** * Type of repository that contains the source code to be built. Valid values: `BITBUCKET`, * `CODECOMMIT`, `CODEPIPELINE`, `GITHUB`, `GITHUB_ENTERPRISE`, `GITLAB`, `GITLAB_SELF_MANAGED`, `NO_SOURCE`, `S3`. */ type: string; } interface ProjectSourceAuth { /** * The ARN of the resource to use for authentication. For type `CODECONNECTIONS` this should be * an AWS CodeStar Connection. For type `SECRETS_MANAGER` this should be an AWS Secrets Manager secret. */ resource: string; /** * The type of authentication AWS CodeBuild should perform. Valid values are `CODECONNECTIONS` and * `SECRETS_MANAGER`. */ type: string; } interface ProjectSourceBuildStatusConfig { /** * Specifies the context of the build status CodeBuild sends to the source provider. The usage of * this parameter depends on the source provider. */ context?: string; /** * Specifies the target url of the build status CodeBuild sends to the source provider. The * usage of this parameter depends on the source provider. */ targetUrl?: string; } interface ProjectSourceGitSubmodulesConfig { /** * Whether to fetch Git submodules for the AWS CodeBuild build project. */ fetchSubmodules: boolean; } interface ProjectVpcConfig { /** * Security group IDs to assign to running builds. */ securityGroupIds: string[]; /** * Subnet IDs within which to run builds. */ subnets: string[]; /** * ID of the VPC within which to run builds. */ vpcId: string; } interface ReportGroupExportConfig { /** * contains information about the S3 bucket where the run of a report is exported. see S3 Destination documented below. */ s3Destination?: outputs.codebuild.ReportGroupExportConfigS3Destination; /** * The export configuration type. Valid values are `S3` and `NO_EXPORT`. */ type: string; } interface ReportGroupExportConfigS3Destination { /** * The name of the S3 bucket where the raw data of a report are exported. */ bucket: string; /** * A boolean value that specifies if the results of a report are encrypted. * **Note: the API does not currently allow setting encryption as disabled** */ encryptionDisabled?: boolean; /** * The encryption key for the report's encrypted raw data. The KMS key ARN. */ encryptionKey: string; /** * The type of build output artifact to create. Valid values are: `NONE` (default) and `ZIP`. */ packaging?: string; /** * The path to the exported report's raw data results. */ path?: string; } interface WebhookFilterGroup { /** * A webhook filter for the group. See filter for details. */ filters?: outputs.codebuild.WebhookFilterGroupFilter[]; } interface WebhookFilterGroupFilter { /** * If set to `true`, the specified filter does *not* trigger a build. Defaults to `false`. */ excludeMatchedPattern?: boolean; /** * For a filter that uses `EVENT` type, a comma-separated string that specifies one event: `PUSH`, `PULL_REQUEST_CREATED`, `PULL_REQUEST_UPDATED`, `PULL_REQUEST_REOPENED`. `PULL_REQUEST_MERGED`, `WORKFLOW_JOB_QUEUED` works with GitHub & GitHub Enterprise only. For a filter that uses any of the other filter types, a regular expression. */ pattern: string; /** * The webhook filter group's type. Valid values for this parameter are: `EVENT`, `BASE_REF`, `HEAD_REF`, `ACTOR_ACCOUNT_ID`, `FILE_PATH`, `COMMIT_MESSAGE`, `WORKFLOW_NAME`, `TAG_NAME`, `RELEASE_NAME`, `REPOSITORY_NAME`. At least one filter group must specify `EVENT` as its type. */ type: string; } interface WebhookPullRequestBuildPolicy { /** * List of repository roles that have approval privileges for pull request builds when comment approval is required. This argument must be specified only when `requiresCommentApproval` is not `DISABLED`. See the [AWS documentation](https://docs.aws.amazon.com/codebuild/latest/userguide/pull-request-build-policy.html#pull-request-build-policy.configuration) for valid values and defaults. */ approverRoles: string[]; /** * Specifies when comment-based approval is required before triggering a build on pull requests. Valid values are: `DISABLED`, `ALL_PULL_REQUESTS`, and `FORK_PULL_REQUESTS`. */ requiresCommentApproval: string; } interface WebhookScopeConfiguration { /** * The domain of the GitHub Enterprise organization. Required if your project's source type is GITHUB_ENTERPRISE. */ domain?: string; /** * The name of either the enterprise or organization. */ name: string; /** * The type of scope for a GitHub webhook. Valid values for this parameter are: `GITHUB_ORGANIZATION`, `GITHUB_GLOBAL`. */ scope: string; } } export declare namespace codecatalyst { interface DevEnvironmentIdes { /** * The name of the IDE. Valid values include Cloud9, IntelliJ, PyCharm, GoLand, and VSCode. */ name?: string; /** * A link to the IDE runtime image. This parameter is not required if the name is VSCode. Values of the runtime can be for example public.ecr.aws/jetbrains/py,public.ecr.aws/jetbrains/go */ runtime?: string; } interface DevEnvironmentPersistentStorage { /** * The size of the persistent storage in gigabytes (specifically GiB). Valid values for storage are based on memory sizes in 16GB increments. Valid values are 16, 32, and 64. */ size: number; } interface DevEnvironmentRepository { /** * The name of the branch in a source repository. * * persistent storage (` persistentStorage `) supports the following: */ branchName?: string; /** * The name of the source repository. */ repositoryName: string; } interface GetDevEnvironmentIde { name: string; runtime: string; } interface GetDevEnvironmentPersistentStorage { size: number; } interface GetDevEnvironmentRepository { branchName: string; repositoryName: string; } } export declare namespace codecommit { interface TriggerTrigger { /** * The branches that will be included in the trigger configuration. If no branches are specified, the trigger will apply to all branches. */ branches?: string[]; /** * Any custom data associated with the trigger that will be included in the information sent to the target of the trigger. */ customData?: string; /** * The ARN of the resource that is the target for a trigger. For example, the ARN of a topic in Amazon Simple Notification Service (SNS). */ destinationArn: string; /** * The repository events that will cause the trigger to run actions in another service, such as sending a notification through Amazon Simple Notification Service (SNS). If no events are specified, the trigger will run for all repository events. Event types include: `all`, `updateReference`, `createReference`, `deleteReference`. */ events: string[]; /** * The name of the trigger. */ name: string; } } export declare namespace codeconnections { interface ConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface HostTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface HostVpcConfiguration { /** * ID of the security group or security groups associated with the Amazon VPC connected to the infrastructure where your provider type is installed. */ securityGroupIds: string[]; /** * The ID of the subnet or subnets associated with the Amazon VPC connected to the infrastructure where your provider type is installed. */ subnetIds: string[]; /** * Value of the TLS certificate associated with the infrastructure where your provider type is installed. */ tlsCertificate?: string; /** * The ID of the Amazon VPC connected to the infrastructure where your provider type is installed. */ vpcId: string; } } export declare namespace codedeploy { interface DeploymentConfigMinimumHealthyHosts { /** * The type can either be `FLEET_PERCENT` or `HOST_COUNT`. */ type?: string; /** * The value when the type is `FLEET_PERCENT` represents the minimum number of healthy instances as * a percentage of the total number of instances in the deployment. If you specify FLEET_PERCENT, at the start of the * deployment, AWS CodeDeploy converts the percentage to the equivalent number of instance and rounds up fractional instances. * When the type is `HOST_COUNT`, the value represents the minimum number of healthy instances as an absolute value. */ value?: number; } interface DeploymentConfigTrafficRoutingConfig { /** * The time based canary configuration information. If `type` is `TimeBasedLinear`, use `timeBasedLinear` instead. */ timeBasedCanary?: outputs.codedeploy.DeploymentConfigTrafficRoutingConfigTimeBasedCanary; /** * The time based linear configuration information. If `type` is `TimeBasedCanary`, use `timeBasedCanary` instead. */ timeBasedLinear?: outputs.codedeploy.DeploymentConfigTrafficRoutingConfigTimeBasedLinear; /** * Type of traffic routing config. One of `TimeBasedCanary`, `TimeBasedLinear`, `AllAtOnce`. */ type?: string; } interface DeploymentConfigTrafficRoutingConfigTimeBasedCanary { /** * The number of minutes between the first and second traffic shifts of a `TimeBasedCanary` deployment. */ interval?: number; /** * The percentage of traffic to shift in the first increment of a `TimeBasedCanary` deployment. */ percentage?: number; } interface DeploymentConfigTrafficRoutingConfigTimeBasedLinear { /** * The number of minutes between each incremental traffic shift of a `TimeBasedLinear` deployment. */ interval?: number; /** * The percentage of traffic that is shifted at the start of each increment of a `TimeBasedLinear` deployment. */ percentage?: number; } interface DeploymentConfigZonalConfig { /** * The period of time, in seconds, that CodeDeploy must wait after completing a deployment to the first Availability Zone. CodeDeploy will wait this amount of time before starting a deployment to the second Availability Zone. If you don't specify a value for `firstZoneMonitorDurationInSeconds`, then CodeDeploy uses the `monitorDurationInSeconds` value for the first Availability Zone. */ firstZoneMonitorDurationInSeconds?: number; /** * The number or percentage of instances that must remain available per Availability Zone during a deployment. If you don't specify a value under `minimumHealthyHostsPerZone`, then CodeDeploy uses a default value of 0 percent. This block is more documented below. */ minimumHealthyHostsPerZone?: outputs.codedeploy.DeploymentConfigZonalConfigMinimumHealthyHostsPerZone; /** * The period of time, in seconds, that CodeDeploy must wait after completing a deployment to an Availability Zone. CodeDeploy will wait this amount of time before starting a deployment to the next Availability Zone. If you don't specify a `monitorDurationInSeconds`, CodeDeploy starts deploying to the next Availability Zone immediately. */ monitorDurationInSeconds?: number; } interface DeploymentConfigZonalConfigMinimumHealthyHostsPerZone { /** * The type can either be `FLEET_PERCENT` or `HOST_COUNT`. */ type?: string; /** * The value when the type is `FLEET_PERCENT` represents the minimum number of healthy instances as a percentage of the total number of instances in the Availability Zone during a deployment. If you specify FLEET_PERCENT, at the start of the deployment, AWS CodeDeploy converts the percentage to the equivalent number of instance and rounds up fractional instances. When the type is `HOST_COUNT`, the value represents the minimum number of healthy instances in the Availability Zone as an absolute value. */ value?: number; } interface DeploymentGroupAlarmConfiguration { /** * A list of alarms configured for the deployment group. */ alarms?: string[]; /** * Indicates whether the alarm configuration is enabled. This option is useful when you want to temporarily deactivate alarm monitoring for a deployment group without having to add the same alarms again later. */ enabled?: boolean; /** * Indicates whether a deployment should continue if information about the current state of alarms cannot be retrieved from CloudWatch. The default value is `false`. */ ignorePollAlarmFailure?: boolean; } interface DeploymentGroupAutoRollbackConfiguration { /** * Indicates whether a defined automatic rollback configuration is currently enabled for this Deployment Group. If you enable automatic rollback, you must specify at least one event type. */ enabled?: boolean; /** * The event type or types that trigger a rollback. Supported types are `DEPLOYMENT_FAILURE`, `DEPLOYMENT_STOP_ON_ALARM` and `DEPLOYMENT_STOP_ON_REQUEST`. * * _Only one `autoRollbackConfiguration` is allowed_. */ events?: string[]; } interface DeploymentGroupBlueGreenDeploymentConfig { /** * Information about the action to take when newly provisioned instances are ready to receive traffic in a blue/green deployment (documented below). */ deploymentReadyOption?: outputs.codedeploy.DeploymentGroupBlueGreenDeploymentConfigDeploymentReadyOption; /** * Information about how instances are provisioned for a replacement environment in a blue/green deployment (documented below). */ greenFleetProvisioningOption: outputs.codedeploy.DeploymentGroupBlueGreenDeploymentConfigGreenFleetProvisioningOption; /** * Information about whether to terminate instances in the original fleet during a blue/green deployment (documented below). * * _Only one `blueGreenDeploymentConfig` is allowed_. */ terminateBlueInstancesOnDeploymentSuccess?: outputs.codedeploy.DeploymentGroupBlueGreenDeploymentConfigTerminateBlueInstancesOnDeploymentSuccess; } interface DeploymentGroupBlueGreenDeploymentConfigDeploymentReadyOption { /** * When to reroute traffic from an original environment to a replacement environment in a blue/green deployment. * * `CONTINUE_DEPLOYMENT`: Register new instances with the load balancer immediately after the new application revision is installed on the instances in the replacement environment. * * `STOP_DEPLOYMENT`: Do not register new instances with load balancer unless traffic is rerouted manually. If traffic is not rerouted manually before the end of the specified wait period, the deployment status is changed to Stopped. */ actionOnTimeout?: string; /** * The number of minutes to wait before the status of a blue/green deployment changed to Stopped if rerouting is not started manually. Applies only to the `STOP_DEPLOYMENT` option for `actionOnTimeout`. */ waitTimeInMinutes?: number; } interface DeploymentGroupBlueGreenDeploymentConfigGreenFleetProvisioningOption { /** * The method used to add instances to a replacement environment. * * `DISCOVER_EXISTING`: Use instances that already exist or will be created manually. * * `COPY_AUTO_SCALING_GROUP`: Use settings from a specified **Auto Scaling** group to define and create instances in a new Auto Scaling group. _Exactly one Auto Scaling group must be specified_ when selecting `COPY_AUTO_SCALING_GROUP`. Use `autoscalingGroups` to specify the Auto Scaling group. */ action?: string; } interface DeploymentGroupBlueGreenDeploymentConfigTerminateBlueInstancesOnDeploymentSuccess { /** * The action to take on instances in the original environment after a successful blue/green deployment. * * `TERMINATE`: Instances are terminated after a specified wait time. * * `KEEP_ALIVE`: Instances are left running after they are deregistered from the load balancer and removed from the deployment group. */ action?: string; /** * The number of minutes to wait after a successful blue/green deployment before terminating instances from the original environment. */ terminationWaitTimeInMinutes?: number; } interface DeploymentGroupDeploymentStyle { /** * Indicates whether to route deployment traffic behind a load balancer. Valid Values are `WITH_TRAFFIC_CONTROL` or `WITHOUT_TRAFFIC_CONTROL`. Default is `WITHOUT_TRAFFIC_CONTROL`. */ deploymentOption?: string; /** * Indicates whether to run an in-place deployment or a blue/green deployment. Valid Values are `IN_PLACE` or `BLUE_GREEN`. Default is `IN_PLACE`. * * _Only one `deploymentStyle` is allowed_. */ deploymentType?: string; } interface DeploymentGroupEc2TagFilter { /** * The key of the tag filter. */ key?: string; /** * The type of the tag filter, either `KEY_ONLY`, `VALUE_ONLY`, or `KEY_AND_VALUE`. */ type?: string; /** * The value of the tag filter. * * Multiple occurrences of `ec2TagFilter` are allowed, where any instance that matches to at least one of the tag filters is selected. */ value?: string; } interface DeploymentGroupEc2TagSet { /** * Tag filters associated with the deployment group. See the AWS docs for details. */ ec2TagFilters?: outputs.codedeploy.DeploymentGroupEc2TagSetEc2TagFilter[]; } interface DeploymentGroupEc2TagSetEc2TagFilter { /** * The key of the tag filter. */ key?: string; /** * The type of the tag filter, either `KEY_ONLY`, `VALUE_ONLY`, or `KEY_AND_VALUE`. */ type?: string; /** * The value of the tag filter. * * Multiple occurrences of `ec2TagFilter` are allowed, where any instance that matches to at least one of the tag filters is selected. */ value?: string; } interface DeploymentGroupEcsService { /** * The name of the ECS cluster. */ clusterName: string; /** * The name of the ECS service. */ serviceName: string; } interface DeploymentGroupLoadBalancerInfo { /** * The Classic Elastic Load Balancer to use in a deployment. Conflicts with `targetGroupInfo` and `targetGroupPairInfo`. */ elbInfos?: outputs.codedeploy.DeploymentGroupLoadBalancerInfoElbInfo[]; /** * The (Application/Network Load Balancer) target group to use in a deployment. Conflicts with `elbInfo` and `targetGroupPairInfo`. */ targetGroupInfos?: outputs.codedeploy.DeploymentGroupLoadBalancerInfoTargetGroupInfo[]; /** * The (Application/Network Load Balancer) target group pair to use in a deployment. Conflicts with `elbInfo` and `targetGroupInfo`. */ targetGroupPairInfo?: outputs.codedeploy.DeploymentGroupLoadBalancerInfoTargetGroupPairInfo; } interface DeploymentGroupLoadBalancerInfoElbInfo { /** * The name of the load balancer that will be used to route traffic from original instances to replacement instances in a blue/green deployment. For in-place deployments, the name of the load balancer that instances are deregistered from so they are not serving traffic during a deployment, and then re-registered with after the deployment completes. */ name?: string; } interface DeploymentGroupLoadBalancerInfoTargetGroupInfo { /** * The name of the target group that instances in the original environment are deregistered from, and instances in the replacement environment registered with. For in-place deployments, the name of the target group that instances are deregistered from, so they are not serving traffic during a deployment, and then re-registered with after the deployment completes. */ name?: string; } interface DeploymentGroupLoadBalancerInfoTargetGroupPairInfo { /** * Configuration block for the production traffic route (documented below). */ prodTrafficRoute: outputs.codedeploy.DeploymentGroupLoadBalancerInfoTargetGroupPairInfoProdTrafficRoute; /** * Configuration blocks for a target group within a target group pair (documented below). */ targetGroups: outputs.codedeploy.DeploymentGroupLoadBalancerInfoTargetGroupPairInfoTargetGroup[]; /** * Configuration block for the test traffic route (documented below). */ testTrafficRoute?: outputs.codedeploy.DeploymentGroupLoadBalancerInfoTargetGroupPairInfoTestTrafficRoute; } interface DeploymentGroupLoadBalancerInfoTargetGroupPairInfoProdTrafficRoute { /** * List of ARNs of the load balancer listeners. Must contain exactly one listener ARN. */ listenerArns: string[]; } interface DeploymentGroupLoadBalancerInfoTargetGroupPairInfoTargetGroup { /** * Name of the target group. */ name: string; } interface DeploymentGroupLoadBalancerInfoTargetGroupPairInfoTestTrafficRoute { /** * List of ARNs of the load balancer listeners. */ listenerArns: string[]; } interface DeploymentGroupOnPremisesInstanceTagFilter { /** * The key of the tag filter. */ key?: string; /** * The type of the tag filter, either `KEY_ONLY`, `VALUE_ONLY`, or `KEY_AND_VALUE`. */ type?: string; /** * The value of the tag filter. */ value?: string; } interface DeploymentGroupTriggerConfiguration { /** * The event type or types for which notifications are triggered. Some values that are supported: `DeploymentStart`, `DeploymentSuccess`, `DeploymentFailure`, `DeploymentStop`, `DeploymentRollback`, `InstanceStart`, `InstanceSuccess`, `InstanceFailure`. See [the CodeDeploy documentation](http://docs.aws.amazon.com/codedeploy/latest/userguide/monitoring-sns-event-notifications-create-trigger.html) for all possible values. */ triggerEvents: string[]; /** * The name of the notification trigger. */ triggerName: string; /** * The ARN of the SNS topic through which notifications are sent. */ triggerTargetArn: string; } } export declare namespace codeguruprofiler { interface GetProfilingGroupAgentOrchestrationConfig { profilingEnabled: boolean; } interface GetProfilingGroupProfilingStatus { latestAgentOrchestratedAt: string; latestAgentProfileReportedAt: string; latestAggregatedProfiles: outputs.codeguruprofiler.GetProfilingGroupProfilingStatusLatestAggregatedProfile[]; } interface GetProfilingGroupProfilingStatusLatestAggregatedProfile { period: string; start: string; } interface ProfilingGroupAgentOrchestrationConfig { /** * (Required) Boolean that specifies whether the profiling agent collects profiling data or */ profilingEnabled: boolean; } } export declare namespace codegurureviewer { interface RepositoryAssociationKmsKeyDetails { /** * Encryption option for a repository association. It is either owned by KMS (`AWS_OWNED_CMK`) or customer managed (`CUSTOMER_MANAGED_CMK`). */ encryptionOption?: string; /** * The ID of the AWS KMS key that is associated with a repository association. */ kmsKeyId?: string; } interface RepositoryAssociationRepository { bitbucket?: outputs.codegurureviewer.RepositoryAssociationRepositoryBitbucket; codecommit?: outputs.codegurureviewer.RepositoryAssociationRepositoryCodecommit; githubEnterpriseServer?: outputs.codegurureviewer.RepositoryAssociationRepositoryGithubEnterpriseServer; s3Bucket?: outputs.codegurureviewer.RepositoryAssociationRepositoryS3Bucket; } interface RepositoryAssociationRepositoryBitbucket { /** * ARN of an AWS CodeStar Connections connection. */ connectionArn: string; /** * The name of the third party source repository. */ name: string; /** * The username for the account that owns the repository. */ owner: string; } interface RepositoryAssociationRepositoryCodecommit { /** * The name of the AWS CodeCommit repository. */ name: string; } interface RepositoryAssociationRepositoryGithubEnterpriseServer { /** * ARN of an AWS CodeStar Connections connection. */ connectionArn: string; /** * The name of the third party source repository. */ name: string; /** * The username for the account that owns the repository. */ owner: string; } interface RepositoryAssociationRepositoryS3Bucket { /** * The name of the S3 bucket used for associating a new S3 repository. Note: The name must begin with `codeguru-reviewer-`. */ bucketName: string; /** * The name of the repository in the S3 bucket. */ name: string; } interface RepositoryAssociationS3RepositoryDetail { /** * The name of the S3 bucket used for associating a new S3 repository. Note: The name must begin with `codeguru-reviewer-`. */ bucketName: string; codeArtifacts: outputs.codegurureviewer.RepositoryAssociationS3RepositoryDetailCodeArtifact[]; } interface RepositoryAssociationS3RepositoryDetailCodeArtifact { buildArtifactsObjectKey: string; sourceCodeArtifactsObjectKey: string; } } export declare namespace codepipeline { interface CustomActionTypeConfigurationProperty { /** * The description of the action configuration property. */ description?: string; /** * Whether the configuration property is a key. */ key: boolean; /** * The name of the action configuration property. */ name: string; /** * Indicates that the property will be used in conjunction with PollForJobs. */ queryable?: boolean; /** * Whether the configuration property is a required value. */ required: boolean; /** * Whether the configuration property is secret. */ secret: boolean; /** * The type of the configuration property. Valid values: `String`, `Number`, `Boolean` */ type?: string; } interface CustomActionTypeInputArtifactDetails { /** * The maximum number of artifacts allowed for the action type. Min: 0, Max: 5 */ maximumCount: number; /** * The minimum number of artifacts allowed for the action type. Min: 0, Max: 5 */ minimumCount: number; } interface CustomActionTypeOutputArtifactDetails { /** * The maximum number of artifacts allowed for the action type. Min: 0, Max: 5 */ maximumCount: number; /** * The minimum number of artifacts allowed for the action type. Min: 0, Max: 5 */ minimumCount: number; } interface CustomActionTypeSettings { /** * The URL returned to the AWS CodePipeline console that provides a deep link to the resources of the external system. */ entityUrlTemplate?: string; /** * The URL returned to the AWS CodePipeline console that contains a link to the top-level landing page for the external system. */ executionUrlTemplate?: string; /** * The URL returned to the AWS CodePipeline console that contains a link to the page where customers can update or change the configuration of the external action. */ revisionUrlTemplate?: string; /** * The URL of a sign-up page where users can sign up for an external service and perform initial configuration of the action provided by that service. */ thirdPartyConfigurationUrl?: string; } interface PipelineArtifactStore { /** * Encryption key block AWS CodePipeline uses to encrypt the data in the artifact store, such as a KMS key. If you don't specify a key, AWS CodePipeline uses the default key for S3. An `encryptionKey` block is documented below. */ encryptionKey?: outputs.codepipeline.PipelineArtifactStoreEncryptionKey; /** * The location where AWS CodePipeline stores artifacts for a pipeline; currently only `S3` is supported. */ location: string; /** * The region where the artifact store is located. Required for a cross-region CodePipeline, do not provide for a single-region CodePipeline. */ region?: string; /** * The type of the artifact store, such as Amazon S3 */ type: string; } interface PipelineArtifactStoreEncryptionKey { /** * The KMS key ARN or ID */ id: string; /** * The type of key; currently only `KMS` is supported */ type: string; } interface PipelineStage { /** * The action(s) to include in the stage. Defined as an `action` block below */ actions: outputs.codepipeline.PipelineStageAction[]; /** * The method to use when a stage allows entry. For example, configuring this field for conditions will allow entry to the stage when the conditions are met. */ beforeEntry?: outputs.codepipeline.PipelineStageBeforeEntry; /** * The name of the stage. */ name: string; /** * The method to use when a stage has not completed successfully. For example, configuring this field for rollback will roll back a failed stage automatically to the last successful pipeline execution in the stage. */ onFailure?: outputs.codepipeline.PipelineStageOnFailure; /** * The method to use when a stage has succeeded. For example, configuring this field for conditions will allow the stage to succeed when the conditions are met. */ onSuccess?: outputs.codepipeline.PipelineStageOnSuccess; } interface PipelineStageAction { /** * A category defines what kind of action can be taken in the stage, and constrains the provider type for the action. Possible values are `Approval`, `Build`, `Deploy`, `Invoke`, `Source`, `Compute` and `Test`. */ category: string; /** * A list of shell commands to run with the compute action. */ commands?: string[]; /** * A map of the action declaration's configuration. Configurations options for action types and providers can be found in the [Pipeline Structure Reference](http://docs.aws.amazon.com/codepipeline/latest/userguide/reference-pipeline-structure.html#action-requirements) and [Action Structure Reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference.html) documentation. Note: The `DetectChanges` parameter (optional, default value is true) in the `configuration` section causes CodePipeline to automatically start your pipeline upon new commits. Please refer to AWS Documentation for more details: https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference-CodestarConnectionSource.html#action-reference-CodestarConnectionSource-config. */ configuration?: { [key: string]: string; }; /** * A list of artifact names to be worked on. */ inputArtifacts?: string[]; /** * The action declaration's name. */ name: string; /** * The namespace all output variables will be accessed from. */ namespace?: string; /** * A list of artifact names to output. Output artifact names must be unique within a pipeline. If the action is `Compute`, this argument is ignored. */ outputArtifacts?: string[]; /** * A block of output artifacts for the compute action. If the action is not `Compute`, this argument is ignored. */ outputArtifactsForComputeActions?: outputs.codepipeline.PipelineStageActionOutputArtifactsForComputeAction[]; /** * A list of variables that are to be exported from the compute action. */ outputVariables?: string[]; /** * The creator of the action being called. Possible values are `AWS`, `Custom` and `ThirdParty`. */ owner: string; /** * The provider of the service being called by the action. Valid providers are determined by the action category. Provider names are listed in the [Action Structure Reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference.html) documentation. */ provider: string; /** * The region in which to run the action. */ region: string; /** * The ARN of the IAM service role that will perform the declared action. This is assumed through the roleArn for the pipeline. */ roleArn?: string; /** * The order in which actions are run. */ runOrder: number; /** * The action timeout for the rule. */ timeoutInMinutes?: number; /** * A string that identifies the action type. */ version: string; } interface PipelineStageActionOutputArtifactsForComputeAction { /** * A list of the files to associate with the output artifact that will be exported from the compute action. */ files?: string[]; /** * The name of the output artifact. */ name: string; } interface PipelineStageBeforeEntry { /** * The conditions that are configured as entry condition. Defined as a `condition` block below. */ condition: outputs.codepipeline.PipelineStageBeforeEntryCondition; } interface PipelineStageBeforeEntryCondition { /** * The action to be done when the condition is met. For example, rolling back an execution for a failure condition. Possible values are `ROLLBACK`, `FAIL`, `RETRY` and `SKIP`. */ result?: string; /** * The rules that make up the condition. Defined as a `rule` block below. */ rules: outputs.codepipeline.PipelineStageBeforeEntryConditionRule[]; } interface PipelineStageBeforeEntryConditionRule { /** * The shell commands to run with your commands rule in CodePipeline. All commands are supported except multi-line formats. */ commands?: string[]; /** * The action configuration fields for the rule. Configurations options for rule types and providers can be found in the [Rule structure reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/rule-reference.html). */ configuration?: { [key: string]: string; }; /** * The list of the input artifacts fields for the rule, such as specifying an input file for the rule. */ inputArtifacts?: string[]; /** * The name of the rule that is created for the condition, such as `VariableCheck`. */ name: string; /** * The Region for the condition associated with the rule. */ region?: string; /** * The pipeline role ARN associated with the rule. */ roleArn?: string; /** * The ID for the rule type, which is made up of the combined values for `category`, `owner`, `provider`, and `version`. Defined as an `ruleTypeId` block below. */ ruleTypeId: outputs.codepipeline.PipelineStageBeforeEntryConditionRuleRuleTypeId; /** * The action timeout for the rule. */ timeoutInMinutes?: number; } interface PipelineStageBeforeEntryConditionRuleRuleTypeId { /** * A category defines what kind of rule can be run in the stage, and constrains the provider type for the rule. The valid category is `Rule`. */ category: string; /** * The creator of the rule being called. The valid value for the Owner field in the rule category is `AWS`. */ owner?: string; /** * The rule provider, such as the DeploymentWindow rule. For a list of rule provider names, see the rules listed in the [AWS CodePipeline rule reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/rule-reference.html). */ provider: string; /** * A string that describes the rule version. */ version?: string; } interface PipelineStageOnFailure { /** * The conditions that are failure conditions. Defined as a `condition` block below. */ condition?: outputs.codepipeline.PipelineStageOnFailureCondition; /** * The conditions that are configured as failure conditions. Possible values are `ROLLBACK`, `FAIL`, `RETRY` and `SKIP`. */ result?: string; /** * The retry configuration specifies automatic retry for a failed stage, along with the configured retry mode. Defined as a `retryConfiguration` block below. */ retryConfiguration?: outputs.codepipeline.PipelineStageOnFailureRetryConfiguration; } interface PipelineStageOnFailureCondition { /** * The action to be done when the condition is met. For example, rolling back an execution for a failure condition. Possible values are `ROLLBACK`, `FAIL`, `RETRY` and `SKIP`. */ result?: string; /** * The rules that make up the condition. Defined as a `rule` block below. */ rules: outputs.codepipeline.PipelineStageOnFailureConditionRule[]; } interface PipelineStageOnFailureConditionRule { /** * The shell commands to run with your commands rule in CodePipeline. All commands are supported except multi-line formats. */ commands?: string[]; /** * The action configuration fields for the rule. Configurations options for rule types and providers can be found in the [Rule structure reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/rule-reference.html). */ configuration?: { [key: string]: string; }; /** * The list of the input artifacts fields for the rule, such as specifying an input file for the rule. */ inputArtifacts?: string[]; /** * The name of the rule that is created for the condition, such as `VariableCheck`. */ name: string; /** * The Region for the condition associated with the rule. */ region?: string; /** * The pipeline role ARN associated with the rule. */ roleArn?: string; /** * The ID for the rule type, which is made up of the combined values for `category`, `owner`, `provider`, and `version`. Defined as an `ruleTypeId` block below. */ ruleTypeId: outputs.codepipeline.PipelineStageOnFailureConditionRuleRuleTypeId; /** * The action timeout for the rule. */ timeoutInMinutes?: number; } interface PipelineStageOnFailureConditionRuleRuleTypeId { /** * A category defines what kind of rule can be run in the stage, and constrains the provider type for the rule. The valid category is `Rule`. */ category: string; /** * The creator of the rule being called. The valid value for the Owner field in the rule category is `AWS`. */ owner?: string; /** * The rule provider, such as the DeploymentWindow rule. For a list of rule provider names, see the rules listed in the [AWS CodePipeline rule reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/rule-reference.html). */ provider: string; /** * A string that describes the rule version. */ version?: string; } interface PipelineStageOnFailureRetryConfiguration { /** * The method that you want to configure for automatic stage retry on stage failure. You can specify to retry only failed action in the stage or all actions in the stage. Possible values are `FAILED_ACTIONS` and `ALL_ACTIONS`. */ retryMode?: string; } interface PipelineStageOnSuccess { /** * The conditions that are success conditions. Defined as a `condition` block below. */ condition: outputs.codepipeline.PipelineStageOnSuccessCondition; } interface PipelineStageOnSuccessCondition { /** * The action to be done when the condition is met. For example, rolling back an execution for a failure condition. Possible values are `ROLLBACK`, `FAIL`, `RETRY` and `SKIP`. */ result?: string; /** * The rules that make up the condition. Defined as a `rule` block below. */ rules: outputs.codepipeline.PipelineStageOnSuccessConditionRule[]; } interface PipelineStageOnSuccessConditionRule { /** * The shell commands to run with your commands rule in CodePipeline. All commands are supported except multi-line formats. */ commands?: string[]; /** * The action configuration fields for the rule. Configurations options for rule types and providers can be found in the [Rule structure reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/rule-reference.html). */ configuration?: { [key: string]: string; }; /** * The list of the input artifacts fields for the rule, such as specifying an input file for the rule. */ inputArtifacts?: string[]; /** * The name of the rule that is created for the condition, such as `VariableCheck`. */ name: string; /** * The Region for the condition associated with the rule. */ region?: string; /** * The pipeline role ARN associated with the rule. */ roleArn?: string; /** * The ID for the rule type, which is made up of the combined values for `category`, `owner`, `provider`, and `version`. Defined as an `ruleTypeId` block below. */ ruleTypeId: outputs.codepipeline.PipelineStageOnSuccessConditionRuleRuleTypeId; /** * The action timeout for the rule. */ timeoutInMinutes?: number; } interface PipelineStageOnSuccessConditionRuleRuleTypeId { /** * A category defines what kind of rule can be run in the stage, and constrains the provider type for the rule. The valid category is `Rule`. */ category: string; /** * The creator of the rule being called. The valid value for the Owner field in the rule category is `AWS`. */ owner?: string; /** * The rule provider, such as the DeploymentWindow rule. For a list of rule provider names, see the rules listed in the [AWS CodePipeline rule reference](https://docs.aws.amazon.com/codepipeline/latest/userguide/rule-reference.html). */ provider: string; /** * A string that describes the rule version. */ version?: string; } interface PipelineTrigger { /** * Provides the filter criteria and the source stage for the repository event that starts the pipeline. For more information, refer to the [AWS documentation](https://docs.aws.amazon.com/codepipeline/latest/userguide/pipelines-filter.html). A `gitConfiguration` block is documented below. */ gitConfiguration: outputs.codepipeline.PipelineTriggerGitConfiguration; /** * The source provider for the event. Possible value is `CodeStarSourceConnection`. */ providerType: string; } interface PipelineTriggerAll { /** * Provides the filter criteria and the source stage for the repository event that starts the pipeline. For more information, refer to the [AWS documentation](https://docs.aws.amazon.com/codepipeline/latest/userguide/pipelines-filter.html). A `gitConfiguration` block is documented below. */ gitConfigurations: outputs.codepipeline.PipelineTriggerAllGitConfiguration[]; /** * The source provider for the event. Possible value is `CodeStarSourceConnection`. */ providerType: string; } interface PipelineTriggerAllGitConfiguration { /** * The field where the repository event that will start the pipeline is specified as pull requests. A `pullRequest` block is documented below. */ pullRequests: outputs.codepipeline.PipelineTriggerAllGitConfigurationPullRequest[]; /** * The field where the repository event that will start the pipeline, such as pushing Git tags, is specified with details. A `push` block is documented below. */ pushes: outputs.codepipeline.PipelineTriggerAllGitConfigurationPush[]; /** * The name of the pipeline source action where the trigger configuration, such as Git tags, is specified. The trigger configuration will start the pipeline upon the specified change only. */ sourceActionName: string; } interface PipelineTriggerAllGitConfigurationPullRequest { /** * The field that specifies to filter on branches for the pull request trigger configuration. A `branches` block is documented below. */ branches: outputs.codepipeline.PipelineTriggerAllGitConfigurationPullRequestBranch[]; /** * A list that specifies which pull request events to filter on (opened, updated, closed) for the trigger configuration. Possible values are `OPEN`, ` UPDATED ` and `CLOSED`. */ events: string[]; /** * The field that specifies to filter on file paths for the pull request trigger configuration. A `filePaths` block is documented below. */ filePaths: outputs.codepipeline.PipelineTriggerAllGitConfigurationPullRequestFilePath[]; } interface PipelineTriggerAllGitConfigurationPullRequestBranch { /** * A list of patterns of Git branches that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes: string[]; /** * A list of patterns of Git branches that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes: string[]; } interface PipelineTriggerAllGitConfigurationPullRequestFilePath { /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes: string[]; /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes: string[]; } interface PipelineTriggerAllGitConfigurationPush { /** * The field that specifies to filter on branches for the push trigger configuration. A `branches` block is documented below. */ branches: outputs.codepipeline.PipelineTriggerAllGitConfigurationPushBranch[]; /** * The field that specifies to filter on file paths for the push trigger configuration. A `filePaths` block is documented below. */ filePaths: outputs.codepipeline.PipelineTriggerAllGitConfigurationPushFilePath[]; /** * The field that contains the details for the Git tags trigger configuration. A `tags` block is documented below. */ tags: outputs.codepipeline.PipelineTriggerAllGitConfigurationPushTag[]; } interface PipelineTriggerAllGitConfigurationPushBranch { /** * A list of patterns of Git branches that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes: string[]; /** * A list of patterns of Git branches that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes: string[]; } interface PipelineTriggerAllGitConfigurationPushFilePath { /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes: string[]; /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes: string[]; } interface PipelineTriggerAllGitConfigurationPushTag { /** * A list of patterns of Git tags that, when pushed, are to be excluded from starting the pipeline. */ excludes: string[]; /** * A list of patterns of Git tags that, when pushed, are to be included as criteria that starts the pipeline. */ includes: string[]; } interface PipelineTriggerGitConfiguration { /** * The field where the repository event that will start the pipeline is specified as pull requests. A `pullRequest` block is documented below. */ pullRequests?: outputs.codepipeline.PipelineTriggerGitConfigurationPullRequest[]; /** * The field where the repository event that will start the pipeline, such as pushing Git tags, is specified with details. A `push` block is documented below. */ pushes?: outputs.codepipeline.PipelineTriggerGitConfigurationPush[]; /** * The name of the pipeline source action where the trigger configuration, such as Git tags, is specified. The trigger configuration will start the pipeline upon the specified change only. */ sourceActionName: string; } interface PipelineTriggerGitConfigurationPullRequest { /** * The field that specifies to filter on branches for the pull request trigger configuration. A `branches` block is documented below. */ branches?: outputs.codepipeline.PipelineTriggerGitConfigurationPullRequestBranches; /** * A list that specifies which pull request events to filter on (opened, updated, closed) for the trigger configuration. Possible values are `OPEN`, ` UPDATED ` and `CLOSED`. */ events?: string[]; /** * The field that specifies to filter on file paths for the pull request trigger configuration. A `filePaths` block is documented below. */ filePaths?: outputs.codepipeline.PipelineTriggerGitConfigurationPullRequestFilePaths; } interface PipelineTriggerGitConfigurationPullRequestBranches { /** * A list of patterns of Git branches that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes?: string[]; /** * A list of patterns of Git branches that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes?: string[]; } interface PipelineTriggerGitConfigurationPullRequestFilePaths { /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes?: string[]; /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes?: string[]; } interface PipelineTriggerGitConfigurationPush { /** * The field that specifies to filter on branches for the push trigger configuration. A `branches` block is documented below. */ branches?: outputs.codepipeline.PipelineTriggerGitConfigurationPushBranches; /** * The field that specifies to filter on file paths for the push trigger configuration. A `filePaths` block is documented below. */ filePaths?: outputs.codepipeline.PipelineTriggerGitConfigurationPushFilePaths; /** * The field that contains the details for the Git tags trigger configuration. A `tags` block is documented below. */ tags?: outputs.codepipeline.PipelineTriggerGitConfigurationPushTags; } interface PipelineTriggerGitConfigurationPushBranches { /** * A list of patterns of Git branches that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes?: string[]; /** * A list of patterns of Git branches that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes?: string[]; } interface PipelineTriggerGitConfigurationPushFilePaths { /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be excluded from starting the pipeline. */ excludes?: string[]; /** * A list of patterns of Git repository file paths that, when a commit is pushed, are to be included as criteria that starts the pipeline. */ includes?: string[]; } interface PipelineTriggerGitConfigurationPushTags { /** * A list of patterns of Git tags that, when pushed, are to be excluded from starting the pipeline. */ excludes?: string[]; /** * A list of patterns of Git tags that, when pushed, are to be included as criteria that starts the pipeline. */ includes?: string[]; } interface PipelineVariable { /** * The default value of a pipeline-level variable. */ defaultValue?: string; /** * The description of a pipeline-level variable. */ description?: string; /** * The name of a pipeline-level variable. */ name: string; } interface WebhookAuthenticationConfiguration { /** * A valid CIDR block for `IP` filtering. Required for `IP`. */ allowedIpRange?: string; /** * The shared secret for the GitHub repository webhook. Set this as `secret` in your `githubRepositoryWebhook`'s `configuration` block. Required for `GITHUB_HMAC`. */ secretToken?: string; } interface WebhookFilter { /** * The [JSON path](https://github.com/json-path/JsonPath) to filter on. */ jsonPath: string; /** * The value to match on (e.g., `refs/heads/{Branch}`). See [AWS docs](https://docs.aws.amazon.com/codepipeline/latest/APIReference/API_WebhookFilterRule.html) for details. */ matchEquals: string; } } export declare namespace codestarconnections { interface HostVpcConfiguration { /** * ID of the security group or security groups associated with the Amazon VPC connected to the infrastructure where your provider type is installed. */ securityGroupIds: string[]; /** * The ID of the subnet or subnets associated with the Amazon VPC connected to the infrastructure where your provider type is installed. */ subnetIds: string[]; /** * Value of the TLS certificate associated with the infrastructure where your provider type is installed. */ tlsCertificate?: string; /** * The ID of the Amazon VPC connected to the infrastructure where your provider type is installed. */ vpcId: string; } } export declare namespace codestarnotifications { interface NotificationRuleTarget { /** * The ARN of the Amazon Q Developer in chat applications topic or Amazon Q Developer in chat applications client. */ address: string; /** * The status of the notification rule. Possible values are `ENABLED` and `DISABLED`, default is `ENABLED`. */ status: string; /** * The type of the notification target. Valid values are `SNS`, `AWSChatbotSlack`, and `AWSChatbotMicrosoftTeams`. Default value is `SNS`. */ type?: string; } } export declare namespace cognito { interface GetIdentityPoolCognitoIdentityProvider { clientId: string; providerName: string; serverSideTokenCheck: boolean; } interface GetUserGroupsGroup { /** * Description of the user group. */ description: string; /** * Name of the user group. */ groupName: string; /** * Precedence of the user group. */ precedence: number; /** * ARN of the IAM role to be associated with the user group. */ roleArn: string; } interface GetUserPoolAccountRecoverySetting { recoveryMechanisms: outputs.cognito.GetUserPoolAccountRecoverySettingRecoveryMechanism[]; } interface GetUserPoolAccountRecoverySettingRecoveryMechanism { /** * - Name of the attribute. */ name: string; /** * - Priority of this mechanism in the recovery process (lower numbers are higher priority). */ priority: number; } interface GetUserPoolAdminCreateUserConfig { /** * - Whether only admins can create users. */ allowAdminCreateUserOnly: boolean; inviteMessageTemplates: outputs.cognito.GetUserPoolAdminCreateUserConfigInviteMessageTemplate[]; /** * - Number of days an unconfirmed user account remains valid. * * invite_message_template - Templates for invitation messages. */ unusedAccountValidityDays: number; } interface GetUserPoolAdminCreateUserConfigInviteMessageTemplate { /** * - Email message content. */ emailMessage: string; /** * - Email message subject. */ emailSubject: string; /** * - SMS message content. */ smsMessage: string; } interface GetUserPoolClientAnalyticsConfiguration { /** * (Optional) Application ARN for an AWS End User Messaging application. Conflicts with `externalId` and `roleArn`. */ applicationArn: string; /** * (Optional) Application ID for an AWS End User Messaging application. */ applicationId: string; /** * (Optional) ID for the Analytics Configuration. Conflicts with `applicationArn`. */ externalId: string; /** * (Optional) ARN of an IAM role that authorizes Amazon Cognito to publish events to AWS End User Messaging analytics. Conflicts with `applicationArn`. */ roleArn: string; /** * (Optional) If set to `true`, Amazon Cognito will include user data in the events it publishes to AWS End User Messaging analytics. */ userDataShared: boolean; } interface GetUserPoolClientRefreshTokenRotation { /** * (Required) The state of refresh token rotation for the current app client. Valid values are `ENABLED` or `DISABLED`. */ feature: string; /** * (Optional) A period of time in seconds that the user has to use the old refresh token before it is invalidated. Valid values are between `0` and `60`. */ retryGracePeriodSeconds: number; } interface GetUserPoolClientTokenValidityUnit { /** * (Optional) Time unit in for the value in `accessTokenValidity`, defaults to `hours`. */ accessToken: string; /** * (Optional) Time unit in for the value in `idTokenValidity`, defaults to `hours`. */ idToken: string; /** * (Optional) Time unit in for the value in `refreshTokenValidity`, defaults to `days`. */ refreshToken: string; } interface GetUserPoolDeviceConfiguration { /** * - Whether a challenge is required on new devices. */ challengeRequiredOnNewDevice: boolean; /** * - Whether devices are only remembered if the user prompts it. */ deviceOnlyRememberedOnUserPrompt: boolean; } interface GetUserPoolEmailConfiguration { /** * - Configuration set used for sending emails. */ configurationSet: string; /** * - Email sending account. */ emailSendingAccount: string; /** * - Email sender address. */ from: string; /** * - Reply-to email address. */ replyToEmailAddress: string; /** * - Source ARN for emails. */ sourceArn: string; } interface GetUserPoolLambdaConfig { createAuthChallenge: string; customEmailSenders: outputs.cognito.GetUserPoolLambdaConfigCustomEmailSender[]; customMessage: string; customSmsSenders: outputs.cognito.GetUserPoolLambdaConfigCustomSmsSender[]; defineAuthChallenge: string; kmsKeyId: string; postAuthentication: string; postConfirmation: string; preAuthentication: string; preSignUp: string; preTokenGeneration: string; preTokenGenerationConfigs: outputs.cognito.GetUserPoolLambdaConfigPreTokenGenerationConfig[]; userMigration: string; verifyAuthChallengeResponse: string; } interface GetUserPoolLambdaConfigCustomEmailSender { /** * - ARN of the Lambda function. */ lambdaArn: string; /** * - Version of the Lambda function. */ lambdaVersion: string; } interface GetUserPoolLambdaConfigCustomSmsSender { /** * - ARN of the Lambda function. */ lambdaArn: string; /** * - Version of the Lambda function. */ lambdaVersion: string; } interface GetUserPoolLambdaConfigPreTokenGenerationConfig { /** * - ARN of the Lambda function. */ lambdaArn: string; /** * - Version of the Lambda function. */ lambdaVersion: string; } interface GetUserPoolSchemaAttribute { /** * - Data type of the attribute (e.g., string, number). */ attributeDataType: string; /** * - Whether the attribute is for developer use only. */ developerOnlyAttribute: boolean; /** * - Whether the attribute can be changed after user creation. */ mutable: boolean; /** * - Name of the attribute. */ name: string; numberAttributeConstraints: outputs.cognito.GetUserPoolSchemaAttributeNumberAttributeConstraint[]; /** * - Whether the attribute is required during user registration. * * number_attribute_constraints - Constraints for numeric attributes. * * string_attribute_constraints - Constraints for string attributes. */ required: boolean; stringAttributeConstraints: outputs.cognito.GetUserPoolSchemaAttributeStringAttributeConstraint[]; } interface GetUserPoolSchemaAttributeNumberAttributeConstraint { /** * - Maximum allowed value. */ maxValue: string; /** * - Minimum allowed value. */ minValue: string; } interface GetUserPoolSchemaAttributeStringAttributeConstraint { /** * - Maximum allowed length. */ maxLength: string; /** * - Minimum allowed length. */ minLength: string; } interface GetUserPoolUserPoolAddOn { /** * A block of the threat protection configuration options for additional authentication types in your user pool, including custom authentication. Detailed below. */ advancedSecurityAdditionalFlows: outputs.cognito.GetUserPoolUserPoolAddOnAdvancedSecurityAdditionalFlow[]; /** * Mode for advanced security. */ advancedSecurityMode: string; } interface GetUserPoolUserPoolAddOnAdvancedSecurityAdditionalFlow { /** * Mode of threat protection operation in custom authentication. */ customAuthMode: string; } interface IdentityPoolCognitoIdentityProvider { /** * The client ID for the Amazon Cognito Identity User Pool. */ clientId?: string; /** * The provider name for an Amazon Cognito Identity User Pool. */ providerName?: string; /** * Whether server-side token validation is enabled for the identity provider’s token or not. */ serverSideTokenCheck?: boolean; } interface IdentityPoolRoleAttachmentRoleMapping { /** * Specifies the action to be taken if either no rules match the claim value for the Rules type, or there is no cognito:preferred_role claim and there are multiple cognito:roles matches for the Token type. `Required` if you specify Token or Rules as the Type. */ ambiguousRoleResolution?: string; /** * A string identifying the identity provider, for example, "graph.facebook.com" or "cognito-idp.us-east-1.amazonaws.com/us-east-1_abcdefghi:app_client_id". Depends on `cognitoIdentityProviders` set on `aws.cognito.IdentityPool` resource or a `aws.cognito.IdentityProvider` resource. */ identityProvider: string; /** * The Rules Configuration to be used for mapping users to roles. You can specify up to 25 rules per identity provider. Rules are evaluated in order. The first one to match specifies the role. */ mappingRules?: outputs.cognito.IdentityPoolRoleAttachmentRoleMappingMappingRule[]; /** * The role mapping type. */ type: string; } interface IdentityPoolRoleAttachmentRoleMappingMappingRule { /** * The claim name that must be present in the token, for example, "isAdmin" or "paid". */ claim: string; /** * The match condition that specifies how closely the claim value in the IdP token must match Value. */ matchType: string; /** * The role ARN. */ roleArn: string; /** * A brief string that the claim must match, for example, "paid" or "yes". */ value: string; } interface LogDeliveryConfigurationLogConfiguration { /** * Configuration for CloudWatch Logs delivery. See CloudWatch Logs Configuration below. */ cloudWatchLogsConfiguration?: outputs.cognito.LogDeliveryConfigurationLogConfigurationCloudWatchLogsConfiguration; /** * The event source to configure logging for. Valid values are `userNotification` and `userAuthEvents`. */ eventSource: string; /** * Configuration for Kinesis Data Firehose delivery. See Firehose Configuration below. */ firehoseConfiguration?: outputs.cognito.LogDeliveryConfigurationLogConfigurationFirehoseConfiguration; /** * The log level to set for the event source. Valid values are `ERROR` and `INFO`. */ logLevel: string; /** * Configuration for S3 delivery. See S3 Configuration below. * * > **Note:** At least one destination configuration (`cloudWatchLogsConfiguration`, `firehoseConfiguration`, or `s3Configuration`) must be specified for each log configuration. */ s3Configuration?: outputs.cognito.LogDeliveryConfigurationLogConfigurationS3Configuration; } interface LogDeliveryConfigurationLogConfigurationCloudWatchLogsConfiguration { /** * The ARN of the CloudWatch Logs log group to which the logs should be delivered. */ logGroupArn?: string; } interface LogDeliveryConfigurationLogConfigurationFirehoseConfiguration { /** * The ARN of the Kinesis Data Firehose delivery stream to which the logs should be delivered. */ streamArn?: string; } interface LogDeliveryConfigurationLogConfigurationS3Configuration { /** * The ARN of the S3 bucket to which the logs should be delivered. */ bucketArn?: string; } interface ManagedLoginBrandingAsset { /** * Image file, in Base64-encoded binary. */ bytes?: string; /** * Category that the image corresponds to. See [AWS documentation](https://docs.aws.amazon.com/cognito-user-identity-pools/latest/APIReference/API_AssetType.html#CognitoUserPools-Type-AssetType-Category) for valid values. */ category: string; /** * Display-mode target of the asset. Valid values: `LIGHT`, `DARK`, `DYNAMIC`. */ colorMode: string; extension: string; /** * Asset ID. */ resourceId?: string; } interface ManagedUserPoolClientAnalyticsConfiguration { /** * Application ARN for an AWS End User Messaging application. It conflicts with `externalId` and `roleArn`. */ applicationArn?: string; /** * Unique identifier for an AWS End User Messaging application. */ applicationId?: string; /** * ID for the Analytics Configuration and conflicts with `applicationArn`. */ externalId?: string; /** * ARN of an IAM role that authorizes Amazon Cognito to publish events to AWS End User Messaging analytics. It conflicts with `applicationArn`. */ roleArn: string; /** * If `userDataShared` is set to `true`, Amazon Cognito will include user data in the events it publishes to AWS End User Messaging analytics. */ userDataShared: boolean; } interface ManagedUserPoolClientRefreshTokenRotation { /** * The state of refresh token rotation for the current app client. Valid values are `ENABLED` or `DISABLED`. */ feature: string; /** * A period of time in seconds that the user has to use the old refresh token before it is invalidated. Valid values are between `0` and `60`. */ retryGracePeriodSeconds?: number; } interface ManagedUserPoolClientTokenValidityUnits { /** * Time unit for the value in `accessTokenValidity` and defaults to `hours`. */ accessToken: string; /** * Time unit for the value in `idTokenValidity`, and it defaults to `hours`. */ idToken: string; /** * Time unit for the value in `refreshTokenValidity` and defaults to `days`. */ refreshToken: string; } interface ResourceServerScope { /** * The scope description. */ scopeDescription: string; /** * The scope name. */ scopeName: string; } interface RiskConfigurationAccountTakeoverRiskConfiguration { /** * Account takeover risk configuration actions. See details below. */ actions: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationActions; /** * The notify configuration used to construct email notifications. See details below. */ notifyConfiguration?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfiguration; } interface RiskConfigurationAccountTakeoverRiskConfigurationActions { /** * Action to take for a high risk. See action block below. */ highAction?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationActionsHighAction; /** * Action to take for a low risk. See action block below. */ lowAction?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationActionsLowAction; /** * Action to take for a medium risk. See action block below. */ mediumAction?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationActionsMediumAction; } interface RiskConfigurationAccountTakeoverRiskConfigurationActionsHighAction { eventAction: string; /** * Whether to send a notification. */ notify: boolean; } interface RiskConfigurationAccountTakeoverRiskConfigurationActionsLowAction { eventAction: string; /** * Whether to send a notification. */ notify: boolean; } interface RiskConfigurationAccountTakeoverRiskConfigurationActionsMediumAction { eventAction: string; /** * Whether to send a notification. */ notify: boolean; } interface RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfiguration { /** * Email template used when a detected risk event is blocked. See notify email type below. */ blockEmail?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfigurationBlockEmail; /** * The email address that is sending the email. The address must be either individually verified with Amazon Simple Email Service, or from a domain that has been verified with Amazon SES. */ from?: string; /** * The multi-factor authentication (MFA) email template used when MFA is challenged as part of a detected risk. See notify email type below. */ mfaEmail?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfigurationMfaEmail; /** * The email template used when a detected risk event is allowed. See notify email type below. */ noActionEmail?: outputs.cognito.RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfigurationNoActionEmail; /** * The destination to which the receiver of an email should reply to. */ replyTo?: string; /** * ARN of the identity that is associated with the sending authorization policy. This identity permits Amazon Cognito to send for the email address specified in the From parameter. */ sourceArn: string; } interface RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfigurationBlockEmail { /** * The email HTML body. */ htmlBody: string; /** * The email subject. */ subject: string; /** * The email text body. */ textBody: string; } interface RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfigurationMfaEmail { /** * The email HTML body. */ htmlBody: string; /** * The email subject. */ subject: string; /** * The email text body. */ textBody: string; } interface RiskConfigurationAccountTakeoverRiskConfigurationNotifyConfigurationNoActionEmail { /** * The email HTML body. */ htmlBody: string; /** * The email subject. */ subject: string; /** * The email text body. */ textBody: string; } interface RiskConfigurationCompromisedCredentialsRiskConfiguration { /** * The compromised credentials risk configuration actions. See details below. */ actions: outputs.cognito.RiskConfigurationCompromisedCredentialsRiskConfigurationActions; /** * Perform the action for these events. The default is to perform all events if no event filter is specified. Valid values are `SIGN_IN`, `PASSWORD_CHANGE`, and `SIGN_UP`. */ eventFilters: string[]; } interface RiskConfigurationCompromisedCredentialsRiskConfigurationActions { /** * The event action. Valid values are `BLOCK` or `NO_ACTION`. */ eventAction: string; } interface RiskConfigurationRiskExceptionConfiguration { /** * Overrides the risk decision to always block the pre-authentication requests. * The IP range is in CIDR notation, a compact representation of an IP address and its routing prefix. * Can contain a maximum of 200 items. */ blockedIpRangeLists?: string[]; /** * Risk detection isn't performed on the IP addresses in this range list. * The IP range is in CIDR notation. * Can contain a maximum of 200 items. */ skippedIpRangeLists?: string[]; } interface UserPoolAccountRecoverySetting { /** * List of Account Recovery Options of the following structure: */ recoveryMechanisms: outputs.cognito.UserPoolAccountRecoverySettingRecoveryMechanism[]; } interface UserPoolAccountRecoverySettingRecoveryMechanism { /** * Recovery method for a user. Can be of the following: `verifiedEmail`, `verifiedPhoneNumber`, and `adminOnly`. */ name: string; /** * Positive integer specifying priority of a method with 1 being the highest priority. */ priority: number; } interface UserPoolAdminCreateUserConfig { /** * Set to True if only the administrator is allowed to create user profiles. Set to False if users can sign themselves up via an app. */ allowAdminCreateUserOnly?: boolean; /** * Invite message template structure. Detailed below. */ inviteMessageTemplate?: outputs.cognito.UserPoolAdminCreateUserConfigInviteMessageTemplate; } interface UserPoolAdminCreateUserConfigInviteMessageTemplate { /** * Message template for email messages. Must contain `{username}` and `{####}` placeholders, for username and temporary password, respectively. */ emailMessage?: string; /** * Subject line for email messages. */ emailSubject?: string; /** * Message template for SMS messages. Must contain `{username}` and `{####}` placeholders, for username and temporary password, respectively. */ smsMessage?: string; } interface UserPoolClientAnalyticsConfiguration { /** * Application ARN for an AWS End User Messaging application. Conflicts with `externalId` and `roleArn`. */ applicationArn?: string; /** * Application ID for an AWS End User Messaging application. */ applicationId?: string; /** * ID for the Analytics Configuration. Conflicts with `applicationArn`. */ externalId?: string; /** * ARN of an IAM role that authorizes Amazon Cognito to publish events to AWS End User Messaging analytics. Conflicts with `applicationArn`. */ roleArn: string; /** * If set to `true`, Amazon Cognito will include user data in the events it publishes to AWS End User Messaging analytics. */ userDataShared: boolean; } interface UserPoolClientRefreshTokenRotation { /** * The state of refresh token rotation for the current app client. Valid values are `ENABLED` or `DISABLED`. */ feature: string; /** * A period of time in seconds that the user has to use the old refresh token before it is invalidated. Valid values are between `0` and `60`. */ retryGracePeriodSeconds?: number; } interface UserPoolClientTokenValidityUnits { /** * Time unit in for the value in `accessTokenValidity`, defaults to `hours`. */ accessToken: string; /** * Time unit in for the value in `idTokenValidity`, defaults to `hours`. */ idToken: string; /** * Time unit in for the value in `refreshTokenValidity`, defaults to `days`. */ refreshToken: string; } interface UserPoolDeviceConfiguration { /** * Whether a challenge is required on a new device. Only applicable to a new device. */ challengeRequiredOnNewDevice?: boolean; /** * Whether a device is only remembered on user prompt. `false` equates to "Always" remember, `true` is "User Opt In," and not using a `deviceConfiguration` block is "No." */ deviceOnlyRememberedOnUserPrompt?: boolean; } interface UserPoolEmailConfiguration { /** * Email configuration set name from SES. */ configurationSet?: string; /** * Email delivery method to use. `COGNITO_DEFAULT` for the default email functionality built into Cognito or `DEVELOPER` to use your Amazon SES configuration. Required to be `DEVELOPER` if `fromEmailAddress` is set. */ emailSendingAccount?: string; /** * Sender’s email address or sender’s display name with their email address (e.g., `john@example.com`, `John Smith ` or `\"John Smith Ph.D.\" `). Escaped double quotes are required around display names that contain certain characters as specified in [RFC 5322](https://tools.ietf.org/html/rfc5322). */ fromEmailAddress?: string; /** * REPLY-TO email address. */ replyToEmailAddress?: string; /** * ARN of the SES verified email identity to use. Required if `emailSendingAccount` is set to `DEVELOPER`. */ sourceArn?: string; } interface UserPoolEmailMfaConfiguration { /** * The template for the email messages that your user pool sends to users with codes for MFA and sign-in with email OTPs. The message must contain the {####} placeholder. In the message, Amazon Cognito replaces this placeholder with the code. If you don't provide this parameter, Amazon Cognito sends messages in the default format. */ message?: string; /** * The subject of the email messages that your user pool sends to users with codes for MFA and email OTP sign-in. */ subject?: string; } interface UserPoolLambdaConfig { /** * ARN of the lambda creating an authentication challenge. */ createAuthChallenge?: string; /** * A custom email sender AWS Lambda trigger. See customEmailSender Below. */ customEmailSender?: outputs.cognito.UserPoolLambdaConfigCustomEmailSender; /** * Custom Message AWS Lambda trigger. */ customMessage?: string; /** * A custom SMS sender AWS Lambda trigger. See customSmsSender Below. */ customSmsSender?: outputs.cognito.UserPoolLambdaConfigCustomSmsSender; /** * Defines the authentication challenge. */ defineAuthChallenge?: string; /** * ARN of KMS Customer master keys. Amazon Cognito uses the key to encrypt codes and temporary passwords sent to CustomEmailSender and CustomSMSSender. */ kmsKeyId?: string; /** * Post-authentication AWS Lambda trigger. */ postAuthentication?: string; /** * Post-confirmation AWS Lambda trigger. */ postConfirmation?: string; /** * Pre-authentication AWS Lambda trigger. */ preAuthentication?: string; /** * Pre-registration AWS Lambda trigger. */ preSignUp?: string; /** * Allow to customize identity token claims before token generation. Set this parameter for legacy purposes; for new instances of pre token generation triggers, set the lambdaArn of `preTokenGenerationConfig`. */ preTokenGeneration: string; /** * Allow to customize access tokens. See pre_token_configuration_type */ preTokenGenerationConfig: outputs.cognito.UserPoolLambdaConfigPreTokenGenerationConfig; /** * User migration Lambda config type. */ userMigration?: string; /** * Verifies the authentication challenge response. */ verifyAuthChallengeResponse?: string; } interface UserPoolLambdaConfigCustomEmailSender { /** * Lambda ARN of the Lambda function that Amazon Cognito triggers to send email notifications to users. */ lambdaArn: string; /** * The Lambda version represents the signature of the "request" attribute in the "event" information Amazon Cognito passes to your custom email Lambda function. The only supported value is `V1_0`. */ lambdaVersion: string; } interface UserPoolLambdaConfigCustomSmsSender { /** * Lambda ARN of the Lambda function that Amazon Cognito triggers to send SMS notifications to users. */ lambdaArn: string; /** * The Lambda version represents the signature of the "request" attribute in the "event" information Amazon Cognito passes to your custom SMS Lambda function. The only supported value is `V1_0`. */ lambdaVersion: string; } interface UserPoolLambdaConfigPreTokenGenerationConfig { lambdaArn: string; lambdaVersion: string; } interface UserPoolPasswordPolicy { /** * Minimum length of the password policy that you have set. */ minimumLength?: number; /** * Number of previous passwords that you want Amazon Cognito to restrict each user from reusing. Users can't set a password that matches any of number of previous passwords specified by this argument. A value of 0 means that password history is not enforced. Valid values are between 0 and 24. * * **Note:** This argument requires advanced security features to be active in the user pool. */ passwordHistorySize?: number; /** * Whether you have required users to use at least one lowercase letter in their password. */ requireLowercase?: boolean; /** * Whether you have required users to use at least one number in their password. */ requireNumbers?: boolean; /** * Whether you have required users to use at least one symbol in their password. */ requireSymbols?: boolean; /** * Whether you have required users to use at least one uppercase letter in their password. */ requireUppercase?: boolean; /** * In the password policy you have set, refers to the number of days a temporary password is valid. If the user does not sign-in during this time, their password will need to be reset by an administrator. */ temporaryPasswordValidityDays: number; } interface UserPoolSchema { /** * Attribute data type. Must be one of `Boolean`, `Number`, `String`, `DateTime`. */ attributeDataType: string; /** * Whether the attribute type is developer only. */ developerOnlyAttribute?: boolean; /** * Whether the attribute can be changed once it has been created. */ mutable?: boolean; /** * Name of the attribute. */ name: string; /** * Configuration block for the constraints for an attribute of the number type. Detailed below. */ numberAttributeConstraints?: outputs.cognito.UserPoolSchemaNumberAttributeConstraints; /** * Whether a user pool attribute is required. If the attribute is required and the user does not provide a value, registration or sign-in will fail. */ required?: boolean; /** * Constraints for an attribute of the string type. Detailed below. */ stringAttributeConstraints?: outputs.cognito.UserPoolSchemaStringAttributeConstraints; } interface UserPoolSchemaNumberAttributeConstraints { /** * Maximum value of an attribute that is of the number data type. */ maxValue?: string; /** * Minimum value of an attribute that is of the number data type. */ minValue?: string; } interface UserPoolSchemaStringAttributeConstraints { /** * Maximum length of an attribute value of the string type. */ maxLength?: string; /** * Minimum length of an attribute value of the string type. */ minLength?: string; } interface UserPoolSignInPolicy { /** * The sign in methods your user pool supports as the first factor. This is a list of strings, allowed values are `PASSWORD`, `EMAIL_OTP`, `SMS_OTP`, and `WEB_AUTHN`. */ allowedFirstAuthFactors?: string[]; } interface UserPoolSmsConfiguration { /** * External ID used in IAM role trust relationships. For more information about using external IDs, see [How to Use an External ID When Granting Access to Your AWS Resources to a Third Party](http://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-user_externalid.html). */ externalId: string; /** * ARN of the Amazon SNS caller. This is usually the IAM role that you've given Cognito permission to assume. */ snsCallerArn: string; /** * The AWS Region to use with Amazon SNS integration. You can choose the same Region as your user pool, or a supported Legacy Amazon SNS alternate Region. Amazon Cognito resources in the Asia Pacific (Seoul) AWS Region must use your Amazon SNS configuration in the Asia Pacific (Tokyo) Region. For more information, see [SMS message settings for Amazon Cognito user pools](https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-sms-settings.html). */ snsRegion: string; } interface UserPoolSoftwareTokenMfaConfiguration { /** * Boolean whether to enable software token Multi-Factor (MFA) tokens, such as Time-based One-Time Password (TOTP). To disable software token MFA When `smsConfiguration` is not present, the `mfaConfiguration` argument must be set to `OFF` and the `softwareTokenMfaConfiguration` configuration block must be fully removed. */ enabled: boolean; } interface UserPoolUserAttributeUpdateSettings { /** * A list of attributes requiring verification before update. If set, the provided value(s) must also be set in `autoVerifiedAttributes`. Valid values: `email`, `phoneNumber`. */ attributesRequireVerificationBeforeUpdates: string[]; } interface UserPoolUserPoolAddOns { /** * A block to specify the threat protection configuration options for additional authentication types in your user pool, including custom authentication. Detailed below. */ advancedSecurityAdditionalFlows?: outputs.cognito.UserPoolUserPoolAddOnsAdvancedSecurityAdditionalFlows; /** * Mode for advanced security, must be one of `OFF`, `AUDIT` or `ENFORCED`. */ advancedSecurityMode: string; } interface UserPoolUserPoolAddOnsAdvancedSecurityAdditionalFlows { /** * Mode of threat protection operation in custom authentication. Valid values are `AUDIT` or `ENFORCED`. The default value is `AUDIT`. */ customAuthMode: string; } interface UserPoolUsernameConfiguration { /** * Whether username case sensitivity will be applied for all users in the user pool through Cognito APIs. */ caseSensitive: boolean; } interface UserPoolVerificationMessageTemplate { /** * Default email option. Must be either `CONFIRM_WITH_CODE` or `CONFIRM_WITH_LINK`. Defaults to `CONFIRM_WITH_CODE`. */ defaultEmailOption?: string; /** * Email message template. Must contain the `{####}` placeholder. Conflicts with `emailVerificationMessage` argument. */ emailMessage: string; /** * Email message template for sending a confirmation link to the user, it must contain the `{##Click Here##}` placeholder. */ emailMessageByLink: string; /** * Subject line for the email message template. Conflicts with `emailVerificationSubject` argument. */ emailSubject: string; /** * Subject line for the email message template for sending a confirmation link to the user. */ emailSubjectByLink: string; /** * SMS message template. Must contain the `{####}` placeholder. Conflicts with `smsVerificationMessage` argument. */ smsMessage: string; } interface UserPoolWebAuthnConfiguration { /** * The authentication domain that passkeys providers use as a relying party. */ relyingPartyId?: string; /** * If your user pool should require a passkey. Must be one of `required` or `preferred`. */ userVerification?: string; } } export declare namespace comprehend { interface DocumentClassifierInputDataConfig { /** * List of training datasets produced by Amazon SageMaker AI Ground Truth. * Used if `dataFormat` is `AUGMENTED_MANIFEST`. * See the `augmentedManifests` Configuration Block section below. */ augmentedManifests?: outputs.comprehend.DocumentClassifierInputDataConfigAugmentedManifest[]; /** * The format for the training data. * One of `COMPREHEND_CSV` or `AUGMENTED_MANIFEST`. */ dataFormat?: string; /** * Delimiter between labels when training a multi-label classifier. * Valid values are `|`, `~`, `!`, `@`, `#`, `$`, `%`, `^`, `*`, `-`, `_`, `+`, `=`, `\`, `:`, `;`, `>`, `?`, `/`, ``, and ``. * Default is `|`. */ labelDelimiter: string; /** * Location of training documents. * Used if `dataFormat` is `COMPREHEND_CSV`. */ s3Uri?: string; testS3Uri?: string; } interface DocumentClassifierInputDataConfigAugmentedManifest { /** * Location of annotation files. */ annotationDataS3Uri?: string; /** * The JSON attribute that contains the annotations for the training documents. */ attributeNames: string[]; /** * Type of augmented manifest. * One of `PLAIN_TEXT_DOCUMENT` or `SEMI_STRUCTURED_DOCUMENT`. */ documentType?: string; /** * Location of augmented manifest file. */ s3Uri: string; /** * Location of source PDF files. */ sourceDocumentsS3Uri?: string; /** * Purpose of data in augmented manifest. * One of `TRAIN` or `TEST`. */ split?: string; } interface DocumentClassifierOutputDataConfig { /** * KMS Key used to encrypt the output documents. * Can be a KMS Key ID, a KMS Key ARN, a KMS Alias name, or a KMS Alias ARN. */ kmsKeyId?: string; /** * Full path for the output documents. */ outputS3Uri: string; /** * Destination path for the output documents. * The full path to the output file will be returned in `outputS3Uri`. */ s3Uri: string; } interface DocumentClassifierVpcConfig { /** * List of security group IDs. */ securityGroupIds: string[]; /** * List of VPC subnets. */ subnets: string[]; } interface EntityRecognizerInputDataConfig { /** * Specifies location of the document annotation data. * See the `annotations` Configuration Block section below. * One of `annotations` or `entityList` is required. */ annotations?: outputs.comprehend.EntityRecognizerInputDataConfigAnnotations; /** * List of training datasets produced by Amazon SageMaker AI Ground Truth. * Used if `dataFormat` is `AUGMENTED_MANIFEST`. * See the `augmentedManifests` Configuration Block section below. */ augmentedManifests?: outputs.comprehend.EntityRecognizerInputDataConfigAugmentedManifest[]; /** * The format for the training data. * One of `COMPREHEND_CSV` or `AUGMENTED_MANIFEST`. */ dataFormat?: string; /** * Specifies a collection of training documents. * Used if `dataFormat` is `COMPREHEND_CSV`. * See the `documents` Configuration Block section below. */ documents?: outputs.comprehend.EntityRecognizerInputDataConfigDocuments; /** * Specifies location of the entity list data. * See the `entityList` Configuration Block section below. * One of `entityList` or `annotations` is required. */ entityList?: outputs.comprehend.EntityRecognizerInputDataConfigEntityList; /** * Set of entity types to be recognized. * Has a maximum of 25 items. * See the `entityTypes` Configuration Block section below. */ entityTypes: outputs.comprehend.EntityRecognizerInputDataConfigEntityType[]; } interface EntityRecognizerInputDataConfigAnnotations { /** * Location of training annotations. */ s3Uri: string; testS3Uri?: string; } interface EntityRecognizerInputDataConfigAugmentedManifest { /** * Location of annotation files. */ annotationDataS3Uri?: string; /** * The JSON attribute that contains the annotations for the training documents. */ attributeNames: string[]; /** * Type of augmented manifest. * One of `PLAIN_TEXT_DOCUMENT` or `SEMI_STRUCTURED_DOCUMENT`. */ documentType?: string; /** * Location of augmented manifest file. */ s3Uri: string; /** * Location of source PDF files. */ sourceDocumentsS3Uri?: string; /** * Purpose of data in augmented manifest. * One of `TRAIN` or `TEST`. */ split?: string; } interface EntityRecognizerInputDataConfigDocuments { /** * Specifies how the input files should be processed. * One of `ONE_DOC_PER_LINE` or `ONE_DOC_PER_FILE`. */ inputFormat?: string; /** * Location of training documents. */ s3Uri: string; testS3Uri?: string; } interface EntityRecognizerInputDataConfigEntityList { /** * Location of entity list. */ s3Uri: string; } interface EntityRecognizerInputDataConfigEntityType { /** * An entity type to be matched by the Entity Recognizer. * Cannot contain a newline (`\n`), carriage return (`\r`), or tab (`\t`). */ type: string; } interface EntityRecognizerVpcConfig { /** * List of security group IDs. */ securityGroupIds: string[]; /** * List of VPC subnets. */ subnets: string[]; } } export declare namespace computeoptimizer { interface EnrollmentStatusTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface RecommendationPreferencesExternalMetricsPreference { /** * The source options for external metrics preferences. Valid values: `Datadog`, `Dynatrace`, `NewRelic`, `Instana`. */ source: string; } interface RecommendationPreferencesPreferredResource { /** * The preferred resource type values to exclude from the recommendation candidates. If this isn’t specified, all supported resources are included by default. */ excludeLists?: string[]; /** * The preferred resource type values to include in the recommendation candidates. You can specify the exact resource type value, such as `"m5.large"`, or use wild card expressions, such as `"m5"`. If this isn’t specified, all supported resources are included by default. */ includeLists?: string[]; name: string; } interface RecommendationPreferencesScope { /** * The name of the scope. Valid values: `Organization`, `AccountId`, `ResourceArn`. */ name: string; /** * The value of the scope. `ALL_ACCOUNTS` for `Organization` scopes, AWS account ID for `AccountId` scopes, ARN of an EC2 instance or an Auto Scaling group for `ResourceArn` scopes. */ value: string; } interface RecommendationPreferencesUtilizationPreference { /** * The name of the resource utilization metric name to customize. Valid values: `CpuUtilization`, `MemoryUtilization`. */ metricName: string; /** * The parameters to set when customizing the resource utilization thresholds. */ metricParameters: outputs.computeoptimizer.RecommendationPreferencesUtilizationPreferenceMetricParameters; } interface RecommendationPreferencesUtilizationPreferenceMetricParameters { /** * The headroom value in percentage used for the specified metric parameter. Valid values: `PERCENT_30`, `PERCENT_20`, `PERCENT_10`, `PERCENT_0`. */ headroom: string; /** * The threshold value used for the specified metric parameter. You can only specify the threshold value for CPU utilization. Valid values: `P90`, `P95`, `P99_5`. */ threshold?: string; } } export declare namespace config { interface AssumeRoleWithWebIdentity { /** * The duration, between 15 minutes and 12 hours, of the role session. Valid time units are ns, us (or µs), ms, s, h, or m. */ duration?: string; /** * IAM Policy JSON describing further restricting permissions for the IAM Role being assumed. */ policy?: string; /** * Amazon Resource Names (ARNs) of IAM Policies describing further restricting permissions for the IAM Role being assumed. */ policyArns?: string[]; /** * Amazon Resource Name (ARN) of an IAM Role to assume prior to making API calls. */ roleArn?: string; /** * An identifier for the assumed role session. */ sessionName?: string; webIdentityToken?: string; webIdentityTokenFile?: string; } interface AssumeRoles { /** * The duration, between 15 minutes and 12 hours, of the role session. Valid time units are ns, us (or µs), ms, s, h, or m. */ duration?: string; /** * A unique identifier that might be required when you assume a role in another account. */ externalId?: string; /** * IAM Policy JSON describing further restricting permissions for the IAM Role being assumed. */ policy?: string; /** * Amazon Resource Names (ARNs) of IAM Policies describing further restricting permissions for the IAM Role being assumed. */ policyArns?: string[]; /** * Amazon Resource Name (ARN) of an IAM Role to assume prior to making API calls. */ roleArn?: string; /** * An identifier for the assumed role session. */ sessionName?: string; /** * Source identity specified by the principal assuming the role. */ sourceIdentity?: string; /** * Assume role session tags. */ tags?: { [key: string]: string; }; /** * Assume role session tag keys to pass to any subsequent sessions. */ transitiveTagKeys?: string[]; } interface DefaultTags { /** * Resource tags to default across all resources. Can also be configured with environment variables like `TF_AWS_DEFAULT_TAGS_`. */ tags?: { [key: string]: string; }; } interface Endpoints { /** * Use this to override the default service endpoint URL */ accessanalyzer?: string; /** * Use this to override the default service endpoint URL */ account?: string; /** * Use this to override the default service endpoint URL */ accountaccess?: string; /** * Use this to override the default service endpoint URL */ acm?: string; /** * Use this to override the default service endpoint URL */ acmpca?: string; /** * Use this to override the default service endpoint URL */ agentregistry?: string; /** * Use this to override the default service endpoint URL */ amg?: string; /** * Use this to override the default service endpoint URL */ amp?: string; /** * Use this to override the default service endpoint URL */ amplify?: string; /** * Use this to override the default service endpoint URL */ apigateway?: string; /** * Use this to override the default service endpoint URL */ apigatewayv2?: string; /** * Use this to override the default service endpoint URL */ appautoscaling?: string; /** * Use this to override the default service endpoint URL */ appconfig?: string; /** * Use this to override the default service endpoint URL */ appfabric?: string; /** * Use this to override the default service endpoint URL */ appflow?: string; /** * Use this to override the default service endpoint URL */ appintegrations?: string; /** * Use this to override the default service endpoint URL */ appintegrationsservice?: string; /** * Use this to override the default service endpoint URL */ applicationautoscaling?: string; /** * Use this to override the default service endpoint URL */ applicationinsights?: string; /** * Use this to override the default service endpoint URL */ applicationsignals?: string; /** * Use this to override the default service endpoint URL */ appmesh?: string; /** * Use this to override the default service endpoint URL */ appregistry?: string; /** * Use this to override the default service endpoint URL */ apprunner?: string; /** * Use this to override the default service endpoint URL */ appstream?: string; /** * Use this to override the default service endpoint URL */ appsync?: string; /** * Use this to override the default service endpoint URL */ arcregionswitch?: string; /** * Use this to override the default service endpoint URL */ arczonalshift?: string; /** * Use this to override the default service endpoint URL */ athena?: string; /** * Use this to override the default service endpoint URL */ auditmanager?: string; /** * Use this to override the default service endpoint URL */ autoscaling?: string; /** * Use this to override the default service endpoint URL */ autoscalingplans?: string; /** * Use this to override the default service endpoint URL */ backup?: string; /** * Use this to override the default service endpoint URL */ batch?: string; /** * Use this to override the default service endpoint URL */ bcmdataexports?: string; /** * Use this to override the default service endpoint URL */ beanstalk?: string; /** * Use this to override the default service endpoint URL */ bedrock?: string; /** * Use this to override the default service endpoint URL */ bedrockagent?: string; /** * Use this to override the default service endpoint URL */ bedrockagentcore?: string; /** * Use this to override the default service endpoint URL */ bedrockruntime?: string; /** * Use this to override the default service endpoint URL */ billing?: string; /** * Use this to override the default service endpoint URL */ budgets?: string; /** * Use this to override the default service endpoint URL */ ce?: string; /** * Use this to override the default service endpoint URL */ chatbot?: string; /** * Use this to override the default service endpoint URL */ chime?: string; /** * Use this to override the default service endpoint URL */ chimesdkmediapipelines?: string; /** * Use this to override the default service endpoint URL */ chimesdkvoice?: string; /** * Use this to override the default service endpoint URL */ cleanrooms?: string; /** * Use this to override the default service endpoint URL */ cloud9?: string; /** * Use this to override the default service endpoint URL */ cloudcontrol?: string; /** * Use this to override the default service endpoint URL */ cloudcontrolapi?: string; /** * Use this to override the default service endpoint URL */ cloudformation?: string; /** * Use this to override the default service endpoint URL */ cloudfront?: string; /** * Use this to override the default service endpoint URL */ cloudfrontkeyvaluestore?: string; /** * Use this to override the default service endpoint URL */ cloudhsm?: string; /** * Use this to override the default service endpoint URL */ cloudhsmv2?: string; /** * Use this to override the default service endpoint URL */ cloudsearch?: string; /** * Use this to override the default service endpoint URL */ cloudtrail?: string; /** * Use this to override the default service endpoint URL */ cloudwatch?: string; /** * Use this to override the default service endpoint URL */ cloudwatchevents?: string; /** * Use this to override the default service endpoint URL */ cloudwatchevidently?: string; /** * Use this to override the default service endpoint URL */ cloudwatchlog?: string; /** * Use this to override the default service endpoint URL */ cloudwatchlogs?: string; /** * Use this to override the default service endpoint URL */ cloudwatchobservabilityaccessmanager?: string; /** * Use this to override the default service endpoint URL */ cloudwatchrum?: string; /** * Use this to override the default service endpoint URL */ codeartifact?: string; /** * Use this to override the default service endpoint URL */ codebuild?: string; /** * Use this to override the default service endpoint URL */ codecatalyst?: string; /** * Use this to override the default service endpoint URL */ codecommit?: string; /** * Use this to override the default service endpoint URL */ codeconnections?: string; /** * Use this to override the default service endpoint URL */ codedeploy?: string; /** * Use this to override the default service endpoint URL */ codeguruprofiler?: string; /** * Use this to override the default service endpoint URL */ codegurureviewer?: string; /** * Use this to override the default service endpoint URL */ codepipeline?: string; /** * Use this to override the default service endpoint URL */ codestarconnections?: string; /** * Use this to override the default service endpoint URL */ codestarnotifications?: string; /** * Use this to override the default service endpoint URL */ cognitoidentity?: string; /** * Use this to override the default service endpoint URL */ cognitoidentityprovider?: string; /** * Use this to override the default service endpoint URL */ cognitoidp?: string; /** * Use this to override the default service endpoint URL */ comprehend?: string; /** * Use this to override the default service endpoint URL */ computeoptimizer?: string; /** * Use this to override the default service endpoint URL */ config?: string; /** * Use this to override the default service endpoint URL */ configservice?: string; /** * Use this to override the default service endpoint URL */ connect?: string; /** * Use this to override the default service endpoint URL */ connectcases?: string; /** * Use this to override the default service endpoint URL */ controltower?: string; /** * Use this to override the default service endpoint URL */ costandusagereportservice?: string; /** * Use this to override the default service endpoint URL */ costexplorer?: string; /** * Use this to override the default service endpoint URL */ costoptimizationhub?: string; /** * Use this to override the default service endpoint URL */ cur?: string; /** * Use this to override the default service endpoint URL */ customerprofiles?: string; /** * Use this to override the default service endpoint URL */ databasemigration?: string; /** * Use this to override the default service endpoint URL */ databasemigrationservice?: string; /** * Use this to override the default service endpoint URL */ databrew?: string; /** * Use this to override the default service endpoint URL */ dataexchange?: string; /** * Use this to override the default service endpoint URL */ datapipeline?: string; /** * Use this to override the default service endpoint URL */ datasync?: string; /** * Use this to override the default service endpoint URL */ datazone?: string; /** * Use this to override the default service endpoint URL */ dax?: string; /** * Use this to override the default service endpoint URL */ deploy?: string; /** * Use this to override the default service endpoint URL */ detective?: string; /** * Use this to override the default service endpoint URL */ devicefarm?: string; /** * Use this to override the default service endpoint URL */ devopsagent?: string; /** * Use this to override the default service endpoint URL */ devopsguru?: string; /** * Use this to override the default service endpoint URL */ directconnect?: string; /** * Use this to override the default service endpoint URL */ directoryservice?: string; /** * Use this to override the default service endpoint URL */ directoryservicedata?: string; /** * Use this to override the default service endpoint URL */ dlm?: string; /** * Use this to override the default service endpoint URL */ dms?: string; /** * Use this to override the default service endpoint URL */ docdb?: string; /** * Use this to override the default service endpoint URL */ docdbelastic?: string; /** * Use this to override the default service endpoint URL */ drs?: string; /** * Use this to override the default service endpoint URL */ ds?: string; /** * Use this to override the default service endpoint URL */ dsql?: string; /** * Use this to override the default service endpoint URL */ dynamodb?: string; /** * Use this to override the default service endpoint URL */ ec2?: string; /** * Use this to override the default service endpoint URL */ ecr?: string; /** * Use this to override the default service endpoint URL */ ecrpublic?: string; /** * Use this to override the default service endpoint URL */ ecs?: string; /** * Use this to override the default service endpoint URL */ efs?: string; /** * Use this to override the default service endpoint URL */ eks?: string; /** * Use this to override the default service endpoint URL */ elasticache?: string; /** * Use this to override the default service endpoint URL */ elasticbeanstalk?: string; /** * Use this to override the default service endpoint URL */ elasticloadbalancing?: string; /** * Use this to override the default service endpoint URL */ elasticloadbalancingv2?: string; /** * Use this to override the default service endpoint URL */ elasticsearch?: string; /** * Use this to override the default service endpoint URL */ elasticsearchservice?: string; /** * Use this to override the default service endpoint URL */ elastictranscoder?: string; /** * Use this to override the default service endpoint URL */ elb?: string; /** * Use this to override the default service endpoint URL */ elbv2?: string; /** * Use this to override the default service endpoint URL */ emr?: string; /** * Use this to override the default service endpoint URL */ emrcontainers?: string; /** * Use this to override the default service endpoint URL */ emrserverless?: string; /** * Use this to override the default service endpoint URL */ es?: string; /** * Use this to override the default service endpoint URL */ eventbridge?: string; /** * Use this to override the default service endpoint URL */ events?: string; /** * Use this to override the default service endpoint URL */ evidently?: string; /** * Use this to override the default service endpoint URL */ evs?: string; /** * Use this to override the default service endpoint URL */ finspace?: string; /** * Use this to override the default service endpoint URL */ firehose?: string; /** * Use this to override the default service endpoint URL */ fis?: string; /** * Use this to override the default service endpoint URL */ fms?: string; /** * Use this to override the default service endpoint URL */ fsx?: string; /** * Use this to override the default service endpoint URL */ gamelift?: string; /** * Use this to override the default service endpoint URL */ glacier?: string; /** * Use this to override the default service endpoint URL */ globalaccelerator?: string; /** * Use this to override the default service endpoint URL */ glue?: string; /** * Use this to override the default service endpoint URL */ gluedatabrew?: string; /** * Use this to override the default service endpoint URL */ grafana?: string; /** * Use this to override the default service endpoint URL */ greengrass?: string; /** * Use this to override the default service endpoint URL */ groundstation?: string; /** * Use this to override the default service endpoint URL */ guardduty?: string; /** * Use this to override the default service endpoint URL */ healthlake?: string; /** * Use this to override the default service endpoint URL */ iam?: string; /** * Use this to override the default service endpoint URL */ identitystore?: string; /** * Use this to override the default service endpoint URL */ imagebuilder?: string; /** * Use this to override the default service endpoint URL */ inspector?: string; /** * Use this to override the default service endpoint URL */ inspector2?: string; /** * Use this to override the default service endpoint URL */ inspectorv2?: string; /** * Use this to override the default service endpoint URL */ interconnect?: string; /** * Use this to override the default service endpoint URL */ internetmonitor?: string; /** * Use this to override the default service endpoint URL */ invoicing?: string; /** * Use this to override the default service endpoint URL */ iot?: string; /** * Use this to override the default service endpoint URL */ ivs?: string; /** * Use this to override the default service endpoint URL */ ivschat?: string; /** * Use this to override the default service endpoint URL */ kafka?: string; /** * Use this to override the default service endpoint URL */ kafkaconnect?: string; /** * Use this to override the default service endpoint URL */ kendra?: string; /** * Use this to override the default service endpoint URL */ keyspaces?: string; /** * Use this to override the default service endpoint URL */ kinesis?: string; /** * Use this to override the default service endpoint URL */ kinesisanalytics?: string; /** * Use this to override the default service endpoint URL */ kinesisanalyticsv2?: string; /** * Use this to override the default service endpoint URL */ kinesisvideo?: string; /** * Use this to override the default service endpoint URL */ kms?: string; /** * Use this to override the default service endpoint URL */ lakeformation?: string; /** * Use this to override the default service endpoint URL */ lambda?: string; /** * Use this to override the default service endpoint URL */ lambdacore?: string; /** * Use this to override the default service endpoint URL */ lambdamicrovms?: string; /** * Use this to override the default service endpoint URL */ launchwizard?: string; /** * Use this to override the default service endpoint URL */ lex?: string; /** * Use this to override the default service endpoint URL */ lexmodelbuilding?: string; /** * Use this to override the default service endpoint URL */ lexmodelbuildingservice?: string; /** * Use this to override the default service endpoint URL */ lexmodels?: string; /** * Use this to override the default service endpoint URL */ lexmodelsv2?: string; /** * Use this to override the default service endpoint URL */ lexv2models?: string; /** * Use this to override the default service endpoint URL */ licensemanager?: string; /** * Use this to override the default service endpoint URL */ lightsail?: string; /** * Use this to override the default service endpoint URL */ location?: string; /** * Use this to override the default service endpoint URL */ locationservice?: string; /** * Use this to override the default service endpoint URL */ logs?: string; /** * Use this to override the default service endpoint URL */ m2?: string; /** * Use this to override the default service endpoint URL */ macie2?: string; /** * Use this to override the default service endpoint URL */ mailmanager?: string; /** * Use this to override the default service endpoint URL */ managedgrafana?: string; /** * Use this to override the default service endpoint URL */ mediaconnect?: string; /** * Use this to override the default service endpoint URL */ mediaconvert?: string; /** * Use this to override the default service endpoint URL */ medialive?: string; /** * Use this to override the default service endpoint URL */ mediapackage?: string; /** * Use this to override the default service endpoint URL */ mediapackagev2?: string; /** * Use this to override the default service endpoint URL */ mediapackagevod?: string; /** * Use this to override the default service endpoint URL */ mediastore?: string; /** * Use this to override the default service endpoint URL */ memorydb?: string; /** * Use this to override the default service endpoint URL */ mgn?: string; /** * Use this to override the default service endpoint URL */ mpa?: string; /** * Use this to override the default service endpoint URL */ mq?: string; /** * Use this to override the default service endpoint URL */ msk?: string; /** * Use this to override the default service endpoint URL */ mwaa?: string; /** * Use this to override the default service endpoint URL */ mwaaserverless?: string; /** * Use this to override the default service endpoint URL */ neptune?: string; /** * Use this to override the default service endpoint URL */ neptunegraph?: string; /** * Use this to override the default service endpoint URL */ networkfirewall?: string; /** * Use this to override the default service endpoint URL */ networkflowmonitor?: string; /** * Use this to override the default service endpoint URL */ networkmanager?: string; /** * Use this to override the default service endpoint URL */ networkmonitor?: string; /** * Use this to override the default service endpoint URL */ notifications?: string; /** * Use this to override the default service endpoint URL */ notificationscontacts?: string; /** * Use this to override the default service endpoint URL */ oam?: string; /** * Use this to override the default service endpoint URL */ observabilityadmin?: string; /** * Use this to override the default service endpoint URL */ odb?: string; /** * Use this to override the default service endpoint URL */ opensearch?: string; /** * Use this to override the default service endpoint URL */ opensearchingestion?: string; /** * Use this to override the default service endpoint URL */ opensearchserverless?: string; /** * Use this to override the default service endpoint URL */ opensearchservice?: string; /** * Use this to override the default service endpoint URL */ organizations?: string; /** * Use this to override the default service endpoint URL */ osis?: string; /** * Use this to override the default service endpoint URL */ outposts?: string; /** * Use this to override the default service endpoint URL */ paymentcryptography?: string; /** * Use this to override the default service endpoint URL */ pcaconnectorad?: string; /** * Use this to override the default service endpoint URL */ pcs?: string; /** * Use this to override the default service endpoint URL */ pinpoint?: string; /** * Use this to override the default service endpoint URL */ pinpointsmsvoicev2?: string; /** * Use this to override the default service endpoint URL */ pipes?: string; /** * Use this to override the default service endpoint URL */ polly?: string; /** * Use this to override the default service endpoint URL */ pricing?: string; /** * Use this to override the default service endpoint URL */ prometheus?: string; /** * Use this to override the default service endpoint URL */ prometheusservice?: string; /** * Use this to override the default service endpoint URL */ qbusiness?: string; /** * Use this to override the default service endpoint URL */ qldb?: string; /** * Use this to override the default service endpoint URL */ quicksight?: string; /** * Use this to override the default service endpoint URL */ ram?: string; /** * Use this to override the default service endpoint URL */ rbin?: string; /** * Use this to override the default service endpoint URL */ rds?: string; /** * Use this to override the default service endpoint URL */ rdsdata?: string; /** * Use this to override the default service endpoint URL */ rdsdataservice?: string; /** * Use this to override the default service endpoint URL */ recyclebin?: string; /** * Use this to override the default service endpoint URL */ redshift?: string; /** * Use this to override the default service endpoint URL */ redshiftdata?: string; /** * Use this to override the default service endpoint URL */ redshiftdataapiservice?: string; /** * Use this to override the default service endpoint URL */ redshiftserverless?: string; /** * Use this to override the default service endpoint URL */ rekognition?: string; /** * Use this to override the default service endpoint URL */ resiliencehub?: string; /** * Use this to override the default service endpoint URL */ resiliencehubv2?: string; /** * Use this to override the default service endpoint URL */ resourceexplorer2?: string; /** * Use this to override the default service endpoint URL */ resourcegroups?: string; /** * Use this to override the default service endpoint URL */ resourcegroupstagging?: string; /** * Use this to override the default service endpoint URL */ resourcegroupstaggingapi?: string; /** * Use this to override the default service endpoint URL */ rolesanywhere?: string; /** * Use this to override the default service endpoint URL */ route53?: string; /** * Use this to override the default service endpoint URL */ route53domains?: string; /** * Use this to override the default service endpoint URL */ route53profiles?: string; /** * Use this to override the default service endpoint URL */ route53recoverycontrolconfig?: string; /** * Use this to override the default service endpoint URL */ route53recoveryreadiness?: string; /** * Use this to override the default service endpoint URL */ route53resolver?: string; /** * Use this to override the default service endpoint URL */ rum?: string; /** * Use this to override the default service endpoint URL */ s3?: string; /** * Use this to override the default service endpoint URL */ s3api?: string; /** * Use this to override the default service endpoint URL */ s3control?: string; /** * Use this to override the default service endpoint URL */ s3files?: string; /** * Use this to override the default service endpoint URL */ s3outposts?: string; /** * Use this to override the default service endpoint URL */ s3tables?: string; /** * Use this to override the default service endpoint URL */ s3vectors?: string; /** * Use this to override the default service endpoint URL */ sagemaker?: string; /** * Use this to override the default service endpoint URL */ savingsplans?: string; /** * Use this to override the default service endpoint URL */ scheduler?: string; /** * Use this to override the default service endpoint URL */ schemas?: string; /** * Use this to override the default service endpoint URL */ secretsmanager?: string; /** * Use this to override the default service endpoint URL */ securityhub?: string; /** * Use this to override the default service endpoint URL */ securitylake?: string; /** * Use this to override the default service endpoint URL */ serverlessapplicationrepository?: string; /** * Use this to override the default service endpoint URL */ serverlessapprepo?: string; /** * Use this to override the default service endpoint URL */ serverlessrepo?: string; /** * Use this to override the default service endpoint URL */ servicecatalog?: string; /** * Use this to override the default service endpoint URL */ servicecatalogappregistry?: string; /** * Use this to override the default service endpoint URL */ servicediscovery?: string; /** * Use this to override the default service endpoint URL */ servicequotas?: string; /** * Use this to override the default service endpoint URL */ ses?: string; /** * Use this to override the default service endpoint URL */ sesv2?: string; /** * Use this to override the default service endpoint URL */ sfn?: string; /** * Use this to override the default service endpoint URL */ shield?: string; /** * Use this to override the default service endpoint URL */ signer?: string; /** * Use this to override the default service endpoint URL */ sns?: string; /** * Use this to override the default service endpoint URL */ sqs?: string; /** * Use this to override the default service endpoint URL */ ssm?: string; /** * Use this to override the default service endpoint URL */ ssmcontacts?: string; /** * Use this to override the default service endpoint URL */ ssmincidents?: string; /** * Use this to override the default service endpoint URL */ ssmquicksetup?: string; /** * Use this to override the default service endpoint URL */ ssmsap?: string; /** * Use this to override the default service endpoint URL */ sso?: string; /** * Use this to override the default service endpoint URL */ ssoadmin?: string; /** * Use this to override the default service endpoint URL */ stepfunctions?: string; /** * Use this to override the default service endpoint URL */ storagegateway?: string; /** * Use this to override the default service endpoint URL */ sts?: string; /** * Use this to override the default service endpoint URL */ swf?: string; /** * Use this to override the default service endpoint URL */ synthetics?: string; /** * Use this to override the default service endpoint URL */ taxsettings?: string; /** * Use this to override the default service endpoint URL */ timestreaminfluxdb?: string; /** * Use this to override the default service endpoint URL */ timestreamquery?: string; /** * Use this to override the default service endpoint URL */ timestreamwrite?: string; /** * Use this to override the default service endpoint URL */ transcribe?: string; /** * Use this to override the default service endpoint URL */ transcribeservice?: string; /** * Use this to override the default service endpoint URL */ transfer?: string; /** * Use this to override the default service endpoint URL */ uxc?: string; /** * Use this to override the default service endpoint URL */ verifiedpermissions?: string; /** * Use this to override the default service endpoint URL */ vpclattice?: string; /** * Use this to override the default service endpoint URL */ waf?: string; /** * Use this to override the default service endpoint URL */ wafregional?: string; /** * Use this to override the default service endpoint URL */ wafv2?: string; /** * Use this to override the default service endpoint URL */ wellarchitected?: string; /** * Use this to override the default service endpoint URL */ workmail?: string; /** * Use this to override the default service endpoint URL */ workspaces?: string; /** * Use this to override the default service endpoint URL */ workspacesweb?: string; /** * Use this to override the default service endpoint URL */ xray?: string; } interface IgnoreTags { /** * Resource tag key prefixes to ignore across all resources. Can also be configured with the TF_AWS_IGNORE_TAGS_KEY_PREFIXES environment variable. */ keyPrefixes?: string[]; /** * Resource tag keys to ignore across all resources. Can also be configured with the TF_AWS_IGNORE_TAGS_KEYS environment variable. */ keys?: string[]; } } export declare namespace connect { interface BotAssociationLexBot { /** * The Region that the Amazon Lex (V1) bot was created in. Defaults to current region. */ lexRegion: string; /** * The name of the Amazon Lex (V1) bot. */ name: string; } interface GetBotAssociationLexBot { /** * Region that the Amazon Lex (V1) bot was created in. */ lexRegion: string; /** * Name of the Amazon Lex (V1) bot. */ name: string; } interface GetHoursOfOperationConfig { /** * Day that the hours of operation applies to. */ day: string; /** * End time block specifies the time that your contact center closes. The `endTime` is documented below. */ endTimes: outputs.connect.GetHoursOfOperationConfigEndTime[]; /** * Start time block specifies the time that your contact center opens. The `startTime` is documented below. */ startTimes: outputs.connect.GetHoursOfOperationConfigStartTime[]; } interface GetHoursOfOperationConfigEndTime { /** * Hour of opening. */ hours: number; /** * Minute of opening. */ minutes: number; } interface GetHoursOfOperationConfigStartTime { /** * Hour of opening. */ hours: number; /** * Minute of opening. */ minutes: number; } interface GetInstanceStorageConfigStorageConfig { /** * A block that specifies the configuration of the Kinesis Firehose delivery stream. Documented below. */ kinesisFirehoseConfigs: outputs.connect.GetInstanceStorageConfigStorageConfigKinesisFirehoseConfig[]; /** * A block that specifies the configuration of the Kinesis data stream. Documented below. */ kinesisStreamConfigs: outputs.connect.GetInstanceStorageConfigStorageConfigKinesisStreamConfig[]; /** * A block that specifies the configuration of the Kinesis video stream. Documented below. */ kinesisVideoStreamConfigs: outputs.connect.GetInstanceStorageConfigStorageConfigKinesisVideoStreamConfig[]; /** * A block that specifies the configuration of S3 Bucket. Documented below. */ s3Configs: outputs.connect.GetInstanceStorageConfigStorageConfigS3Config[]; /** * A valid storage type. Valid Values: `S3` | `KINESIS_VIDEO_STREAM` | `KINESIS_STREAM` | `KINESIS_FIREHOSE`. */ storageType: string; } interface GetInstanceStorageConfigStorageConfigKinesisFirehoseConfig { /** * ARN of the delivery stream. */ firehoseArn: string; } interface GetInstanceStorageConfigStorageConfigKinesisStreamConfig { /** * ARN of the data stream. */ streamArn: string; } interface GetInstanceStorageConfigStorageConfigKinesisVideoStreamConfig { /** * The encryption configuration. Documented below. */ encryptionConfigs: outputs.connect.GetInstanceStorageConfigStorageConfigKinesisVideoStreamConfigEncryptionConfig[]; /** * The prefix of the video stream. Minimum length of `1`. Maximum length of `128`. When read from the state, the value returned is `-connect--contact-` since the API appends additional details to the `prefix`. */ prefix: string; /** * The number of hours to retain the data in a data store associated with the stream. Minimum value of `0`. Maximum value of `87600`. A value of `0` indicates that the stream does not persist data. */ retentionPeriodHours: number; } interface GetInstanceStorageConfigStorageConfigKinesisVideoStreamConfigEncryptionConfig { /** * The type of encryption. Valid Values: `KMS`. */ encryptionType: string; /** * The full ARN of the encryption key. Be sure to provide the full ARN of the encryption key, not just the ID. */ keyId: string; } interface GetInstanceStorageConfigStorageConfigS3Config { /** * The S3 bucket name. */ bucketName: string; /** * The S3 bucket prefix. */ bucketPrefix: string; /** * The encryption configuration. Documented below. */ encryptionConfigs: outputs.connect.GetInstanceStorageConfigStorageConfigS3ConfigEncryptionConfig[]; } interface GetInstanceStorageConfigStorageConfigS3ConfigEncryptionConfig { /** * The type of encryption. Valid Values: `KMS`. */ encryptionType: string; /** * The full ARN of the encryption key. Be sure to provide the full ARN of the encryption key, not just the ID. */ keyId: string; } interface GetQueueOutboundCallerConfig { /** * Specifies the caller ID name. */ outboundCallerIdName: string; /** * Specifies the caller ID number. */ outboundCallerIdNumberId: string; /** * Outbound whisper flow to be used during an outbound call. */ outboundFlowId: string; } interface GetQuickConnectQuickConnectConfig { /** * Phone configuration of the Quick Connect. This is returned only if `quickConnectType` is `PHONE_NUMBER`. The `phoneConfig` block is documented below. */ phoneConfigs: outputs.connect.GetQuickConnectQuickConnectConfigPhoneConfig[]; /** * Queue configuration of the Quick Connect. This is returned only if `quickConnectType` is `QUEUE`. The `queueConfig` block is documented below. */ queueConfigs: outputs.connect.GetQuickConnectQuickConnectConfigQueueConfig[]; /** * Configuration type of the Quick Connect. Valid values are `PHONE_NUMBER`, `QUEUE`, `USER`. */ quickConnectType: string; /** * User configuration of the Quick Connect. This is returned only if `quickConnectType` is `USER`. The `userConfig` block is documented below. */ userConfigs: outputs.connect.GetQuickConnectQuickConnectConfigUserConfig[]; } interface GetQuickConnectQuickConnectConfigPhoneConfig { /** * Phone number in in E.164 format. */ phoneNumber: string; } interface GetQuickConnectQuickConnectConfigQueueConfig { /** * Identifier of the contact flow. */ contactFlowId: string; /** * Identifier for the queue. */ queueId: string; } interface GetQuickConnectQuickConnectConfigUserConfig { /** * Identifier of the contact flow. */ contactFlowId: string; /** * Identifier for the user. */ userId: string; } interface GetRoutingProfileMediaConcurrency { /** * Channels agents can handle in the Contact Control Panel (CCP) for this routing profile. Valid values are `VOICE`, `CHAT`, `TASK`. */ channel: string; /** * Number of contacts an agent can have on a channel simultaneously. Valid Range for `VOICE`: Minimum value of 1. Maximum value of 1. Valid Range for `CHAT`: Minimum value of 1. Maximum value of 10. Valid Range for `TASK`: Minimum value of 1. Maximum value of 10. */ concurrency: number; /** * Configuration block for cross-channel behavior. Documented below. */ crossChannelBehaviors: outputs.connect.GetRoutingProfileMediaConcurrencyCrossChannelBehavior[]; } interface GetRoutingProfileMediaConcurrencyCrossChannelBehavior { /** * Cross-channel behavior for routing contacts across multiple channels. Valid values are `ROUTE_CURRENT_CHANNEL_ONLY`, `ROUTE_ANY_CHANNEL`. */ behaviorType: string; } interface GetRoutingProfileQueueConfig { /** * Channels agents can handle in the Contact Control Panel (CCP) for this routing profile. Valid values are `VOICE`, `CHAT`, `TASK`. */ channel: string; /** * Delay, in seconds, that a contact should be in the queue before they are routed to an available agent */ delay: number; /** * Order in which contacts are to be handled for the queue. */ priority: number; /** * ARN for the queue. */ queueArn: string; /** * Identifier for the queue. */ queueId: string; /** * Name for the queue. */ queueName: string; } interface GetUserHierarchyGroupHierarchyPath { /** * Details of level five. See below. */ levelFives: outputs.connect.GetUserHierarchyGroupHierarchyPathLevelFife[]; /** * Details of level four. See below. */ levelFours: outputs.connect.GetUserHierarchyGroupHierarchyPathLevelFour[]; /** * Details of level one. See below. */ levelOnes: outputs.connect.GetUserHierarchyGroupHierarchyPathLevelOne[]; /** * Details of level three. See below. */ levelThrees: outputs.connect.GetUserHierarchyGroupHierarchyPathLevelThree[]; /** * Details of level two. See below. */ levelTwos: outputs.connect.GetUserHierarchyGroupHierarchyPathLevelTwo[]; } interface GetUserHierarchyGroupHierarchyPathLevelFife { /** * ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * Returns information on a specific hierarchy group by name * * > **NOTE:** `instanceId` and one of either `name` or `hierarchyGroupId` is required. */ name: string; } interface GetUserHierarchyGroupHierarchyPathLevelFour { /** * ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * Returns information on a specific hierarchy group by name * * > **NOTE:** `instanceId` and one of either `name` or `hierarchyGroupId` is required. */ name: string; } interface GetUserHierarchyGroupHierarchyPathLevelOne { /** * ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * Returns information on a specific hierarchy group by name * * > **NOTE:** `instanceId` and one of either `name` or `hierarchyGroupId` is required. */ name: string; } interface GetUserHierarchyGroupHierarchyPathLevelThree { /** * ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * Returns information on a specific hierarchy group by name * * > **NOTE:** `instanceId` and one of either `name` or `hierarchyGroupId` is required. */ name: string; } interface GetUserHierarchyGroupHierarchyPathLevelTwo { /** * ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * Returns information on a specific hierarchy group by name * * > **NOTE:** `instanceId` and one of either `name` or `hierarchyGroupId` is required. */ name: string; } interface GetUserHierarchyStructureHierarchyStructure { /** * Details of level five. See below. */ levelFives: outputs.connect.GetUserHierarchyStructureHierarchyStructureLevelFife[]; /** * Details of level four. See below. */ levelFours: outputs.connect.GetUserHierarchyStructureHierarchyStructureLevelFour[]; /** * Details of level one. See below. */ levelOnes: outputs.connect.GetUserHierarchyStructureHierarchyStructureLevelOne[]; /** * Details of level three. See below. */ levelThrees: outputs.connect.GetUserHierarchyStructureHierarchyStructureLevelThree[]; /** * Details of level two. See below. */ levelTwos: outputs.connect.GetUserHierarchyStructureHierarchyStructureLevelTwo[]; } interface GetUserHierarchyStructureHierarchyStructureLevelFife { /** * ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * Name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface GetUserHierarchyStructureHierarchyStructureLevelFour { /** * ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * Name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface GetUserHierarchyStructureHierarchyStructureLevelOne { /** * ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * Name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface GetUserHierarchyStructureHierarchyStructureLevelThree { /** * ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * Name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface GetUserHierarchyStructureHierarchyStructureLevelTwo { /** * ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * Name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface GetUserIdentityInfo { /** * The email address. */ email: string; /** * The first name. */ firstName: string; /** * The last name. */ lastName: string; /** * The secondary email address. If present, email notifications will be sent to this email address instead of the primary one. */ secondaryEmail: string; } interface GetUserPhoneConfig { /** * The After Call Work (ACW) timeout setting, in seconds. */ afterContactWorkTimeLimit: number; /** * When Auto-Accept Call is enabled for an available agent, the agent connects to contacts automatically. */ autoAccept: boolean; /** * The phone number for the user's desk phone. */ deskPhoneNumber: string; /** * The phone type. Valid values are `DESK_PHONE` and `SOFT_PHONE`. */ phoneType: string; } interface HoursOfOperationConfig { /** * Specifies the day that the hours of operation applies to. */ day: string; /** * A end time block specifies the time that your contact center closes. The `endTime` is documented below. */ endTime: outputs.connect.HoursOfOperationConfigEndTime; /** * A start time block specifies the time that your contact center opens. The `startTime` is documented below. */ startTime: outputs.connect.HoursOfOperationConfigStartTime; } interface HoursOfOperationConfigEndTime { /** * Specifies the hour of closing. */ hours: number; /** * Specifies the minute of closing. */ minutes: number; } interface HoursOfOperationConfigStartTime { /** * Specifies the hour of opening. */ hours: number; /** * Specifies the minute of opening. */ minutes: number; } interface InstanceStorageConfigStorageConfig { /** * A block that specifies the configuration of the Kinesis Firehose delivery stream. Documented below. */ kinesisFirehoseConfig?: outputs.connect.InstanceStorageConfigStorageConfigKinesisFirehoseConfig; /** * A block that specifies the configuration of the Kinesis data stream. Documented below. */ kinesisStreamConfig?: outputs.connect.InstanceStorageConfigStorageConfigKinesisStreamConfig; /** * A block that specifies the configuration of the Kinesis video stream. Documented below. */ kinesisVideoStreamConfig?: outputs.connect.InstanceStorageConfigStorageConfigKinesisVideoStreamConfig; /** * A block that specifies the configuration of S3 Bucket. Documented below. */ s3Config?: outputs.connect.InstanceStorageConfigStorageConfigS3Config; /** * A valid storage type. Valid Values: `S3` | `KINESIS_VIDEO_STREAM` | `KINESIS_STREAM` | `KINESIS_FIREHOSE`. */ storageType: string; } interface InstanceStorageConfigStorageConfigKinesisFirehoseConfig { /** * ARN of the delivery stream. */ firehoseArn: string; } interface InstanceStorageConfigStorageConfigKinesisStreamConfig { /** * ARN of the data stream. */ streamArn: string; } interface InstanceStorageConfigStorageConfigKinesisVideoStreamConfig { /** * The encryption configuration. Documented below. */ encryptionConfig: outputs.connect.InstanceStorageConfigStorageConfigKinesisVideoStreamConfigEncryptionConfig; /** * The prefix of the video stream. Minimum length of `1`. Maximum length of `128`. When read from the state, the value returned is `-connect--contact-` since the API appends additional details to the `prefix`. */ prefix: string; /** * The number of hours data is retained in the stream. Kinesis Video Streams retains the data in a data store that is associated with the stream. Minimum value of `0`. Maximum value of `87600`. A value of `0`, indicates that the stream does not persist data. */ retentionPeriodHours: number; } interface InstanceStorageConfigStorageConfigKinesisVideoStreamConfigEncryptionConfig { /** * The type of encryption. Valid Values: `KMS`. */ encryptionType: string; /** * The full ARN of the encryption key. Be sure to provide the full ARN of the encryption key, not just the ID. */ keyId: string; } interface InstanceStorageConfigStorageConfigS3Config { /** * The S3 bucket name. */ bucketName: string; /** * The S3 bucket prefix. */ bucketPrefix: string; /** * The encryption configuration. Documented below. */ encryptionConfig?: outputs.connect.InstanceStorageConfigStorageConfigS3ConfigEncryptionConfig; } interface InstanceStorageConfigStorageConfigS3ConfigEncryptionConfig { /** * The type of encryption. Valid Values: `KMS`. */ encryptionType: string; /** * The full ARN of the encryption key. Be sure to provide the full ARN of the encryption key, not just the ID. */ keyId: string; } interface PhoneNumberStatus { /** * The status message. */ message: string; /** * The status of the phone number. Valid Values: `CLAIMED` | `IN_PROGRESS` | `FAILED`. */ status: string; } interface QueueOutboundCallerConfig { /** * Specifies the caller ID name. */ outboundCallerIdName?: string; /** * Specifies the caller ID number. */ outboundCallerIdNumberId?: string; /** * Specifies outbound whisper flow to be used during an outbound call. */ outboundFlowId?: string; } interface QuickConnectQuickConnectConfig { /** * Specifies the phone configuration of the Quick Connect. This is required only if `quickConnectType` is `PHONE_NUMBER`. The `phoneConfig` block is documented below. */ phoneConfigs?: outputs.connect.QuickConnectQuickConnectConfigPhoneConfig[]; /** * Specifies the queue configuration of the Quick Connect. This is required only if `quickConnectType` is `QUEUE`. The `queueConfig` block is documented below. */ queueConfigs?: outputs.connect.QuickConnectQuickConnectConfigQueueConfig[]; /** * Specifies the configuration type of the quick connect. valid values are `PHONE_NUMBER`, `QUEUE`, `USER`. */ quickConnectType: string; /** * Specifies the user configuration of the Quick Connect. This is required only if `quickConnectType` is `USER`. The `userConfig` block is documented below. */ userConfigs?: outputs.connect.QuickConnectQuickConnectConfigUserConfig[]; } interface QuickConnectQuickConnectConfigPhoneConfig { /** * Specifies the phone number in in E.164 format. */ phoneNumber: string; } interface QuickConnectQuickConnectConfigQueueConfig { /** * Specifies the identifier of the contact flow. */ contactFlowId: string; /** * Specifies the identifier for the queue. */ queueId: string; } interface QuickConnectQuickConnectConfigUserConfig { /** * Specifies the identifier of the contact flow. */ contactFlowId: string; /** * Specifies the identifier for the user. */ userId: string; } interface RoutingProfileMediaConcurrency { /** * Specifies the channels that agents can handle in the Contact Control Panel (CCP). Valid values are `VOICE`, `CHAT`, `TASK`. */ channel: string; /** * Specifies the number of contacts an agent can have on a channel simultaneously. Valid Range for `VOICE`: Minimum value of `1`. Maximum value of `1`. Valid Range for `CHAT`: Minimum value of `1`. Maximum value of `10`. Valid Range for `TASK`: Minimum value of `1`. Maximum value of `10`. */ concurrency: number; /** * Defines the cross-channel routing behavior for each traffic type. **Out-of-band changes are only detected when this argument is explicitly configured in your Terraform configuration.** Documented below. */ crossChannelBehavior?: outputs.connect.RoutingProfileMediaConcurrencyCrossChannelBehavior; } interface RoutingProfileMediaConcurrencyCrossChannelBehavior { /** * Specifies the cross-channel behavior for routing contacts across multiple channels. Valid values are `ROUTE_CURRENT_CHANNEL_ONLY` and `ROUTE_ANY_CHANNEL`. `ROUTE_CURRENT_CHANNEL_ONLY` restricts agents to receive contacts only from the channel they are currently handling. `ROUTE_ANY_CHANNEL` allows agents to receive contacts from any channel regardless of what they are currently handling. */ behaviorType: string; } interface RoutingProfileQueueConfig { /** * Specifies the channels agents can handle in the Contact Control Panel (CCP) for this routing profile. Valid values are `VOICE`, `CHAT`, `TASK`. */ channel: string; /** * Specifies the delay, in seconds, that a contact should be in the queue before they are routed to an available agent */ delay: number; /** * Specifies the order in which contacts are to be handled for the queue. */ priority: number; /** * ARN for the queue. */ queueArn: string; /** * Specifies the identifier for the queue. */ queueId: string; /** * Name for the queue. */ queueName: string; } interface UserHierarchyGroupHierarchyPath { /** * A block that defines the details of level five. The level block is documented below. */ levelFives: outputs.connect.UserHierarchyGroupHierarchyPathLevelFife[]; /** * A block that defines the details of level four. The level block is documented below. */ levelFours: outputs.connect.UserHierarchyGroupHierarchyPathLevelFour[]; /** * A block that defines the details of level one. The level block is documented below. */ levelOnes: outputs.connect.UserHierarchyGroupHierarchyPathLevelOne[]; /** * A block that defines the details of level three. The level block is documented below. */ levelThrees: outputs.connect.UserHierarchyGroupHierarchyPathLevelThree[]; /** * A block that defines the details of level two. The level block is documented below. */ levelTwos: outputs.connect.UserHierarchyGroupHierarchyPathLevelTwo[]; } interface UserHierarchyGroupHierarchyPathLevelFife { /** * The ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * The name of the user hierarchy group. Must not be more than 100 characters. */ name: string; } interface UserHierarchyGroupHierarchyPathLevelFour { /** * The ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * The name of the user hierarchy group. Must not be more than 100 characters. */ name: string; } interface UserHierarchyGroupHierarchyPathLevelOne { /** * The ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * The name of the user hierarchy group. Must not be more than 100 characters. */ name: string; } interface UserHierarchyGroupHierarchyPathLevelThree { /** * The ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * The name of the user hierarchy group. Must not be more than 100 characters. */ name: string; } interface UserHierarchyGroupHierarchyPathLevelTwo { /** * The ARN of the hierarchy group. */ arn: string; /** * The identifier of the hierarchy group. */ id: string; /** * The name of the user hierarchy group. Must not be more than 100 characters. */ name: string; } interface UserHierarchyStructureHierarchyStructure { /** * A block that defines the details of level five. The level block is documented below. * * Each level block supports the following arguments: */ levelFive: outputs.connect.UserHierarchyStructureHierarchyStructureLevelFive; /** * A block that defines the details of level four. The level block is documented below. */ levelFour: outputs.connect.UserHierarchyStructureHierarchyStructureLevelFour; /** * A block that defines the details of level one. The level block is documented below. */ levelOne: outputs.connect.UserHierarchyStructureHierarchyStructureLevelOne; /** * A block that defines the details of level three. The level block is documented below. */ levelThree: outputs.connect.UserHierarchyStructureHierarchyStructureLevelThree; /** * A block that defines the details of level two. The level block is documented below. */ levelTwo: outputs.connect.UserHierarchyStructureHierarchyStructureLevelTwo; } interface UserHierarchyStructureHierarchyStructureLevelFive { /** * The ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * The name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface UserHierarchyStructureHierarchyStructureLevelFour { /** * The ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * The name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface UserHierarchyStructureHierarchyStructureLevelOne { /** * The ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * The name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface UserHierarchyStructureHierarchyStructureLevelThree { /** * The ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * The name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface UserHierarchyStructureHierarchyStructureLevelTwo { /** * The ARN of the hierarchy level. */ arn: string; /** * The identifier of the hierarchy level. */ id: string; /** * The name of the user hierarchy level. Must not be more than 50 characters. */ name: string; } interface UserIdentityInfo { /** * The email address. If you are using SAML for identity management and include this parameter, an error is returned. Note that updates to the `email` is supported. From the [UpdateUserIdentityInfo API documentation](https://docs.aws.amazon.com/connect/latest/APIReference/API_UpdateUserIdentityInfo.html) it is strongly recommended to limit who has the ability to invoke `UpdateUserIdentityInfo`. Someone with that ability can change the login credentials of other users by changing their email address. This poses a security risk to your organization. They can change the email address of a user to the attacker's email address, and then reset the password through email. For more information, see [Best Practices for Security Profiles](https://docs.aws.amazon.com/connect/latest/adminguide/security-profile-best-practices.html) in the Amazon Connect Administrator Guide. */ email?: string; /** * The first name. This is required if you are using Amazon Connect or SAML for identity management. Minimum length of 1. Maximum length of 100. */ firstName?: string; /** * The last name. This is required if you are using Amazon Connect or SAML for identity management. Minimum length of 1. Maximum length of 100. */ lastName?: string; /** * The secondary email address. If present, email notifications will be sent to this email address instead of the primary one. */ secondaryEmail?: string; } interface UserPhoneConfig { /** * The After Call Work (ACW) timeout setting, in seconds. Minimum value of 0. */ afterContactWorkTimeLimit?: number; /** * When Auto-Accept Call is enabled for an available agent, the agent connects to contacts automatically. */ autoAccept?: boolean; /** * The phone number for the user's desk phone. Required if `phoneType` is set as `DESK_PHONE`. */ deskPhoneNumber?: string; /** * The phone type. Valid values are `DESK_PHONE` and `SOFT_PHONE`. */ phoneType: string; } } export declare namespace controltower { interface BaselineParameters { /** * The key of the parameter. */ key: string; /** * The value of the parameter. */ value: string; } interface BaselineTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ControlTowerControlParameter { /** * The name of the parameter. */ key: string; /** * The value of the parameter. */ value: string; } interface LandingZoneDriftStatus { /** * The drift status of the landing zone. */ status: string; } } export declare namespace costexplorer { interface AnomalySubscriptionSubscriber { /** * The address of the subscriber. If type is `SNS`, this will be the arn of the sns topic. If type is `EMAIL`, this will be the destination email address. */ address: string; /** * The type of subscription. Valid Values: `SNS` | `EMAIL`. */ type: string; } interface AnomalySubscriptionThresholdExpression { /** * Return results that match both Dimension objects. */ ands?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionAnd[]; /** * Configuration block for the filter that's based on values. See Cost Category below. */ costCategory?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionCostCategory; /** * Configuration block for the specific Dimension to use for. */ dimension?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionDimension; /** * Return results that do not match the Dimension object. */ not?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionNot; /** * Return results that match either Dimension object. */ ors?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionOr[]; /** * Configuration block for the specific Tag to use for. See Tags below. */ tags?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionTags; } interface AnomalySubscriptionThresholdExpressionAnd { /** * Configuration block for the filter that's based on values. See Cost Category below. */ costCategory?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionAndCostCategory; /** * Configuration block for the specific Dimension to use for. */ dimension?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionAndDimension; /** * A map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionAndTags; } interface AnomalySubscriptionThresholdExpressionAndCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionAndDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionAndTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionNot { /** * Configuration block for the filter that's based on values. See Cost Category below. */ costCategory?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionNotCostCategory; /** * Configuration block for the specific Dimension to use for. */ dimension?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionNotDimension; /** * A map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionNotTags; } interface AnomalySubscriptionThresholdExpressionNotCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionNotDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionNotTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionOr { /** * Configuration block for the filter that's based on values. See Cost Category below. */ costCategory?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionOrCostCategory; /** * Configuration block for the specific Dimension to use for. */ dimension?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionOrDimension; /** * A map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.AnomalySubscriptionThresholdExpressionOrTags; } interface AnomalySubscriptionThresholdExpressionOrCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionOrDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionOrTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface AnomalySubscriptionThresholdExpressionTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRule { /** * Configuration block for the value the line item is categorized as if the line item contains the matched dimension. See below. */ inheritedValue?: outputs.costexplorer.CostCategoryRuleInheritedValue; /** * Configuration block for the `Expression` object used to categorize costs. See below. */ rule?: outputs.costexplorer.CostCategoryRuleRule; /** * You can define the CostCategoryRule rule type as either `REGULAR` or `INHERITED_VALUE`. */ type?: string; /** * Default value for the cost category. */ value?: string; } interface CostCategoryRuleInheritedValue { /** * Key to extract cost category values. */ dimensionKey?: string; /** * Name of the dimension that's used to group costs. If you specify `LINKED_ACCOUNT_NAME`, the cost category value is based on account name. If you specify `TAG`, the cost category value will be based on the value of the specified tag key. Valid values are `LINKED_ACCOUNT_NAME`, `TAG` */ dimensionName?: string; } interface CostCategoryRuleRule { /** * Return results that match both `Dimension` objects. */ ands?: outputs.costexplorer.CostCategoryRuleRuleAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleDimension; /** * Return results that match both `Dimension` object. */ not?: outputs.costexplorer.CostCategoryRuleRuleNot; /** * Return results that match both `Dimension` object. */ ors?: outputs.costexplorer.CostCategoryRuleRuleOr[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags?: outputs.costexplorer.CostCategoryRuleRuleTags; } interface CostCategoryRuleRuleAnd { /** * Return results that match both `Dimension` objects. */ ands?: outputs.costexplorer.CostCategoryRuleRuleAndAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleAndCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleAndDimension; /** * Return results that match both `Dimension` object. */ not?: outputs.costexplorer.CostCategoryRuleRuleAndNot; /** * Return results that match both `Dimension` object. */ ors?: outputs.costexplorer.CostCategoryRuleRuleAndOr[]; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleAndTags; } interface CostCategoryRuleRuleAndAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleAndAndCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleAndAndDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleAndAndTags; } interface CostCategoryRuleRuleAndAndCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndAndDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndAndTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndNot { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleAndNotCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleAndNotDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleAndNotTags; } interface CostCategoryRuleRuleAndNotCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndNotDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndNotTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndOr { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleAndOrCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleAndOrDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleAndOrTags; } interface CostCategoryRuleRuleAndOrCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndOrDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndOrTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleAndTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNot { /** * Return results that match both `Dimension` objects. */ ands?: outputs.costexplorer.CostCategoryRuleRuleNotAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleNotCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleNotDimension; /** * Return results that match both `Dimension` object. */ not?: outputs.costexplorer.CostCategoryRuleRuleNotNot; /** * Return results that match both `Dimension` object. */ ors?: outputs.costexplorer.CostCategoryRuleRuleNotOr[]; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleNotTags; } interface CostCategoryRuleRuleNotAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleNotAndCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleNotAndDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleNotAndTags; } interface CostCategoryRuleRuleNotAndCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotAndDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotAndTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotNot { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleNotNotCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleNotNotDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleNotNotTags; } interface CostCategoryRuleRuleNotNotCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotNotDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotNotTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotOr { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleNotOrCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleNotOrDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleNotOrTags; } interface CostCategoryRuleRuleNotOrCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotOrDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotOrTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleNotTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOr { /** * Return results that match both `Dimension` objects. */ ands?: outputs.costexplorer.CostCategoryRuleRuleOrAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleOrCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleOrDimension; /** * Return results that match both `Dimension` object. */ not?: outputs.costexplorer.CostCategoryRuleRuleOrNot; /** * Return results that match both `Dimension` object. */ ors?: outputs.costexplorer.CostCategoryRuleRuleOrOr[]; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleOrTags; } interface CostCategoryRuleRuleOrAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleOrAndCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleOrAndDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleOrAndTags; } interface CostCategoryRuleRuleOrAndCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrAndDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrAndTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrNot { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleOrNotCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleOrNotDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleOrNotTags; } interface CostCategoryRuleRuleOrNotCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrNotDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrNotTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrOr { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategory?: outputs.costexplorer.CostCategoryRuleRuleOrOrCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimension?: outputs.costexplorer.CostCategoryRuleRuleOrOrDimension; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: outputs.costexplorer.CostCategoryRuleRuleOrOrTags; } interface CostCategoryRuleRuleOrOrCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrOrDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrOrTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleOrTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategoryRuleRuleTags { /** * Key for the tag. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface CostCategorySplitChargeRule { /** * Method that's used to define how to split your source costs across your targets. Valid values are `FIXED`, `PROPORTIONAL`, `EVEN` */ method: string; /** * Configuration block for the parameters for a split charge method. This is only required for the `FIXED` method. See below. */ parameters?: outputs.costexplorer.CostCategorySplitChargeRuleParameter[]; /** * Cost Category value that you want to split. */ source: string; /** * Cost Category values that you want to split costs across. These values can't be used as a source in other split charge rules. */ targets: string[]; } interface CostCategorySplitChargeRuleParameter { /** * Parameter type. */ type?: string; /** * Parameter values. */ values?: string[]; } interface GetCostCategoryRule { /** * Configuration block for the value the line item is categorized as if the line item contains the matched dimension. See below. */ inheritedValues: outputs.costexplorer.GetCostCategoryRuleInheritedValue[]; /** * Configuration block for the `Expression` object used to categorize costs. See below. */ rules: outputs.costexplorer.GetCostCategoryRuleRule[]; /** * Parameter type. */ type: string; /** * Default value for the cost category. */ value: string; } interface GetCostCategoryRuleInheritedValue { /** * Key to extract cost category values. */ dimensionKey: string; /** * Name of the dimension that's used to group costs. If you specify `LINKED_ACCOUNT_NAME`, the cost category value is based on account name. If you specify `TAG`, the cost category value will be based on the value of the specified tag key. Valid values are `LINKED_ACCOUNT_NAME`, `TAG` */ dimensionName: string; } interface GetCostCategoryRuleRule { /** * Return results that match both `Dimension` objects. */ ands: outputs.costexplorer.GetCostCategoryRuleRuleAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleDimension[]; /** * Return results that do not match the `Dimension` object. */ nots: outputs.costexplorer.GetCostCategoryRuleRuleNot[]; /** * Return results that match either `Dimension` object. */ ors: outputs.costexplorer.GetCostCategoryRuleRuleOr[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleTag[]; } interface GetCostCategoryRuleRuleAnd { /** * Return results that match both `Dimension` objects. */ ands: outputs.costexplorer.GetCostCategoryRuleRuleAndAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleAndCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleAndDimension[]; /** * Return results that do not match the `Dimension` object. */ nots: outputs.costexplorer.GetCostCategoryRuleRuleAndNot[]; /** * Return results that match either `Dimension` object. */ ors: outputs.costexplorer.GetCostCategoryRuleRuleAndOr[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleAndTag[]; } interface GetCostCategoryRuleRuleAndAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleAndAndCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleAndAndDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleAndAndTag[]; } interface GetCostCategoryRuleRuleAndAndCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndAndDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndAndTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndNot { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleAndNotCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleAndNotDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleAndNotTag[]; } interface GetCostCategoryRuleRuleAndNotCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndNotDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndNotTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndOr { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleAndOrCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleAndOrDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleAndOrTag[]; } interface GetCostCategoryRuleRuleAndOrCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndOrDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndOrTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleAndTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNot { /** * Return results that match both `Dimension` objects. */ ands: outputs.costexplorer.GetCostCategoryRuleRuleNotAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleNotCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleNotDimension[]; /** * Return results that do not match the `Dimension` object. */ nots: outputs.costexplorer.GetCostCategoryRuleRuleNotNot[]; /** * Return results that match either `Dimension` object. */ ors: outputs.costexplorer.GetCostCategoryRuleRuleNotOr[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleNotTag[]; } interface GetCostCategoryRuleRuleNotAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleNotAndCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleNotAndDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleNotAndTag[]; } interface GetCostCategoryRuleRuleNotAndCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotAndDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotAndTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotNot { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleNotNotCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleNotNotDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleNotNotTag[]; } interface GetCostCategoryRuleRuleNotNotCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotNotDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotNotTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotOr { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleNotOrCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleNotOrDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleNotOrTag[]; } interface GetCostCategoryRuleRuleNotOrCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotOrDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotOrTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleNotTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOr { /** * Return results that match both `Dimension` objects. */ ands: outputs.costexplorer.GetCostCategoryRuleRuleOrAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleOrCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleOrDimension[]; /** * Return results that do not match the `Dimension` object. */ nots: outputs.costexplorer.GetCostCategoryRuleRuleOrNot[]; /** * Return results that match either `Dimension` object. */ ors: outputs.costexplorer.GetCostCategoryRuleRuleOrOr[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleOrTag[]; } interface GetCostCategoryRuleRuleOrAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleOrAndCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleOrAndDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleOrAndTag[]; } interface GetCostCategoryRuleRuleOrAndCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrAndDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrAndTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrNot { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleOrNotCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleOrNotDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleOrNotTag[]; } interface GetCostCategoryRuleRuleOrNotCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrNotDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrNotTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrOr { /** * Configuration block for the filter that's based on `CostCategory` values. See below. */ costCategories: outputs.costexplorer.GetCostCategoryRuleRuleOrOrCostCategory[]; /** * Configuration block for the specific `Dimension` to use for `Expression`. See below. */ dimensions: outputs.costexplorer.GetCostCategoryRuleRuleOrOrDimension[]; /** * Configuration block for the specific `Tag` to use for `Expression`. See below. */ tags: outputs.costexplorer.GetCostCategoryRuleRuleOrOrTag[]; } interface GetCostCategoryRuleRuleOrOrCostCategory { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrOrDimension { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrOrTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleOrTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategoryRuleRuleTag { /** * Key for the tag. */ key: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions: string[]; /** * Parameter values. */ values: string[]; } interface GetCostCategorySplitChargeRule { /** * Method that's used to define how to split your source costs across your targets. Valid values are `FIXED`, `PROPORTIONAL`, `EVEN` */ method: string; /** * Configuration block for the parameters for a split charge method. This is only required for the `FIXED` method. See below. */ parameters: outputs.costexplorer.GetCostCategorySplitChargeRuleParameter[]; /** * Cost Category value that you want to split. */ source: string; /** * Cost Category values that you want to split costs across. These values can't be used as a source in other split charge rules. */ targets: string[]; } interface GetCostCategorySplitChargeRuleParameter { /** * Parameter type. */ type: string; /** * Parameter values. */ values: string[]; } interface GetTagsFilter { /** * Return results that match both `Dimension` objects. */ ands?: outputs.costexplorer.GetTagsFilterAnd[]; /** * Configuration block for the filter that's based on `CostCategory` values. See `costCategory` block below for details. */ costCategory?: outputs.costexplorer.GetTagsFilterCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See `dimension` block below for details. */ dimension?: outputs.costexplorer.GetTagsFilterDimension; /** * Return results that match both `Dimension` object. */ not?: outputs.costexplorer.GetTagsFilterNot; /** * Return results that match both `Dimension` object. */ ors?: outputs.costexplorer.GetTagsFilterOr[]; /** * Tags that match your request. */ tags?: outputs.costexplorer.GetTagsFilterTags; } interface GetTagsFilterAnd { /** * Configuration block for the filter that's based on `CostCategory` values. See `costCategory` block below for details. */ costCategory?: outputs.costexplorer.GetTagsFilterAndCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See `dimension` block below for details. */ dimension?: outputs.costexplorer.GetTagsFilterAndDimension; /** * Tags that match your request. */ tags?: outputs.costexplorer.GetTagsFilterAndTags; } interface GetTagsFilterAndCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterAndDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterAndTags { key?: string; matchOptions?: string[]; values?: string[]; } interface GetTagsFilterCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterNot { /** * Configuration block for the filter that's based on `CostCategory` values. See `costCategory` block below for details. */ costCategory?: outputs.costexplorer.GetTagsFilterNotCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See `dimension` block below for details. */ dimension?: outputs.costexplorer.GetTagsFilterNotDimension; /** * Tags that match your request. */ tags?: outputs.costexplorer.GetTagsFilterNotTags; } interface GetTagsFilterNotCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterNotDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterNotTags { key?: string; matchOptions?: string[]; values?: string[]; } interface GetTagsFilterOr { /** * Configuration block for the filter that's based on `CostCategory` values. See `costCategory` block below for details. */ costCategory?: outputs.costexplorer.GetTagsFilterOrCostCategory; /** * Configuration block for the specific `Dimension` to use for `Expression`. See `dimension` block below for details. */ dimension?: outputs.costexplorer.GetTagsFilterOrDimension; /** * Tags that match your request. */ tags?: outputs.costexplorer.GetTagsFilterOrTags; } interface GetTagsFilterOrCostCategory { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterOrDimension { /** * Unique name of the Cost Category. */ key?: string; /** * Match options that you can use to filter your results. MatchOptions is only applicable for actions related to cost category. The default values for MatchOptions is `EQUALS` and `CASE_SENSITIVE`. Valid values are: `EQUALS`, `ABSENT`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CASE_SENSITIVE`, `CASE_INSENSITIVE`. */ matchOptions?: string[]; /** * Specific value of the Cost Category. */ values?: string[]; } interface GetTagsFilterOrTags { key?: string; matchOptions?: string[]; values?: string[]; } interface GetTagsFilterTags { key?: string; matchOptions?: string[]; values?: string[]; } interface GetTagsSortBy { /** * key that's used to sort the data. Valid values are: `BlendedCost`, `UnblendedCost`, `AmortizedCost`, `NetAmortizedCost`, `NetUnblendedCost`, `UsageQuantity`, `NormalizedUsageAmount`. */ key?: string; /** * order that's used to sort the data. Valid values are: `ASCENDING`, `DESCENDING`. */ sortOrder?: string; } interface GetTagsTimePeriod { /** * Beginning of the time period. */ end: string; /** * End of the time period. */ start: string; } } export declare namespace customerprofiles { interface DomainMatching { /** * A block that specifies the configuration about the auto-merging process. Documented below. */ autoMerging: outputs.customerprofiles.DomainMatchingAutoMerging; /** * The flag that enables the matching process of duplicate profiles. */ enabled: boolean; /** * A block that specifies the configuration for exporting Identity Resolution results. Documented below. */ exportingConfig?: outputs.customerprofiles.DomainMatchingExportingConfig; /** * A block that specifies the day and time when you want to start the Identity Resolution Job every week. Documented below. */ jobSchedule?: outputs.customerprofiles.DomainMatchingJobSchedule; } interface DomainMatchingAutoMerging { /** * A block that specifies how the auto-merging process should resolve conflicts between different profiles. Documented below. */ conflictResolution?: outputs.customerprofiles.DomainMatchingAutoMergingConflictResolution; /** * A block that specifies a list of matching attributes that represent matching criteria. If two profiles meet at least one of the requirements in the matching attributes list, they will be merged. Documented below. * * ` minAllowedConfidenceScoreForMerging ` - (Optional) A number between 0 and 1 that represents the minimum confidence score required for profiles within a matching group to be merged during the auto-merge process. A higher score means higher similarity required to merge profiles. */ consolidation?: outputs.customerprofiles.DomainMatchingAutoMergingConsolidation; /** * The flag that enables the auto-merging of duplicate profiles. */ enabled: boolean; minAllowedConfidenceScoreForMerging?: number; } interface DomainMatchingAutoMergingConflictResolution { /** * How the auto-merging process should resolve conflicts between different profiles. Valid values are `RECENCY` and `SOURCE` */ conflictResolvingModel: string; /** * The `ObjectType` name that is used to resolve profile merging conflicts when choosing `SOURCE` as the `ConflictResolvingModel`. */ sourceName?: string; } interface DomainMatchingAutoMergingConsolidation { /** * A list of matching criteria. */ matchingAttributesLists: string[][]; } interface DomainMatchingExportingConfig { s3Exporting?: outputs.customerprofiles.DomainMatchingExportingConfigS3Exporting; } interface DomainMatchingExportingConfigS3Exporting { /** * The name of the S3 bucket where Identity Resolution Jobs write result files. */ s3BucketName: string; /** * The S3 key name of the location where Identity Resolution Jobs write result files. */ s3KeyName?: string; } interface DomainMatchingJobSchedule { /** * The day when the Identity Resolution Job should run every week. */ dayOfTheWeek: string; /** * The time when the Identity Resolution Job should run every week. */ time: string; } interface DomainRuleBasedMatching { /** * A block that configures information about the `AttributeTypesSelector` where the rule-based identity resolution uses to match profiles. Documented below. */ attributeTypesSelector?: outputs.customerprofiles.DomainRuleBasedMatchingAttributeTypesSelector; /** * A block that specifies how the auto-merging process should resolve conflicts between different profiles. Documented below. */ conflictResolution?: outputs.customerprofiles.DomainRuleBasedMatchingConflictResolution; /** * The flag that enables the rule-based matching process of duplicate profiles. */ enabled: boolean; /** * A block that specifies the configuration for exporting Identity Resolution results. Documented below. */ exportingConfig?: outputs.customerprofiles.DomainRuleBasedMatchingExportingConfig; /** * A block that configures how the rule-based matching process should match profiles. You can have up to 15 `rule` in the `natchingRules`. Documented below. */ matchingRules?: outputs.customerprofiles.DomainRuleBasedMatchingMatchingRule[]; /** * Indicates the maximum allowed rule level for matching. */ maxAllowedRuleLevelForMatching?: number; /** * Indicates the maximum allowed rule level for merging. */ maxAllowedRuleLevelForMerging?: number; status: string; } interface DomainRuleBasedMatchingAttributeTypesSelector { /** * The `Address` type. You can choose from `Address`, `BusinessAddress`, `MaillingAddress`, and `ShippingAddress`. */ addresses?: string[]; /** * Configures the `AttributeMatchingModel`, you can either choose `ONE_TO_ONE` or `MANY_TO_MANY`. */ attributeMatchingModel: string; /** * The `Email` type. You can choose from `EmailAddress`, `BusinessEmailAddress` and `PersonalEmailAddress`. */ emailAddresses?: string[]; /** * The `PhoneNumber` type. You can choose from `PhoneNumber`, `HomePhoneNumber`, and `MobilePhoneNumber`. */ phoneNumbers?: string[]; } interface DomainRuleBasedMatchingConflictResolution { /** * How the auto-merging process should resolve conflicts between different profiles. Valid values are `RECENCY` and `SOURCE` */ conflictResolvingModel: string; /** * The `ObjectType` name that is used to resolve profile merging conflicts when choosing `SOURCE` as the `ConflictResolvingModel`. */ sourceName?: string; } interface DomainRuleBasedMatchingExportingConfig { s3Exporting?: outputs.customerprofiles.DomainRuleBasedMatchingExportingConfigS3Exporting; } interface DomainRuleBasedMatchingExportingConfigS3Exporting { /** * The name of the S3 bucket where Identity Resolution Jobs write result files. */ s3BucketName: string; /** * The S3 key name of the location where Identity Resolution Jobs write result files. */ s3KeyName?: string; } interface DomainRuleBasedMatchingMatchingRule { /** * A single rule level of the `matchRules`. Configures how the rule-based matching process should match profiles. */ rules: string[]; } interface ProfileAddress { /** * The first line of a customer address. */ address1?: string; /** * The second line of a customer address. */ address2?: string; /** * The third line of a customer address. */ address3?: string; /** * The fourth line of a customer address. */ address4?: string; /** * The city in which a customer lives. */ city?: string; /** * The country in which a customer lives. */ country?: string; /** * The county in which a customer lives. */ county?: string; /** * The postal code of a customer address. */ postalCode?: string; /** * The province in which a customer lives. */ province?: string; /** * The state in which a customer lives. */ state?: string; } interface ProfileBillingAddress { /** * The first line of a customer address. */ address1?: string; /** * The second line of a customer address. */ address2?: string; /** * The third line of a customer address. */ address3?: string; /** * The fourth line of a customer address. */ address4?: string; /** * The city in which a customer lives. */ city?: string; /** * The country in which a customer lives. */ country?: string; /** * The county in which a customer lives. */ county?: string; /** * The postal code of a customer address. */ postalCode?: string; /** * The province in which a customer lives. */ province?: string; /** * The state in which a customer lives. */ state?: string; } interface ProfileMailingAddress { /** * The first line of a customer address. */ address1?: string; /** * The second line of a customer address. */ address2?: string; /** * The third line of a customer address. */ address3?: string; /** * The fourth line of a customer address. */ address4?: string; /** * The city in which a customer lives. */ city?: string; /** * The country in which a customer lives. */ country?: string; /** * The county in which a customer lives. */ county?: string; /** * The postal code of a customer address. */ postalCode?: string; /** * The province in which a customer lives. */ province?: string; /** * The state in which a customer lives. */ state?: string; } interface ProfileShippingAddress { /** * The first line of a customer address. */ address1?: string; /** * The second line of a customer address. */ address2?: string; /** * The third line of a customer address. */ address3?: string; /** * The fourth line of a customer address. */ address4?: string; /** * The city in which a customer lives. */ city?: string; /** * The country in which a customer lives. */ country?: string; /** * The county in which a customer lives. */ county?: string; /** * The postal code of a customer address. */ postalCode?: string; /** * The province in which a customer lives. */ province?: string; /** * The state in which a customer lives. */ state?: string; } } export declare namespace dataexchange { interface EventActionAction { /** * Configuration for an Export Revision to S3 action. * Described in `exportRevisionToS3` Configuration Block */ exportRevisionToS3: outputs.dataexchange.EventActionActionExportRevisionToS3; } interface EventActionActionExportRevisionToS3 { /** * Configures server-side encryption of the exported revision. * Described in `encryption` Configuration Block below. */ encryption?: outputs.dataexchange.EventActionActionExportRevisionToS3Encryption; /** * Configures the S3 destination of the exported revision. * Described in `revisionDestination` Configuration Block below. */ revisionDestination: outputs.dataexchange.EventActionActionExportRevisionToS3RevisionDestination; } interface EventActionActionExportRevisionToS3Encryption { /** * ARN of the KMS key used for encryption. */ kmsKeyArn?: string; /** * Type of server-side encryption. * Valid values are `aws:kms` or `aws:s3`. */ type?: string; } interface EventActionActionExportRevisionToS3RevisionDestination { /** * The S3 bucket where the revision will be exported. */ bucket: string; /** * Pattern for naming revisions in the S3 bucket. * Defaults to `${Revision.CreatedAt}/${Asset.Name}`. */ keyPattern: string; } interface EventActionEvent { /** * Configuration for a Revision Published event. * Described in `revisionPublished` Configuration Block below. */ revisionPublished: outputs.dataexchange.EventActionEventRevisionPublished; } interface EventActionEventRevisionPublished { /** * The ID of the data set to monitor for revision publications. * Changing this value will recreate the resource. */ dataSetId: string; } interface RevisionAssetsAsset { /** * The ARN of the Data Exchange Revision Assets. */ arn: string; /** * A block to create S3 data access from an S3 bucket. See Create S3 Data Access from S3 Bucket for more details. */ createS3DataAccessFromS3Bucket?: outputs.dataexchange.RevisionAssetsAssetCreateS3DataAccessFromS3Bucket; /** * The timestamp when the revision was created, in RFC3339 format. */ createdAt: string; /** * The unique identifier for the revision. */ id: string; /** * A block to import assets from S3. See Import Assets from S3 for more details. */ importAssetsFromS3?: outputs.dataexchange.RevisionAssetsAssetImportAssetsFromS3; /** * A block to import assets from a signed URL. See Import Assets from Signed URL for more details. */ importAssetsFromSignedUrl?: outputs.dataexchange.RevisionAssetsAssetImportAssetsFromSignedUrl; name: string; /** * The timestamp when the revision was last updated, in RFC3339 format. */ updatedAt: string; } interface RevisionAssetsAssetCreateS3DataAccessFromS3Bucket { accessPointAlias: string; accessPointArn: string; /** * A block specifying the source bucket for the asset. This block supports the following: */ assetSource?: outputs.dataexchange.RevisionAssetsAssetCreateS3DataAccessFromS3BucketAssetSource; } interface RevisionAssetsAssetCreateS3DataAccessFromS3BucketAssetSource { /** * The name of the S3 bucket. */ bucket: string; /** * List of key prefixes in the S3 bucket. */ keyPrefixes?: string[]; /** * List of object keys in the S3 bucket. */ keys?: string[]; kmsKeysToGrants?: outputs.dataexchange.RevisionAssetsAssetCreateS3DataAccessFromS3BucketAssetSourceKmsKeysToGrant[]; } interface RevisionAssetsAssetCreateS3DataAccessFromS3BucketAssetSourceKmsKeysToGrant { /** * The ARN of the KMS key. */ kmsKeyArn: string; } interface RevisionAssetsAssetImportAssetsFromS3 { /** * A block specifying the source bucket and key for the asset. This block supports the following: */ assetSource?: outputs.dataexchange.RevisionAssetsAssetImportAssetsFromS3AssetSource; } interface RevisionAssetsAssetImportAssetsFromS3AssetSource { /** * The name of the S3 bucket. */ bucket: string; /** * The key of the object in the S3 bucket. */ key: string; } interface RevisionAssetsAssetImportAssetsFromSignedUrl { /** * The name of the file to import. */ filename: string; } interface RevisionAssetsTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } } export declare namespace datapipeline { interface GetPipelineDefinitionParameterObject { attributes: outputs.datapipeline.GetPipelineDefinitionParameterObjectAttribute[]; /** * ID of the object. */ id: string; } interface GetPipelineDefinitionParameterObjectAttribute { /** * Field identifier. */ key: string; /** * Field value, expressed as a String. */ stringValue: string; } interface GetPipelineDefinitionParameterValue { /** * ID of the object. */ id: string; /** * Field value, expressed as a String. */ stringValue: string; } interface GetPipelineDefinitionPipelineObject { /** * Key-value pairs that define the properties of the object. See below */ fields?: outputs.datapipeline.GetPipelineDefinitionPipelineObjectField[]; /** * ID of the object. */ id: string; /** * ARN of the storage connector. */ name: string; } interface GetPipelineDefinitionPipelineObjectField { /** * Field identifier. */ key: string; /** * Field value, expressed as the identifier of another object */ refValue: string; /** * Field value, expressed as a String. */ stringValue: string; } interface PipelineDefinitionParameterObject { /** * Configuration block for attributes of the parameter object. See below */ attributes?: outputs.datapipeline.PipelineDefinitionParameterObjectAttribute[]; /** * ID of the parameter object. */ id: string; } interface PipelineDefinitionParameterObjectAttribute { /** * Field identifier. */ key: string; /** * Field value, expressed as a String. */ stringValue: string; } interface PipelineDefinitionParameterValue { /** * ID of the parameter value. */ id: string; /** * Field value, expressed as a String. */ stringValue: string; } interface PipelineDefinitionPipelineObject { /** * Configuration block for Key-value pairs that define the properties of the object. See below */ fields?: outputs.datapipeline.PipelineDefinitionPipelineObjectField[]; /** * ID of the object. */ id: string; /** * ARN of the storage connector. */ name: string; } interface PipelineDefinitionPipelineObjectField { /** * Field identifier. */ key: string; /** * Field value, expressed as the identifier of another object */ refValue?: string; /** * Field value, expressed as a String. */ stringValue?: string; } } export declare namespace datasync { interface EfsLocationEc2Config { /** * List of ARNs of the EC2 Security Groups that are associated with the EFS Mount Target. */ securityGroupArns: string[]; /** * ARN of the EC2 Subnet that is associated with the EFS Mount Target. */ subnetArn: string; } interface FsxOpenZfsFileSystemProtocol { /** * Represents the Network File System (NFS) protocol that DataSync uses to access your FSx for OpenZFS file system. See below. */ nfs: outputs.datasync.FsxOpenZfsFileSystemProtocolNfs; } interface FsxOpenZfsFileSystemProtocolNfs { /** * Represents the mount options that are available for DataSync to access an NFS location. See below. */ mountOptions: outputs.datasync.FsxOpenZfsFileSystemProtocolNfsMountOptions; } interface FsxOpenZfsFileSystemProtocolNfsMountOptions { /** * The specific NFS version that you want DataSync to use for mounting your NFS share. Valid values: `AUTOMATIC`, `NFS3`, `NFS4_0` and `NFS4_1`. Default: `AUTOMATIC` */ version?: string; } interface LocationAzureBlobSasConfiguration { /** * A SAS token that provides permissions to access your Azure Blob Storage. */ token: string; } interface LocationFsxOntapFileSystemProtocol { /** * Network File System (NFS) protocol that DataSync uses to access your FSx ONTAP file system. See NFS below. */ nfs?: outputs.datasync.LocationFsxOntapFileSystemProtocolNfs; /** * Server Message Block (SMB) protocol that DataSync uses to access your FSx ONTAP file system. See [SMB] (#smb) below. */ smb?: outputs.datasync.LocationFsxOntapFileSystemProtocolSmb; } interface LocationFsxOntapFileSystemProtocolNfs { /** * Mount options that are available for DataSync to access an NFS location. See NFS Mount Options below. */ mountOptions: outputs.datasync.LocationFsxOntapFileSystemProtocolNfsMountOptions; } interface LocationFsxOntapFileSystemProtocolNfsMountOptions { version?: string; } interface LocationFsxOntapFileSystemProtocolSmb { /** * Fully qualified domain name of the Microsoft Active Directory (AD) that your storage virtual machine belongs to. */ domain?: string; /** * Mount options that are available for DataSync to access an SMB location. See SMB Mount Options below. */ mountOptions: outputs.datasync.LocationFsxOntapFileSystemProtocolSmbMountOptions; /** * Password of a user who has permission to access your SVM. */ password: string; /** * Username that can mount the location and access the files, folders, and metadata that you need in the SVM. */ user: string; } interface LocationFsxOntapFileSystemProtocolSmbMountOptions { version?: string; } interface LocationHdfsNameNode { /** * The hostname of the NameNode in the HDFS cluster. This value is the IP address or Domain Name Service (DNS) name of the NameNode. An agent that's installed on-premises uses this hostname to communicate with the NameNode in the network. */ hostname: string; /** * The port that the NameNode uses to listen to client requests. */ port: number; } interface LocationHdfsQopConfiguration { /** * The data transfer protection setting configured on the HDFS cluster. This setting corresponds to your dfs.data.transfer.protection setting in the hdfs-site.xml file on your Hadoop cluster. Valid values are `DISABLED`, `AUTHENTICATION`, `INTEGRITY` and `PRIVACY`. */ dataTransferProtection: string; /** * The RPC protection setting configured on the HDFS cluster. This setting corresponds to your hadoop.rpc.protection setting in your core-site.xml file on your Hadoop cluster. Valid values are `DISABLED`, `AUTHENTICATION`, `INTEGRITY` and `PRIVACY`. */ rpcProtection: string; } interface LocationSmbMountOptions { /** * The specific SMB version that you want DataSync to use for mounting your SMB share. Valid values: `AUTOMATIC`, `SMB2`, and `SMB3`. Default: `AUTOMATIC` */ version?: string; } interface NfsLocationMountOptions { /** * The specific NFS version that you want DataSync to use for mounting your NFS share. Valid values: `AUTOMATIC`, `NFS3`, `NFS4_0` and `NFS4_1`. Default: `AUTOMATIC` */ version?: string; } interface NfsLocationOnPremConfig { /** * List of ARNs of the DataSync Agents used to connect to the NFS server. */ agentArns: string[]; } interface S3LocationS3Config { /** * ARN of the IAM Role used to connect to the S3 Bucket. */ bucketAccessRoleArn: string; } interface TaskExcludes { /** * The type of filter rule to apply. Valid values: `SIMPLE_PATTERN`. */ filterType?: string; /** * A single filter string that consists of the patterns to exclude. The patterns are delimited by "|" (that is, a pipe), for example: `/folder1|/folder2` */ value?: string; } interface TaskIncludes { /** * The type of filter rule to apply. Valid values: `SIMPLE_PATTERN`. */ filterType?: string; /** * A single filter string that consists of the patterns to include. The patterns are delimited by "|" (that is, a pipe), for example: `/folder1|/folder2` */ value?: string; } interface TaskOptions { /** * A file metadata that shows the last time a file was accessed (that is when the file was read or written to). If set to `BEST_EFFORT`, the DataSync Task attempts to preserve the original (that is, the version before sync `PREPARING` phase) `atime` attribute on all source files. Valid values: `BEST_EFFORT`, `NONE`. Default: `BEST_EFFORT`. */ atime?: string; /** * Limits the bandwidth utilized. For example, to set a maximum of 1 MB, set this value to `1048576`. Value values: `-1` or greater. Default: `-1` (unlimited). */ bytesPerSecond?: number; /** * Group identifier of the file's owners. Valid values: `BOTH`, `INT_VALUE`, `NAME`, `NONE`. Default: `INT_VALUE` (preserve integer value of the ID). */ gid?: string; /** * Determines the type of logs that DataSync publishes to a log stream in the Amazon CloudWatch log group that you provide. Valid values: `OFF`, `BASIC`, `TRANSFER`. Default: `OFF`. */ logLevel?: string; /** * A file metadata that indicates the last time a file was modified (written to) before the sync `PREPARING` phase. Value values: `NONE`, `PRESERVE`. Default: `PRESERVE`. */ mtime?: string; /** * Specifies whether object tags are maintained when transferring between object storage systems. If you want your DataSync task to ignore object tags, specify the NONE value. Valid values: `PRESERVE`, `NONE`. Default value: `PRESERVE`. */ objectTags?: string; /** * Determines whether files at the destination should be overwritten or preserved when copying files. Valid values: `ALWAYS`, `NEVER`. Default: `ALWAYS`. */ overwriteMode?: string; /** * Determines which users or groups can access a file for a specific purpose such as reading, writing, or execution of the file. Valid values: `NONE`, `PRESERVE`. Default: `PRESERVE`. */ posixPermissions?: string; /** * Whether files deleted in the source should be removed or preserved in the destination file system. Valid values: `PRESERVE`, `REMOVE`. Default: `PRESERVE`. */ preserveDeletedFiles?: string; /** * Whether the DataSync Task should preserve the metadata of block and character devices in the source files system, and recreate the files with that device name and metadata on the destination. The DataSync Task can’t sync the actual contents of such devices, because many of the devices are non-terminal and don’t return an end of file (EOF) marker. Valid values: `NONE`, `PRESERVE`. Default: `NONE` (ignore special devices). */ preserveDevices?: string; /** * Determines which components of the SMB security descriptor are copied from source to destination objects. This value is only used for transfers between SMB and Amazon FSx for Windows File Server locations, or between two Amazon FSx for Windows File Server locations. Valid values: `NONE`, `OWNER_DACL`, `OWNER_DACL_SACL`. Default: `OWNER_DACL`. */ securityDescriptorCopyFlags: string; /** * Determines whether tasks should be queued before executing the tasks. Valid values: `ENABLED`, `DISABLED`. Default `ENABLED`. */ taskQueueing?: string; /** * Determines whether DataSync transfers only the data and metadata that differ between the source and the destination location, or whether DataSync transfers all the content from the source, without comparing to the destination location. Valid values: `CHANGED`, `ALL`. Default: `CHANGED` */ transferMode?: string; /** * User identifier of the file's owners. Valid values: `BOTH`, `INT_VALUE`, `NAME`, `NONE`. Default: `INT_VALUE` (preserve integer value of the ID). */ uid?: string; /** * Whether a data integrity verification should be performed at the end of a task execution after all data and metadata have been transferred. Valid values: `NONE`, `POINT_IN_TIME_CONSISTENT`, `ONLY_FILES_TRANSFERRED`. Default: `POINT_IN_TIME_CONSISTENT`. */ verifyMode?: string; } interface TaskSchedule { /** * Specifies the schedule you want your task to use for repeated executions. For more information, see [Schedule Expressions for Rules](https://docs.aws.amazon.com/AmazonCloudWatch/latest/events/ScheduledEvents.html). */ scheduleExpression: string; /** * Whether to enable or disable your task schedule. Valid values: `ENABLED`, `DISABLED`. Default: `ENABLED`. */ status: string; } interface TaskTaskReportConfig { /** * Specifies the type of task report you'd like. Valid values: `SUMMARY_ONLY` and `STANDARD`. */ outputType?: string; /** * Specifies whether you want your task report to include only what went wrong with your transfer or a list of what succeeded and didn't. Valid values: `ERRORS_ONLY` and `SUCCESSES_AND_ERRORS`. */ reportLevel?: string; /** * Configuration block containing the configuration of the reporting level for aspects of your task report. See `reportOverrides` below. */ reportOverrides?: outputs.datasync.TaskTaskReportConfigReportOverrides; /** * Configuration block containing the configuration for the Amazon S3 bucket where DataSync uploads your task report. See `s3Destination` below. */ s3Destination: outputs.datasync.TaskTaskReportConfigS3Destination; /** * Specifies whether your task report includes the new version of each object transferred into an S3 bucket. This only applies if you enable versioning on your bucket. Keep in mind that setting this to INCLUDE can increase the duration of your task execution. Valid values: `INCLUDE` and `NONE`. */ s3ObjectVersioning?: string; } interface TaskTaskReportConfigReportOverrides { /** * Specifies the level of reporting for the files, objects, and directories that DataSync attempted to delete in your destination location. This only applies if you configure your task to delete data in the destination that isn't in the source. Valid values: `ERRORS_ONLY` and `SUCCESSES_AND_ERRORS`. */ deletedOverride?: string; /** * Specifies the level of reporting for the files, objects, and directories that DataSync attempted to skip during your transfer. Valid values: `ERRORS_ONLY` and `SUCCESSES_AND_ERRORS`. */ skippedOverride?: string; /** * Specifies the level of reporting for the files, objects, and directories that DataSync attempted to transfer. Valid values: `ERRORS_ONLY` and `SUCCESSES_AND_ERRORS`. */ transferredOverride?: string; /** * Specifies the level of reporting for the files, objects, and directories that DataSync attempted to verify at the end of your transfer. Valid values: `ERRORS_ONLY` and `SUCCESSES_AND_ERRORS`. * * > **NOTE:** If any `reportOverrides` are set to the same value as `task_report_config.report_level`, they will always be flagged as changed. Only set overrides to a value that differs from `task_report_config.report_level`. */ verifiedOverride?: string; } interface TaskTaskReportConfigS3Destination { /** * ARN of the IAM policy that allows DataSync to upload a task report to your S3 bucket. */ bucketAccessRoleArn: string; /** * Specifies the ARN of the S3 bucket where DataSync uploads your report. */ s3BucketArn: string; /** * Specifies a bucket prefix for your report. */ subdirectory?: string; } } export declare namespace datazone { interface AssetTypeFormsInput { mapBlockKey: string; required?: boolean; typeIdentifier: string; typeRevision: string; } interface AssetTypeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface DomainSingleSignOn { type: string; userAssignment?: string; } interface DomainTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface EnvironmentLastDeployment { deploymentId: string; deploymentStatus: string; deploymentType: string; failureReasons: outputs.datazone.EnvironmentLastDeploymentFailureReason[]; isDeploymentComplete: boolean; messages: string[]; } interface EnvironmentLastDeploymentFailureReason { code: string; message: string; } interface EnvironmentProfileUserParameter { /** * Name of the environment profile parameter. */ name?: string; /** * Value of the environment profile parameter. */ value?: string; } interface EnvironmentProvisionedResource { /** * The name of the environment. */ name: string; provider: string; type: string; /** * The value of an environment profile parameter. */ value: string; } interface EnvironmentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface EnvironmentUserParameter { /** * The name of an environment profile parameter. */ name?: string; /** * The value of an environment profile parameter. */ value?: string; } interface FormTypeImport { /** * Name of the form type. Must be the name of the structure in smithy document. */ name: string; /** * Revision of the Form Type. */ revision: string; } interface FormTypeModel { /** * Smithy document that indicates the model of the API. Must be between the lengths 1 and 100,000 and be encoded as a smithy document. * * The following arguments are optional: */ smithy: string; } interface FormTypeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface GlossaryTermTermRelations { /** * String array that calssifies the term relations. */ classifies?: string[]; isAs?: string[]; } interface GlossaryTermTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface PolicyGrantDetail { /** * Configuration for the `ADD_TO_PROJECT_MEMBER_POOL` policy type. See `addToProjectMemberPool` Block below. */ addToProjectMemberPool?: outputs.datazone.PolicyGrantDetailAddToProjectMemberPool; /** * Configuration for the `CREATE_ASSET_TYPE` policy type. See `createAssetType` Block below. */ createAssetType?: outputs.datazone.PolicyGrantDetailCreateAssetType; /** * Configuration for the `CREATE_DOMAIN_UNIT` policy type. See `createDomainUnit` Block below. */ createDomainUnit?: outputs.datazone.PolicyGrantDetailCreateDomainUnit; /** * Configuration for the `CREATE_ENVIRONMENT` policy type. Empty block. */ createEnvironment?: outputs.datazone.PolicyGrantDetailCreateEnvironment; /** * Configuration for the `CREATE_ENVIRONMENT_FROM_BLUEPRINT` policy type. Empty block. */ createEnvironmentFromBlueprint?: outputs.datazone.PolicyGrantDetailCreateEnvironmentFromBlueprint; /** * Configuration for the `CREATE_ENVIRONMENT_PROFILE` policy type. See `createEnvironmentProfile` Block below. */ createEnvironmentProfile?: outputs.datazone.PolicyGrantDetailCreateEnvironmentProfile; /** * Configuration for the `CREATE_FORM_TYPE` policy type. See `createFormType` Block below. */ createFormType?: outputs.datazone.PolicyGrantDetailCreateFormType; /** * Configuration for the `CREATE_GLOSSARY` policy type. See `createGlossary` Block below. */ createGlossary?: outputs.datazone.PolicyGrantDetailCreateGlossary; /** * Configuration for the `CREATE_PROJECT` policy type. See `createProject` Block below. */ createProject?: outputs.datazone.PolicyGrantDetailCreateProject; /** * Configuration for the `CREATE_PROJECT_FROM_PROJECT_PROFILE` policy type. See `createProjectFromProjectProfile` Block below. */ createProjectFromProjectProfile?: outputs.datazone.PolicyGrantDetailCreateProjectFromProjectProfile; /** * Configuration for the `DELEGATE_CREATE_ENVIRONMENT_PROFILE` policy type. Empty block. */ delegateCreateEnvironmentProfile?: outputs.datazone.PolicyGrantDetailDelegateCreateEnvironmentProfile; /** * Configuration for the `OVERRIDE_DOMAIN_UNIT_OWNERS` policy type. See `overrideDomainUnitOwners` Block below. */ overrideDomainUnitOwners?: outputs.datazone.PolicyGrantDetailOverrideDomainUnitOwners; /** * Configuration for the `OVERRIDE_PROJECT_OWNERS` policy type. See `overrideProjectOwners` Block below. */ overrideProjectOwners?: outputs.datazone.PolicyGrantDetailOverrideProjectOwners; /** * Configuration for the `USE_ASSET_TYPE` policy type. See `useAssetType` Block below. */ useAssetType?: outputs.datazone.PolicyGrantDetailUseAssetType; } interface PolicyGrantDetailAddToProjectMemberPool { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailCreateAssetType { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailCreateDomainUnit { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailCreateEnvironment { } interface PolicyGrantDetailCreateEnvironmentFromBlueprint { } interface PolicyGrantDetailCreateEnvironmentProfile { /** * Identifier of the domain unit. */ domainUnitId?: string; } interface PolicyGrantDetailCreateFormType { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailCreateGlossary { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailCreateProject { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailCreateProjectFromProjectProfile { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; /** * List of project profile identifiers. */ projectProfiles?: string[]; } interface PolicyGrantDetailDelegateCreateEnvironmentProfile { } interface PolicyGrantDetailOverrideDomainUnitOwners { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailOverrideProjectOwners { /** * Whether to include child domain units. */ includeChildDomainUnits?: boolean; } interface PolicyGrantDetailUseAssetType { /** * Identifier of the domain unit. */ domainUnitId?: string; } interface PolicyGrantPrincipal { /** * Domain unit principal. See `domainUnit` Block below. */ domainUnit?: outputs.datazone.PolicyGrantPrincipalDomainUnit; /** * Group principal. See `group` Block below. */ group?: outputs.datazone.PolicyGrantPrincipalGroup; /** * Project principal. See `project` Block below. */ project?: outputs.datazone.PolicyGrantPrincipalProject; /** * User principal. See `user` Block below. */ user?: outputs.datazone.PolicyGrantPrincipalUser; } interface PolicyGrantPrincipalDomainUnit { /** * Filter to grant access to all domain units. Empty block. */ allDomainUnitsGrantFilter?: outputs.datazone.PolicyGrantPrincipalDomainUnitAllDomainUnitsGrantFilter; /** * Designation of the domain unit principal. Valid values: `OWNER`. */ domainUnitDesignation: string; /** * Identifier of the domain unit. */ domainUnitIdentifier?: string; } interface PolicyGrantPrincipalDomainUnitAllDomainUnitsGrantFilter { } interface PolicyGrantPrincipalGroup { /** * Identifier of the group principal. */ groupIdentifier: string; } interface PolicyGrantPrincipalProject { /** * Filter for domain unit scoping. See `domainUnitFilter` Block below. */ domainUnitFilter?: outputs.datazone.PolicyGrantPrincipalProjectDomainUnitFilter; /** * Designation of the project principal. Valid values: `CONTRIBUTOR`, `OWNER`, `PROJECT_CATALOG_STEWARD`. */ projectDesignation: string; /** * Identifier of the project. */ projectIdentifier?: string; } interface PolicyGrantPrincipalProjectDomainUnitFilter { /** * Identifier of the domain unit for filtering. */ domainUnit: string; /** * Whether to include child domain units in the filter. */ includeChildDomainUnits?: boolean; } interface PolicyGrantPrincipalUser { /** * Filter to grant access to all users. Empty block. */ allUsersGrantFilter?: outputs.datazone.PolicyGrantPrincipalUserAllUsersGrantFilter; /** * Identifier of the user principal. */ userIdentifier?: string; } interface PolicyGrantPrincipalUserAllUsersGrantFilter { } interface ProjectFailureReason { code: string; message: string; } interface ProjectTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface UserProfileDetail { iams: outputs.datazone.UserProfileDetailIam[]; ssos: outputs.datazone.UserProfileDetailSso[]; } interface UserProfileDetailIam { arn: string; } interface UserProfileDetailSso { firstName: string; lastName: string; userName: string; } interface UserProfileTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace dax { interface ClusterNode { address: string; availabilityZone: string; id: string; /** * The port used by the configuration endpoint */ port: number; } interface ClusterServerSideEncryption { /** * Whether to enable encryption at rest. Defaults to `false`. */ enabled?: boolean; } interface ParameterGroupParameter { /** * The name of the parameter. */ name: string; /** * The value for the parameter. */ value: string; } } export declare namespace devicefarm { interface DevicePoolRule { /** * The rule's stringified attribute. Valid values are: `APPIUM_VERSION`, `ARN`, `AVAILABILITY`, `FLEET_TYPE`, `FORM_FACTOR`, `INSTANCE_ARN`, `INSTANCE_LABELS`, `MANUFACTURER`, `MODEL`, `OS_VERSION`, `PLATFORM`, `REMOTE_ACCESS_ENABLED`, `REMOTE_DEBUG_ENABLED`. */ attribute?: string; /** * Specifies how Device Farm compares the rule's attribute to the value. For the operators that are supported by each attribute. Valid values are: `EQUALS`, `NOT_IN`, `IN`, `GREATER_THAN`, `GREATER_THAN_OR_EQUALS`, `LESS_THAN`, `LESS_THAN_OR_EQUALS`, `CONTAINS`. */ operator?: string; /** * The rule's value. */ value?: string; } interface TestGridProjectVpcConfig { /** * A list of VPC security group IDs in your Amazon VPC. */ securityGroupIds: string[]; /** * A list of VPC subnet IDs in your Amazon VPC. */ subnetIds: string[]; /** * The ID of the Amazon VPC. */ vpcId: string; } } export declare namespace devopsguru { interface EventSourcesConfigEventSource { /** * Stores whether DevOps Guru is configured to consume recommendations which are generated from AWS CodeGuru Profiler. See `amazonCodeGuruProfiler` below. */ amazonCodeGuruProfilers: outputs.devopsguru.EventSourcesConfigEventSourceAmazonCodeGuruProfiler[]; } interface EventSourcesConfigEventSourceAmazonCodeGuruProfiler { /** * Status of the CodeGuru Profiler integration. Valid values are `ENABLED` and `DISABLED`. */ status: string; } interface GetNotificationChannelFilter { /** * Events to receive notifications for. */ messageTypes: string[]; /** * Severity levels to receive notifications for. */ severities: string[]; } interface GetNotificationChannelSn { /** * ARN of an Amazon Simple Notification Service topic. */ topicArn: string; } interface GetResourceCollectionCloudformation { /** * Array of the names of the AWS CloudFormation stacks. */ stackNames: string[]; } interface GetResourceCollectionTag { /** * An AWS tag key that is used to identify the AWS resources that DevOps Guru analyzes. */ appBoundaryKey: string; /** * Array of tag values. */ tagValues: string[]; } interface NotificationChannelFilters { /** * Events to receive notifications for. Valid values are `NEW_INSIGHT`, `CLOSED_INSIGHT`, `NEW_ASSOCIATION`, `SEVERITY_UPGRADED`, and `NEW_RECOMMENDATION`. */ messageTypes?: string[]; /** * Severity levels to receive notifications for. Valid values are `LOW`, `MEDIUM`, and `HIGH`. */ severities?: string[]; } interface NotificationChannelSns { /** * ARN of an Amazon Simple Notification Service topic. */ topicArn: string; } interface ResourceCollectionCloudformation { /** * Array of the names of the AWS CloudFormation stacks. If `type` is `AWS_SERVICE` (all acccount resources) this array should be a single item containing a wildcard (`"*"`). */ stackNames: string[]; } interface ResourceCollectionTags { /** * An AWS tag key that is used to identify the AWS resources that DevOps Guru analyzes. All AWS resources in your account and Region tagged with this key make up your DevOps Guru application and analysis boundary. The key must begin with the prefix `DevOps-Guru-`. Any casing can be used for the prefix, but the associated tags __must use the same casing__ in their tag key. */ appBoundaryKey: string; /** * Array of tag values. These can be used to further filter for specific resources within the application boundary. To analyze all resources tagged with the `appBoundaryKey` regardless of the corresponding tag value, this array should be a single item containing a wildcard (`"*"`). */ tagValues: string[]; } interface ServiceIntegrationKmsServerSideEncryption { /** * KMS key ID. This value can be a key ID, key ARN, alias name, or alias ARN. */ kmsKeyId: string; /** * Specifies whether KMS integration is enabled. Valid values are `DISABLED` and `ENABLED`. */ optInStatus: string; /** * Type of KMS key used. Valid values are `CUSTOMER_MANAGED_KEY` and `AWS_OWNED_KMS_KEY`. */ type: string; } interface ServiceIntegrationLogsAnomalyDetection { /** * Specifies if DevOps Guru is configured to perform log anomaly detection on CloudWatch log groups. Valid values are `DISABLED` and `ENABLED`. */ optInStatus: string; } interface ServiceIntegrationOpsCenter { /** * Specifies if DevOps Guru is enabled to create an AWS Systems Manager OpsItem for each created insight. Valid values are `DISABLED` and `ENABLED`. */ optInStatus: string; } } export declare namespace directconnect { interface ConnectionRateLimiterStatus { /** * Number of rate limiters currently in use. */ inUse: number; /** * Maximum number of rate limiters allowed on the connection. */ maxAllowed: number; /** * Number of rate limiters remaining (available). */ remaining: number; /** * Total bandwidth allocated across all rate limiters. */ totalBandwidth: string; } interface GetConnectionRateLimiterStatus { /** * Number of rate limiters currently in use. */ inUse: number; /** * Maximum number of rate limiters allowed on the connection. */ maxAllowed: number; /** * Number of rate limiters remaining (available). */ remaining: number; /** * Total bandwidth allocated across all rate limiters. */ totalBandwidth: string; } interface GetRouterConfigurationRouter { /** * Router platform */ platform: string; /** * ID of the Router Type. For example: `CiscoSystemsInc-2900SeriesRouters-IOS124` * * There is currently no AWS API to retrieve the full list of `routerTypeIdentifier` values. Here is a list of known `RouterType` objects that can be used: * * ```json * { * "routerTypes": [ * {"platform":"2900 Series Routers","routerTypeIdentifier":"CiscoSystemsInc-2900SeriesRouters-IOS124","software":"IOS 12.4+","vendor":"Cisco Systems, Inc.","xsltTemplateName":"customer-router-cisco-generic.xslt","xsltTemplateNameForMacSec":""}, * {"platform":"3700 Series Routers","routerTypeIdentifier":"CiscoSystemsInc-3700SeriesRouters-IOS124","software":"IOS 12.4+","vendor":"Cisco Systems, Inc.","xsltTemplateName":"customer-router-cisco-generic.xslt","xsltTemplateNameForMacSec":""}, * {"platform":"7200 Series Routers","routerTypeIdentifier":"CiscoSystemsInc-7200SeriesRouters-IOS124","software":"IOS 12.4+","vendor":"Cisco Systems, Inc.","xsltTemplateName":"customer-router-cisco-generic.xslt","xsltTemplateNameForMacSec":""}, * {"platform":"Nexus 7000 Series Switches","routerTypeIdentifier":"CiscoSystemsInc-Nexus7000SeriesSwitches-NXOS51","software":"NX-OS 5.1+","vendor":"Cisco Systems, Inc.","xsltTemplateName":"customer-switch-cisco-nexus-generic.xslt","xsltTemplateNameForMacSec":""}, * {"platform":"Nexus 9K+ Series Switches","routerTypeIdentifier":"CiscoSystemsInc-Nexus9KSeriesSwitches-NXOS93","software":"NX-OS 9.3+","vendor":"Cisco Systems, Inc.","xsltTemplateName":"customer-switch-cisco-nexus-generic.xslt","xsltTemplateNameForMacSec":"customer-switch-cisco-nexus-generic-macsec.xslt"}, * {"platform":"M/MX Series Routers","routerTypeIdentifier":"JuniperNetworksInc-MMXSeriesRouters-JunOS95","software":"JunOS 9.5+","vendor":"Juniper Networks, Inc.","xsltTemplateName":"customer-router-juniper-generic.xslt","xsltTemplateNameForMacSec":"customer-router-juniper-generic-macsec.xslt"}, * {"platform":"SRX Series Routers","routerTypeIdentifier":"JuniperNetworksInc-SRXSeriesRouters-JunOS95","software":"JunOS 9.5+","vendor":"Juniper Networks, Inc.","xsltTemplateName":"customer-router-juniper-generic.xslt","xsltTemplateNameForMacSec":""}, * {"platform":"T Series Routers","routerTypeIdentifier":"JuniperNetworksInc-TSeriesRouters-JunOS95","software":"JunOS 9.5+","vendor":"Juniper Networks, Inc.","xsltTemplateName":"customer-router-juniper-generic.xslt","xsltTemplateNameForMacSec":""}, * {"platform":"PA-3000+ and 5000+ series","routerTypeIdentifier":"PaloAltoNetworks-PA3000and5000series-PANOS803","software":"PAN-OS 8.0.3+","vendor":"Palo Alto Networks","xsltTemplateName":"customer-router-palo-alto-generic.xslt","xsltTemplateNameForMacSec":""}] * } * ``` */ routerTypeIdentifier: string; /** * Router operating system */ software: string; /** * Router vendor */ vendor: string; /** * Router XSLT Template Name */ xsltTemplateName: string; xsltTemplateNameForMacSec: string; } interface LinkAggregationGroupRateLimiterStatus { /** * Number of rate limiters currently in use. */ inUse: number; /** * Maximum number of rate limiters allowed on the LAG. */ maxAllowed: number; /** * Number of rate limiters remaining (available). */ remaining: number; /** * Total bandwidth allocated across all rate limiters. */ totalBandwidth: string; } } export declare namespace directoryservice { interface DirectoryConnectSettings { availabilityZones: string[]; /** * The IP addresses of the AD Connector servers. */ connectIps: string[]; /** * The DNS IP addresses of the domain to connect to. */ customerDnsIps: string[]; /** * The username corresponding to the password provided. */ customerUsername: string; /** * The identifiers of the subnets for the directory servers (2 subnets in 2 different AZs). */ subnetIds: string[]; /** * The identifier of the VPC that the directory is in. */ vpcId: string; } interface DirectoryVpcSettings { availabilityZones: string[]; /** * The identifiers of the subnets for the directory servers (2 subnets in 2 different AZs). */ subnetIds: string[]; /** * The identifier of the VPC that the directory is in. */ vpcId: string; } interface GetDirectoryConnectSetting { availabilityZones: string[]; /** * IP addresses of the AD Connector servers. */ connectIps: string[]; /** * DNS IP addresses of the domain to connect to. */ customerDnsIps: string[]; /** * Username corresponding to the password provided. */ customerUsername: string; /** * Identifiers of the subnets for the connector servers (2 subnets in 2 different AZs). */ subnetIds: string[]; /** * ID of the VPC that the connector is in. */ vpcId: string; } interface GetDirectoryRadiusSetting { /** * The protocol specified for your RADIUS endpoints. */ authenticationProtocol: string; /** * Display label. */ displayLabel: string; /** * Port that your RADIUS server is using for communications. */ radiusPort: number; /** * Maximum number of times that communication with the RADIUS server is attempted. */ radiusRetries: number; /** * Set of strings that contains the fully qualified domain name (FQDN) or IP addresses of the RADIUS server endpoints, or the FQDN or IP addresses of your RADIUS server load balancer. */ radiusServers: string[]; /** * Amount of time, in seconds, to wait for the RADIUS server to respond. */ radiusTimeout: number; /** * Not currently used. */ useSameUsername: boolean; } interface GetDirectoryVpcSetting { availabilityZones: string[]; /** * Identifiers of the subnets for the connector servers (2 subnets in 2 different AZs). */ subnetIds: string[]; /** * ID of the VPC that the connector is in. */ vpcId: string; } interface ServiceRegionVpcSettings { /** * The identifiers of the subnets for the directory servers. */ subnetIds: string[]; /** * The identifier of the VPC in which to create the directory. */ vpcId: string; } interface SharedDirectoryTarget { /** * Identifier of the directory consumer account. */ id: string; /** * Type of identifier to be used in the `id` field. Valid value is `ACCOUNT`. Default is `ACCOUNT`. */ type?: string; } } export declare namespace dlm { interface LifecyclePolicyPolicyDetails { /** * The actions to be performed when the event-based policy is triggered. You can specify only one action per policy. This parameter is required for event-based policies only. If you are creating a snapshot or AMI policy, omit this parameter. See the `action` configuration block. */ action?: outputs.dlm.LifecyclePolicyPolicyDetailsAction; copyTags?: boolean; /** * How often the policy should run and create snapshots or AMIs. valid values range from `1` to `7`. Default value is `1`. */ createInterval?: number; /** * The event that triggers the event-based policy. This parameter is required for event-based policies only. If you are creating a snapshot or AMI policy, omit this parameter. See the `eventSource` configuration block. */ eventSource?: outputs.dlm.LifecyclePolicyPolicyDetailsEventSource; /** * Specifies exclusion parameters for volumes or instances for which you do not want to create snapshots or AMIs. See the `exclusions` configuration block. */ exclusions?: outputs.dlm.LifecyclePolicyPolicyDetailsExclusions; /** * snapshot or AMI retention behavior for the policy if the source volume or instance is deleted, or if the policy enters the error, disabled, or deleted state. Default value is `false`. */ extendDeletion?: boolean; parameters?: outputs.dlm.LifecyclePolicyPolicyDetailsParameters; /** * Type of policy to create. `SIMPLIFIED` To create a default policy. `STANDARD` To create a custom policy. */ policyLanguage: string; /** * The valid target resource types and actions a policy can manage. Specify `EBS_SNAPSHOT_MANAGEMENT` to create a lifecycle policy that manages the lifecycle of Amazon EBS snapshots. Specify `IMAGE_MANAGEMENT` to create a lifecycle policy that manages the lifecycle of EBS-backed AMIs. Specify `EVENT_BASED_POLICY` to create an event-based policy that performs specific actions when a defined event occurs in your AWS account. Default value is `EBS_SNAPSHOT_MANAGEMENT`. */ policyType?: string; /** * The location of the resources to backup. If the source resources are located in an AWS Region, specify `CLOUD`. If the source resources are located on an Outpost in your account, specify `OUTPOST`. If the source resources are located in a Local Zone, specify `LOCAL_ZONE`. Valid values are `CLOUD`, `LOCAL_ZONE`, and `OUTPOST`. */ resourceLocations: string; /** * Type of default policy to create. Valid values are `VOLUME` and `INSTANCE`. */ resourceType?: string; /** * A list of resource types that should be targeted by the lifecycle policy. Valid values are `VOLUME` and `INSTANCE`. */ resourceTypes?: string[]; /** * Specifies how long the policy should retain snapshots or AMIs before deleting them. valid values range from `2` to `14`. Default value is `7`. */ retainInterval?: number; /** * See the `schedule` configuration block. */ schedules?: outputs.dlm.LifecyclePolicyPolicyDetailsSchedule[]; /** * A map of tag keys and their values. Any resources that match the `resourceTypes` and are tagged with _any_ of these tags will be targeted. Required when `policyType` is `EBS_SNAPSHOT_MANAGEMENT` or `IMAGE_MANAGEMENT`. Must not be specified when `policyType` is `EVENT_BASED_POLICY`. * * > Note: You cannot have overlapping lifecycle policies that share the same `targetTags`. Pulumi is unable to detect this at plan time but it will fail during apply. */ targetTags?: { [key: string]: string; }; } interface LifecyclePolicyPolicyDetailsAction { /** * The rule for copying shared snapshots across Regions. See the `crossRegionCopy` configuration block. */ crossRegionCopies: outputs.dlm.LifecyclePolicyPolicyDetailsActionCrossRegionCopy[]; name: string; } interface LifecyclePolicyPolicyDetailsActionCrossRegionCopy { /** * The encryption settings for the copied snapshot. See the `encryptionConfiguration` block. Max of 1 per action. */ encryptionConfiguration: outputs.dlm.LifecyclePolicyPolicyDetailsActionCrossRegionCopyEncryptionConfiguration; retainRule?: outputs.dlm.LifecyclePolicyPolicyDetailsActionCrossRegionCopyRetainRule; target: string; } interface LifecyclePolicyPolicyDetailsActionCrossRegionCopyEncryptionConfiguration { cmkArn?: string; encrypted?: boolean; } interface LifecyclePolicyPolicyDetailsActionCrossRegionCopyRetainRule { interval: number; intervalUnit: string; } interface LifecyclePolicyPolicyDetailsEventSource { parameters: outputs.dlm.LifecyclePolicyPolicyDetailsEventSourceParameters; /** * The source of the event. Currently only managed CloudWatch Events rules are supported. Valid values are `MANAGED_CWE`. */ type: string; } interface LifecyclePolicyPolicyDetailsEventSourceParameters { /** * The snapshot description that can trigger the policy. The description pattern is specified using a regular expression. The policy runs only if a snapshot with a description that matches the specified pattern is shared with your account. */ descriptionRegex: string; /** * The type of event. Currently, only `shareSnapshot` events are supported. */ eventType: string; /** * The IDs of the AWS accounts that can trigger policy by sharing snapshots with your account. The policy only runs if one of the specified AWS accounts shares a snapshot with your account. */ snapshotOwners: string[]; } interface LifecyclePolicyPolicyDetailsExclusions { /** * Indicates whether to exclude volumes that are attached to instances as the boot volume. To exclude boot volumes, specify `true`. */ excludeBootVolumes?: boolean; /** * Map specifies whether to exclude volumes that have specific tags. */ excludeTags?: { [key: string]: string; }; /** * List specifies the volume types to exclude. */ excludeVolumeTypes?: string[]; } interface LifecyclePolicyPolicyDetailsParameters { /** * Indicates whether to exclude the root volume from snapshots created using CreateSnapshots. The default is `false`. */ excludeBootVolume?: boolean; /** * Map specifies whether to exclude volumes that have specific tags. */ excludeDataVolumeTags?: { [key: string]: string; }; /** * Applies to AMI lifecycle policies only. Indicates whether targeted instances are rebooted when the lifecycle policy runs. `true` indicates that targeted instances are not rebooted when the policy runs. `false` indicates that target instances are rebooted when the policy runs. The default is `true` (instances are not rebooted). */ noReboot?: boolean; } interface LifecyclePolicyPolicyDetailsSchedule { /** * Specifies a snapshot archiving rule for a schedule. See `archiveRule` block. */ archiveRule?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleArchiveRule; copyTags: boolean; /** * See the `createRule` block. Max of 1 per schedule. */ createRule: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleCreateRule; /** * See the `crossRegionCopyRule` block. Max of 3 per schedule. */ crossRegionCopyRules?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleCrossRegionCopyRule[]; deprecateRule?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleDeprecateRule; /** * See the `fastRestoreRule` block. Max of 1 per schedule. */ fastRestoreRule?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleFastRestoreRule; name: string; retainRule: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleRetainRule; /** * See the `shareRule` block. Max of 1 per schedule. */ shareRule?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleShareRule; /** * A map of tag keys and their values. DLM lifecycle policies will already tag the snapshot with the tags on the volume. This configuration adds extra tags on top of these. */ tagsToAdd?: { [key: string]: string; }; /** * A map of tag keys and variable values, where the values are determined when the policy is executed. Only `$(instance-id)` or `$(timestamp)` are valid values. Can only be used when `resourceTypes` is `INSTANCE`. */ variableTags?: { [key: string]: string; }; } interface LifecyclePolicyPolicyDetailsScheduleArchiveRule { /** * Information about the retention period for the snapshot archiving rule. See the `archiveRetainRule` block. */ archiveRetainRule: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleArchiveRuleArchiveRetainRule; } interface LifecyclePolicyPolicyDetailsScheduleArchiveRuleArchiveRetainRule { /** * Information about retention period in the Amazon EBS Snapshots Archive. See the `retentionArchiveTier` block. */ retentionArchiveTier: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleArchiveRuleArchiveRetainRuleRetentionArchiveTier; } interface LifecyclePolicyPolicyDetailsScheduleArchiveRuleArchiveRetainRuleRetentionArchiveTier { count?: number; interval?: number; intervalUnit?: string; } interface LifecyclePolicyPolicyDetailsScheduleCreateRule { /** * The schedule, as a Cron expression. The schedule interval must be between 1 hour and 1 year. Conflicts with `interval`, `intervalUnit`, and `times`. For details on valid Cron expressions, see [here](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-scheduled-rule-pattern.html#eb-cron-expressions). */ cronExpression?: string; interval?: number; intervalUnit: string; /** * Specifies the destination for snapshots created by the policy. To create snapshots in the same Region as the source resource, specify `CLOUD`. To create snapshots on the same Outpost as the source resource, specify `OUTPOST_LOCAL`. If you omit this parameter, `CLOUD` is used by default. If the policy targets resources in an AWS Region, then you must create snapshots in the same Region as the source resource. If the policy targets resources on an Outpost, then you can create snapshots on the same Outpost as the source resource, or in the Region of that Outpost. Valid values are `CLOUD` and `OUTPOST_LOCAL`. */ location: string; /** * Specifies pre and/or post scripts for a snapshot lifecycle policy that targets instances. Valid only when `resourceType` is INSTANCE. See the `scripts` configuration block. */ scripts?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleCreateRuleScripts; /** * A list of times in 24 hour clock format that sets when the lifecycle policy should be evaluated. Max of 1. Conflicts with `cronExpression`. Must be set if `interval` is set. */ times: string; } interface LifecyclePolicyPolicyDetailsScheduleCreateRuleScripts { /** * Indicates whether Amazon Data Lifecycle Manager should default to crash-consistent snapshots if the pre script fails. The default is `true`. */ executeOperationOnScriptFailure: boolean; /** * The SSM document that includes the pre and/or post scripts to run. In case automating VSS backups, specify `AWS_VSS_BACKUP`. In case automating application-consistent snapshots for SAP HANA workloads, specify `AWSSystemsManagerSAP-CreateDLMSnapshotForSAPHANA`. If you are using a custom SSM document that you own, specify either the name or ARN of the SSM document. */ executionHandler: string; /** * Indicates the service used to execute the pre and/or post scripts. If using custom SSM documents or automating application-consistent snapshots of SAP HANA workloads, specify `AWS_SYSTEMS_MANAGER`. In case automating VSS Backups, omit this parameter. The default is `AWS_SYSTEMS_MANAGER`. */ executionHandlerService: string; /** * Specifies a timeout period, in seconds, after which Amazon Data Lifecycle Manager fails the script run attempt if it has not completed. In case automating VSS Backups, omit this parameter. The default is `10`. */ executionTimeout: number; /** * Specifies the number of times Amazon Data Lifecycle Manager should retry scripts that fail. Must be an integer between `0` and `3`. The default is `0`. */ maximumRetryCount: number; /** * List to indicate which scripts Amazon Data Lifecycle Manager should run on target instances. Pre scripts run before Amazon Data Lifecycle Manager initiates snapshot creation. Post scripts run after Amazon Data Lifecycle Manager initiates snapshot creation. Valid values: `PRE` and `POST`. The default is `PRE` and `POST` */ stages?: string[]; } interface LifecyclePolicyPolicyDetailsScheduleCrossRegionCopyRule { cmkArn?: string; copyTags: boolean; deprecateRule?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleCrossRegionCopyRuleDeprecateRule; encrypted: boolean; retainRule?: outputs.dlm.LifecyclePolicyPolicyDetailsScheduleCrossRegionCopyRuleRetainRule; target?: string; /** * Use only for DLM policies of `policy_type=IMAGE_MANAGEMENT`. The target Region or the ARN of the target Outpost for the snapshot copies. */ targetRegion?: string; } interface LifecyclePolicyPolicyDetailsScheduleCrossRegionCopyRuleDeprecateRule { interval: number; intervalUnit: string; } interface LifecyclePolicyPolicyDetailsScheduleCrossRegionCopyRuleRetainRule { interval: number; intervalUnit: string; } interface LifecyclePolicyPolicyDetailsScheduleDeprecateRule { count?: number; interval?: number; intervalUnit?: string; } interface LifecyclePolicyPolicyDetailsScheduleFastRestoreRule { /** * The Availability Zones in which to enable fast snapshot restore. */ availabilityZones: string[]; count?: number; interval?: number; intervalUnit?: string; } interface LifecyclePolicyPolicyDetailsScheduleRetainRule { count?: number; interval?: number; intervalUnit?: string; } interface LifecyclePolicyPolicyDetailsScheduleShareRule { /** * The IDs of the AWS accounts with which to share the snapshots. */ targetAccounts: string[]; /** * The period after which snapshots that are shared with other AWS accounts are automatically unshared. */ unshareInterval?: number; /** * The unit of time for the automatic unsharing interval. Valid values are `DAYS`, `WEEKS`, `MONTHS`, `YEARS`. */ unshareIntervalUnit?: string; } } export declare namespace dms { interface DataProviderSettings { /** * Settings for the `docdb` engine. See `docDbSettings` Block below. */ docDbSettings?: outputs.dms.DataProviderSettingsDocDbSettings; /** * Settings for the `db2` engine. See `ibmDb2LuwSettings` Block below. */ ibmDb2LuwSettings?: outputs.dms.DataProviderSettingsIbmDb2LuwSettings; /** * Settings for the `db2-zos` engine. See `ibmDb2ZosSettings` Block below. */ ibmDb2ZosSettings?: outputs.dms.DataProviderSettingsIbmDb2ZosSettings; /** * Settings for the `mariadb` engine. See `mariaDbSettings` Block below. */ mariaDbSettings?: outputs.dms.DataProviderSettingsMariaDbSettings; /** * Settings for the `sqlserver` engine. See `microsoftSqlServerSettings` Block below. */ microsoftSqlServerSettings?: outputs.dms.DataProviderSettingsMicrosoftSqlServerSettings; /** * Settings for the `mongodb` engine. See `mongoDbSettings` Block below. */ mongoDbSettings?: outputs.dms.DataProviderSettingsMongoDbSettings; /** * Settings for the `mysql` and `aurora` engines. See `mysqlSettings` Block below. */ mysqlSettings?: outputs.dms.DataProviderSettingsMysqlSettings; /** * Settings for the `oracle` engine. See `oracleSettings` Block below. */ oracleSettings?: outputs.dms.DataProviderSettingsOracleSettings; /** * Settings for the `postgres` and `aurora-postgresql` engines. See `postgresqlSettings` Block below. */ postgresqlSettings?: outputs.dms.DataProviderSettingsPostgresqlSettings; /** * Settings for the `redshift` engine. See `redshiftSettings` Block below. */ redshiftSettings?: outputs.dms.DataProviderSettingsRedshiftSettings; /** * Settings for the `sybase` engine. See `sybaseAseSettings` Block below. */ sybaseAseSettings?: outputs.dms.DataProviderSettingsSybaseAseSettings; } interface DataProviderSettingsDocDbSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the DocumentDB data provider. */ databaseName?: string; /** * Port of the DocumentDB server. Valid values are between `1` and `65535`. */ port?: number; /** * Hostname of the DocumentDB server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsIbmDb2LuwSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the IBM DB2 LUW data provider. */ databaseName?: string; /** * Integer identifying the encryption algorithm for the connection. When omitted, AWS uses its default behavior. */ encryptionAlgorithm: number; /** * Port of the IBM DB2 LUW server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Integer identifying the authentication mechanism for the connection. When omitted, AWS uses its default behavior. */ securityMechanism: number; /** * Hostname of the IBM DB2 LUW server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none` and `verify-ca`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsIbmDb2ZosSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the IBM DB2 for z/OS data provider. */ databaseName?: string; /** * Port of the IBM DB2 for z/OS server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Hostname of the IBM DB2 for z/OS server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none` and `verify-ca`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsMariaDbSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Port of the MariaDB server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Hostname of the MariaDB server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsMicrosoftSqlServerSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the Microsoft SQL Server data provider. */ databaseName?: string; /** * Port of the Microsoft SQL Server instance. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Hostname of the Microsoft SQL Server instance. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsMongoDbSettings { /** * Authentication mechanism for the connection. Valid values: `default`, `mongodbCr`, and `scramSha1`. */ authMechanism: string; /** * Database used to verify credentials. Defaults to `admin`. Not used when `authType` is `no`. */ authSource: string; /** * Authentication type for the connection. Valid values: `no` and `password`. */ authType: string; /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the MongoDB data provider. */ databaseName?: string; /** * Port of the MongoDB server. Valid values are between `1` and `65535`. */ port?: number; /** * Hostname of the MongoDB server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsMysqlSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Port of the MySQL server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Hostname of the MySQL server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsOracleSettings { /** * Address of the Oracle Automatic Storage Management (ASM) server used with Binary Reader. See [Oracle change data capture configuration](https://docs.aws.amazon.com/dms/latest/userguide/CHAP_Source.Oracle.html#CHAP_Source.Oracle.CDC.Configuration). */ asmServer?: string; /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the Oracle data provider. */ databaseName?: string; /** * Port of the Oracle server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * ARN of the IAM role that grants access to the Secrets Manager secret containing Oracle ASM connection details. */ secretsManagerOracleAsmAccessRoleArn?: string; /** * Identifier of the Secrets Manager secret containing Oracle ASM connection details. Required when the data provider uses an Oracle ASM server. */ secretsManagerOracleAsmSecretId?: string; /** * ARN of the IAM role that grants access to the Secrets Manager secret containing the transparent data encryption (TDE) password. */ secretsManagerSecurityDbEncryptionAccessRoleArn?: string; /** * Identifier of the Secrets Manager secret containing the TDE password used by Binary Reader to access encrypted Oracle redo logs. */ secretsManagerSecurityDbEncryptionSecretId?: string; /** * Hostname of the Oracle server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsPostgresqlSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the PostgreSQL data provider. */ databaseName?: string; /** * Port of the PostgreSQL server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Hostname of the PostgreSQL server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface DataProviderSettingsRedshiftSettings { /** * Database name on the Amazon Redshift data provider. */ databaseName?: string; /** * Port of the Amazon Redshift server. Valid values are between `1` and `65535`. */ port?: number; /** * ARN of the IAM role used to access the S3 bucket containing the user-defined schema. */ s3AccessRoleArn?: string; /** * S3 path containing the user-defined schema. */ s3Path?: string; /** * Hostname of the Amazon Redshift server. */ serverName?: string; } interface DataProviderSettingsSybaseAseSettings { /** * ARN of the DMS certificate used for the SSL connection. */ certificateArn?: string; /** * Database name on the SAP ASE data provider. */ databaseName?: string; /** * Whether to encrypt the connection password during transmission. Defaults to `true`. */ encryptPassword: boolean; /** * Port of the SAP ASE server. Valid values are between `1` and `65535`. */ port?: number; /** * Hostname of the SAP ASE server. */ serverName?: string; /** * SSL mode for the connection. Valid values: `none`, `require`, `verify-ca`, and `verify-full`. Defaults to `none`. */ sslMode: string; } interface EndpointElasticsearchSettings { /** * Endpoint for the OpenSearch cluster. */ endpointUri: string; /** * Maximum number of seconds for which DMS retries failed API requests to the OpenSearch cluster. Default is `300`. */ errorRetryDuration?: number; /** * Maximum percentage of records that can fail to be written before a full load operation stops. Default is `10`. */ fullLoadErrorPercentage?: number; /** * ARN of the IAM Role with permissions to write to the OpenSearch cluster. */ serviceAccessRoleArn: string; /** * Enable to migrate documentation using the documentation type `_doc`. OpenSearch and an Elasticsearch clusters only support the _doc documentation type in versions 7.x and later. The default value is `false`. */ useNewMappingType?: boolean; } interface EndpointKafkaSettings { /** * Kafka broker location. Specify in the form broker-hostname-or-ip:port. */ broker: string; /** * Shows detailed control information for table definition, column definition, and table and column changes in the Kafka message output. Default is `false`. */ includeControlDetails?: boolean; /** * Include NULL and empty columns for records migrated to the endpoint. Default is `false`. */ includeNullAndEmpty?: boolean; /** * Shows the partition value within the Kafka message output unless the partition type is `schema-table-type`. Default is `false`. */ includePartitionValue?: boolean; /** * Includes any data definition language (DDL) operations that change the table in the control data, such as `rename-table`, `drop-table`, `add-column`, `drop-column`, and `rename-column`. Default is `false`. */ includeTableAlterOperations?: boolean; /** * Provides detailed transaction information from the source database. This information includes a commit timestamp, a log position, and values for `transactionId`, previous `transactionId`, and `transactionRecordId` (the record offset within a transaction). Default is `false`. */ includeTransactionDetails?: boolean; /** * Output format for the records created on the endpoint. Message format is `JSON` (default) or `JSON_UNFORMATTED` (a single line with no tab). */ messageFormat?: string; /** * Maximum size in bytes for records created on the endpoint Default is `1,000,000`. */ messageMaxBytes?: number; /** * Set this optional parameter to true to avoid adding a '0x' prefix to raw data in hexadecimal format. For example, by default, AWS DMS adds a '0x' prefix to the LOB column type in hexadecimal format moving from an Oracle source to a Kafka target. Use the `noHexPrefix` endpoint setting to enable migration of RAW data type columns without adding the `'0x'` prefix. */ noHexPrefix?: boolean; /** * Prefixes schema and table names to partition values, when the partition type is `primary-key-type`. Doing this increases data distribution among Kafka partitions. For example, suppose that a SysBench schema has thousands of tables and each table has only limited range for a primary key. In this case, the same primary key is sent from thousands of tables to the same partition, which causes throttling. Default is `false`. */ partitionIncludeSchemaTable?: boolean; /** * For SASL/SSL authentication, AWS DMS supports the `scram-sha-512` mechanism by default. AWS DMS versions 3.5.0 and later also support the PLAIN mechanism. To use the PLAIN mechanism, set this parameter to `plain`. */ saslMechanism?: string; /** * Secure password you created when you first set up your MSK cluster to validate a client identity and make an encrypted connection between server and client using SASL-SSL authentication. */ saslPassword?: string; /** * Secure user name you created when you first set up your MSK cluster to validate a client identity and make an encrypted connection between server and client using SASL-SSL authentication. */ saslUsername?: string; /** * Set secure connection to a Kafka target endpoint using TLS. Options include `ssl-encryption`, `ssl-authentication`, and `sasl-ssl`. `sasl-ssl` requires `saslUsername` and `saslPassword`. */ securityProtocol?: string; /** * ARN for the private certificate authority (CA) cert that AWS DMS uses to securely connect to your Kafka target endpoint. */ sslCaCertificateArn?: string; /** * ARN of the client certificate used to securely connect to a Kafka target endpoint. */ sslClientCertificateArn?: string; /** * ARN for the client private key used to securely connect to a Kafka target endpoint. */ sslClientKeyArn?: string; /** * Password for the client private key used to securely connect to a Kafka target endpoint. */ sslClientKeyPassword?: string; /** * Kafka topic for migration. Default is `kafka-default-topic`. */ topic?: string; } interface EndpointKinesisSettings { /** * Shows detailed control information for table definition, column definition, and table and column changes in the Kinesis message output. Default is `false`. */ includeControlDetails?: boolean; /** * Include NULL and empty columns in the target. Default is `false`. */ includeNullAndEmpty?: boolean; /** * Shows the partition value within the Kinesis message output, unless the partition type is schema-table-type. Default is `false`. */ includePartitionValue?: boolean; /** * Includes any data definition language (DDL) operations that change the table in the control data. Default is `false`. */ includeTableAlterOperations?: boolean; /** * Provides detailed transaction information from the source database. Default is `false`. */ includeTransactionDetails?: boolean; /** * Output format for the records created. Default is `json`. Valid values are `json` and `json-unformatted` (a single line with no tab). */ messageFormat?: string; /** * Prefixes schema and table names to partition values, when the partition type is primary-key-type. Default is `false`. */ partitionIncludeSchemaTable?: boolean; /** * ARN of the IAM Role with permissions to write to the Kinesis data stream. */ serviceAccessRoleArn?: string; /** * ARN of the Kinesis data stream. */ streamArn?: string; /** * Use up to 18 digit int instead of casting ints as doubles, available from AWS DMS version 3.5.4. Default is `false`. */ useLargeIntegerValue?: boolean; } interface EndpointMongodbSettings { /** * Authentication mechanism to access the MongoDB source endpoint. Default is `default`. */ authMechanism?: string; /** * Authentication database name. Not used when `authType` is `no`. Default is `admin`. */ authSource?: string; /** * Authentication type to access the MongoDB source endpoint. Default is `password`. */ authType?: string; /** * Number of documents to preview to determine the document organization. Use this setting when `nestingLevel` is set to `one`. Default is `1000`. */ docsToInvestigate?: string; /** * Document ID. Use this setting when `nestingLevel` is set to `none`. Default is `false`. */ extractDocId?: string; /** * Specifies either document or table mode. Default is `none`. Valid values are `one` (table mode) and `none` (document mode). */ nestingLevel?: string; /** * If `true`, DMS retrieves the entire document from the MongoDB source during migration. Default is `false`. */ useUpdateLookup?: boolean; } interface EndpointMysqlSettings { /** * Script to run immediately after AWS DMS connects to the endpoint. */ afterConnectScript: string; /** * Authentication method to use. Valid values: `password`, `iam`. */ authenticationMethod: string; /** * Whether to clean and recreate table metadata information on the replication instance when a mismatch occurs. */ cleanSourceMetadataOnMismatch: boolean; /** * Time interval to check the binary log for new changes/events when the database is idle. Default is `5`. */ eventsPollInterval: number; /** * Client statement timeout (in seconds) for a MySQL source endpoint. */ executeTimeout: number; /** * Maximum size (in KB) of any .csv file used to transfer data to a MySQL-compatible database. */ maxFileSize: number; /** * Number of threads to use to load the data into the MySQL-compatible target database. */ parallelLoadThreads: number; /** * Time zone for the source MySQL database. */ serverTimezone: string; /** * ARN of the IAM role to authenticate when connecting to the endpoint. */ serviceAccessRoleArn: string; /** * Where to migrate source tables on the target. Valid values are `specific-database` and `multiple-databases`. */ targetDbType: string; } interface EndpointOracleSettings { /** * Set this attribute to `false` in order to use the Binary Reader to capture change data for an Amazon RDS for Oracle as the source. */ accessAlternateDirectly: boolean; /** * Set this attribute to set up table-level supplemental logging for the Oracle database. This attribute enables PRIMARY KEY supplemental logging on all tables selected for a migration task. */ addSupplementalLogging: boolean; /** * Set this attribute with `archivedLogDestId` in a primary/standby setup. This attribute is useful in the case of a switchover. */ additionalArchivedLogDestId: number; /** * Set this attribute to `true` to enable replication of Oracle tables containing columns that are nested tables or defined types. */ allowSelectedNestedTables: boolean; /** * Specifies the ID of the destination for the archived redo logs. This value should be the same as a number in the destId column of the v$archived_log view. */ archivedLogDestId: number; /** * When this field is set to `true`, AWS DMS only accesses the archived redo logs. */ archivedLogsOnly: boolean; /** * For an Oracle source endpoint, your Oracle Automatic Storage Management (ASM) password. */ asmPassword: string; /** * For an Oracle source endpoint, your ASM server address. */ asmServer: string; /** * For an Oracle source endpoint, your ASM user name. */ asmUser: string; /** * Authentication mechanism to access the Oracle source endpoint. Default is `password`. Valid values are `password` and `kerberos`. */ authenticationMethod: string; /** * Specifies whether the length of a character column is in bytes or in characters. Valid values are `default`, `char`, and `byte`. */ charLengthSemantics: string; /** * When `true`, converts timestamps with the timezone datatype to their UTC value. */ convertTimestampWithZoneToUtc: boolean; /** * When set to `true`, this attribute helps to increase the commit rate on the Oracle target database by writing directly to tables and not writing a trail to database logs. */ directPathNoLog: boolean; /** * When set to `true`, this attribute specifies a parallel load when useDirectPathFullLoad is set to true. */ directPathParallelLoad: boolean; /** * Set this attribute to enable homogenous tablespace replication and create existing tables or indexes under the same tablespace on the target. */ enableHomogenousTablespace: boolean; /** * Specifies the IDs of one more destinations for one or more archived redo logs. These IDs are the values of the destId column in the v$archived_log view. */ extraArchivedLogDestIds: number[]; /** * When set to `true`, this attribute causes a task to fail if the actual size of an LOB column is greater than the specified lob_max_size. */ failTaskOnLobTruncation: boolean; /** * Specifies the number scale. */ numberDatatypeScale: number; /** * The timeframe in minutes to check for open transactions for a CDC-only task. You can specify an integer value between 0 (the default) and 240 (the maximum). */ openTransactionWindow: number; /** * Set this string attribute to the required value in order to use the Binary Reader to capture change data for an Amazon RDS for Oracle as the source. This value specifies the default Oracle root used to access the redo logs. */ oraclePathPrefix: string; /** * Set this attribute to change the number of threads that DMS configures to perform a change data capture (CDC) load using Oracle Automatic Storage Management (ASM). You can specify an integer value between 2 (the default) and 8 (the maximum). */ parallelAsmReadThreads: number; /** * Set this attribute to change the number of read-ahead blocks that DMS configures to perform a change data capture (CDC) load using Oracle Automatic Storage Management (ASM). You can specify an integer value between 1000 (the default) and 200,000 (the maximum). */ readAheadBlocks: number; /** * When set to `true`, this attribute supports tablespace replication. */ readTableSpaceName: boolean; /** * Set this attribute to `true` in order to use the Binary Reader to capture change data for an Amazon RDS for Oracle as the source. This setting tells DMS instance to replace the default Oracle root with the specified `usePathPrefix` setting to access the redo logs. */ replacePathPrefix: boolean; /** * Specifies the number of seconds that the system waits before resending a query. */ retryInterval: number; /** * Required only if your Oracle endpoint uses Automatic Storage Management (ASM). The full ARN of the IAM role that specifies AWS DMS as the trusted entity and grants the required permissions to access the `secretsManagerOracleAsmSecretId`. */ secretsManagerOracleAsmAccessRoleArn: string; /** * Required only if your Oracle endpoint uses Automatic Storage Management (ASM). The full ARN, partial ARN, or friendly name of the secret that contains the Oracle ASM connection details for the Oracle endpoint. */ secretsManagerOracleAsmSecretId: string; /** * For an Oracle source endpoint, the transparent data encryption (TDE) password required by AWM DMS to access Oracle redo logs encrypted by TDE using Binary Reader. */ securityDbEncryption: string; /** * For an Oracle source endpoint, the name of a key used for the transparent data encryption (TDE) of the columns and tablespaces in an Oracle source database that is encrypted using TDE. */ securityDbEncryptionName: string; /** * Use this attribute to convert SDO_GEOMETRY to GEOJSON format. By default, DMS calls the SDO2GEOJSON custom function if present and accessible. */ spatialDataOptionToGeoJsonFunctionName: string; /** * Use this attribute to specify a time in minutes for the delay in standby sync. If the source is an Oracle Active Data Guard standby database, use this attribute to specify the time lag between primary and standby databases. */ standbyDelayTime: number; /** * Use this attribute to trim data on CHAR and NCHAR data types during migration. The default value is `true`. */ trimSpaceInChar: boolean; /** * Set this attribute to `true` in order to use the Binary Reader to capture change data for an Amazon RDS for Oracle as the source. This tells the DMS instance to use any specified prefix replacement to access all online redo logs. */ useAlternateFolderForOnline: boolean; /** * Set this attribute to `true` to capture change data using the Binary Reader utility. Set `useLogminerReader` to `false` to set this attribute to `true`. */ useBfile: boolean; /** * Set this attribute to `true` to have AWS DMS use a direct path full load. Specify this value to use the direct path protocol in the Oracle Call Interface (OCI). */ useDirectPathFullLoad: boolean; /** * Set this attribute to `true` to capture change data using the Oracle LogMiner utility (the default). Set this attribute to `false` if you want to access the redo logs as a binary file. */ useLogminerReader: boolean; /** * Set this string attribute to the required value in order to use the Binary Reader to capture change data for an Amazon RDS for Oracle as the source. This value specifies the path prefix used to replace the default Oracle root to access the redo logs. */ usePathPrefix: string; } interface EndpointPostgresSettings { /** * For use with change data capture (CDC) only, this attribute has AWS DMS bypass foreign keys and user triggers to reduce the time it takes to bulk load data. */ afterConnectScript?: string; /** * Specifies the authentication method. Valid values: `password`, `iam`. */ authenticationMethod: string; /** * The Babelfish for Aurora PostgreSQL database name for the endpoint. */ babelfishDatabaseName?: string; /** * To capture DDL events, AWS DMS creates various artifacts in the PostgreSQL database when the task starts. */ captureDdls?: boolean; /** * Specifies the default behavior of the replication's handling of PostgreSQL- compatible endpoints that require some additional configuration, such as Babelfish endpoints. */ databaseMode?: string; /** * Sets the schema in which the operational DDL database artifacts are created. Default is `public`. */ ddlArtifactsSchema?: string; /** * Sets the client statement timeout for the PostgreSQL instance, in seconds. Default value is `60`. */ executeTimeout?: number; /** * When set to `true`, this value causes a task to fail if the actual size of a LOB column is greater than the specified `LobMaxSize`. Default is `false`. */ failTasksOnLobTruncation?: boolean; /** * The write-ahead log (WAL) heartbeat feature mimics a dummy transaction. By doing this, it prevents idle logical replication slots from holding onto old WAL logs, which can result in storage full situations on the source. */ heartbeatEnable?: boolean; /** * Sets the WAL heartbeat frequency (in minutes). Default value is `5`. */ heartbeatFrequency?: number; /** * Sets the schema in which the heartbeat artifacts are created. Default value is `public`. */ heartbeatSchema?: string; /** * You can use PostgreSQL endpoint settings to map a boolean as a boolean from your PostgreSQL source to a Amazon Redshift target. Default value is `false`. */ mapBooleanAsBoolean?: boolean; /** * Optional When true, DMS migrates JSONB values as CLOB. */ mapJsonbAsClob?: boolean; /** * Specifies how DMS maps LONG VARCHAR values. Valid values are `wstring`, `clob`, and `nclob`. */ mapLongVarcharAs?: string; /** * Specifies the maximum size (in KB) of any .csv file used to transfer data to PostgreSQL. Default is `32,768 KB`. */ maxFileSize?: number; /** * Specifies the plugin to use to create a replication slot. Valid values: `pglogical`, `test-decoding`. */ pluginName?: string; /** * Specifies the IAM role to use to authenticate the connection. */ serviceAccessRoleArn?: string; /** * Sets the name of a previously created logical replication slot for a CDC load of the PostgreSQL source instance. */ slotName?: string; } interface EndpointRedisSettings { /** * The password provided with the auth-role and auth-token options of the AuthType setting for a Redis target endpoint. */ authPassword?: string; /** * The type of authentication to perform when connecting to a Redis target. Options include `none`, `auth-token`, and `auth-role`. The `auth-token` option requires an `authPassword` value to be provided. The `auth-role` option requires `authUserName` and `authPassword` values to be provided. */ authType: string; /** * The username provided with the `auth-role` option of the AuthType setting for a Redis target endpoint. */ authUserName?: string; /** * TCP port for the endpoint. */ port: number; /** * Fully qualified domain name of the endpoint. */ serverName: string; /** * ARN for the certificate authority (CA) that DMS uses to connect to your Redis target endpoint. */ sslCaCertificateArn?: string; /** * The plaintext option doesn't provide TLS encryption for traffic between endpoint and database. Options include `plaintext`, `ssl-encryption`. The default is `ssl-encryption`. */ sslSecurityProtocol?: string; } interface EndpointRedshiftSettings { /** * Custom S3 Bucket Object prefix for intermediate storage. */ bucketFolder?: string; /** * Custom S3 Bucket name for intermediate storage. */ bucketName?: string; /** * The server-side encryption mode that you want to encrypt your intermediate .csv object files copied to S3. Defaults to `SSE_S3`. Valid values are `SSE_S3` and `SSE_KMS`. */ encryptionMode?: string; /** * ARN or Id of KMS Key to use when `encryptionMode` is `SSE_KMS`. */ serverSideEncryptionKmsKeyId?: string; /** * ARN of the IAM Role with permissions to read from or write to the S3 Bucket for intermediate storage. */ serviceAccessRoleArn?: string; } interface GetEndpointElasticsearchSetting { endpointUri: string; errorRetryDuration: number; fullLoadErrorPercentage: number; serviceAccessRoleArn: string; } interface GetEndpointKafkaSetting { broker: string; includeControlDetails: boolean; includeNullAndEmpty: boolean; includePartitionValue: boolean; includeTableAlterOperations: boolean; includeTransactionDetails: boolean; messageFormat: string; messageMaxBytes: number; noHexPrefix: boolean; partitionIncludeSchemaTable: boolean; saslMechanism: string; saslPassword: string; saslUsername: string; securityProtocol: string; sslCaCertificateArn: string; sslClientCertificateArn: string; sslClientKeyArn: string; sslClientKeyPassword: string; topic: string; } interface GetEndpointKinesisSetting { includeControlDetails: boolean; includeNullAndEmpty: boolean; includePartitionValue: boolean; includeTableAlterOperations: boolean; includeTransactionDetails: boolean; messageFormat: string; partitionIncludeSchemaTable: boolean; serviceAccessRoleArn: string; streamArn: string; useLargeIntegerValue: boolean; } interface GetEndpointMongodbSetting { authMechanism: string; authSource: string; authType: string; docsToInvestigate: string; extractDocId: string; nestingLevel: string; useUpdateLookup: boolean; } interface GetEndpointMysqlSetting { afterConnectScript: string; authenticationMethod: string; cleanSourceMetadataOnMismatch: boolean; eventsPollInterval: number; executeTimeout: number; maxFileSize: number; parallelLoadThreads: number; serverTimezone: string; serviceAccessRoleArn: string; targetDbType: string; } interface GetEndpointPostgresSetting { afterConnectScript: string; authenticationMethod: string; babelfishDatabaseName: string; captureDdls: boolean; databaseMode: string; ddlArtifactsSchema: string; executeTimeout: number; failTasksOnLobTruncation: boolean; heartbeatEnable: boolean; heartbeatFrequency: number; heartbeatSchema: string; mapBooleanAsBoolean: boolean; mapJsonbAsClob: boolean; mapLongVarcharAs: string; maxFileSize: number; pluginName: string; serviceAccessRoleArn: string; slotName: string; } interface GetEndpointRedisSetting { authPassword: string; authType: string; authUserName: string; port: number; serverName: string; sslCaCertificateArn: string; sslSecurityProtocol: string; } interface GetEndpointRedshiftSetting { bucketFolder: string; bucketName: string; encryptionMode: string; serverSideEncryptionKmsKeyId: string; serviceAccessRoleArn: string; } interface GetEndpointS3Setting { addColumnName: boolean; bucketFolder: string; bucketName: string; cannedAclForObjects: string; cdcInsertsAndUpdates: boolean; cdcInsertsOnly: boolean; cdcMaxBatchInterval: number; cdcMinFileSize: number; cdcPath: string; compressionType: string; csvDelimiter: string; csvNoSupValue: string; csvNullValue: string; csvRowDelimiter: string; dataFormat: string; dataPageSize: number; datePartitionDelimiter: string; datePartitionEnabled: boolean; datePartitionSequence: string; dictPageSizeLimit: number; enableStatistics: boolean; encodingType: string; encryptionMode: string; externalTableDefinition: string; glueCatalogGeneration: boolean; ignoreHeaderRows: number; ignoreHeadersRow: number; includeOpForFullLoad: boolean; maxFileSize: number; parquetTimestampInMillisecond: boolean; parquetVersion: string; preserveTransactions: boolean; rfc4180: boolean; rowGroupLength: number; serverSideEncryptionKmsKeyId: string; serviceAccessRoleArn: string; timestampColumnName: string; useCsvNoSupValue: boolean; useTaskStartTimeForFullLoadTimestamp: boolean; } interface MigrationProjectSchemaConversionApplicationAttributes { /** * S3 bucket path that the application uses for exporting assessment reports. */ s3BucketPath?: string; /** * ARN of the IAM role the application uses to access its S3 bucket. */ s3BucketRoleArn?: string; } interface MigrationProjectSourceDataProviderDescriptor { /** * ARN of the data provider. * * The following arguments are optional: */ dataProviderArn: string; /** * Name of the source data provider. */ dataProviderName: string; /** * ARN of the IAM role used to access AWS Secrets Manager. */ secretsManagerAccessRoleArn?: string; /** * Identifier of the Secrets Manager secret used to store access credentials for the data provider. */ secretsManagerSecretId?: string; } interface MigrationProjectTargetDataProviderDescriptor { /** * ARN of the data provider. * * The following arguments are optional: */ dataProviderArn: string; /** * Name of the target data provider. */ dataProviderName: string; /** * ARN of the IAM role used to access AWS Secrets Manager. */ secretsManagerAccessRoleArn?: string; /** * Identifier of the Secrets Manager secret used to store access credentials for the data provider. */ secretsManagerSecretId?: string; } interface MigrationProjectTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface ReplicationConfigComputeConfig { /** * The Availability Zone where the DMS Serverless replication using this configuration will run. The default value is a random. */ availabilityZone: string; /** * A list of custom DNS name servers supported for the DMS Serverless replication to access your source or target database. */ dnsNameServers?: string; /** * KMS key ARN that is used to encrypt the data during DMS Serverless replication. If you don't specify a value for the KmsKeyId parameter, DMS uses your default encryption key. */ kmsKeyId: string; /** * Specifies the maximum value of the DMS capacity units (DCUs) for which a given DMS Serverless replication can be provisioned. A single DCU is 2GB of RAM, with 1 DCUs as the minimum value allowed. The list of valid DCU values includes 1, 2, 4, 8, 16, 32, 64, 128, 192, 256, and 384. */ maxCapacityUnits?: number; /** * Specifies the minimum value of the DMS capacity units (DCUs) for which a given DMS Serverless replication can be provisioned. The list of valid DCU values includes 1, 2, 4, 8, 16, 32, 64, 128, 192, 256, and 384. If this value isn't set DMS sets the lowest allowed value, 1. */ minCapacityUnits?: number; /** * Specifies if the replication instance is a multi-az deployment. You cannot set the `availabilityZone` parameter if the `multiAz` parameter is set to `true`. */ multiAz: boolean; /** * The weekly time range during which system maintenance can occur, in Universal Coordinated Time (UTC). * * - Default: A 30-minute window selected at random from an 8-hour block of time per region, occurring on a random day of the week. * - Format: `ddd:hh24:mi-ddd:hh24:mi` * - Valid Days: `mon, tue, wed, thu, fri, sat, sun` * - Constraints: Minimum 30-minute window. */ preferredMaintenanceWindow: string; /** * Specifies a subnet group identifier to associate with the DMS Serverless replication. */ replicationSubnetGroupId: string; /** * VPC security group to use with the DMS Serverless replication. The VPC security group must work with the VPC containing the replication. */ vpcSecurityGroupIds: string[]; } interface ReplicationInstanceKerberosAuthenticationSettings { /** * ARN of the IAM role that grants AWS DMS access to the secret containing key cache file for the Kerberos authentication. */ keyCacheSecretIamArn: string; /** * Secret ID that stores the key cache file required for Kerberos authentication. */ keyCacheSecretId: string; /** * Contents of krb5 configuration file required for Kerberos authentication. */ krb5FileContents: string; } } export declare namespace docdb { interface ClusterMasterUserSecret { /** * The ARN for the KMS encryption key. When specifying `kmsKeyId`, `storageEncrypted` needs to be set to true. */ kmsKeyId: string; secretArn: string; secretStatus: string; } interface ClusterParameterGroupParameter { /** * Valid values are `immediate` and `pending-reboot`. Defaults to `pending-reboot`. */ applyMethod?: string; /** * The name of the DocumentDB parameter. */ name: string; /** * The value of the DocumentDB parameter. */ value: string; } interface ClusterRestoreToPointInTime { /** * The date and time to restore from. Value must be a time in Universal Coordinated Time (UTC) format and must be before the latest restorable time for the DB instance. Cannot be specified with `useLatestRestorableTime`. */ restoreToTime?: string; /** * The type of restore to be performed. Valid values are `full-copy`, `copy-on-write`. */ restoreType?: string; /** * The identifier of the source DB cluster from which to restore. Must match the identifier of an existing DB cluster. */ sourceClusterIdentifier: string; /** * A boolean value that indicates whether the DB cluster is restored from the latest backup time. Defaults to `false`. Cannot be specified with `restoreToTime`. */ useLatestRestorableTime?: boolean; } interface ClusterServerlessV2ScalingConfiguration { /** * Maximum number of Amazon DocumentDB capacity units (DCUs) for an instance in an Amazon DocumentDB Serverless cluster. Valid values are multiples of 0.5 between 1 and 256. */ maxCapacity: number; /** * Minimum number of Amazon DocumentDB capacity units (DCUs) for an instance in an Amazon DocumentDB Serverless cluster. Valid values are multiples of 0.5 between 0.5 and 256. */ minCapacity: number; } interface ElasticClusterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GlobalClusterGlobalClusterMember { /** * ARN of member DB Cluster. */ dbClusterArn: string; /** * Whether the member is the primary DB Cluster. */ isWriter: boolean; } } export declare namespace drs { interface ReplicationConfigurationTemplatePitPolicy { /** * Whether this rule is enabled or not. */ enabled?: boolean; /** * How often, in the chosen units, a snapshot should be taken. */ interval: number; /** * Duration to retain a snapshot for, in the chosen `units`. */ retentionDuration: number; /** * ID of the rule. Valid values are integers. */ ruleId?: number; /** * Units used to measure the `interval` and `retentionDuration`. Valid values are `MINUTE`, `HOUR`, and `DAY`. */ units: string; } interface ReplicationConfigurationTemplateTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace dsql { interface ClusterEncryptionDetail { /** * The status of encryption for the DSQL Cluster. */ encryptionStatus: string; /** * The type of encryption that protects the data on the DSQL Cluster. */ encryptionType: string; } interface ClusterMultiRegionProperties { /** * List of DSQL Cluster ARNs peered to this cluster. */ clusters: string[]; /** * Witness region for the multi-region clusters. Setting this makes this cluster a multi-region cluster. Changing it recreates the resource. */ witnessRegion?: string; } interface ClusterPeeringTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface ClusterPolicyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ClusterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace dynamodb { interface GetBackupsBackupSummary { /** * ARN of the backup. */ backupArn: string; /** * Time at which the backup was created. */ backupCreationDateTime: string; /** * Time at which the automatic on-demand backup created by DynamoDB will expire. */ backupExpiryDateTime: string; /** * Name of the specified backup. */ backupName: string; /** * Size of the backup in bytes. */ backupSizeBytes: number; /** * Backup can be in one of the following states: `CREATING`, `DELETED`, `AVAILABLE`. */ backupStatus: string; /** * Backup type. Valid values: `USER`, `SYSTEM`, `AWS_BACKUP`, `ALL`. */ backupType: string; /** * ARN associated with the table. */ tableArn: string; /** * Unique identifier for the table. */ tableId: string; /** * Name of the table to list backups for. */ tableName: string; } interface GetTableAttribute { /** * Name of the DynamoDB table. */ name: string; type: string; } interface GetTableGlobalSecondaryIndex { hashKey: string; keySchemas: outputs.dynamodb.GetTableGlobalSecondaryIndexKeySchema[]; /** * Name of the DynamoDB table. */ name: string; nonKeyAttributes: string[]; onDemandThroughputs: outputs.dynamodb.GetTableGlobalSecondaryIndexOnDemandThroughput[]; projectionType: string; rangeKey: string; readCapacity: number; warmThroughputs: outputs.dynamodb.GetTableGlobalSecondaryIndexWarmThroughput[]; writeCapacity: number; } interface GetTableGlobalSecondaryIndexKeySchema { attributeName: string; keyType: string; } interface GetTableGlobalSecondaryIndexOnDemandThroughput { maxReadRequestUnits: number; maxWriteRequestUnits: number; } interface GetTableGlobalSecondaryIndexWarmThroughput { readUnitsPerSecond: number; writeUnitsPerSecond: number; } interface GetTableLocalSecondaryIndex { /** * Name of the DynamoDB table. */ name: string; nonKeyAttributes: string[]; projectionType: string; rangeKey: string; } interface GetTableOnDemandThroughput { maxReadRequestUnits: number; maxWriteRequestUnits: number; } interface GetTablePointInTimeRecovery { enabled: boolean; recoveryPeriodInDays: number; } interface GetTableReplica { kmsKeyArn: string; regionName: string; } interface GetTableServerSideEncryption { enabled: boolean; kmsKeyArn: string; } interface GetTableTtl { attributeName: string; enabled: boolean; } interface GetTableWarmThroughput { readUnitsPerSecond: number; writeUnitsPerSecond: number; } interface GlobalSecondaryIndexKeySchema { /** * Name of the attribute. */ attributeName: string; /** * Type of the attribute in the index. * Valid values are `S` (string), `N` (number), or `B` (binary). */ attributeType: string; /** * Key type. * Valid values are `HASH` or `RANGE`. */ keyType: string; } interface GlobalSecondaryIndexOnDemandThroughput { /** * Maximum number of read request units for this index. */ maxReadRequestUnits: number; /** * Maximum number of write request units for this index. */ maxWriteRequestUnits: number; } interface GlobalSecondaryIndexProjection { /** * Specifies which additional attributes to include in the index. * Only valid when `projectionType` is `INCLUDE`.` */ nonKeyAttributes?: string[]; /** * The set of attributes represented in the index. * One of `ALL`, `INCLUDE`, or `KEYS_ONLY`. */ projectionType: string; } interface GlobalSecondaryIndexProvisionedThroughput { /** * Number of read capacity units for this index. */ readCapacityUnits: number; /** * Number of write capacity units for this index. */ writeCapacityUnits: number; } interface GlobalSecondaryIndexTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GlobalSecondaryIndexWarmThroughput { /** * Number of read operations this index can instantaneously support. */ readUnitsPerSecond: number; /** * Number of write operations this index can instantaneously support. */ writeUnitsPerSecond: number; } interface GlobalTableReplica { /** * AWS region name of replica DynamoDB TableE.g., `us-east-1` */ regionName: string; } interface TableAttribute { /** * Name of the attribute */ name: string; /** * Attribute type. Valid values are `S` (string), `N` (number), `B` (binary). */ type: string; } interface TableExportIncrementalExportSpecification { exportFromTime: string; exportToTime: string; exportViewType: string; } interface TableGlobalSecondaryIndex { /** * Name of the hash key in the index; must be defined as an attribute in the resource. Mutually exclusive with `keySchema`. Use `keySchema` instead. * * @deprecated hash_key is deprecated. Use keySchema instead. */ hashKey: string; /** * Configuration block(s) for the key schema. Mutually exclusive with `hashKey` and `rangeKey`. Required if `hashKey` is not specified. Supports multi-attribute keys for the [Multi-Attribute Keys design pattern](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/GSI.DesignPattern.MultiAttributeKeys.html). See below. */ keySchemas: outputs.dynamodb.TableGlobalSecondaryIndexKeySchema[]; /** * Name of the index. */ name: string; /** * Only required with `INCLUDE` as a projection type; a list of attributes to project into the index. These do not need to be defined as attributes on the table. */ nonKeyAttributes?: string[]; /** * Sets the maximum number of read and write units for the specified on-demand index. See below. */ onDemandThroughput?: outputs.dynamodb.TableGlobalSecondaryIndexOnDemandThroughput; /** * One of `ALL`, `INCLUDE` or `KEYS_ONLY` where `ALL` projects every attribute into the index, `KEYS_ONLY` projects into the index only the table and index hashKey and sortKey attributes, `INCLUDE` projects into the index all of the attributes that are defined in `nonKeyAttributes` in addition to the attributes that `KEYS_ONLY` project. */ projectionType: string; /** * Name of the range key; must be defined as an attribute in the resource. Mutually exclusive with `keySchema`. Use `keySchema` instead. * * @deprecated range_key is deprecated. Use keySchema instead. */ rangeKey?: string; /** * Number of read units for this index. Must be set if billingMode is set to PROVISIONED. */ readCapacity: number; /** * Sets the number of warm read and write units for this index. See below. */ warmThroughput: outputs.dynamodb.TableGlobalSecondaryIndexWarmThroughput; /** * Number of write units for this index. Must be set if billingMode is set to PROVISIONED. */ writeCapacity: number; } interface TableGlobalSecondaryIndexKeySchema { /** * Name of the attribute; must be defined as an attribute in the resource. */ attributeName: string; /** * The type of key. Valid values are `HASH` (partition key) or `RANGE` (sort key). You can specify up to 4 attributes with `keyType = "HASH"` and up to 4 attributes with `keyType = "RANGE"`. */ keyType: string; } interface TableGlobalSecondaryIndexOnDemandThroughput { /** * Maximum number of read request units for the specified table. To specify set the value greater than or equal to 1. To remove set the value to -1. */ maxReadRequestUnits: number; /** * Maximum number of write request units for the specified table. To specify set the value greater than or equal to 1. To remove set the value to -1. */ maxWriteRequestUnits: number; } interface TableGlobalSecondaryIndexWarmThroughput { /** * Number of read operations a table or index can instantaneously support. For the base table, this value cannot be decreased. For a global secondary index, this value can be increased or decreased. Minimum value of `12000` (default). */ readUnitsPerSecond: number; /** * Number of write operations a table or index can instantaneously support. For the base table, this value cannot be decreased. For a global secondary index, this value can be increased or decreased. Minimum value of `4000` (default). */ writeUnitsPerSecond: number; } interface TableGlobalTableWitness { /** * Name of the AWS Region that serves as a witness for the MRSC global table. */ regionName: string; } interface TableImportTable { /** * Type of compression to be used on the input coming from the imported table. * Valid values are `GZIP`, `ZSTD` and `NONE`. */ inputCompressionType?: string; /** * The format of the source data. * Valid values are `CSV`, `DYNAMODB_JSON`, and `ION`. */ inputFormat: string; /** * Describe the format options for the data that was imported into the target table. * There is one value, `csv`. * See below. */ inputFormatOptions?: outputs.dynamodb.TableImportTableInputFormatOptions; /** * Values for the S3 bucket the source file is imported from. * See below. */ s3BucketSource: outputs.dynamodb.TableImportTableS3BucketSource; } interface TableImportTableInputFormatOptions { /** * This block contains the processing options for the CSV file being imported: */ csv?: outputs.dynamodb.TableImportTableInputFormatOptionsCsv; } interface TableImportTableInputFormatOptionsCsv { /** * The delimiter used for separating items in the CSV file being imported. */ delimiter?: string; /** * List of the headers used to specify a common header for all source CSV files being imported. */ headerLists?: string[]; } interface TableImportTableS3BucketSource { /** * The S3 bucket that is being imported from. */ bucket: string; /** * The account number of the S3 bucket that is being imported from. */ bucketOwner?: string; /** * The key prefix shared by all S3 Objects that are being imported. */ keyPrefix?: string; } interface TableLocalSecondaryIndex { /** * Name of the index */ name: string; /** * Only required with `INCLUDE` as a projection type; a list of attributes to project into the index. These do not need to be defined as attributes on the table. */ nonKeyAttributes?: string[]; /** * One of `ALL`, `INCLUDE` or `KEYS_ONLY` where `ALL` projects every attribute into the index, `KEYS_ONLY` projects into the index only the table and index hashKey and sortKey attributes , `INCLUDE` projects into the index all of the attributes that are defined in `nonKeyAttributes` in addition to the attributes that that`KEYS_ONLY` project. */ projectionType: string; /** * Name of the range key. */ rangeKey: string; } interface TableOnDemandThroughput { /** * Maximum number of read request units for the specified table. To specify set the value greater than or equal to 1. To remove set the value to -1. */ maxReadRequestUnits: number; /** * Maximum number of write request units for the specified table. To specify set the value greater than or equal to 1. To remove set the value to -1. */ maxWriteRequestUnits: number; } interface TablePointInTimeRecovery { /** * Whether to enable point-in-time recovery. It can take 10 minutes to enable for new tables. If the `pointInTimeRecovery` block is not provided, this defaults to `false`. */ enabled: boolean; /** * Number of preceding days for which continuous backups are taken and maintained. Default is 35. */ recoveryPeriodInDays: number; } interface TableReplica { /** * ARN of the table * * `replica.*.arn` - ARN of the replica * * `replica.*.stream_arn` - ARN of the replica Table Stream. Only available when `streamEnabled = true`. * * `replica.*.stream_label` - Timestamp, in ISO 8601 format, for the replica stream. Note that this timestamp is not a unique identifier for the stream on its own. However, the combination of AWS customer ID, table name and this field is guaranteed to be unique. It can be used for creating CloudWatch Alarms. Only available when `streamEnabled = true`. */ arn: string; /** * Whether this global table will be using `STRONG` consistency mode or `EVENTUAL` consistency mode. Default value is `EVENTUAL`. */ consistencyMode?: string; /** * Whether deletion protection is enabled (true) or disabled (false) on the replica. Default is `false`. */ deletionProtectionEnabled: boolean; /** * ARN of the CMK that should be used for the AWS KMS encryption. * This argument should only be used if the key is different from the default KMS-managed DynamoDB key, `alias/aws/dynamodb`. * **Note:** This attribute will _not_ be populated with the ARN of _default_ keys. * **Note:** Changing this value will recreate the replica. */ kmsKeyArn: string; /** * Whether to enable Point In Time Recovery for the replica. Default is `false`. */ pointInTimeRecovery?: boolean; /** * Whether to propagate the global table's tags to a replica. * Default is `false`. * Changes to tags only move in one direction: from global (source) to replica. * Tag drift on a replica will not trigger an update. * Tag changes on the global table are propagated to replicas. * Changing from `true` to `false` on a subsequent `apply` leaves replica tags as-is and no longer manages them. */ propagateTags?: boolean; /** * Region name of the replica. */ regionName: string; /** * ARN of the Table Stream. Only available when `streamEnabled = true` */ streamArn: string; /** * Timestamp, in ISO 8601 format, for this stream. Note that this timestamp is not a unique identifier for the stream on its own. However, the combination of AWS customer ID, table name and this field is guaranteed to be unique. It can be used for creating CloudWatch Alarms. Only available when `streamEnabled = true`. */ streamLabel: string; } interface TableServerSideEncryption { /** * Whether or not to enable encryption at rest using an AWS managed KMS customer master key (CMK). If `enabled` is `false` then server-side encryption is set to AWS-_owned_ key (shown as `DEFAULT` in the AWS console). Potentially confusingly, if `enabled` is `true` and no `kmsKeyArn` is specified then server-side encryption is set to the _default_ KMS-_managed_ key (shown as `KMS` in the AWS console). The [AWS KMS documentation](https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html) explains the difference between AWS-_owned_ and KMS-_managed_ keys. */ enabled: boolean; /** * ARN of the CMK that should be used for the AWS KMS encryption. This argument should only be used if the key is different from the default KMS-managed DynamoDB key, `alias/aws/dynamodb`. **Note:** This attribute will _not_ be populated with the ARN of _default_ keys. */ kmsKeyArn: string; } interface TableTtl { /** * Name of the table attribute to store the TTL timestamp in. * Required if `enabled` is `true`, must not be set otherwise. */ attributeName?: string; /** * Whether TTL is enabled. * Default value is `false`. */ enabled?: boolean; } interface TableWarmThroughput { /** * Number of read operations a table or index can instantaneously support. For the base table, this value cannot be decreased. For a global secondary index, this value can be increased or decreased. Minimum value of `12000` (default). */ readUnitsPerSecond: number; /** * Number of write operations a table or index can instantaneously support. For the base table, this value cannot be decreased. For a global secondary index, this value can be increased or decreased. Minimum value of `4000` (default). */ writeUnitsPerSecond: number; } } export declare namespace ebs { interface FastSnapshotRestoreTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface GetEbsVolumesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumes.html). * For example, if matching against the `size` filter, use: * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const tenOrTwentyGbVolumes = aws.ebs.getEbsVolumes({ * filters: [{ * name: "size", * values: [ * "10", * "20", * ], * }], * }); * ``` */ name: string; /** * Set of values that are accepted for the given field. * EBS Volume IDs will be selected if any one of the given values match. */ values: string[]; } interface GetSnapshotFilter { name: string; values: string[]; } interface GetSnapshotIdsFilter { name: string; values: string[]; } interface GetVolumeFilter { name: string; values: string[]; } interface SnapshotImportClientData { /** * A user-defined comment about the disk upload. */ comment?: string; /** * The time that the disk upload ends. */ uploadEnd: string; /** * The size of the uploaded disk image, in GiB. */ uploadSize: number; /** * The time that the disk upload starts. */ uploadStart: string; } interface SnapshotImportDiskContainer { /** * The description of the disk image being imported. */ description?: string; /** * The format of the disk image being imported. One of `VHD` or `VMDK`. */ format: string; /** * The URL to the Amazon S3-based disk image being imported. It can either be a https URL (https://..) or an Amazon S3 URL (s3://..). One of `url` or `userBucket` must be set. */ url?: string; /** * The Amazon S3 bucket for the disk image. One of `url` or `userBucket` must be set. Detailed below. */ userBucket?: outputs.ebs.SnapshotImportDiskContainerUserBucket; } interface SnapshotImportDiskContainerUserBucket { /** * The name of the Amazon S3 bucket where the disk image is located. */ s3Bucket: string; /** * The file name of the disk image. */ s3Key: string; } interface VolumeCopyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace ec2 { interface AllowedImagesSettingsImageCriterion { /** * Condition based on AMI creation date. See `creationDateCondition` below. */ creationDateCondition?: outputs.ec2.AllowedImagesSettingsImageCriterionCreationDateCondition; /** * Condition based on AMI deprecation time. See `deprecationTimeCondition` below. */ deprecationTimeCondition?: outputs.ec2.AllowedImagesSettingsImageCriterionDeprecationTimeCondition; /** * Set of AMI name patterns to allow. Maximum of 50 names. */ imageNames?: string[]; /** * Set of image providers to allow. Maximum of 200 providers. Valid values include `amazon`, `aws-marketplace`, `aws-backup-vault`, `none`, or a 12-digit AWS account ID. */ imageProviders?: string[]; /** * Set of AWS Marketplace product codes to allow. Maximum of 50 product codes. */ marketplaceProductCodes?: string[]; } interface AllowedImagesSettingsImageCriterionCreationDateCondition { /** * Maximum number of days since the AMI was created. */ maximumDaysSinceCreated?: number; } interface AllowedImagesSettingsImageCriterionDeprecationTimeCondition { /** * Maximum number of days since the AMI was deprecated. Setting this to `0` means no deprecated images are allowed. */ maximumDaysSinceDeprecated?: number; } interface AmiCopyEbsBlockDevice { /** * Boolean controlling whether the EBS volumes created to * support each created instance will be deleted once that instance is terminated. */ deleteOnTermination: boolean; /** * Path at which the device is exposed to created instances. */ deviceName: string; /** * Boolean controlling whether the created EBS volumes will be encrypted. Can't be used with `snapshotId`. */ encrypted: boolean; /** * Number of I/O operations per second the * created volumes will support. */ iops: number; /** * ARN of the Outpost on which the snapshot is stored. * * > **Note:** You can specify `encrypted` or `snapshotId` but not both. */ outpostArn: string; /** * ID of an EBS snapshot that will be used to initialize the created * EBS volumes. If set, the `volumeSize` attribute must be at least as large as the referenced * snapshot. */ snapshotId: string; /** * Throughput that the EBS volume supports, in MiB/s. Only valid for `volumeType` of `gp3`. */ throughput: number; /** * Size of created volumes in GiB. * If `snapshotId` is set and `volumeSize` is omitted then the volume will have the same size * as the selected snapshot. */ volumeSize: number; /** * Type of EBS volume to create. Can be `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1` or `st1` (Default: `standard`). */ volumeType: string; } interface AmiCopyEphemeralBlockDevice { /** * Path at which the device is exposed to created instances. */ deviceName: string; /** * Name for the ephemeral device, of the form "ephemeralN" where * *N* is a volume number starting from zero. */ virtualName: string; } interface AmiEbsBlockDevice { /** * Boolean controlling whether the EBS volumes created to * support each created instance will be deleted once that instance is terminated. */ deleteOnTermination?: boolean; /** * Path at which the device is exposed to created instances. */ deviceName: string; /** * Boolean controlling whether the created EBS volumes will be encrypted. Can't be used with `snapshotId`. */ encrypted?: boolean; /** * Number of I/O operations per second the * created volumes will support. */ iops?: number; /** * ARN of the Outpost on which the snapshot is stored. * * > **Note:** You can specify `encrypted` or `snapshotId` but not both. */ outpostArn?: string; /** * ID of an EBS snapshot that will be used to initialize the created * EBS volumes. If set, the `volumeSize` attribute must be at least as large as the referenced * snapshot. */ snapshotId?: string; /** * Throughput that the EBS volume supports, in MiB/s. Only valid for `volumeType` of `gp3`. */ throughput: number; /** * Size of created volumes in GiB. * If `snapshotId` is set and `volumeSize` is omitted then the volume will have the same size * as the selected snapshot. */ volumeSize: number; /** * Type of EBS volume to create. Can be `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1` or `st1` (Default: `standard`). */ volumeType?: string; } interface AmiEphemeralBlockDevice { /** * Path at which the device is exposed to created instances. */ deviceName: string; /** * Name for the ephemeral device, of the form "ephemeralN" where * *N* is a volume number starting from zero. */ virtualName: string; } interface AmiFromInstanceEbsBlockDevice { /** * Boolean controlling whether the EBS volumes created to * support each created instance will be deleted once that instance is terminated. */ deleteOnTermination: boolean; /** * Path at which the device is exposed to created instances. */ deviceName: string; /** * Boolean controlling whether the created EBS volumes will be encrypted. Can't be used with `snapshotId`. */ encrypted: boolean; /** * Number of I/O operations per second the * created volumes will support. */ iops: number; /** * ARN of the Outpost on which the snapshot is stored. * * > **Note:** You can specify `encrypted` or `snapshotId` but not both. */ outpostArn: string; /** * ID of an EBS snapshot that will be used to initialize the created * EBS volumes. If set, the `volumeSize` attribute must be at least as large as the referenced * snapshot. */ snapshotId: string; /** * Throughput that the EBS volume supports, in MiB/s. Only valid for `volumeType` of `gp3`. */ throughput: number; /** * Size of created volumes in GiB. * If `snapshotId` is set and `volumeSize` is omitted then the volume will have the same size * as the selected snapshot. */ volumeSize: number; /** * Type of EBS volume to create. Can be `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1` or `st1` (Default: `standard`). */ volumeType: string; } interface AmiFromInstanceEphemeralBlockDevice { /** * Path at which the device is exposed to created instances. */ deviceName: string; /** * Name for the ephemeral device, of the form "ephemeralN" where * *N* is a volume number starting from zero. */ virtualName: string; } interface CapacityBlockReservationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface DefaultCreditSpecificationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DefaultNetworkAclEgress { /** * The action to take. */ action: string; /** * The CIDR block to match. This must be a valid network mask. */ cidrBlock?: string; /** * The from port to match. */ fromPort: number; /** * The ICMP type code to be used. Default 0. */ icmpCode?: number; /** * The ICMP type to be used. Default 0. */ icmpType?: number; /** * The IPv6 CIDR block. * * > For more information on ICMP types and codes, see [Internet Control Message Protocol (ICMP) Parameters](https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml). */ ipv6CidrBlock?: string; /** * The protocol to match. If using the -1 'all' protocol, you must specify a from and to port of 0. */ protocol: string; /** * The rule number. Used for ordering. */ ruleNo: number; /** * The to port to match. * * The following arguments are optional: */ toPort: number; } interface DefaultNetworkAclIngress { /** * The action to take. */ action: string; /** * The CIDR block to match. This must be a valid network mask. */ cidrBlock?: string; /** * The from port to match. */ fromPort: number; /** * The ICMP type code to be used. Default 0. */ icmpCode?: number; /** * The ICMP type to be used. Default 0. */ icmpType?: number; /** * The IPv6 CIDR block. * * > For more information on ICMP types and codes, see [Internet Control Message Protocol (ICMP) Parameters](https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml). */ ipv6CidrBlock?: string; /** * The protocol to match. If using the -1 'all' protocol, you must specify a from and to port of 0. */ protocol: string; /** * The rule number. Used for ordering. */ ruleNo: number; /** * The to port to match. * * The following arguments are optional: */ toPort: number; } interface DefaultRouteTableRoute { /** * The CIDR block of the route. */ cidrBlock?: string; /** * ARN of a core network. */ coreNetworkArn?: string; /** * The ID of a managed prefix list destination of the route. * * One of the following target arguments must be supplied: */ destinationPrefixListId?: string; /** * Identifier of a VPC Egress Only Internet Gateway. */ egressOnlyGatewayId?: string; /** * Identifier of a VPC internet gateway or a virtual private gateway. */ gatewayId?: string; /** * Identifier of an EC2 instance. */ instanceId?: string; /** * The Ipv6 CIDR block of the route */ ipv6CidrBlock?: string; /** * Identifier of a VPC NAT gateway. */ natGatewayId?: string; /** * Identifier of an EC2 network interface. */ networkInterfaceId?: string; /** * Identifier of an EC2 Transit Gateway. */ transitGatewayId?: string; /** * Identifier of a VPC Endpoint. This route must be removed prior to VPC Endpoint deletion. */ vpcEndpointId?: string; /** * Identifier of a VPC peering connection. * * Note that the default route, mapping the VPC's CIDR block to "local", is created implicitly and cannot be specified. */ vpcPeeringConnectionId?: string; } interface DefaultSecurityGroupEgress { /** * List of CIDR blocks. */ cidrBlocks?: string[]; /** * Description of this rule. */ description?: string; /** * Start port (or ICMP type number if protocol is `icmp`) */ fromPort: number; /** * List of IPv6 CIDR blocks. */ ipv6CidrBlocks?: string[]; /** * List of prefix list IDs (for allowing access to VPC endpoints) */ prefixListIds?: string[]; /** * Protocol. If you select a protocol of "-1" (semantically equivalent to `all`, which is not a valid value here), you must specify a `fromPort` and `toPort` equal to `0`. If not `icmp`, `tcp`, `udp`, or `-1` use the [protocol number](https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml). */ protocol: string; /** * List of security groups. A group name can be used relative to the default VPC. Otherwise, group ID. */ securityGroups?: string[]; /** * Whether the security group itself will be added as a source to this egress rule. */ self?: boolean; /** * End range port (or ICMP code if protocol is `icmp`). */ toPort: number; } interface DefaultSecurityGroupIngress { /** * List of CIDR blocks. */ cidrBlocks?: string[]; /** * Description of the security group. */ description?: string; /** * Start port (or ICMP type number if protocol is `icmp`) */ fromPort: number; /** * List of IPv6 CIDR blocks. */ ipv6CidrBlocks?: string[]; /** * List of prefix list IDs (for allowing access to VPC endpoints) */ prefixListIds?: string[]; /** * Protocol. If you select a protocol of "-1" (semantically equivalent to `all`, which is not a valid value here), you must specify a `fromPort` and `toPort` equal to `0`. If not `icmp`, `tcp`, `udp`, or `-1` use the [protocol number](https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml). */ protocol: string; /** * List of security groups. A group name can be used relative to the default VPC. Otherwise, group ID. */ securityGroups?: string[]; /** * Whether the security group itself will be added as a source to this egress rule. */ self?: boolean; /** * End range port (or ICMP code if protocol is `icmp`). */ toPort: number; } interface EipDomainNameTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface EncryptionControlResourceExclusions { /** * `state` and `stateMessage` describing encryption enforcement state for Egress-Only Internet Gateways. */ egressOnlyInternetGateway: outputs.ec2.EncryptionControlResourceExclusionsEgressOnlyInternetGateway; /** * `state` and `stateMessage` describing encryption enforcement state for Elastic File System (EFS). */ elasticFileSystem: outputs.ec2.EncryptionControlResourceExclusionsElasticFileSystem; /** * `state` and `stateMessage` describing encryption enforcement state for Internet Gateways. */ internetGateway: outputs.ec2.EncryptionControlResourceExclusionsInternetGateway; /** * `state` and `stateMessage` describing encryption enforcement state for Lambda Functions. */ lambda: outputs.ec2.EncryptionControlResourceExclusionsLambda; /** * `state` and `stateMessage` describing encryption enforcement state for NAT Gateways. */ natGateway: outputs.ec2.EncryptionControlResourceExclusionsNatGateway; /** * `state` and `stateMessage` describing encryption enforcement state for Virtual Private Gateways. */ virtualPrivateGateway: outputs.ec2.EncryptionControlResourceExclusionsVirtualPrivateGateway; /** * `state` and `stateMessage` describing encryption enforcement state for VPC Lattice. */ vpcLattice: outputs.ec2.EncryptionControlResourceExclusionsVpcLattice; /** * `state` and `stateMessage` describing encryption enforcement state for peered VPCs. */ vpcPeering: outputs.ec2.EncryptionControlResourceExclusionsVpcPeering; } interface EncryptionControlResourceExclusionsEgressOnlyInternetGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsElasticFileSystem { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsInternetGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsLambda { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsNatGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsVirtualPrivateGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsVpcLattice { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlResourceExclusionsVpcPeering { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface EncryptionControlTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface FleetFleetInstanceSet { /** * The IDs of the instances. */ instanceIds: string[]; /** * The instance type. */ instanceType: string; /** * Indicates if the instance that was launched is a Spot Instance or On-Demand Instance. */ lifecycle: string; /** * The value is `Windows` for Windows instances. Otherwise, the value is blank. */ platform: string; } interface FleetLaunchTemplateConfig { /** * Nested argument containing EC2 Launch Template to use. Defined below. */ launchTemplateSpecification?: outputs.ec2.FleetLaunchTemplateConfigLaunchTemplateSpecification; /** * Nested argument(s) containing parameters to override the same parameters in the Launch Template. Defined below. */ overrides?: outputs.ec2.FleetLaunchTemplateConfigOverride[]; } interface FleetLaunchTemplateConfigLaunchTemplateSpecification { /** * The ID of the launch template. */ launchTemplateId?: string; /** * The name of the launch template. */ launchTemplateName?: string; /** * The launch template version number, `$Latest`, or `$Default.` */ version: string; } interface FleetLaunchTemplateConfigOverride { /** * Availability Zone in which to launch the instances. */ availabilityZone?: string; /** * Override the instance type in the Launch Template with instance types that satisfy the requirements. */ instanceRequirements?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirements; /** * Instance type. */ instanceType?: string; /** * Maximum price per unit hour that you are willing to pay for a Spot Instance. */ maxPrice?: string; /** * Priority for the launch template override. If `onDemandOptions` `allocationStrategy` is set to `prioritized`, EC2 Fleet uses priority to determine which launch template override to use first in fulfilling On-Demand capacity. The highest priority is launched first. The lower the number, the higher the priority. If no number is set, the launch template override has the lowest priority. Valid values are whole numbers starting at 0. */ priority?: number; /** * ID of the subnet in which to launch the instances. */ subnetId?: string; /** * Number of units provided by the specified instance type. */ weightedCapacity?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirements { /** * Block describing the minimum and maximum number of accelerators (GPUs, FPGAs, or AWS Inferentia chips). Default is no minimum or maximum limits. */ acceleratorCount?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorCount; /** * List of accelerator manufacturer names. Default is any manufacturer. */ acceleratorManufacturers?: string[]; /** * List of accelerator names. Default is any acclerator. */ acceleratorNames?: string[]; /** * Block describing the minimum and maximum total memory of the accelerators. Default is no minimum or maximum. */ acceleratorTotalMemoryMib?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorTotalMemoryMib; /** * The accelerator types that must be on the instance type. Default is any accelerator type. */ acceleratorTypes?: string[]; /** * The instance types to apply your specified attributes against. All other instance types are ignored, even if they match your specified attributes. You can use strings with one or more wild cards,represented by an asterisk (\*). The following are examples: `c5*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are excluding the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are excluding all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is no excluded instance types. Default is any instance type. * * If you specify `AllowedInstanceTypes`, you can't specify `ExcludedInstanceTypes`. */ allowedInstanceTypes?: string[]; /** * Indicate whether bare metal instace types should be `included`, `excluded`, or `required`. Default is `excluded`. */ bareMetal?: string; /** * Block describing the minimum and maximum baseline EBS bandwidth, in Mbps. Default is no minimum or maximum. */ baselineEbsBandwidthMbps?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsBaselineEbsBandwidthMbps; /** * Indicates whether burstable performance T instance types are `included`, `excluded`, or `required`. Default is `excluded`. */ burstablePerformance?: string; /** * The CPU manufacturers to include. Default is any manufacturer. * > **NOTE:** Don't confuse the CPU hardware manufacturer with the CPU hardware architecture. Instances will be launched with a compatible CPU architecture based on the AMI that you specify in your launch template. */ cpuManufacturers?: string[]; /** * The instance types to exclude. You can use strings with one or more wild cards, represented by an asterisk (\*). The following are examples: `c5*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are excluding the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are excluding all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is no excluded instance types. * * If you specify `AllowedInstanceTypes`, you can't specify `ExcludedInstanceTypes`. */ excludedInstanceTypes?: string[]; /** * Indicates whether current or previous generation instance types are included. The current generation instance types are recommended for use. Valid values are `current` and `previous`. Default is `current` and `previous` generation instance types. */ instanceGenerations?: string[]; /** * Indicate whether instance types with local storage volumes are `included`, `excluded`, or `required`. Default is `included`. */ localStorage?: string; /** * List of local storage type names. Valid values are `hdd` and `ssd`. Default any storage type. */ localStorageTypes?: string[]; /** * The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Conflicts with `spotMaxPricePercentageOverLowestPrice` */ maxSpotPriceAsPercentageOfOptimalOnDemandPrice?: number; /** * Block describing the minimum and maximum amount of memory (GiB) per vCPU. Default is no minimum or maximum. */ memoryGibPerVcpu?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsMemoryGibPerVcpu; /** * The minimum and maximum amount of memory per vCPU, in GiB. Default is no minimum or maximum limits. */ memoryMib: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsMemoryMib; /** * The minimum and maximum amount of network bandwidth, in gigabits per second (Gbps). Default is No minimum or maximum. */ networkBandwidthGbps?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsNetworkBandwidthGbps; /** * Block describing the minimum and maximum number of network interfaces. Default is no minimum or maximum. */ networkInterfaceCount?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsNetworkInterfaceCount; /** * The price protection threshold for On-Demand Instances. This is the maximum you’ll pay for an On-Demand Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 20. * * If you set `targetCapacityUnitType` to `vcpu` or `memory-mib`, the price protection threshold is applied based on the per-vCPU or per-memory price instead of the per-instance price. */ onDemandMaxPricePercentageOverLowestPrice?: number; /** * Indicate whether instance types must support On-Demand Instance Hibernation, either `true` or `false`. Default is `false`. */ requireHibernateSupport?: boolean; /** * The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 100. Conflicts with `maxSpotPriceAsPercentageOfOptimalOnDemandPrice` * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ spotMaxPricePercentageOverLowestPrice?: number; /** * Block describing the minimum and maximum total local storage (GB). Default is no minimum or maximum. */ totalLocalStorageGb?: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsTotalLocalStorageGb; /** * Block describing the minimum and maximum number of vCPUs. Default is no maximum. */ vcpuCount: outputs.ec2.FleetLaunchTemplateConfigOverrideInstanceRequirementsVcpuCount; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorCount { /** * Maximum. Set to `0` to exclude instance types with accelerators. */ max?: number; /** * Minimum. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorTotalMemoryMib { /** * The maximum amount of accelerator memory, in MiB. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum amount of accelerator memory, in MiB. To specify no minimum limit, omit this parameter. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsBaselineEbsBandwidthMbps { /** * The maximum baseline bandwidth, in Mbps. To specify no maximum limit, omit this parameter.. */ max?: number; /** * The minimum baseline bandwidth, in Mbps. To specify no minimum limit, omit this parameter.. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsMemoryGibPerVcpu { /** * The maximum amount of memory per vCPU, in GiB. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum amount of memory per vCPU, in GiB. To specify no minimum limit, omit this parameter. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsMemoryMib { /** * The maximum amount of memory, in MiB. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum amount of memory, in MiB. To specify no minimum limit, specify `0`. */ min: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsNetworkBandwidthGbps { /** * The maximum amount of network bandwidth, in Gbps. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum amount of network bandwidth, in Gbps. To specify no minimum limit, omit this parameter. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsNetworkInterfaceCount { /** * The maximum number of network interfaces. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum number of network interfaces. To specify no minimum limit, omit this parameter. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsTotalLocalStorageGb { /** * The maximum amount of total local storage, in GB. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum amount of total local storage, in GB. To specify no minimum limit, omit this parameter. */ min?: number; } interface FleetLaunchTemplateConfigOverrideInstanceRequirementsVcpuCount { /** * The maximum number of vCPUs. To specify no maximum limit, omit this parameter. */ max?: number; /** * The minimum number of vCPUs. To specify no minimum limit, specify `0`. */ min: number; } interface FleetOnDemandOptions { /** * The order of the launch template overrides to use in fulfilling On-Demand capacity. Valid values: `lowestPrice`, `prioritized`. Default: `lowestPrice`. */ allocationStrategy?: string; /** * The strategy for using unused Capacity Reservations for fulfilling On-Demand capacity. Supported only for fleets of type `instant`. */ capacityReservationOptions?: outputs.ec2.FleetOnDemandOptionsCapacityReservationOptions; /** * The maximum amount per hour for On-Demand Instances that you're willing to pay. */ maxTotalPrice?: string; /** * The minimum target capacity for On-Demand Instances in the fleet. If the minimum target capacity is not reached, the fleet launches no instances. Supported only for fleets of type `instant`. * If you specify `minTargetCapacity`, at least one of the following must be specified: `singleAvailabilityZone` or `singleInstanceType`. */ minTargetCapacity?: number; /** * Indicates that the fleet launches all On-Demand Instances into a single Availability Zone. Supported only for fleets of type `instant`. */ singleAvailabilityZone?: boolean; /** * Indicates that the fleet uses a single instance type to launch all On-Demand Instances in the fleet. Supported only for fleets of type `instant`. */ singleInstanceType?: boolean; } interface FleetOnDemandOptionsCapacityReservationOptions { /** * Indicates whether to use unused Capacity Reservations for fulfilling On-Demand capacity. Valid values: `use-capacity-reservations-first`. */ usageStrategy?: string; } interface FleetSpotOptions { /** * How to allocate the target capacity across the Spot pools. Valid values: `diversified`, `lowestPrice`, `capacity-optimized`, `capacity-optimized-prioritized` and `price-capacity-optimized`. Default: `lowestPrice`. */ allocationStrategy?: string; /** * Behavior when a Spot Instance is interrupted. Valid values: `hibernate`, `stop`, `terminate`. Default: `terminate`. */ instanceInterruptionBehavior?: string; /** * Number of Spot pools across which to allocate your target Spot capacity. Valid only when Spot `allocationStrategy` is set to `lowestPrice`. Default: `1`. */ instancePoolsToUseCount?: number; /** * Nested argument containing maintenance strategies for managing your Spot Instances that are at an elevated risk of being interrupted. Defined below. */ maintenanceStrategies?: outputs.ec2.FleetSpotOptionsMaintenanceStrategies; /** * The maximum amount per hour for Spot Instances that you're willing to pay. */ maxTotalPrice?: string; /** * The minimum target capacity for Spot Instances in the fleet. If the minimum target capacity is not reached, the fleet launches no instances. Supported only for fleets of type `instant`. */ minTargetCapacity?: number; /** * Indicates that the fleet launches all Spot Instances into a single Availability Zone. Supported only for fleets of type `instant`. */ singleAvailabilityZone?: boolean; /** * Indicates that the fleet uses a single instance type to launch all Spot Instances in the fleet. Supported only for fleets of type `instant`. */ singleInstanceType?: boolean; } interface FleetSpotOptionsMaintenanceStrategies { /** * Nested argument containing the capacity rebalance for your fleet request. Defined below. */ capacityRebalance?: outputs.ec2.FleetSpotOptionsMaintenanceStrategiesCapacityRebalance; } interface FleetSpotOptionsMaintenanceStrategiesCapacityRebalance { /** * The replacement strategy to use. Only available for fleets of `type` set to `maintain`. Valid values: `launch`. */ replacementStrategy?: string; terminationDelay?: number; } interface FleetTargetCapacitySpecification { /** * Default target capacity type. Valid values: `on-demand`, `spot`. */ defaultTargetCapacityType: string; /** * The number of On-Demand units to request. */ onDemandTargetCapacity?: number; /** * The number of Spot units to request. */ spotTargetCapacity?: number; /** * The unit for the target capacity. * If you specify `targetCapacityUnitType`, `instanceRequirements` must be specified. */ targetCapacityUnitType?: string; /** * The number of units to request, filled using `defaultTargetCapacityType`. */ totalTargetCapacity: number; } interface FlowLogDestinationOptions { /** * File format for the flow log. Default value: `plain-text`. Valid values: `plain-text`, `parquet`. */ fileFormat?: string; /** * Whether to use Hive-compatible prefixes for flow logs stored in Amazon S3. Default value: `false`. */ hiveCompatiblePartitions?: boolean; /** * Whether to partition the flow log per hour. This reduces the cost and response time for queries. Default value: `false`. */ perHourPartition?: boolean; } interface FlowLogTagFieldSpecification { /** * Resource type to associate the tag keys with. Valid values: `instance`, `network-interface`, `auto-scaling-group`. */ resourceType: string; /** * Ordered list of tag keys, on resources of `resourceType`, to display in Flow Log records. The position of each key determines which field it populates in `logFormat` (e.g., the first `instance` tag key populates `$${instance-tag}` and the second populates `$${instance-tag-2}`). */ tagKeys: string[]; } interface GetAmiBlockDeviceMapping { /** * Physical name of the device. */ deviceName: string; /** * Map containing EBS information, if the device is EBS based. Unlike most object attributes, these are accessed directly (e.g., `ebs.volume_size` or `ebs["volumeSize"]`) rather than accessed through the first element of a list (e.g., `ebs[0].volume_size`). See `ebs` below. */ ebs: { [key: string]: string; }; /** * Suppresses the specified device included in the block device mapping of the AMI. */ noDevice: string; /** * Virtual device name (for instance stores). */ virtualName: string; } interface GetAmiFilter { /** * Name of the filter. For a full reference, check out [describe-images in the AWS CLI reference](http://docs.aws.amazon.com/cli/latest/reference/ec2/describe-images.html). */ name: string; /** * Set of values that are accepted for the given filter. */ values: string[]; } interface GetAmiIdsFilter { /** * Name of the filter. For a full reference, check out [describe-images in the AWS CLI reference](http://docs.aws.amazon.com/cli/latest/reference/ec2/describe-images.html). */ name: string; /** * Set of values that are accepted for the given filter. */ values: string[]; } interface GetAmiProductCode { /** * The product code. */ productCodeId: string; /** * The type of product code. */ productCodeType: string; } interface GetCapacityBlockReservationCommitmentInfo { /** * Date and time the commitment duration ends in [RFC3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ commitmentEndDate: string; /** * Number of instances committed to the Capacity Block reservation. */ committedInstanceCount: number; } interface GetCapacityBlockReservationFilter { /** * Name of the filter field. See the [DescribeCapacityReservations API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservations.html) for valid values. Common filters include `instance-type`, `availability-zone`, `state`, `instance-platform`, `tenancy`, `outpost-arn`, `placement-group-arn`, `instance-match-criteria`, and `tag:`. */ name: string; /** * Set of values that are accepted for the given filter field. A Capacity Block reservation will be selected if any one of the given values matches. */ values: string[]; } interface GetCapacityBlockReservationInterruptibleCapacityAllocation { /** * Number of instances allocated as interruptible capacity within the Capacity Block reservation. */ instanceCount: number; /** * ID of the interruptible Capacity Reservation associated with this allocation. */ interruptibleCapacityReservationId: string; /** * Type of interruption that occurred. Either `spot-interruption` or `capacity-block-interruption`. */ interruptionType: string; /** * Status of the interruptible capacity allocation. One of `pending`, `confirmed`, or `cancelled`. */ status: string; /** * Target number of interruptible instances for the allocation. */ targetInstanceCount: number; } interface GetCapacityBlockReservationInterruptionInfo { /** * Type of interruption that occurred. Either `spot-interruption` or `capacity-block-interruption`. */ interruptionType: string; /** * ID of the source Capacity Reservation that originally held the capacity, if the reservation was created as a result of an interruption. */ sourceCapacityReservationId: string; } interface GetCoipPoolFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCoipPools.html). */ name: string; /** * Set of values that are accepted for the given field. * A COIP Pool will be selected if any one of the given values matches. */ values: string[]; } interface GetCoipPoolsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCoipPools.html). */ name: string; /** * Set of values that are accepted for the given field. * A COIP Pool will be selected if any one of the given values matches. */ values: string[]; } interface GetCustomerGatewayFilter { name: string; values: string[]; } interface GetDedicatedHostAvailableCapacity { /** * The number of instances that can be launched onto the Dedicated Host for each instance size supported. See `availableInstanceCapacity` below. */ availableInstanceCapacities: outputs.ec2.GetDedicatedHostAvailableCapacityAvailableInstanceCapacity[]; /** * The number of vCPUs available for launching instances onto the Dedicated Host. */ availableVcpus: number; } interface GetDedicatedHostAvailableCapacityAvailableInstanceCapacity { /** * The number of instances that can be launched onto the Dedicated Host based on the host's available capacity. */ availableCapacity: number; /** * The instance type of the running instance. */ instanceType: string; /** * The total number of instances that can be launched onto the Dedicated Host if there are no instances running on it. */ totalCapacity: number; } interface GetDedicatedHostFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHosts.html). */ name: string; /** * Set of values that are accepted for the given field. A host will be selected if any one of the given values matches. */ values: string[]; } interface GetDedicatedHostInstance { /** * The ID of the instance running on the Dedicated Host. */ instanceId: string; /** * The instance type of the running instance. */ instanceType: string; /** * The ID of the AWS account that owns the instance. */ ownerId: string; } interface GetEipsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddresses.html). */ name: string; /** * Set of values that are accepted for the given field. An Elastic IP will be selected if any one of the given values matches. */ values: string[]; } interface GetElasticIpFilter { name: string; values: string[]; } interface GetHostsFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetInstanceCreditSpecification { cpuCredits: string; } interface GetInstanceEbsBlockDevice { /** * If the root block device will be deleted on termination. */ deleteOnTermination: boolean; /** * Physical name of the device. */ deviceName: string; /** * If the EBS volume is encrypted. */ encrypted: boolean; /** * `0` If the volume is not a provisioned IOPS image, otherwise the supported IOPS count. */ iops: number; kmsKeyId: string; /** * ID of the snapshot. */ snapshotId: string; /** * Map of tags assigned to the Instance. */ tags: { [key: string]: string; }; /** * Throughput of the volume, in MiB/s. */ throughput: number; volumeId: string; /** * Size of the volume, in GiB. */ volumeSize: number; /** * Type of the volume. */ volumeType: string; } interface GetInstanceEnclaveOption { /** * Whether Nitro Enclaves are enabled. */ enabled: boolean; } interface GetInstanceEphemeralBlockDevice { /** * Physical name of the device. */ deviceName: string; /** * Whether the specified device included in the device mapping was suppressed or not (Boolean). */ noDevice?: boolean; /** * Virtual device name. */ virtualName?: string; } interface GetInstanceFilter { /** * Name of the filter. * For a full reference of filter names, see [describe-instances in the AWS CLI reference](http://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instances.html). */ name: string; /** * One or more values to match. */ values: string[]; } interface GetInstanceMaintenanceOption { /** * Automatic recovery behavior of the instance. */ autoRecovery: string; } interface GetInstanceMetadataOption { /** * State of the metadata service: `enabled`, `disabled`. */ httpEndpoint: string; /** * Whether the IPv6 endpoint for the instance metadata service is `enabled` or `disabled` */ httpProtocolIpv6: string; /** * Desired HTTP PUT response hop limit for instance metadata requests. */ httpPutResponseHopLimit: number; /** * If session tokens are required: `optional`, `required`. */ httpTokens: string; /** * If access to instance tags is allowed from the metadata service: `enabled`, `disabled`. */ instanceMetadataTags: string; } interface GetInstancePrivateDnsNameOption { /** * Indicates whether to respond to DNS queries for instance hostnames with DNS A records. */ enableResourceNameDnsARecord: boolean; /** * Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records. */ enableResourceNameDnsAaaaRecord: boolean; /** * Type of hostname for EC2 instances. */ hostnameType: string; } interface GetInstanceRootBlockDevice { /** * If the root block device will be deleted on termination. */ deleteOnTermination: boolean; /** * Physical name of the device. */ deviceName: string; /** * If the EBS volume is encrypted. */ encrypted: boolean; /** * `0` If the volume is not a provisioned IOPS image, otherwise the supported IOPS count. */ iops: number; kmsKeyId: string; /** * Map of tags assigned to the Instance. */ tags: { [key: string]: string; }; /** * Throughput of the volume, in MiB/s. */ throughput: number; volumeId: string; /** * Size of the volume, in GiB. */ volumeSize: number; /** * Type of the volume. */ volumeType: string; } interface GetInstanceTypeFpga { count: number; manufacturer: string; /** * Size of the instance memory, in MiB. */ memorySize: number; name: string; } interface GetInstanceTypeGpus { count: number; manufacturer: string; /** * Size of the instance memory, in MiB. */ memorySize: number; name: string; } interface GetInstanceTypeInferenceAccelerator { count: number; manufacturer: string; /** * Size of the instance memory, in MiB. */ memorySize: number; name: string; } interface GetInstanceTypeInstanceDisk { count: number; size: number; type: string; } interface GetInstanceTypeMediaAccelerator { count: number; manufacturer: string; /** * Size of the instance memory, in MiB. */ memorySize: number; name: string; } interface GetInstanceTypeNetworkCard { baselineBandwidth: number; index: number; maximumInterfaces: number; peakBandwidth: number; performance: string; } interface GetInstanceTypeNeuronDevice { coreCount: number; coreVersion: number; count: number; /** * Size of the instance memory, in MiB. */ memorySize: number; name: string; } interface GetInstanceTypeOfferingFilter { /** * Name of the filter. The `location` filter depends on the top-level `locationType` argument and if not specified, defaults to the current region. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetInstanceTypeOfferingsFilter { /** * Name of the filter. The `location` filter depends on the top-level `locationType` argument and if not specified, defaults to the current region. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetInstanceTypesFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetInstancesFilter { /** * Name of the filter. * For a full reference of filter names, see [describe-instances in the AWS CLI reference](http://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instances.html). */ name: string; /** * One or more values to match. */ values: string[]; } interface GetInternetGatewayAttachment { /** * Current state of the attachment between the gateway and the VPC. Present only if a VPC is attached */ state: string; /** * ID of an attached VPC. */ vpcId: string; } interface GetInternetGatewayFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInternetGateways.html). */ name: string; /** * Set of values that are accepted for the given field. * An Internet Gateway will be selected if any one of the given values matches. */ values: string[]; } interface GetKeyPairFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeKeyPairs API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeKeyPairs.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetLaunchConfigurationEbsBlockDevice { /** * Whether the EBS Volume will be deleted on instance termination. */ deleteOnTermination: boolean; /** * Name of the device. */ deviceName: string; /** * Whether the volume is Encrypted. */ encrypted: boolean; /** * Provisioned IOPs of the volume. */ iops: number; /** * Whether the device in the block device mapping of the AMI is suppressed. */ noDevice: boolean; /** * Snapshot ID of the mount. */ snapshotId: string; /** * Throughput of the volume. */ throughput: number; /** * Size of the volume. */ volumeSize: number; /** * Type of the volume. */ volumeType: string; } interface GetLaunchConfigurationEphemeralBlockDevice { /** * Name of the device. */ deviceName: string; /** * Virtual Name of the device. */ virtualName: string; } interface GetLaunchConfigurationMetadataOption { /** * State of the metadata service: `enabled`, `disabled`. */ httpEndpoint: string; /** * The desired HTTP PUT response hop limit for instance metadata requests. */ httpPutResponseHopLimit: number; /** * If session tokens are required: `optional`, `required`. */ httpTokens: string; } interface GetLaunchConfigurationRootBlockDevice { /** * Whether the EBS Volume will be deleted on instance termination. */ deleteOnTermination: boolean; /** * Whether the volume is Encrypted. */ encrypted: boolean; /** * Provisioned IOPs of the volume. */ iops: number; /** * Throughput of the volume. */ throughput: number; /** * Size of the volume. */ volumeSize: number; /** * Type of the volume. */ volumeType: string; } interface GetLaunchTemplateBlockDeviceMapping { deviceName: string; ebs: outputs.ec2.GetLaunchTemplateBlockDeviceMappingEb[]; noDevice: string; virtualName: string; } interface GetLaunchTemplateBlockDeviceMappingEb { deleteOnTermination: string; encrypted: string; iops: number; kmsKeyId: string; snapshotId: string; throughput: number; volumeInitializationRate: number; volumeSize: number; volumeType: string; } interface GetLaunchTemplateCapacityReservationSpecification { capacityReservationPreference: string; capacityReservationTargets: outputs.ec2.GetLaunchTemplateCapacityReservationSpecificationCapacityReservationTarget[]; } interface GetLaunchTemplateCapacityReservationSpecificationCapacityReservationTarget { capacityReservationId: string; capacityReservationResourceGroupArn: string; } interface GetLaunchTemplateCpuOption { amdSevSnp: string; coreCount: number; nestedVirtualization: string; threadsPerCore: number; } interface GetLaunchTemplateCreditSpecification { cpuCredits: string; } interface GetLaunchTemplateEnclaveOption { enabled: boolean; } interface GetLaunchTemplateFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeLaunchTemplates API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLaunchTemplates.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetLaunchTemplateHibernationOption { configured: boolean; } interface GetLaunchTemplateIamInstanceProfile { arn: string; /** * Name of the launch template. */ name: string; } interface GetLaunchTemplateInstanceMarketOption { marketType: string; spotOptions: outputs.ec2.GetLaunchTemplateInstanceMarketOptionSpotOption[]; } interface GetLaunchTemplateInstanceMarketOptionSpotOption { blockDurationMinutes: number; instanceInterruptionBehavior: string; maxPrice: string; spotInstanceType: string; validUntil: string; } interface GetLaunchTemplateInstanceRequirement { acceleratorCounts: outputs.ec2.GetLaunchTemplateInstanceRequirementAcceleratorCount[]; acceleratorManufacturers: string[]; acceleratorNames: string[]; acceleratorTotalMemoryMibs: outputs.ec2.GetLaunchTemplateInstanceRequirementAcceleratorTotalMemoryMib[]; acceleratorTypes: string[]; allowedInstanceTypes: string[]; bareMetal: string; baselineEbsBandwidthMbps: outputs.ec2.GetLaunchTemplateInstanceRequirementBaselineEbsBandwidthMbp[]; burstablePerformance: string; cpuManufacturers: string[]; excludedInstanceTypes: string[]; instanceGenerations: string[]; localStorage: string; localStorageTypes: string[]; maxSpotPriceAsPercentageOfOptimalOnDemandPrice: number; memoryGibPerVcpus: outputs.ec2.GetLaunchTemplateInstanceRequirementMemoryGibPerVcpus[]; memoryMibs: outputs.ec2.GetLaunchTemplateInstanceRequirementMemoryMib[]; networkBandwidthGbps: outputs.ec2.GetLaunchTemplateInstanceRequirementNetworkBandwidthGbp[]; networkInterfaceCounts: outputs.ec2.GetLaunchTemplateInstanceRequirementNetworkInterfaceCount[]; onDemandMaxPricePercentageOverLowestPrice: number; requireHibernateSupport: boolean; spotMaxPricePercentageOverLowestPrice: number; totalLocalStorageGbs: outputs.ec2.GetLaunchTemplateInstanceRequirementTotalLocalStorageGb[]; vcpuCounts: outputs.ec2.GetLaunchTemplateInstanceRequirementVcpuCount[]; } interface GetLaunchTemplateInstanceRequirementAcceleratorCount { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementAcceleratorTotalMemoryMib { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementBaselineEbsBandwidthMbp { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementMemoryGibPerVcpus { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementMemoryMib { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementNetworkBandwidthGbp { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementNetworkInterfaceCount { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementTotalLocalStorageGb { max: number; min: number; } interface GetLaunchTemplateInstanceRequirementVcpuCount { max: number; min: number; } interface GetLaunchTemplateLicenseSpecification { licenseConfigurationArn: string; } interface GetLaunchTemplateMaintenanceOption { autoRecovery: string; } interface GetLaunchTemplateMetadataOption { httpEndpoint: string; httpProtocolIpv6: string; httpPutResponseHopLimit: number; httpTokens: string; instanceMetadataTags: string; } interface GetLaunchTemplateMonitoring { enabled: boolean; } interface GetLaunchTemplateNetworkInterface { associateCarrierIpAddress: string; associatePublicIpAddress?: boolean; connectionTrackingSpecifications: outputs.ec2.GetLaunchTemplateNetworkInterfaceConnectionTrackingSpecification[]; deleteOnTermination?: boolean; description: string; deviceIndex: number; enaQueueCount: number; interfaceType: string; ipv4AddressCount: number; ipv4Addresses: string[]; ipv4PrefixCount: number; ipv4Prefixes: string[]; ipv6AddressCount: number; ipv6Addresses: string[]; ipv6PrefixCount: number; ipv6Prefixes: string[]; networkCardIndex: number; networkInterfaceId: string; primaryIpv6: string; privateIpAddress: string; securityGroups: string[]; subnetId: string; } interface GetLaunchTemplateNetworkInterfaceConnectionTrackingSpecification { tcpEstablishedTimeout: number; udpStreamTimeout: number; udpTimeout: number; } interface GetLaunchTemplateNetworkPerformanceOption { bandwidthWeighting: string; } interface GetLaunchTemplatePlacement { affinity: string; availabilityZone: string; groupId: string; groupName: string; hostId: string; hostResourceGroupArn: string; partitionNumber: number; spreadDomain: string; tenancy: string; } interface GetLaunchTemplatePrivateDnsNameOption { enableResourceNameDnsARecord: boolean; enableResourceNameDnsAaaaRecord: boolean; hostnameType: string; } interface GetLaunchTemplateSecondaryInterface { deleteOnTermination: boolean; deviceIndex: number; interfaceType: string; networkCardIndex: number; privateIpAddressCount: number; privateIpAddresses: string[]; secondarySubnetId: string; } interface GetLaunchTemplateTagSpecification { resourceType: string; /** * Map of tags, each pair of which must exactly match a pair on the desired Launch Template. */ tags: { [key: string]: string; }; } interface GetLocalGatewayFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGateways.html). */ name: string; /** * Set of values that are accepted for the given field. * A Local Gateway will be selected if any one of the given values matches. */ values: string[]; } interface GetLocalGatewayRouteTableFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTables.html). */ name: string; /** * Set of values that are accepted for the given field. * A local gateway route table will be selected if any one of the given values matches. */ values: string[]; } interface GetLocalGatewayRouteTablesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTables.html). */ name: string; /** * Set of values that are accepted for the given field. * A Local Gateway Route Table will be selected if any one of the given values matches. */ values: string[]; } interface GetLocalGatewayVirtualInterfaceFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetLocalGatewayVirtualInterfaceGroupFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetLocalGatewayVirtualInterfaceGroupsFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetLocalGatewaysFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGateways.html). */ name: string; /** * Set of values that are accepted for the given field. * A Local Gateway will be selected if any one of the given values matches. */ values: string[]; } interface GetManagedPrefixListEntry { cidr: string; description: string; } interface GetManagedPrefixListFilter { /** * Name of the filter field. Valid values can be found in the EC2 [DescribeManagedPrefixLists](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeManagedPrefixLists.html) API Reference. */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetManagedPrefixListsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeManagedPrefixLists.html). */ name: string; /** * Set of values that are accepted for the given field. * A managed prefix list will be selected if any one of the given values matches. */ values: string[]; } interface GetNatGatewayAvailabilityZoneAddress { /** * List of allocation IDs of the Elastic IP addresses (EIPs) to be used for handling outbound NAT traffic in this specific Availability Zone. */ allocationIds: string[]; /** * Availability Zone where this specific NAT gateway configuration is active. */ availabilityZone: string; /** * Availability Zone ID where this specific NAT gateway configuration is active */ availabilityZoneId: string; } interface GetNatGatewayFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNatGateways.html). */ name: string; /** * Set of values that are accepted for the given field. * An Nat Gateway will be selected if any one of the given values matches. */ values: string[]; } interface GetNatGatewayRegionalNatGatewayAddress { /** * Allocation ID of the Elastic IP address. */ allocationId: string; /** * Association ID of the Elastic IP address. */ associationId: string; /** * Availability Zone where this specific NAT gateway configuration is active. */ availabilityZone: string; /** * Availability Zone ID where this specific NAT gateway configuration is active */ availabilityZoneId: string; /** * ID of the network interface. */ networkInterfaceId: string; /** * Public IP address. */ publicIp: string; /** * Status of the NAT gateway address. */ status: string; } interface GetNatGatewaysFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNatGateways.html). */ name: string; /** * Set of values that are accepted for the given field. * A Nat Gateway will be selected if any one of the given values matches. */ values: string[]; } interface GetNetworkAclsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkAcls.html). */ name: string; /** * Set of values that are accepted for the given field. * A VPC will be selected if any one of the given values matches. */ values: string[]; } interface GetNetworkInsightsAnalysisAlternatePathHint { componentArn: string; componentId: string; } interface GetNetworkInsightsAnalysisExplanation { aclRules: outputs.ec2.GetNetworkInsightsAnalysisExplanationAclRule[]; acls: outputs.ec2.GetNetworkInsightsAnalysisExplanationAcl[]; address: string; addresses: string[]; attachedTos: outputs.ec2.GetNetworkInsightsAnalysisExplanationAttachedTo[]; availabilityZones: string[]; cidrs: string[]; classicLoadBalancerListeners: outputs.ec2.GetNetworkInsightsAnalysisExplanationClassicLoadBalancerListener[]; components: outputs.ec2.GetNetworkInsightsAnalysisExplanationComponent[]; customerGateways: outputs.ec2.GetNetworkInsightsAnalysisExplanationCustomerGateway[]; destinationVpcs: outputs.ec2.GetNetworkInsightsAnalysisExplanationDestinationVpc[]; destinations: outputs.ec2.GetNetworkInsightsAnalysisExplanationDestination[]; direction: string; elasticLoadBalancerListeners: outputs.ec2.GetNetworkInsightsAnalysisExplanationElasticLoadBalancerListener[]; explanationCode: string; ingressRouteTables: outputs.ec2.GetNetworkInsightsAnalysisExplanationIngressRouteTable[]; internetGateways: outputs.ec2.GetNetworkInsightsAnalysisExplanationInternetGateway[]; loadBalancerArn: string; loadBalancerListenerPort: number; loadBalancerTargetGroup: outputs.ec2.GetNetworkInsightsAnalysisExplanationLoadBalancerTargetGroup[]; loadBalancerTargetGroups: outputs.ec2.GetNetworkInsightsAnalysisExplanationLoadBalancerTargetGroup[]; loadBalancerTargetPort: number; missingComponent: string; natGateways: outputs.ec2.GetNetworkInsightsAnalysisExplanationNatGateway[]; networkInterfaces: outputs.ec2.GetNetworkInsightsAnalysisExplanationNetworkInterface[]; packetField: string; port: number; portRanges: outputs.ec2.GetNetworkInsightsAnalysisExplanationPortRange[]; prefixLists: outputs.ec2.GetNetworkInsightsAnalysisExplanationPrefixList[]; protocols: string[]; routeTableRoutes: outputs.ec2.GetNetworkInsightsAnalysisExplanationRouteTableRoute[]; routeTables: outputs.ec2.GetNetworkInsightsAnalysisExplanationRouteTable[]; securityGroup: outputs.ec2.GetNetworkInsightsAnalysisExplanationSecurityGroup[]; securityGroupRules: outputs.ec2.GetNetworkInsightsAnalysisExplanationSecurityGroupRule[]; securityGroups: outputs.ec2.GetNetworkInsightsAnalysisExplanationSecurityGroup[]; sourceVpcs: outputs.ec2.GetNetworkInsightsAnalysisExplanationSourceVpc[]; state: string; subnetRouteTables: outputs.ec2.GetNetworkInsightsAnalysisExplanationSubnetRouteTable[]; subnets: outputs.ec2.GetNetworkInsightsAnalysisExplanationSubnet[]; transitGatewayAttachments: outputs.ec2.GetNetworkInsightsAnalysisExplanationTransitGatewayAttachment[]; transitGatewayRouteTableRoutes: outputs.ec2.GetNetworkInsightsAnalysisExplanationTransitGatewayRouteTableRoute[]; transitGatewayRouteTables: outputs.ec2.GetNetworkInsightsAnalysisExplanationTransitGatewayRouteTable[]; transitGateways: outputs.ec2.GetNetworkInsightsAnalysisExplanationTransitGateway[]; vpcEndpoints: outputs.ec2.GetNetworkInsightsAnalysisExplanationVpcEndpoint[]; vpcPeeringConnections: outputs.ec2.GetNetworkInsightsAnalysisExplanationVpcPeeringConnection[]; vpcs: outputs.ec2.GetNetworkInsightsAnalysisExplanationVpc[]; vpnConnections: outputs.ec2.GetNetworkInsightsAnalysisExplanationVpnConnection[]; vpnGateways: outputs.ec2.GetNetworkInsightsAnalysisExplanationVpnGateway[]; } interface GetNetworkInsightsAnalysisExplanationAcl { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationAclRule { cidr: string; egress: boolean; portRanges: outputs.ec2.GetNetworkInsightsAnalysisExplanationAclRulePortRange[]; protocol: string; ruleAction: string; ruleNumber: number; } interface GetNetworkInsightsAnalysisExplanationAclRulePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisExplanationAttachedTo { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationClassicLoadBalancerListener { instancePort: number; loadBalancerPort: number; } interface GetNetworkInsightsAnalysisExplanationComponent { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationCustomerGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationDestination { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationDestinationVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationElasticLoadBalancerListener { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationIngressRouteTable { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationInternetGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationLoadBalancerTargetGroup { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationNatGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationNetworkInterface { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationPortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisExplanationPrefixList { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationRouteTable { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationRouteTableRoute { destinationCidr: string; destinationPrefixListId: string; egressOnlyInternetGatewayId: string; gatewayId: string; instanceId: string; natGatewayId: string; networkInterfaceId: string; origin: string; transitGatewayId: string; vpcPeeringConnectionId: string; } interface GetNetworkInsightsAnalysisExplanationSecurityGroup { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationSecurityGroupRule { cidr: string; direction: string; portRanges: outputs.ec2.GetNetworkInsightsAnalysisExplanationSecurityGroupRulePortRange[]; prefixListId: string; protocol: string; securityGroupId: string; } interface GetNetworkInsightsAnalysisExplanationSecurityGroupRulePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisExplanationSourceVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationSubnet { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationSubnetRouteTable { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationTransitGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationTransitGatewayAttachment { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationTransitGatewayRouteTable { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationTransitGatewayRouteTableRoute { attachmentId: string; destinationCidr: string; prefixListId: string; resourceId: string; resourceType: string; routeOrigin: string; state: string; } interface GetNetworkInsightsAnalysisExplanationVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationVpcEndpoint { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationVpcPeeringConnection { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationVpnConnection { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisExplanationVpnGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisFilter { /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetNetworkInsightsAnalysisForwardPathComponent { aclRules: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentAclRule[]; additionalDetails: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentAdditionalDetail[]; attachedTos: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentAttachedTo[]; components: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentComponent[]; destinationVpcs: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentDestinationVpc[]; inboundHeaders: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentInboundHeader[]; outboundHeaders: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentOutboundHeader[]; routeTableRoutes: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentRouteTableRoute[]; securityGroupRules: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentSecurityGroupRule[]; sequenceNumber: number; sourceVpcs: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentSourceVpc[]; subnets: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentSubnet[]; transitGatewayRouteTableRoutes: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentTransitGatewayRouteTableRoute[]; transitGateways: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentTransitGateway[]; vpcs: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentVpc[]; } interface GetNetworkInsightsAnalysisForwardPathComponentAclRule { cidr: string; egress: boolean; portRanges: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentAclRulePortRange[]; protocol: string; ruleAction: string; ruleNumber: number; } interface GetNetworkInsightsAnalysisForwardPathComponentAclRulePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisForwardPathComponentAdditionalDetail { additionalDetailType: string; components: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentAdditionalDetailComponent[]; } interface GetNetworkInsightsAnalysisForwardPathComponentAdditionalDetailComponent { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentAttachedTo { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentComponent { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentDestinationVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentInboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentInboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentInboundHeaderSourcePortRange[]; } interface GetNetworkInsightsAnalysisForwardPathComponentInboundHeaderDestinationPortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisForwardPathComponentInboundHeaderSourcePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisForwardPathComponentOutboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentOutboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentOutboundHeaderSourcePortRange[]; } interface GetNetworkInsightsAnalysisForwardPathComponentOutboundHeaderDestinationPortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisForwardPathComponentOutboundHeaderSourcePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisForwardPathComponentRouteTableRoute { destinationCidr: string; destinationPrefixListId: string; egressOnlyInternetGatewayId: string; gatewayId: string; instanceId: string; natGatewayId: string; networkInterfaceId: string; origin: string; transitGatewayId: string; vpcPeeringConnectionId: string; } interface GetNetworkInsightsAnalysisForwardPathComponentSecurityGroupRule { cidr: string; direction: string; portRanges: outputs.ec2.GetNetworkInsightsAnalysisForwardPathComponentSecurityGroupRulePortRange[]; prefixListId: string; protocol: string; securityGroupId: string; } interface GetNetworkInsightsAnalysisForwardPathComponentSecurityGroupRulePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisForwardPathComponentSourceVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentSubnet { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentTransitGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisForwardPathComponentTransitGatewayRouteTableRoute { attachmentId: string; destinationCidr: string; prefixListId: string; resourceId: string; resourceType: string; routeOrigin: string; state: string; } interface GetNetworkInsightsAnalysisForwardPathComponentVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponent { aclRules: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentAclRule[]; additionalDetails: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentAdditionalDetail[]; attachedTos: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentAttachedTo[]; components: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentComponent[]; destinationVpcs: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentDestinationVpc[]; inboundHeaders: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentInboundHeader[]; outboundHeaders: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentOutboundHeader[]; routeTableRoutes: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentRouteTableRoute[]; securityGroupRules: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentSecurityGroupRule[]; sequenceNumber: number; sourceVpcs: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentSourceVpc[]; subnets: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentSubnet[]; transitGatewayRouteTableRoutes: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentTransitGatewayRouteTableRoute[]; transitGateways: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentTransitGateway[]; vpcs: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentVpc[]; } interface GetNetworkInsightsAnalysisReturnPathComponentAclRule { cidr: string; egress: boolean; portRanges: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentAclRulePortRange[]; protocol: string; ruleAction: string; ruleNumber: number; } interface GetNetworkInsightsAnalysisReturnPathComponentAclRulePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisReturnPathComponentAdditionalDetail { additionalDetailType: string; components: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentAdditionalDetailComponent[]; } interface GetNetworkInsightsAnalysisReturnPathComponentAdditionalDetailComponent { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentAttachedTo { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentComponent { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentDestinationVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentInboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentInboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentInboundHeaderSourcePortRange[]; } interface GetNetworkInsightsAnalysisReturnPathComponentInboundHeaderDestinationPortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisReturnPathComponentInboundHeaderSourcePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisReturnPathComponentOutboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentOutboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentOutboundHeaderSourcePortRange[]; } interface GetNetworkInsightsAnalysisReturnPathComponentOutboundHeaderDestinationPortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisReturnPathComponentOutboundHeaderSourcePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisReturnPathComponentRouteTableRoute { destinationCidr: string; destinationPrefixListId: string; egressOnlyInternetGatewayId: string; gatewayId: string; instanceId: string; natGatewayId: string; networkInterfaceId: string; origin: string; transitGatewayId: string; vpcPeeringConnectionId: string; } interface GetNetworkInsightsAnalysisReturnPathComponentSecurityGroupRule { cidr: string; direction: string; portRanges: outputs.ec2.GetNetworkInsightsAnalysisReturnPathComponentSecurityGroupRulePortRange[]; prefixListId: string; protocol: string; securityGroupId: string; } interface GetNetworkInsightsAnalysisReturnPathComponentSecurityGroupRulePortRange { from: number; to: number; } interface GetNetworkInsightsAnalysisReturnPathComponentSourceVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentSubnet { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentTransitGateway { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsAnalysisReturnPathComponentTransitGatewayRouteTableRoute { attachmentId: string; destinationCidr: string; prefixListId: string; resourceId: string; resourceType: string; routeOrigin: string; state: string; } interface GetNetworkInsightsAnalysisReturnPathComponentVpc { /** * ARN of the selected Network Insights Analysis. */ arn: string; id: string; /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsAnalyses`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) API Reference. */ name: string; } interface GetNetworkInsightsPathFilter { /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeNetworkInsightsPaths`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsPaths.html) API Reference. */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetNetworkInsightsPathFilterAtDestination { destinationAddress: string; destinationPortRanges: outputs.ec2.GetNetworkInsightsPathFilterAtDestinationDestinationPortRange[]; sourceAddress: string; sourcePortRanges: outputs.ec2.GetNetworkInsightsPathFilterAtDestinationSourcePortRange[]; } interface GetNetworkInsightsPathFilterAtDestinationDestinationPortRange { fromPort: number; toPort: number; } interface GetNetworkInsightsPathFilterAtDestinationSourcePortRange { fromPort: number; toPort: number; } interface GetNetworkInsightsPathFilterAtSource { destinationAddress: string; destinationPortRanges: outputs.ec2.GetNetworkInsightsPathFilterAtSourceDestinationPortRange[]; sourceAddress: string; sourcePortRanges: outputs.ec2.GetNetworkInsightsPathFilterAtSourceSourcePortRange[]; } interface GetNetworkInsightsPathFilterAtSourceDestinationPortRange { fromPort: number; toPort: number; } interface GetNetworkInsightsPathFilterAtSourceSourcePortRange { fromPort: number; toPort: number; } interface GetNetworkInterfaceAssociation { /** * Allocation ID. */ allocationId: string; /** * Association ID. */ associationId: string; /** * Carrier IP address associated with the network interface. This attribute is only set when the network interface is in a subnet which is associated with a Wavelength Zone. */ carrierIp: string; /** * Customer-owned IP address. */ customerOwnedIp: string; /** * ID of the Elastic IP address owner. */ ipOwnerId: string; /** * Public DNS name. */ publicDnsName: string; /** * Address of the Elastic IP address bound to the network interface. */ publicIp: string; } interface GetNetworkInterfaceAttachment { /** * ID of the network interface attachment. */ attachmentId: string; /** * Device index of the network interface attachment on the instance. */ deviceIndex: number; /** * ID of the instance. */ instanceId: string; /** * AWS account ID of the owner of the instance. */ instanceOwnerId: string; /** * Index of the network card. */ networkCardIndex: number; } interface GetNetworkInterfaceEnaSrdSpecification { /** * Whether ENA Express is enabled for the network interface. */ enaSrdEnabled: boolean; /** * ENA Express UDP configuration. See below. */ enaSrdUdpSpecifications: outputs.ec2.GetNetworkInterfaceEnaSrdSpecificationEnaSrdUdpSpecification[]; } interface GetNetworkInterfaceEnaSrdSpecificationEnaSrdUdpSpecification { /** * Whether UDP traffic uses ENA Express. */ enaSrdUdpEnabled: boolean; } interface GetNetworkInterfaceFilter { name: string; values: string[]; } interface GetNetworkInterfacesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfaces.html). */ name: string; /** * Set of values that are accepted for the given field. */ values: string[]; } interface GetPrefixListFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribePrefixLists API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePrefixLists.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetPublicIpv4PoolPoolAddressRange { /** * Number of addresses in the range. */ addressCount: number; /** * Number of available addresses in the range. */ availableAddressCount: number; /** * First address in the range. */ firstAddress: string; /** * Last address in the range. */ lastAddress: string; } interface GetPublicIpv4PoolsFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePublicIpv4Pools.html). */ name: string; /** * Set of values that are accepted for the given field. Pool IDs will be selected if any one of the given values match. */ values: string[]; } interface GetRouteTableAssociation { /** * ID of an Internet Gateway or Virtual Private Gateway which is connected to the Route Table (not exported if not passed as a parameter). */ gatewayId: string; /** * Whether the association is due to the main route table. */ main: boolean; /** * Association ID. */ routeTableAssociationId: string; /** * ID of the specific Route Table to retrieve. */ routeTableId: string; /** * ID of a Subnet which is connected to the Route Table (not exported if not passed as a parameter). */ subnetId: string; } interface GetRouteTableFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteTables.html). */ name: string; /** * Set of values that are accepted for the given field. A Route Table will be selected if any one of the given values matches. */ values: string[]; } interface GetRouteTableRoute { /** * ID of the Carrier Gateway. */ carrierGatewayId: string; /** * CIDR block of the route. */ cidrBlock: string; /** * ARN of the core network. */ coreNetworkArn: string; /** * The ID of a managed prefix list destination of the route. */ destinationPrefixListId: string; /** * ID of the Egress Only Internet Gateway. */ egressOnlyGatewayId: string; /** * ID of an Internet Gateway or Virtual Private Gateway which is connected to the Route Table (not exported if not passed as a parameter). */ gatewayId: string; /** * EC2 instance ID. */ instanceId: string; /** * IPv6 CIDR block of the route. */ ipv6CidrBlock: string; /** * Local Gateway ID. */ localGatewayId: string; /** * NAT Gateway ID. */ natGatewayId: string; /** * ID of the elastic network interface (eni) to use. */ networkInterfaceId: string; /** * ARN of the ODB network. */ odbNetworkArn: string; /** * EC2 Transit Gateway ID. */ transitGatewayId: string; /** * VPC Endpoint ID. */ vpcEndpointId: string; /** * VPC Peering ID. */ vpcPeeringConnectionId: string; } interface GetRouteTablesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteTables.html). */ name: string; /** * Set of values that are accepted for the given field. * A Route Table will be selected if any one of the given values matches. */ values: string[]; } interface GetSecurityGroupFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroups.html). */ name: string; /** * Set of values that are accepted for the given field. * A Security Group will be selected if any one of the given values matches. */ values: string[]; } interface GetSecurityGroupsFilter { name: string; values: string[]; } interface GetServiceLinkVirtualInterfaceFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetServiceLinkVirtualInterfacesFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetSpotPriceFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetSubnetFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSubnets.html). */ name: string; /** * Set of values that are accepted for the given field. A subnet will be selected if any one of the given values matches. */ values: string[]; } interface GetSubnetsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSubnets.html). * For example, if matching against tag `Name`, use: */ name: string; /** * Set of values that are accepted for the given field. * Subnet IDs will be selected if any one of the given values match. */ values: string[]; } interface GetTransitGatewayRouteTablesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayRouteTables.html). */ name: string; /** * Set of values that are accepted for the given field. * A Transit Gateway Route Table will be selected if any one of the given values matches. */ values: string[]; } interface GetVpcCidrBlockAssociation { /** * Association ID for the IPv4 CIDR block. */ associationId: string; /** * CIDR block of the desired VPC. */ cidrBlock: string; /** * Current state of the desired VPC. Can be either `"pending"` or `"available"`. */ state: string; } interface GetVpcDhcpOptionsFilter { /** * Name of the field to filter. */ name: string; /** * Set of values for filtering. * * For more information about filtering, see the [EC2 API documentation](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeDhcpOptions.html). */ values: string[]; } interface GetVpcEndpointDnsEntry { /** * DNS name. */ dnsName: string; /** * ID of the private hosted zone. */ hostedZoneId: string; } interface GetVpcEndpointDnsOption { /** * The DNS records created for the endpoint. */ dnsRecordIpType: string; /** * Indicates whether to enable private DNS only for inbound endpoints. */ privateDnsOnlyForInboundResolverEndpoint: boolean; /** * Preference for which private domains have a private hosted zone created for and associated with the specified VPC. */ privateDnsPreference: string; /** * List of private domains to create private hosted zones for and associate with the specified VPC. */ privateDnsSpecifiedDomains: string[]; } interface GetVpcEndpointFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpoints.html). */ name: string; /** * Set of values that are accepted for the given field. * A VPC Endpoint will be selected if any one of the given values matches. */ values: string[]; } interface GetVpcEndpointServiceFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeVpcEndpointServices API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServices.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetVpcFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcs.html). */ name: string; /** * Set of values that are accepted for the given field. A VPC will be selected if any one of the given values matches. */ values: string[]; } interface GetVpcIpamOperatingRegion { regionName: string; } interface GetVpcIpamPoolCidrsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPoolCidrs.html). */ name: string; /** * Set of values that are accepted for the given field. */ values: string[]; } interface GetVpcIpamPoolCidrsIpamPoolCidr { /** * A network CIDR. */ cidr: string; /** * The provisioning state of that CIDR. */ state: string; } interface GetVpcIpamPoolFilter { /** * The name of the filter. Filter names are case-sensitive. */ name: string; /** * The filter values. Filter values are case-sensitive. */ values: string[]; } interface GetVpcIpamPoolSourceResource { /** * (Required) ID of the resource. */ resourceId: string; /** * (Required) Owner of the resource. */ resourceOwner: string; /** * (Required) Region where the resource exists. Must match the `locale` of the parent IPAM Pool. */ resourceRegion: string; /** * (Required) Type of the resource. (`vpc`) */ resourceType: string; } interface GetVpcIpamPoolsFilter { /** * The name of the filter. Filter names are case-sensitive. */ name: string; /** * The filter values. Filter values are case-sensitive. */ values: string[]; } interface GetVpcIpamPoolsIpamPool { /** * IP protocol assigned to this pool. */ addressFamily: string; /** * A default netmask length for allocations added to this pool. If, for example, the CIDR assigned to this pool is `10.0.0.0/8` and you enter 16 here, new allocations will default to `10.0.0.0/16`. */ allocationDefaultNetmaskLength: number; /** * The maximum netmask length that will be required for CIDR allocations in this pool. */ allocationMaxNetmaskLength: number; /** * The minimum netmask length that will be required for CIDR allocations in this pool. */ allocationMinNetmaskLength: number; /** * Tags that are required to create resources in using this pool. */ allocationResourceTags: { [key: string]: string; }; /** * ARN of the pool */ arn: string; /** * If enabled, IPAM will continuously look for resources within the CIDR range of this pool and automatically import them as allocations into your IPAM. */ autoImport: boolean; /** * Limits which service in AWS that the pool can be used in. `ec2` for example, allows users to use space for Elastic IP addresses and VPCs. */ awsService: string; /** * Description for the IPAM pool. */ description: string; /** * ID of the IPAM pool. */ id: string; /** * ID of the scope the pool belongs to. */ ipamScopeId: string; ipamScopeType: string; /** * Locale is the Region where your pool is available for allocations. You can only create pools with locales that match the operating Regions of the IPAM. You can only create VPCs from a pool whose locale matches the VPC's Region. */ locale: string; poolDepth: number; /** * Defines whether or not IPv6 pool space is publicly advertisable over the internet. */ publiclyAdvertisable: boolean; /** * ID of the source IPAM pool. */ sourceIpamPoolId: string; state: string; /** * Map of tags to assigned to the resource. */ tags: { [key: string]: string; }; } interface GetVpcIpamsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpams.html). */ name: string; /** * Set of values that are accepted for the given field. * An IPAM resource will be selected if any one of the given values matches. */ values: string[]; } interface GetVpcIpamsIpam { /** * ARN of the IPAM. */ arn: string; /** * The default resource discovery association ID. */ defaultResourceDiscoveryAssociationId: string; /** * The default resource discovery ID. */ defaultResourceDiscoveryId: string; /** * Description for the IPAM. */ description: string; /** * If private GUA is enabled. */ enablePrivateGua: boolean; /** * ID of the IPAM resource. */ id: string; /** * Region that the IPAM exists in. */ ipamRegion: string; meteredAccount: string; /** * Regions that the IPAM is configured to operate in. */ operatingRegions: outputs.ec2.GetVpcIpamsIpamOperatingRegion[]; /** * ID of the account that owns this IPAM. */ ownerId: string; /** * ID of the default private scope. */ privateDefaultScopeId: string; /** * ID of the default public scope. */ publicDefaultScopeId: string; /** * Number of resource discovery associations. */ resourceDiscoveryAssociationCount: number; /** * Number of scopes on this IPAM. */ scopeCount: number; /** * Current state of the IPAM. */ state: string; /** * State message of the IPAM. */ stateMessage: string; /** * IPAM Tier. */ tier: string; } interface GetVpcIpamsIpamOperatingRegion { regionName: string; } interface GetVpcIpv6CidrBlockAssociation { /** * Association ID for the IPv4 CIDR block. */ associationId: string; /** * Source that allocated the IP address space. Values: `amazon`, `byoip`, `none`. */ ipSource: string; /** * Whether the address is `public` or `private`. */ ipv6AddressAttribute: string; /** * IPv6 CIDR block for the association. */ ipv6CidrBlock: string; /** * Name of IPv6 address pool from which the IPv6 CIDR block is allocated. */ ipv6Pool: string; /** * Name of association's network border group. */ networkBorderGroup: string; /** * Current state of the desired VPC. Can be either `"pending"` or `"available"`. */ state: string; } interface GetVpcPeeringConnectionCidrBlockSet { /** * Primary CIDR block of the requester VPC of the specific VPC Peering Connection to retrieve. */ cidrBlock: string; } interface GetVpcPeeringConnectionFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcPeeringConnections.html). */ name: string; /** * Set of values that are accepted for the given field. * A VPC Peering Connection will be selected if any one of the given values matches. */ values: string[]; } interface GetVpcPeeringConnectionIpv6CidrBlockSet { ipv6CidrBlock: string; } interface GetVpcPeeringConnectionPeerCidrBlockSet { /** * Primary CIDR block of the requester VPC of the specific VPC Peering Connection to retrieve. */ cidrBlock: string; } interface GetVpcPeeringConnectionPeerIpv6CidrBlockSet { ipv6CidrBlock: string; } interface GetVpcPeeringConnectionsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcPeeringConnections.html). */ name: string; /** * Set of values that are accepted for the given field. * A VPC Peering Connection will be selected if any one of the given values matches. */ values: string[]; } interface GetVpcsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcs.html). */ name: string; /** * Set of values that are accepted for the given field. * A VPC will be selected if any one of the given values matches. */ values: string[]; } interface GetVpnConnectionFilter { /** * Name of the filter field. Valid values can be found in the [EC2 `DescribeVPNConnections` API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnConnections.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetVpnConnectionRoute { destinationCidrBlock: string; source: string; /** * Current state of the VPN connection. */ state: string; } interface GetVpnConnectionVgwTelemetry { acceptedRouteCount: number; lastStatusChange: string; outsideIpAddress: string; status: string; statusMessage: string; } interface GetVpnGatewayFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](http://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnGateways.html). */ name: string; /** * Set of values that are accepted for the given field. * A VPN Gateway will be selected if any one of the given values matches. */ values: string[]; } interface InstanceCapacityReservationSpecification { /** * Indicates the instance's Capacity Reservation preferences. Can be `"open"` or `"none"`. (Default: `"open"`). */ capacityReservationPreference?: string; /** * Information about the target Capacity Reservation. See Capacity Reservation Target below for more details. * * For more information, see the documentation on [Capacity Reservations](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/capacity-reservations-using.html). */ capacityReservationTarget?: outputs.ec2.InstanceCapacityReservationSpecificationCapacityReservationTarget; } interface InstanceCapacityReservationSpecificationCapacityReservationTarget { /** * ID of the Capacity Reservation in which to run the instance. */ capacityReservationId?: string; /** * ARN of the Capacity Reservation resource group in which to run the instance. */ capacityReservationResourceGroupArn?: string; } interface InstanceCpuOptions { /** * Indicates whether to enable the instance for AMD SEV-SNP. AMD SEV-SNP is supported with M6a, R6a, and C6a instance types only. Valid values are `enabled` and `disabled`. */ amdSevSnp: string; /** * Sets the number of CPU cores for an instance. This option is only supported on creation of instance type that support CPU Options [CPU Cores and Threads Per CPU Core Per Instance Type](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html#cpu-options-supported-instances-values) - specifying this option for unsupported instance types will return an error from the EC2 API. */ coreCount: number; /** * Indicates whether to enable the instance for nested virtualization. Nested virtualization is supported on 8th generation Intel-based instance types (C8i, M8i, R8i, and their flex variants) only. When nested virtualization is enabled, Virtual Secure Mode (VSM) is automatically disabled for the instance. Valid values are `enabled` and `disabled`. */ nestedVirtualization: string; /** * If set to 1, hyperthreading is disabled on the launched instance. Defaults to 2 if not set. See [Optimizing CPU Options](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html) for more information. * * For more information, see the documentation on [Optimizing CPU options](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html). */ threadsPerCore: number; } interface InstanceCreditSpecification { /** * Credit option for CPU usage. Valid values include `standard` or `unlimited`. T3 instances are launched as unlimited by default. T2 instances are launched as standard by default. */ cpuCredits?: string; } interface InstanceEbsBlockDevice { /** * Whether the volume should be destroyed on instance termination. Defaults to `true`. */ deleteOnTermination?: boolean; /** * Name of the device to mount. */ deviceName: string; /** * Enables [EBS encryption](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html) on the volume. Defaults to `false`. Cannot be used with `snapshotId`. Must be configured to perform drift detection. */ encrypted: boolean; /** * Amount of provisioned [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). Only valid for volumeType of `io1`, `io2` or `gp3`. */ iops: number; /** * ARN of the KMS Key to use when encrypting the volume. Must be configured to perform drift detection. */ kmsKeyId: string; /** * Snapshot ID to mount. */ snapshotId: string; /** * Map of tags to assign to the device. **Note:** Tags specified here are applied after instance creation via a separate API call. This means they cannot be used with IAM policies that require tags during resource creation (e.g., ABAC policies with `ec2:CreateAction` conditions or SCPs requiring volume tags). For ABAC compliance, use `volumeTags` instead, which applies uniform tags to all volumes during instance creation. */ tags?: { [key: string]: string; }; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll: { [key: string]: string; }; /** * Throughput to provision for a volume in mebibytes per second (MiB/s). This is only valid for `volumeType` of `gp3`. */ throughput: number; /** * ID of the volume. For example, the ID can be accessed like this, `aws_instance.web.root_block_device.0.volume_id`. */ volumeId: string; /** * Size of the volume in gibibytes (GiB). */ volumeSize: number; /** * Type of volume. Valid values include `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1`, or `st1`. Defaults to `gp2`. * * > **NOTE:** Currently, changes to the `ebsBlockDevice` configuration of _existing_ resources cannot be automatically detected by this provider. To manage changes and attachments of an EBS block to an instance, use the `aws.ebs.Volume` and `aws.ec2.VolumeAttachment` resources instead. If you use `ebsBlockDevice` on an `aws.ec2.Instance`, this provider will assume management over the full set of non-root EBS block devices for the instance, treating additional block devices as drift. For this reason, `ebsBlockDevice` cannot be mixed with external `aws.ebs.Volume` and `aws.ec2.VolumeAttachment` resources for a given instance. */ volumeType: string; } interface InstanceEnclaveOptions { /** * Whether Nitro Enclaves will be enabled on the instance. Defaults to `false`. * * For more information, see the documentation on [Nitro Enclaves](https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html). */ enabled: boolean; } interface InstanceEphemeralBlockDevice { /** * Name of the block device to mount on the instance. */ deviceName: string; /** * Suppresses the specified device included in the AMI's block device mapping. */ noDevice?: boolean; /** * [Instance Store Device Name](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html#InstanceStoreDeviceNames) (e.g., `ephemeral0`). * * Each AWS Instance type has a different set of Instance Store block devices available for attachment. AWS [publishes a list](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html#StorageOnInstanceTypes) of which ephemeral devices are available on each type. The devices are always identified by the `virtualName` in the format `ephemeral{0..N}`. */ virtualName?: string; } interface InstanceInstanceMarketOptions { /** * Type of market for the instance. Valid values are `spot`, `capacity-block`, and `interruptible-capacity-reservation`. Use `interruptible-capacity-reservation` to launch instances into [interruptible Capacity Reservations](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/capacity-consumer-procedures.html). Defaults to `spot`. Required if `spotOptions` is specified. */ marketType: string; /** * Block to configure the options for Spot Instances. See Spot Options below for details on attributes. */ spotOptions: outputs.ec2.InstanceInstanceMarketOptionsSpotOptions; } interface InstanceInstanceMarketOptionsSpotOptions { /** * The behavior when a Spot Instance is interrupted. Valid values include `hibernate`, `stop`, `terminate` . The default is `terminate`. */ instanceInterruptionBehavior: string; /** * The maximum hourly price that you're willing to pay for a Spot Instance. */ maxPrice: string; /** * The Spot Instance request type. Valid values include `one-time`, `persistent`. Persistent Spot Instance requests are only supported when the instance interruption behavior is either hibernate or stop. The default is `one-time`. */ spotInstanceType: string; /** * The end date of the request, in UTC format (YYYY-MM-DDTHH:MM:SSZ). Supported only for persistent requests. */ validUntil: string; } interface InstanceLaunchTemplate { /** * ID of the launch template. Conflicts with `name`. */ id: string; /** * Name of the launch template. Conflicts with `id`. */ name: string; /** * Template version. Can be a specific version number, `$Latest` or `$Default`. The default value is `$Default`. */ version?: string; } interface InstanceMaintenanceOptions { /** * Automatic recovery behavior of the Instance. Can be `"default"` or `"disabled"`. See [Recover your instance](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-recover.html) for more details. */ autoRecovery: string; } interface InstanceMetadataOptions { /** * Whether the metadata service is available. Valid values include `enabled` or `disabled`. Defaults to `enabled`. */ httpEndpoint?: string; /** * Whether the IPv6 endpoint for the instance metadata service is enabled. Defaults to `disabled`. */ httpProtocolIpv6?: string; /** * Desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel. Valid values are integer from `1` to `64`. Defaults to `1`. */ httpPutResponseHopLimit: number; /** * Whether or not the metadata service requires session tokens, also referred to as _Instance Metadata Service Version 2 (IMDSv2)_. Valid values include `optional` or `required`. */ httpTokens: string; /** * Enables or disables access to instance tags from the instance metadata service. Valid values include `enabled` or `disabled`. Defaults to `disabled`. * * For more information, see the documentation on the [Instance Metadata Service](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html). */ instanceMetadataTags: string; } interface InstanceNetworkInterface { /** * Whether or not to delete the network interface on instance termination. Defaults to `false`. Currently, the only valid value is `false`, as this is only supported when creating new network interfaces when launching an instance. */ deleteOnTermination?: boolean; /** * Integer index of the network interface attachment. Limited by instance type. */ deviceIndex: number; /** * Integer index of the network card. Limited by instance type. The default index is `0`. */ networkCardIndex?: number; /** * ID of the network interface to attach. */ networkInterfaceId: string; } interface InstancePrimaryNetworkInterface { /** * Whether the network interface will be deleted when the instance terminates. */ deleteOnTermination: boolean; /** * ID of the network interface to attach. */ networkInterfaceId: string; } interface InstancePrivateDnsNameOptions { /** * Indicates whether to respond to DNS queries for instance hostnames with DNS A records. */ enableResourceNameDnsARecord: boolean; /** * Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records. */ enableResourceNameDnsAaaaRecord: boolean; /** * Type of hostname for Amazon EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 native subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID. Valid values: `ip-name` and `resource-name`. */ hostnameType: string; } interface InstanceRootBlockDevice { /** * Whether the volume should be destroyed on instance termination. Defaults to `true`. */ deleteOnTermination?: boolean; /** * Device name, e.g., `/dev/sdh` or `xvdh`. */ deviceName: string; /** * Whether to enable volume encryption. Defaults to `false`. Must be configured to perform drift detection. */ encrypted: boolean; /** * Amount of provisioned [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). Only valid for volumeType of `io1`, `io2` or `gp3`. */ iops: number; /** * ARN of the KMS Key to use when encrypting the volume. Must be configured to perform drift detection. */ kmsKeyId: string; /** * Map of tags to assign to the device. **Note:** Tags specified here are applied after instance creation via a separate API call. This means they cannot be used with IAM policies that require tags during resource creation (e.g., ABAC policies with `ec2:CreateAction` conditions or SCPs requiring volume tags). For ABAC compliance, use `volumeTags` instead, which applies uniform tags to all volumes during instance creation. */ tags?: { [key: string]: string; }; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll: { [key: string]: string; }; /** * Throughput to provision for a volume in mebibytes per second (MiB/s). This is only valid for `volumeType` of `gp3`. */ throughput: number; /** * ID of the volume. For example, the ID can be accessed like this, `aws_instance.web.root_block_device.0.volume_id`. */ volumeId: string; /** * Size of the volume in gibibytes (GiB). */ volumeSize: number; /** * Type of volume. Valid values include `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1`, or `st1`. Defaults to the volume type that the AMI uses. * * Modifying the `encrypted` or `kmsKeyId` settings of the `rootBlockDevice` requires resource replacement. */ volumeType: string; } interface InstanceSecondaryNetworkInterface { /** * Whether the network interface should be destroyed when the instance is terminated. Defaults to `true`. Forces replacement. */ deleteOnTermination?: boolean; /** * Device index for the network interface attachment. Defaults to `0`. Forces replacement. */ deviceIndex?: number; /** * Type of network interface. Currently only `secondary` is supported. Defaults to `secondary`. Forces replacement. */ interfaceType?: string; macAddress: string; /** * Network card index for the interface. Each network card can have one secondary interface. Forces replacement. */ networkCardIndex: number; /** * Number of private IP addresses to assign to the network interface. Defaults to `1`. Forces replacement. */ privateIpAddressCount?: number; /** * List of private IP addresses to assign to the network interface. If not specified, AWS will automatically assign IP addresses based on `privateIpAddressCount`. Forces replacement. */ privateIpAddresses: string[]; secondaryInterfaceId: string; secondaryNetworkId: string; /** * ID of the secondary subnet in which to create the network interface. Forces replacement. */ secondarySubnetId: string; /** * Controls if traffic is routed to the instance when the destination address does not match the instance. Used for NAT or VPNs. Defaults true. */ sourceDestCheck: boolean; status: string; } interface LaunchConfigurationEbsBlockDevice { /** * Whether the volume should be destroyed * on instance termination (Default: `true`). */ deleteOnTermination?: boolean; /** * The name of the device to mount. */ deviceName: string; /** * Whether the volume should be encrypted or not. Defaults to `false`. */ encrypted: boolean; /** * The amount of provisioned * [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). * This must be set with a `volumeType` of `"io1"`. */ iops: number; /** * Whether the device in the block device mapping of the AMI is suppressed. */ noDevice?: boolean; /** * The Snapshot ID to mount. */ snapshotId: string; /** * The throughput (MiBps) to provision for a `gp3` volume. */ throughput: number; /** * The size of the volume in gigabytes. */ volumeSize: number; /** * The type of volume. Can be `standard`, `gp2`, `gp3`, `st1`, `sc1` or `io1`. */ volumeType: string; } interface LaunchConfigurationEphemeralBlockDevice { /** * The name of the block device to mount on the instance. */ deviceName: string; /** * Whether the device in the block device mapping of the AMI is suppressed. */ noDevice?: boolean; /** * The [Instance Store Device Name](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html#InstanceStoreDeviceNames). */ virtualName?: string; } interface LaunchConfigurationMetadataOptions { /** * The state of the metadata service: `enabled`, `disabled`. */ httpEndpoint: string; /** * The desired HTTP PUT response hop limit for instance metadata requests. */ httpPutResponseHopLimit: number; /** * If session tokens are required: `optional`, `required`. */ httpTokens: string; } interface LaunchConfigurationRootBlockDevice { /** * Whether the volume should be destroyed on instance termination. Defaults to `true`. */ deleteOnTermination?: boolean; /** * Whether the volume should be encrypted or not. Defaults to `false`. */ encrypted: boolean; /** * The amount of provisioned [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). This must be set with a `volumeType` of `io1`. */ iops: number; /** * The throughput (MiBps) to provision for a `gp3` volume. */ throughput: number; /** * The size of the volume in gigabytes. */ volumeSize: number; /** * The type of volume. Can be `standard`, `gp2`, `gp3`, `st1`, `sc1` or `io1`. */ volumeType: string; } interface LaunchTemplateBlockDeviceMapping { /** * The name of the device to mount. */ deviceName?: string; /** * Configure EBS volume properties. */ ebs?: outputs.ec2.LaunchTemplateBlockDeviceMappingEbs; /** * Suppresses the specified device included in the AMI's block device mapping. */ noDevice?: string; /** * The [Instance Store Device * Name](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html#InstanceStoreDeviceNames) * (e.g., `"ephemeral0"`). */ virtualName?: string; } interface LaunchTemplateBlockDeviceMappingEbs { /** * Whether the volume should be destroyed on instance termination. * See [Preserving Amazon EBS Volumes on Instance Termination](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/preserving-volumes-on-termination.html) for more information. */ deleteOnTermination?: string; /** * Enables [EBS encryption](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html) on the volume. * Cannot be used with `snapshotId`. */ encrypted?: string; /** * The amount of provisioned [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). * This must be set with a `volumeType` of `"io1/io2/gp3"`. */ iops: number; /** * Identifier (key ID, key alias, key ARN, or alias ARN) of the customer managed KMS key to use for EBS encryption. * `encrypted` must be set to `true` when this is set. */ kmsKeyId?: string; /** * The Snapshot ID to mount. */ snapshotId?: string; /** * The throughput to provision for a `gp3` volume in MiB/s (specified as an integer, e.g., 500), with a maximum of 1,000 MiB/s. */ throughput: number; /** * The volume initialization rate in MiB/s (specified as an integer, e.g. 100), with a minimum of 100 MiB/s and maximum of 300 MiB/s. */ volumeInitializationRate: number; /** * The size of the volume in gigabytes. */ volumeSize: number; /** * The volume type. * Can be one of `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1` or `st1`. */ volumeType: string; } interface LaunchTemplateCapacityReservationSpecification { /** * Indicates the instance's Capacity Reservation preferences. Can be `capacity-reservations-only`, `open` or `none`. If `capacityReservationId` or `capacityReservationResourceGroupArn` is specified in `capacityReservationTarget` block, either omit `capacityReservationPreference` or set it to `capacity-reservations-only`. */ capacityReservationPreference?: string; /** * Used to target a specific Capacity Reservation: */ capacityReservationTarget?: outputs.ec2.LaunchTemplateCapacityReservationSpecificationCapacityReservationTarget; } interface LaunchTemplateCapacityReservationSpecificationCapacityReservationTarget { /** * The ID of the Capacity Reservation in which to run the instance. */ capacityReservationId?: string; /** * The ARN of the Capacity Reservation resource group in which to run the instance. */ capacityReservationResourceGroupArn?: string; } interface LaunchTemplateCpuOptions { /** * Indicates whether to enable the instance for AMD SEV-SNP. AMD SEV-SNP is supported with M6a, R6a, and C6a instance types only. Valid values are `enabled` and `disabled`. */ amdSevSnp?: string; /** * The number of CPU cores for the instance. */ coreCount?: number; /** * Indicates whether to enable the instance for nested virtualization. Nested virtualization is supported on 8th generation Intel-based instance types (C8i, M8i, R8i, and their flex variants) only. When nested virtualization is enabled, Virtual Secure Mode (VSM) is automatically disabled for the instance. Valid values are `enabled` and `disabled`. */ nestedVirtualization?: string; /** * The number of threads per CPU core. * To disable Intel Hyper-Threading Technology for the instance, specify a value of 1. * Otherwise, specify the default value of 2. * * Both number of CPU cores and threads per core must be specified. Valid number of CPU cores and threads per core for the instance type can be found in the [CPU Options Documentation](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html?shortFooter=true#cpu-options-supported-instances-values) */ threadsPerCore?: number; } interface LaunchTemplateCreditSpecification { /** * The credit option for CPU usage. * Can be `standard` or `unlimited`. * T3 instances are launched as `unlimited` by default. * T2 instances are launched as `standard` by default. */ cpuCredits?: string; } interface LaunchTemplateEnclaveOptions { /** * If set to `true`, Nitro Enclaves will be enabled on the instance. * * For more information, see the documentation on [Nitro Enclaves](https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html). */ enabled?: boolean; } interface LaunchTemplateHibernationOptions { /** * If set to `true`, the launched EC2 instance will hibernation enabled. */ configured: boolean; } interface LaunchTemplateIamInstanceProfile { /** * ARN of the instance profile. Conflicts with `name`. */ arn?: string; /** * The name of the instance profile. */ name?: string; } interface LaunchTemplateInstanceMarketOptions { /** * The market type. Can be `spot`. */ marketType?: string; /** * The options for [Spot Instance](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-spot-instances.html) */ spotOptions?: outputs.ec2.LaunchTemplateInstanceMarketOptionsSpotOptions; } interface LaunchTemplateInstanceMarketOptionsSpotOptions { /** * The required duration in minutes. This value must be a multiple of 60. */ blockDurationMinutes?: number; /** * The behavior when a Spot Instance is interrupted. Can be `hibernate`, * `stop`, or `terminate`. (Default: `terminate`). */ instanceInterruptionBehavior?: string; /** * The maximum hourly price you're willing to pay for the Spot Instances. */ maxPrice?: string; /** * The Spot Instance request type. Can be `one-time`, or `persistent`. */ spotInstanceType?: string; /** * The end date of the request. */ validUntil: string; } interface LaunchTemplateInstanceRequirements { /** * Block describing the minimum and maximum number of accelerators (GPUs, FPGAs, or AWS Inferentia chips). Default is no minimum or maximum. */ acceleratorCount?: outputs.ec2.LaunchTemplateInstanceRequirementsAcceleratorCount; /** * List of accelerator manufacturer names. Default is any manufacturer. * * ``` * Valid names: * * amazon-web-services * * amd * * nvidia * * xilinx * ``` */ acceleratorManufacturers?: string[]; /** * List of accelerator names. Default is any acclerator. * * ``` * Valid names: * * a100 - NVIDIA A100 GPUs * * v100 - NVIDIA V100 GPUs * * k80 - NVIDIA K80 GPUs * * t4 - NVIDIA T4 GPUs * * m60 - NVIDIA M60 GPUs * * radeon-pro-v520 - AMD Radeon Pro V520 GPUs * * vu9p - Xilinx VU9P FPGAs * ``` */ acceleratorNames?: string[]; /** * Block describing the minimum and maximum total memory of the accelerators. Default is no minimum or maximum. */ acceleratorTotalMemoryMib?: outputs.ec2.LaunchTemplateInstanceRequirementsAcceleratorTotalMemoryMib; /** * List of accelerator types. Default is any accelerator type. * * ``` * Valid types: * * fpga * * gpu * * inference * ``` */ acceleratorTypes?: string[]; /** * List of instance types to apply your specified attributes against. All other instance types are ignored, even if they match your specified attributes. You can use strings with one or more wild cards, represented by an asterisk (\*), to allow an instance type, size, or generation. The following are examples: `m5.8xlarge`, `c5*.*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are allowing the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are allowing all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is all instance types. * * > **NOTE:** If you specify `allowedInstanceTypes`, you can't specify `excludedInstanceTypes`. */ allowedInstanceTypes?: string[]; /** * Indicate whether bare metal instace types should be `included`, `excluded`, or `required`. Default is `excluded`. */ bareMetal?: string; /** * Block describing the minimum and maximum baseline EBS bandwidth, in Mbps. Default is no minimum or maximum. */ baselineEbsBandwidthMbps?: outputs.ec2.LaunchTemplateInstanceRequirementsBaselineEbsBandwidthMbps; /** * Indicate whether burstable performance instance types should be `included`, `excluded`, or `required`. Default is `excluded`. */ burstablePerformance?: string; /** * List of CPU manufacturer names. Default is any manufacturer. * * > **NOTE:** Don't confuse the CPU hardware manufacturer with the CPU hardware architecture. Instances will be launched with a compatible CPU architecture based on the AMI that you specify in your launch template. * * ``` * Valid names: * * amazon-web-services * * amd * * intel * ``` */ cpuManufacturers?: string[]; /** * List of instance types to exclude. You can use strings with one or more wild cards, represented by an asterisk (\*), to exclude an instance type, size, or generation. The following are examples: `m5.8xlarge`, `c5*.*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are excluding the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are excluding all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is no excluded instance types. * * > **NOTE:** If you specify `excludedInstanceTypes`, you can't specify `allowedInstanceTypes`. */ excludedInstanceTypes?: string[]; /** * List of instance generation names. Default is any generation. * * ``` * Valid names: * * current - Recommended for best performance. * * previous - For existing applications optimized for older instance types. * ``` */ instanceGenerations?: string[]; /** * Indicate whether instance types with local storage volumes are `included`, `excluded`, or `required`. Default is `included`. */ localStorage?: string; /** * List of local storage type names. Default any storage type. * * ``` * Value names: * * hdd - hard disk drive * * ssd - solid state drive * ``` */ localStorageTypes?: string[]; /** * The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Conflicts with `spotMaxPricePercentageOverLowestPrice` */ maxSpotPriceAsPercentageOfOptimalOnDemandPrice?: number; /** * Block describing the minimum and maximum amount of memory (GiB) per vCPU. Default is no minimum or maximum. */ memoryGibPerVcpu?: outputs.ec2.LaunchTemplateInstanceRequirementsMemoryGibPerVcpu; /** * Block describing the minimum and maximum amount of memory (MiB). Default is no maximum. */ memoryMib: outputs.ec2.LaunchTemplateInstanceRequirementsMemoryMib; /** * Block describing the minimum and maximum amount of network bandwidth, in gigabits per second (Gbps). Default is no minimum or maximum. */ networkBandwidthGbps?: outputs.ec2.LaunchTemplateInstanceRequirementsNetworkBandwidthGbps; /** * Block describing the minimum and maximum number of network interfaces. Default is no minimum or maximum. */ networkInterfaceCount?: outputs.ec2.LaunchTemplateInstanceRequirementsNetworkInterfaceCount; /** * The price protection threshold for On-Demand Instances. This is the maximum you’ll pay for an On-Demand Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 20. * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ onDemandMaxPricePercentageOverLowestPrice?: number; /** * Indicate whether instance types must support On-Demand Instance Hibernation, either `true` or `false`. Default is `false`. */ requireHibernateSupport?: boolean; /** * The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 100. Conflicts with `maxSpotPriceAsPercentageOfOptimalOnDemandPrice` * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ spotMaxPricePercentageOverLowestPrice?: number; /** * Block describing the minimum and maximum total local storage (GB). Default is no minimum or maximum. */ totalLocalStorageGb?: outputs.ec2.LaunchTemplateInstanceRequirementsTotalLocalStorageGb; /** * Block describing the minimum and maximum number of vCPUs. Default is no maximum. */ vcpuCount: outputs.ec2.LaunchTemplateInstanceRequirementsVcpuCount; } interface LaunchTemplateInstanceRequirementsAcceleratorCount { /** * Maximum. Set to `0` to exclude instance types with accelerators. */ max?: number; /** * Minimum. */ min?: number; } interface LaunchTemplateInstanceRequirementsAcceleratorTotalMemoryMib { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface LaunchTemplateInstanceRequirementsBaselineEbsBandwidthMbps { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface LaunchTemplateInstanceRequirementsMemoryGibPerVcpu { /** * Maximum. May be a decimal number, e.g. `0.5`. */ max?: number; /** * Minimum. May be a decimal number, e.g. `0.5`. */ min?: number; } interface LaunchTemplateInstanceRequirementsMemoryMib { /** * Maximum. */ max?: number; /** * Minimum. */ min: number; } interface LaunchTemplateInstanceRequirementsNetworkBandwidthGbps { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface LaunchTemplateInstanceRequirementsNetworkInterfaceCount { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface LaunchTemplateInstanceRequirementsTotalLocalStorageGb { /** * Maximum. May be a decimal number, e.g. `0.5`. */ max?: number; /** * Minimum. May be a decimal number, e.g. `0.5`. */ min?: number; } interface LaunchTemplateInstanceRequirementsVcpuCount { /** * Maximum. */ max?: number; /** * Minimum. */ min: number; } interface LaunchTemplateLicenseSpecification { /** * ARN of the license configuration. */ licenseConfigurationArn: string; } interface LaunchTemplateMaintenanceOptions { /** * Disables the automatic recovery behavior of your instance or sets it to default. Can be `"default"` or `"disabled"`. See [Recover your instance](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-recover.html) for more details. */ autoRecovery?: string; } interface LaunchTemplateMetadataOptions { /** * Whether the metadata service is available. Can be `"enabled"` or `"disabled"`. (Default: `"enabled"`). */ httpEndpoint: string; /** * Enables or disables the IPv6 endpoint for the instance metadata service. Can be `"enabled"` or `"disabled"`. */ httpProtocolIpv6: string; /** * The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel. Can be an integer from `1` to `64`. (Default: `1`). */ httpPutResponseHopLimit: number; /** * Whether or not the metadata service requires session tokens, also referred to as _Instance Metadata Service Version 2 (IMDSv2)_. Can be `"optional"` or `"required"`. (Default: `"optional"`). */ httpTokens: string; /** * Enables or disables access to instance tags from the instance metadata service. Can be `"enabled"` or `"disabled"`. * * For more information, see the documentation on the [Instance Metadata Service](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html). */ instanceMetadataTags: string; } interface LaunchTemplateMonitoring { /** * If `true`, the launched EC2 instance will have detailed monitoring enabled. */ enabled?: boolean; } interface LaunchTemplateNetworkInterface { /** * Associate a Carrier IP address with `eth0` for a new network interface. Use this option when you launch an instance in a Wavelength Zone and want to associate a Carrier IP address with the network interface. Boolean value, can be left unset. */ associateCarrierIpAddress?: string; /** * Associate a public ip address with the network interface. Boolean value, can be left unset. */ associatePublicIpAddress?: string; /** * The Connection Tracking Configuration for the network interface. See [Amazon EC2 security group connection tracking](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-connection-tracking.html#connection-tracking-timeouts) */ connectionTrackingSpecification?: outputs.ec2.LaunchTemplateNetworkInterfaceConnectionTrackingSpecification; /** * Whether the network interface should be destroyed on instance termination. */ deleteOnTermination?: string; /** * Description of the network interface. */ description?: string; /** * The integer index of the network interface attachment. */ deviceIndex?: number; /** * The number of ENA queues to be created with the instance. Requires an instance type and operating system that support [ENA queue configuration](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ena-queues.html). */ enaQueueCount?: number; /** * Configuration for Elastic Network Adapter (ENA) Express settings. Applies to network interfaces that use the [ena Express](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/enhanced-networking-ena-express.html) feature. See details below. */ enaSrdSpecification?: outputs.ec2.LaunchTemplateNetworkInterfaceEnaSrdSpecification; /** * The type of network interface. To create an Elastic Fabric Adapter (EFA), specify `efa`. */ interfaceType?: string; /** * The number of secondary private IPv4 addresses to assign to a network interface. Conflicts with `ipv4Addresses` */ ipv4AddressCount?: number; /** * One or more private IPv4 addresses to associate. Conflicts with `ipv4AddressCount` */ ipv4Addresses?: string[]; /** * The number of IPv4 prefixes to be automatically assigned to the network interface. Conflicts with `ipv4Prefixes` */ ipv4PrefixCount?: number; /** * One or more IPv4 prefixes to be assigned to the network interface. Conflicts with `ipv4PrefixCount` */ ipv4Prefixes?: string[]; /** * The number of IPv6 addresses to assign to a network interface. Conflicts with `ipv6Addresses` */ ipv6AddressCount?: number; /** * One or more specific IPv6 addresses from the IPv6 CIDR block range of your subnet. Conflicts with `ipv6AddressCount` */ ipv6Addresses?: string[]; /** * The number of IPv6 prefixes to be automatically assigned to the network interface. Conflicts with `ipv6Prefixes` */ ipv6PrefixCount?: number; /** * One or more IPv6 prefixes to be assigned to the network interface. Conflicts with `ipv6PrefixCount` */ ipv6Prefixes?: string[]; /** * The index of the network card. Some instance types support multiple network cards. The primary network interface must be assigned to network card index 0. The default is network card index 0. */ networkCardIndex?: number; /** * The ID of the network interface to attach. */ networkInterfaceId?: string; /** * Whether the first IPv6 GUA will be made the primary IPv6 address. */ primaryIpv6?: string; /** * The primary private IPv4 address. */ privateIpAddress?: string; /** * A list of security group IDs to associate. */ securityGroups?: string[]; /** * The VPC Subnet ID to associate. */ subnetId?: string; } interface LaunchTemplateNetworkInterfaceConnectionTrackingSpecification { /** * Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 432000 seconds. Recommended: Less than 432000 seconds. */ tcpEstablishedTimeout?: number; /** * Timeout (in seconds) for idle UDP flows classified as streams which have seen more than one request-response transaction. Min: 60 seconds. Max: 180 seconds (3 minutes). Default: 180 seconds. */ udpStreamTimeout?: number; /** * Timeout (in seconds) for idle UDP flows that have seen traffic only in a single direction or a single request-response transaction. Min: 30 seconds. Max: 60 seconds. Default: 30 seconds. */ udpTimeout?: number; } interface LaunchTemplateNetworkInterfaceEnaSrdSpecification { /** * Whether to enable ENA Express. ENA Express uses AWS Scalable Reliable Datagram (SRD) technology to improve the performance of TCP traffic. */ enaSrdEnabled?: boolean; /** * Configuration for ENA Express UDP optimization. See details below. */ enaSrdUdpSpecification?: outputs.ec2.LaunchTemplateNetworkInterfaceEnaSrdSpecificationEnaSrdUdpSpecification; } interface LaunchTemplateNetworkInterfaceEnaSrdSpecificationEnaSrdUdpSpecification { /** * Whether to enable UDP traffic optimization through ENA Express. Requires `enaSrdEnabled` to be `true`. * * NOTE: ENA Express requires [specific instance types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/enhanced-networking-ena-express.html#ena-express-requirements) and minimum bandwidth of 25 Gbps. */ enaSrdUdpEnabled?: boolean; } interface LaunchTemplateNetworkPerformanceOptions { /** * Specify the bandwidth weighting option to boost the associated type of baseline bandwidth. Valid values: `default`, `vpc-1`, `ebs-1`. Default value is `default`. Setting `vpc-1` boosts networking baseline bandwidth and reduces EBS baseline bandwidth. Setting `ebs-1` boosts EBS baseline bandwidth and reduces networking baseline bandwidth. Only supported on select instance types. See [AWS Documentation](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configure-bandwidth-weighting.html) for more information. */ bandwidthWeighting?: string; } interface LaunchTemplatePlacement { /** * The affinity setting for an instance on a Dedicated Host. */ affinity?: string; /** * The Availability Zone for the instance. */ availabilityZone?: string; /** * The ID of the placement group for the instance. Conflicts with `groupName`. */ groupId?: string; /** * The name of the placement group for the instance. Conflicts with `groupId`. */ groupName?: string; /** * The ID of the Dedicated Host for the instance. */ hostId?: string; /** * The ARN of the Host Resource Group in which to launch instances. */ hostResourceGroupArn?: string; /** * The number of the partition the instance should launch in. Valid only if the placement group strategy is set to partition. */ partitionNumber?: number; /** * Reserved for future use. */ spreadDomain?: string; /** * The tenancy of the instance (if the instance is running in a VPC). Can be `default`, `dedicated`, or `host`. */ tenancy?: string; } interface LaunchTemplatePrivateDnsNameOptions { /** * Indicates whether to respond to DNS queries for instance hostnames with DNS A records. */ enableResourceNameDnsARecord?: boolean; /** * Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records. */ enableResourceNameDnsAaaaRecord?: boolean; /** * The type of hostname for Amazon EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 native subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID. Valid values: `ip-name` and `resource-name`. */ hostnameType?: string; } interface LaunchTemplateSecondaryInterface { /** * Whether the secondary interface is deleted when the instance is terminated. The only supported value is `true`. */ deleteOnTermination?: boolean; /** * Device index for the secondary interface attachment. */ deviceIndex?: number; /** * Type of secondary interface. The only supported value is: `secondary`. */ interfaceType?: string; /** * Index of the network card. */ networkCardIndex?: number; /** * Number of private IPv4 addresses to assign to the secondary interface. */ privateIpAddressCount?: number; /** * Private IPv4 addresses to assign to the secondary interface. */ privateIpAddresses?: string[]; /** * ID of the secondary subnet. */ secondarySubnetId?: string; } interface LaunchTemplateTagSpecification { /** * The type of resource to tag. */ resourceType?: string; /** * A map of tags to assign to the resource. */ tags?: { [key: string]: string; }; } interface LocalGatewayRouteTableTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface ManagedPrefixListEntry { /** * CIDR block of this entry. */ cidr: string; /** * Description of this entry. Due to API limitations, updating only the description of an existing entry requires temporarily removing and re-adding the entry. */ description?: string; } interface NatGatewayAvailabilityZoneAddress { /** * List of allocation IDs of the Elastic IP addresses (EIPs) to be used for handling outbound NAT traffic in this specific Availability Zone. */ allocationIds?: string[]; /** * Availability Zone (e.g. `us-west-2a`) where this specific NAT gateway configuration will be active. Exactly one of `availabilityZone` or `availabilityZoneId` must be specified. */ availabilityZone?: string; /** * Availability Zone ID (e.g. `usw2-az2`) where this specific NAT gateway configuration will be active. Exactly one of `availabilityZone` or `availabilityZoneId` must be specified. */ availabilityZoneId: string; } interface NatGatewayEipAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface NatGatewayRegionalNatGatewayAddress { /** * The Allocation ID of the Elastic IP address for the NAT Gateway. Required when `connectivityType` is set to `public` and `availabilityMode` is set to `zonal`. When `availabilityMode` is set to `regional`, this must not be set; instead, use the `availabilityZoneAddress` block to specify EIPs for each AZ. */ allocationId: string; /** * Association ID of the Elastic IP address. */ associationId: string; /** * Availability Zone where this specific NAT gateway configuration is active. */ availabilityZone: string; /** * Availability Zone ID where this specific NAT gateway configuration is active */ availabilityZoneId: string; /** * ID of the network interface. */ networkInterfaceId: string; /** * Public IP address. */ publicIp: string; /** * Status of the NAT gateway address. */ status: string; } interface NetworkAclEgress { /** * The action to take. */ action: string; /** * The CIDR block to match. This must be a * valid network mask. */ cidrBlock?: string; /** * The from port to match. */ fromPort: number; /** * The ICMP type code to be used. Default 0. * * > Note: For more information on ICMP types and codes, see here: https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml */ icmpCode?: number; /** * The ICMP type to be used. Default 0. */ icmpType?: number; /** * The IPv6 CIDR block. */ ipv6CidrBlock?: string; /** * The protocol to match. If using the -1 'all' * protocol, you must specify a from and to port of 0. */ protocol: string; /** * The rule number. Used for ordering. */ ruleNo: number; /** * The to port to match. */ toPort: number; } interface NetworkAclIngress { /** * The action to take. */ action: string; /** * The CIDR block to match. This must be a * valid network mask. */ cidrBlock?: string; /** * The from port to match. */ fromPort: number; /** * The ICMP type code to be used. Default 0. * * > Note: For more information on ICMP types and codes, see here: https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml */ icmpCode?: number; /** * The ICMP type to be used. Default 0. */ icmpType?: number; /** * The IPv6 CIDR block. */ ipv6CidrBlock?: string; /** * The protocol to match. If using the -1 'all' * protocol, you must specify a from and to port of 0. */ protocol: string; /** * The rule number. Used for ordering. */ ruleNo: number; /** * The to port to match. */ toPort: number; } interface NetworkInsightsAccessScopeExcludePath { /** * Path statement for the destination. * See `source` and `destination` below for details. */ destination?: outputs.ec2.NetworkInsightsAccessScopeExcludePathDestination; /** * Path statement for the source. * See `source` and `destination` below for details. */ source?: outputs.ec2.NetworkInsightsAccessScopeExcludePathSource; /** * Path statement for through resources. * See `throughResources` below for details. */ throughResources?: outputs.ec2.NetworkInsightsAccessScopeExcludePathThroughResource[]; } interface NetworkInsightsAccessScopeExcludePathDestination { /** * Packet header statement. * See `packetHeaderStatement` below for details. */ packetHeaderStatement?: outputs.ec2.NetworkInsightsAccessScopeExcludePathDestinationPacketHeaderStatement; resourceStatement?: outputs.ec2.NetworkInsightsAccessScopeExcludePathDestinationResourceStatement; } interface NetworkInsightsAccessScopeExcludePathDestinationPacketHeaderStatement { /** * Set of destination addresses. */ destinationAddresses?: string[]; /** * Set of destination ports. */ destinationPorts?: string[]; /** * Set of destination prefix lists. */ destinationPrefixLists?: string[]; /** * Set of protocols. * Valid values are `tcp` and `udp`. */ protocols?: string[]; /** * Set of source addresses. */ sourceAddresses?: string[]; /** * Set of source ports. */ sourcePorts?: string[]; /** * Set of source prefix lists. */ sourcePrefixLists?: string[]; } interface NetworkInsightsAccessScopeExcludePathDestinationResourceStatement { /** * List of resource types. * Cannot be specified together with `resources`. */ resourceTypes?: string[]; /** * List of resource ARNs. * Cannot be specified together with `resourceTypes`. */ resources?: string[]; } interface NetworkInsightsAccessScopeExcludePathSource { /** * Packet header statement. * See `packetHeaderStatement` below for details. */ packetHeaderStatement?: outputs.ec2.NetworkInsightsAccessScopeExcludePathSourcePacketHeaderStatement; /** * Resource statement. * Exactly one of `resources` or `resourceTypes` must be specified. * See `resourceStatement` below for details. */ resourceStatement?: outputs.ec2.NetworkInsightsAccessScopeExcludePathSourceResourceStatement; } interface NetworkInsightsAccessScopeExcludePathSourcePacketHeaderStatement { /** * Set of destination addresses. */ destinationAddresses?: string[]; /** * Set of destination ports. */ destinationPorts?: string[]; /** * Set of destination prefix lists. */ destinationPrefixLists?: string[]; /** * Set of protocols. * Valid values are `tcp` and `udp`. */ protocols?: string[]; /** * Set of source addresses. */ sourceAddresses?: string[]; /** * Set of source ports. */ sourcePorts?: string[]; /** * Set of source prefix lists. */ sourcePrefixLists?: string[]; } interface NetworkInsightsAccessScopeExcludePathSourceResourceStatement { /** * List of resource types. * Cannot be specified together with `resources`. */ resourceTypes?: string[]; /** * List of resource ARNs. * Cannot be specified together with `resourceTypes`. */ resources?: string[]; } interface NetworkInsightsAccessScopeExcludePathThroughResource { /** * Resource statement. * Exactly one of `resources` or `resourceTypes` must be specified. * See `resourceStatement` below for details. */ resourceStatement?: outputs.ec2.NetworkInsightsAccessScopeExcludePathThroughResourceResourceStatement; } interface NetworkInsightsAccessScopeExcludePathThroughResourceResourceStatement { /** * List of resource types. * Cannot be specified together with `resources`. */ resourceTypes?: string[]; /** * List of resource ARNs. * Cannot be specified together with `resourceTypes`. */ resources?: string[]; } interface NetworkInsightsAccessScopeMatchPath { /** * Path statement for the destination. * See `source` and `destination` below for details. */ destination?: outputs.ec2.NetworkInsightsAccessScopeMatchPathDestination; /** * Path statement for the source. * See `source` and `destination` below for details. */ source?: outputs.ec2.NetworkInsightsAccessScopeMatchPathSource; } interface NetworkInsightsAccessScopeMatchPathDestination { /** * Packet header statement. * See `packetHeaderStatement` below for details. */ packetHeaderStatement?: outputs.ec2.NetworkInsightsAccessScopeMatchPathDestinationPacketHeaderStatement; resourceStatement?: outputs.ec2.NetworkInsightsAccessScopeMatchPathDestinationResourceStatement; } interface NetworkInsightsAccessScopeMatchPathDestinationPacketHeaderStatement { /** * Set of destination addresses. */ destinationAddresses?: string[]; /** * Set of destination ports. */ destinationPorts?: string[]; /** * Set of destination prefix lists. */ destinationPrefixLists?: string[]; /** * Set of protocols. * Valid values are `tcp` and `udp`. */ protocols?: string[]; /** * Set of source addresses. */ sourceAddresses?: string[]; /** * Set of source ports. */ sourcePorts?: string[]; /** * Set of source prefix lists. */ sourcePrefixLists?: string[]; } interface NetworkInsightsAccessScopeMatchPathDestinationResourceStatement { /** * List of resource types. * Cannot be specified together with `resources`. */ resourceTypes?: string[]; /** * List of resource ARNs. * Cannot be specified together with `resourceTypes`. */ resources?: string[]; } interface NetworkInsightsAccessScopeMatchPathSource { /** * Packet header statement. * See `packetHeaderStatement` below for details. */ packetHeaderStatement?: outputs.ec2.NetworkInsightsAccessScopeMatchPathSourcePacketHeaderStatement; /** * Resource statement. * Exactly one of `resources` or `resourceTypes` must be specified. * See `resourceStatement` below for details. */ resourceStatement?: outputs.ec2.NetworkInsightsAccessScopeMatchPathSourceResourceStatement; } interface NetworkInsightsAccessScopeMatchPathSourcePacketHeaderStatement { /** * Set of destination addresses. */ destinationAddresses?: string[]; /** * Set of destination ports. */ destinationPorts?: string[]; /** * Set of destination prefix lists. */ destinationPrefixLists?: string[]; /** * Set of protocols. * Valid values are `tcp` and `udp`. */ protocols?: string[]; /** * Set of source addresses. */ sourceAddresses?: string[]; /** * Set of source ports. */ sourcePorts?: string[]; /** * Set of source prefix lists. */ sourcePrefixLists?: string[]; } interface NetworkInsightsAccessScopeMatchPathSourceResourceStatement { /** * List of resource types. * Cannot be specified together with `resources`. */ resourceTypes?: string[]; /** * List of resource ARNs. * Cannot be specified together with `resourceTypes`. */ resources?: string[]; } interface NetworkInsightsAnalysisAlternatePathHint { /** * ARN of the component. */ componentArn: string; /** * The ID of the component. */ componentId: string; } interface NetworkInsightsAnalysisExplanation { aclRules: outputs.ec2.NetworkInsightsAnalysisExplanationAclRule[]; acls: outputs.ec2.NetworkInsightsAnalysisExplanationAcl[]; address: string; addresses: string[]; attachedTos: outputs.ec2.NetworkInsightsAnalysisExplanationAttachedTo[]; availabilityZones: string[]; cidrs: string[]; classicLoadBalancerListeners: outputs.ec2.NetworkInsightsAnalysisExplanationClassicLoadBalancerListener[]; components: outputs.ec2.NetworkInsightsAnalysisExplanationComponent[]; customerGateways: outputs.ec2.NetworkInsightsAnalysisExplanationCustomerGateway[]; destinationVpcs: outputs.ec2.NetworkInsightsAnalysisExplanationDestinationVpc[]; destinations: outputs.ec2.NetworkInsightsAnalysisExplanationDestination[]; direction: string; elasticLoadBalancerListeners: outputs.ec2.NetworkInsightsAnalysisExplanationElasticLoadBalancerListener[]; explanationCode: string; ingressRouteTables: outputs.ec2.NetworkInsightsAnalysisExplanationIngressRouteTable[]; internetGateways: outputs.ec2.NetworkInsightsAnalysisExplanationInternetGateway[]; loadBalancerArn: string; loadBalancerListenerPort: number; loadBalancerTargetGroup: outputs.ec2.NetworkInsightsAnalysisExplanationLoadBalancerTargetGroup[]; loadBalancerTargetGroups: outputs.ec2.NetworkInsightsAnalysisExplanationLoadBalancerTargetGroup[]; loadBalancerTargetPort: number; missingComponent: string; natGateways: outputs.ec2.NetworkInsightsAnalysisExplanationNatGateway[]; networkInterfaces: outputs.ec2.NetworkInsightsAnalysisExplanationNetworkInterface[]; packetField: string; port: number; portRanges: outputs.ec2.NetworkInsightsAnalysisExplanationPortRange[]; prefixLists: outputs.ec2.NetworkInsightsAnalysisExplanationPrefixList[]; protocols: string[]; routeTableRoutes: outputs.ec2.NetworkInsightsAnalysisExplanationRouteTableRoute[]; routeTables: outputs.ec2.NetworkInsightsAnalysisExplanationRouteTable[]; securityGroup: outputs.ec2.NetworkInsightsAnalysisExplanationSecurityGroup[]; securityGroupRules: outputs.ec2.NetworkInsightsAnalysisExplanationSecurityGroupRule[]; securityGroups: outputs.ec2.NetworkInsightsAnalysisExplanationSecurityGroup[]; sourceVpcs: outputs.ec2.NetworkInsightsAnalysisExplanationSourceVpc[]; state: string; subnetRouteTables: outputs.ec2.NetworkInsightsAnalysisExplanationSubnetRouteTable[]; subnets: outputs.ec2.NetworkInsightsAnalysisExplanationSubnet[]; transitGatewayAttachments: outputs.ec2.NetworkInsightsAnalysisExplanationTransitGatewayAttachment[]; transitGatewayRouteTableRoutes: outputs.ec2.NetworkInsightsAnalysisExplanationTransitGatewayRouteTableRoute[]; transitGatewayRouteTables: outputs.ec2.NetworkInsightsAnalysisExplanationTransitGatewayRouteTable[]; transitGateways: outputs.ec2.NetworkInsightsAnalysisExplanationTransitGateway[]; vpcEndpoints: outputs.ec2.NetworkInsightsAnalysisExplanationVpcEndpoint[]; vpcPeeringConnections: outputs.ec2.NetworkInsightsAnalysisExplanationVpcPeeringConnection[]; vpcs: outputs.ec2.NetworkInsightsAnalysisExplanationVpc[]; vpnConnections: outputs.ec2.NetworkInsightsAnalysisExplanationVpnConnection[]; vpnGateways: outputs.ec2.NetworkInsightsAnalysisExplanationVpnGateway[]; } interface NetworkInsightsAnalysisExplanationAcl { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationAclRule { cidr: string; egress: boolean; portRanges: outputs.ec2.NetworkInsightsAnalysisExplanationAclRulePortRange[]; protocol: string; ruleAction: string; ruleNumber: number; } interface NetworkInsightsAnalysisExplanationAclRulePortRange { from: number; to: number; } interface NetworkInsightsAnalysisExplanationAttachedTo { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationClassicLoadBalancerListener { instancePort: number; loadBalancerPort: number; } interface NetworkInsightsAnalysisExplanationComponent { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationCustomerGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationDestination { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationDestinationVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationElasticLoadBalancerListener { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationIngressRouteTable { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationInternetGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationLoadBalancerTargetGroup { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationNatGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationNetworkInterface { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationPortRange { from: number; to: number; } interface NetworkInsightsAnalysisExplanationPrefixList { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationRouteTable { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationRouteTableRoute { destinationCidr: string; destinationPrefixListId: string; egressOnlyInternetGatewayId: string; gatewayId: string; instanceId: string; natGatewayId: string; networkInterfaceId: string; origin: string; transitGatewayId: string; vpcPeeringConnectionId: string; } interface NetworkInsightsAnalysisExplanationSecurityGroup { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationSecurityGroupRule { cidr: string; direction: string; portRanges: outputs.ec2.NetworkInsightsAnalysisExplanationSecurityGroupRulePortRange[]; prefixListId: string; protocol: string; securityGroupId: string; } interface NetworkInsightsAnalysisExplanationSecurityGroupRulePortRange { from: number; to: number; } interface NetworkInsightsAnalysisExplanationSourceVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationSubnet { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationSubnetRouteTable { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationTransitGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationTransitGatewayAttachment { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationTransitGatewayRouteTable { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationTransitGatewayRouteTableRoute { attachmentId: string; destinationCidr: string; prefixListId: string; resourceId: string; resourceType: string; routeOrigin: string; state: string; } interface NetworkInsightsAnalysisExplanationVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationVpcEndpoint { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationVpcPeeringConnection { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationVpnConnection { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisExplanationVpnGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponent { aclRules: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentAclRule[]; additionalDetails: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentAdditionalDetail[]; attachedTos: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentAttachedTo[]; components: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentComponent[]; destinationVpcs: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentDestinationVpc[]; inboundHeaders: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentInboundHeader[]; outboundHeaders: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentOutboundHeader[]; routeTableRoutes: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentRouteTableRoute[]; securityGroupRules: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentSecurityGroupRule[]; sequenceNumber: number; sourceVpcs: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentSourceVpc[]; subnets: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentSubnet[]; transitGatewayRouteTableRoutes: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentTransitGatewayRouteTableRoute[]; transitGateways: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentTransitGateway[]; vpcs: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentVpc[]; } interface NetworkInsightsAnalysisForwardPathComponentAclRule { cidr: string; egress: boolean; portRanges: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentAclRulePortRange[]; protocol: string; ruleAction: string; ruleNumber: number; } interface NetworkInsightsAnalysisForwardPathComponentAclRulePortRange { from: number; to: number; } interface NetworkInsightsAnalysisForwardPathComponentAdditionalDetail { additionalDetailType: string; components: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentAdditionalDetailComponent[]; } interface NetworkInsightsAnalysisForwardPathComponentAdditionalDetailComponent { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentAttachedTo { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentComponent { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentDestinationVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentInboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentInboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentInboundHeaderSourcePortRange[]; } interface NetworkInsightsAnalysisForwardPathComponentInboundHeaderDestinationPortRange { from: number; to: number; } interface NetworkInsightsAnalysisForwardPathComponentInboundHeaderSourcePortRange { from: number; to: number; } interface NetworkInsightsAnalysisForwardPathComponentOutboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentOutboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentOutboundHeaderSourcePortRange[]; } interface NetworkInsightsAnalysisForwardPathComponentOutboundHeaderDestinationPortRange { from: number; to: number; } interface NetworkInsightsAnalysisForwardPathComponentOutboundHeaderSourcePortRange { from: number; to: number; } interface NetworkInsightsAnalysisForwardPathComponentRouteTableRoute { destinationCidr: string; destinationPrefixListId: string; egressOnlyInternetGatewayId: string; gatewayId: string; instanceId: string; natGatewayId: string; networkInterfaceId: string; origin: string; transitGatewayId: string; vpcPeeringConnectionId: string; } interface NetworkInsightsAnalysisForwardPathComponentSecurityGroupRule { cidr: string; direction: string; portRanges: outputs.ec2.NetworkInsightsAnalysisForwardPathComponentSecurityGroupRulePortRange[]; prefixListId: string; protocol: string; securityGroupId: string; } interface NetworkInsightsAnalysisForwardPathComponentSecurityGroupRulePortRange { from: number; to: number; } interface NetworkInsightsAnalysisForwardPathComponentSourceVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentSubnet { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentTransitGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisForwardPathComponentTransitGatewayRouteTableRoute { attachmentId: string; destinationCidr: string; prefixListId: string; resourceId: string; resourceType: string; routeOrigin: string; state: string; } interface NetworkInsightsAnalysisForwardPathComponentVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponent { aclRules: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentAclRule[]; additionalDetails: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentAdditionalDetail[]; attachedTos: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentAttachedTo[]; components: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentComponent[]; destinationVpcs: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentDestinationVpc[]; inboundHeaders: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentInboundHeader[]; outboundHeaders: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentOutboundHeader[]; routeTableRoutes: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentRouteTableRoute[]; securityGroupRules: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentSecurityGroupRule[]; sequenceNumber: number; sourceVpcs: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentSourceVpc[]; subnets: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentSubnet[]; transitGatewayRouteTableRoutes: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentTransitGatewayRouteTableRoute[]; transitGateways: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentTransitGateway[]; vpcs: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentVpc[]; } interface NetworkInsightsAnalysisReturnPathComponentAclRule { cidr: string; egress: boolean; portRanges: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentAclRulePortRange[]; protocol: string; ruleAction: string; ruleNumber: number; } interface NetworkInsightsAnalysisReturnPathComponentAclRulePortRange { from: number; to: number; } interface NetworkInsightsAnalysisReturnPathComponentAdditionalDetail { additionalDetailType: string; components: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentAdditionalDetailComponent[]; } interface NetworkInsightsAnalysisReturnPathComponentAdditionalDetailComponent { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentAttachedTo { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentComponent { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentDestinationVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentInboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentInboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentInboundHeaderSourcePortRange[]; } interface NetworkInsightsAnalysisReturnPathComponentInboundHeaderDestinationPortRange { from: number; to: number; } interface NetworkInsightsAnalysisReturnPathComponentInboundHeaderSourcePortRange { from: number; to: number; } interface NetworkInsightsAnalysisReturnPathComponentOutboundHeader { destinationAddresses: string[]; destinationPortRanges: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentOutboundHeaderDestinationPortRange[]; protocol: string; sourceAddresses: string[]; sourcePortRanges: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentOutboundHeaderSourcePortRange[]; } interface NetworkInsightsAnalysisReturnPathComponentOutboundHeaderDestinationPortRange { from: number; to: number; } interface NetworkInsightsAnalysisReturnPathComponentOutboundHeaderSourcePortRange { from: number; to: number; } interface NetworkInsightsAnalysisReturnPathComponentRouteTableRoute { destinationCidr: string; destinationPrefixListId: string; egressOnlyInternetGatewayId: string; gatewayId: string; instanceId: string; natGatewayId: string; networkInterfaceId: string; origin: string; transitGatewayId: string; vpcPeeringConnectionId: string; } interface NetworkInsightsAnalysisReturnPathComponentSecurityGroupRule { cidr: string; direction: string; portRanges: outputs.ec2.NetworkInsightsAnalysisReturnPathComponentSecurityGroupRulePortRange[]; prefixListId: string; protocol: string; securityGroupId: string; } interface NetworkInsightsAnalysisReturnPathComponentSecurityGroupRulePortRange { from: number; to: number; } interface NetworkInsightsAnalysisReturnPathComponentSourceVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentSubnet { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentTransitGateway { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsAnalysisReturnPathComponentTransitGatewayRouteTableRoute { attachmentId: string; destinationCidr: string; prefixListId: string; resourceId: string; resourceType: string; routeOrigin: string; state: string; } interface NetworkInsightsAnalysisReturnPathComponentVpc { /** * ARN of the Network Insights Analysis. */ arn: string; /** * ID of the Network Insights Analysis. */ id: string; name: string; } interface NetworkInsightsPathFilterAtDestination { /** * The destination IPv4 address. */ destinationAddress?: string; /** * The destination port range. See below for details. */ destinationPortRange?: outputs.ec2.NetworkInsightsPathFilterAtDestinationDestinationPortRange; /** * IP address of the source resource. */ sourceAddress?: string; /** * The source port range. See below for details. */ sourcePortRange?: outputs.ec2.NetworkInsightsPathFilterAtDestinationSourcePortRange; } interface NetworkInsightsPathFilterAtDestinationDestinationPortRange { /** * The first port in the range. */ fromPort?: number; /** * The last port in the range. */ toPort?: number; } interface NetworkInsightsPathFilterAtDestinationSourcePortRange { /** * The first port in the range. */ fromPort?: number; /** * The last port in the range. */ toPort?: number; } interface NetworkInsightsPathFilterAtSource { /** * The destination IPv4 address. */ destinationAddress?: string; /** * The destination port range. See below for details. */ destinationPortRange?: outputs.ec2.NetworkInsightsPathFilterAtSourceDestinationPortRange; /** * IP address of the source resource. */ sourceAddress?: string; /** * The source port range. See below for details. */ sourcePortRange?: outputs.ec2.NetworkInsightsPathFilterAtSourceSourcePortRange; } interface NetworkInsightsPathFilterAtSourceDestinationPortRange { /** * The first port in the range. */ fromPort?: number; /** * The last port in the range. */ toPort?: number; } interface NetworkInsightsPathFilterAtSourceSourcePortRange { /** * The first port in the range. */ fromPort?: number; /** * The last port in the range. */ toPort?: number; } interface NetworkInterfaceAttachment { attachmentId: string; /** * Integer to define the devices index. */ deviceIndex: number; /** * ID of the instance to attach to. */ instance: string; /** * Index of the network card. Specify a value greater than 0 when using multiple network cards, which are supported by [some instance types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#network-cards). The default is 0. */ networkCardIndex: number; } interface NetworkInterfaceEnaSrdSpecification { /** * Indicates whether ENA Express is enabled for the network interface. */ enaSrdEnabled?: boolean; /** * Configures ENA Express for UDP network traffic. See ENA SRD UDP Specification below for more details. */ enaSrdUdpSpecification?: outputs.ec2.NetworkInterfaceEnaSrdSpecificationEnaSrdUdpSpecification; } interface NetworkInterfaceEnaSrdSpecificationEnaSrdUdpSpecification { /** * Indicates whether UDP traffic uses ENA Express. Requires `enaSrdEnabled` to be `true`. */ enaSrdUdpEnabled?: boolean; } interface NetworkInterfacePermissionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface PeeringConnectionOptionsAccepter { /** * Allow a local VPC to resolve public DNS hostnames to private IP addresses when queried from instances in the peer VPC. */ allowRemoteVpcDnsResolution?: boolean; } interface PeeringConnectionOptionsRequester { /** * Allow a local VPC to resolve public DNS hostnames to private IP addresses when queried from instances in the peer VPC. */ allowRemoteVpcDnsResolution?: boolean; } interface RouteTableRoute { /** * Identifier of a carrier gateway. This attribute can only be used when the VPC contains a subnet which is associated with a Wavelength Zone. */ carrierGatewayId?: string; /** * The CIDR block of the route. */ cidrBlock?: string; /** * ARN of a core network. */ coreNetworkArn?: string; /** * The ID of a managed prefix list destination of the route. * * One of the following target arguments must be supplied: */ destinationPrefixListId?: string; /** * Identifier of a VPC Egress Only Internet Gateway. */ egressOnlyGatewayId?: string; /** * Identifier of a VPC internet gateway, virtual private gateway, or `local`. `local` routes cannot be created but can be adopted or imported. See the example above. */ gatewayId?: string; /** * The Ipv6 CIDR block of the route. */ ipv6CidrBlock?: string; /** * Identifier of a Outpost local gateway. */ localGatewayId?: string; /** * Identifier of a VPC NAT gateway. */ natGatewayId?: string; /** * Identifier of an EC2 network interface. */ networkInterfaceId?: string; /** * ARN of an ODB network. */ odbNetworkArn?: string; /** * Identifier of an EC2 Transit Gateway. */ transitGatewayId?: string; /** * Identifier of a VPC Endpoint. */ vpcEndpointId?: string; /** * Identifier of a VPC peering connection. * * Note that the default route, mapping the VPC's CIDR block to "local", is created implicitly and cannot be specified. */ vpcPeeringConnectionId?: string; } interface SecondaryNetworkIpv4CidrBlockAssociation { /** * Association ID for the IPv4 CIDR block. */ associationId: string; /** * IPv4 CIDR block. */ cidrBlock: string; /** * State of the IPv4 CIDR block association. */ state: string; } interface SecondaryNetworkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface SecondarySubnetIpv4CidrBlockAssociation { /** * Association ID for the IPv4 CIDR block. */ associationId: string; /** * IPv4 CIDR block. */ cidrBlock: string; /** * State of the IPv4 CIDR block association. */ state: string; } interface SecondarySubnetTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface SecurityGroupEgress { /** * List of CIDR blocks. */ cidrBlocks?: string[]; /** * Description of this egress rule. */ description?: string; /** * Start port (or ICMP type number if protocol is `icmp`) */ fromPort: number; /** * List of IPv6 CIDR blocks. */ ipv6CidrBlocks?: string[]; /** * List of Prefix List IDs. */ prefixListIds?: string[]; /** * Protocol. If you select a protocol of `-1` (semantically equivalent to `all`, which is not a valid value here), you must specify a `fromPort` and `toPort` equal to 0. The supported values are defined in the `IpProtocol` argument in the [IpPermission](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_IpPermission.html) API reference. */ protocol: string; /** * List of security groups. A group name can be used relative to the default VPC. Otherwise, group ID. */ securityGroups?: string[]; /** * Whether the security group itself will be added as a source to this egress rule. */ self?: boolean; /** * End range port (or ICMP code if protocol is `icmp`). * * The following arguments are optional: * * > **Note** Although `cidrBlocks`, `ipv6CidrBlocks`, `prefixListIds`, and `securityGroups` are all marked as optional, you _must_ provide one of them in order to configure the destination of the traffic. */ toPort: number; } interface SecurityGroupIngress { /** * List of CIDR blocks. */ cidrBlocks?: string[]; /** * Description of this ingress rule. */ description?: string; /** * Start port (or ICMP type number if protocol is `icmp` or `icmpv6`). */ fromPort: number; /** * List of IPv6 CIDR blocks. */ ipv6CidrBlocks?: string[]; /** * List of Prefix List IDs. */ prefixListIds?: string[]; /** * Protocol. If you select a protocol of `-1` (semantically equivalent to `all`, which is not a valid value here), you must specify a `fromPort` and `toPort` equal to 0. The supported values are defined in the `IpProtocol` argument on the [IpPermission](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_IpPermission.html) API reference. * * The following arguments are optional: * * > **Note** Although `cidrBlocks`, `ipv6CidrBlocks`, `prefixListIds`, and `securityGroups` are all marked as optional, you _must_ provide one of them in order to configure the source of the traffic. */ protocol: string; /** * List of security groups. A group name can be used relative to the default VPC. Otherwise, group ID. */ securityGroups?: string[]; /** * Whether the security group itself will be added as a source to this ingress rule. */ self?: boolean; /** * End range port (or ICMP code if protocol is `icmp`). */ toPort: number; } interface SpotFleetRequestLaunchSpecification { ami: string; associatePublicIpAddress?: boolean; /** * The availability zone in which to place the request. */ availabilityZone: string; ebsBlockDevices: outputs.ec2.SpotFleetRequestLaunchSpecificationEbsBlockDevice[]; ebsOptimized?: boolean; ephemeralBlockDevices: outputs.ec2.SpotFleetRequestLaunchSpecificationEphemeralBlockDevice[]; iamInstanceProfile?: string; iamInstanceProfileArn?: string; /** * The type of instance to request. */ instanceType: string; keyName: string; monitoring?: boolean; placementGroup: string; placementTenancy?: string; rootBlockDevices: outputs.ec2.SpotFleetRequestLaunchSpecificationRootBlockDevice[]; /** * The maximum bid price per unit hour. */ spotPrice?: string; /** * The subnet in which to launch the requested instance. */ subnetId: string; /** * A map of tags to assign to the resource. .If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: { [key: string]: string; }; userData?: string; vpcSecurityGroupIds: string[]; /** * The capacity added to the fleet by a fulfilled request. */ weightedCapacity?: string; } interface SpotFleetRequestLaunchSpecificationEbsBlockDevice { deleteOnTermination?: boolean; deviceName: string; encrypted: boolean; iops: number; kmsKeyId: string; snapshotId: string; throughput: number; volumeSize: number; volumeType: string; } interface SpotFleetRequestLaunchSpecificationEphemeralBlockDevice { deviceName: string; virtualName: string; } interface SpotFleetRequestLaunchSpecificationRootBlockDevice { deleteOnTermination?: boolean; encrypted: boolean; iops: number; kmsKeyId: string; throughput: number; volumeSize: number; volumeType: string; } interface SpotFleetRequestLaunchTemplateConfig { /** * Launch template specification. See Launch Template Specification below for more details. */ launchTemplateSpecification: outputs.ec2.SpotFleetRequestLaunchTemplateConfigLaunchTemplateSpecification; /** * One or more override configurations. See Overrides below for more details. */ overrides?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverride[]; } interface SpotFleetRequestLaunchTemplateConfigLaunchTemplateSpecification { /** * The ID of the launch template. Conflicts with `name`. */ id?: string; /** * The name of the launch template. Conflicts with `id`. */ name?: string; /** * Template version. Unlike the autoscaling equivalent, does not support `$Latest` or `$Default`, so use the launchTemplate resource's attribute, e.g., `"${aws_launch_template.foo.latest_version}"`. It will use the default version if omitted. * * **Note:** The specified launch template can specify only a subset of the * inputs of `aws.ec2.LaunchTemplate`. There are limitations on * what you can specify as spot fleet does not support all the attributes that are supported by autoscaling groups. [AWS documentation](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#launch-templates-spot-fleet) is currently sparse, but at least `instanceInitiatedShutdownBehavior` is confirmed unsupported. */ version?: string; } interface SpotFleetRequestLaunchTemplateConfigOverride { /** * The availability zone in which to place the request. */ availabilityZone?: string; /** * The instance requirements. See below. */ instanceRequirements?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirements; /** * The type of instance to request. */ instanceType?: string; /** * The priority for the launch template override. The lower the number, the higher the priority. If no number is set, the launch template override has the lowest priority. */ priority: number; /** * The maximum spot bid for this override request. */ spotPrice: string; /** * The subnet in which to launch the requested instance. */ subnetId: string; /** * The capacity added to the fleet by a fulfilled request. */ weightedCapacity: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirements { /** * Block describing the minimum and maximum number of accelerators (GPUs, FPGAs, or AWS Inferentia chips). Default is no minimum or maximum. */ acceleratorCount?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorCount; /** * List of accelerator manufacturer names. Default is any manufacturer. * * ``` * Valid names: * * amazon-web-services * * amd * * nvidia * * xilinx * ``` */ acceleratorManufacturers?: string[]; /** * List of accelerator names. Default is any acclerator. * * ``` * Valid names: * * a100 - NVIDIA A100 GPUs * * v100 - NVIDIA V100 GPUs * * k80 - NVIDIA K80 GPUs * * t4 - NVIDIA T4 GPUs * * m60 - NVIDIA M60 GPUs * * radeon-pro-v520 - AMD Radeon Pro V520 GPUs * * vu9p - Xilinx VU9P FPGAs * ``` */ acceleratorNames?: string[]; /** * Block describing the minimum and maximum total memory of the accelerators. Default is no minimum or maximum. */ acceleratorTotalMemoryMib?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorTotalMemoryMib; /** * List of accelerator types. Default is any accelerator type. * * ``` * Valid types: * * fpga * * gpu * * inference * ``` */ acceleratorTypes?: string[]; /** * List of instance types to apply your specified attributes against. All other instance types are ignored, even if they match your specified attributes. You can use strings with one or more wild cards, represented by an asterisk (\*), to allow an instance type, size, or generation. The following are examples: `m5.8xlarge`, `c5*.*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are allowing the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are allowing all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is all instance types. * * > **NOTE:** If you specify `allowedInstanceTypes`, you can't specify `excludedInstanceTypes`. */ allowedInstanceTypes?: string[]; /** * Indicate whether bare metal instace types should be `included`, `excluded`, or `required`. Default is `excluded`. */ bareMetal?: string; /** * Block describing the minimum and maximum baseline EBS bandwidth, in Mbps. Default is no minimum or maximum. */ baselineEbsBandwidthMbps?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsBaselineEbsBandwidthMbps; /** * Indicate whether burstable performance instance types should be `included`, `excluded`, or `required`. Default is `excluded`. */ burstablePerformance?: string; /** * List of CPU manufacturer names. Default is any manufacturer. * * > **NOTE:** Don't confuse the CPU hardware manufacturer with the CPU hardware architecture. Instances will be launched with a compatible CPU architecture based on the AMI that you specify in your launch template. * * ``` * Valid names: * * amazon-web-services * * amd * * intel * ``` */ cpuManufacturers?: string[]; /** * List of instance types to exclude. You can use strings with one or more wild cards, represented by an asterisk (\*), to exclude an instance type, size, or generation. The following are examples: `m5.8xlarge`, `c5*.*`, `m5a.*`, `r*`, `*3*`. For example, if you specify `c5*`, you are excluding the entire C5 instance family, which includes all C5a and C5n instance types. If you specify `m5a.*`, you are excluding all the M5a instance types, but not the M5n instance types. Maximum of 400 entries in the list; each entry is limited to 30 characters. Default is no excluded instance types. * * > **NOTE:** If you specify `excludedInstanceTypes`, you can't specify `allowedInstanceTypes`. */ excludedInstanceTypes?: string[]; /** * List of instance generation names. Default is any generation. * * ``` * Valid names: * * current - Recommended for best performance. * * previous - For existing applications optimized for older instance types. * ``` */ instanceGenerations?: string[]; /** * Indicate whether instance types with local storage volumes are `included`, `excluded`, or `required`. Default is `included`. */ localStorage?: string; /** * List of local storage type names. Default any storage type. * * ``` * Value names: * * hdd - hard disk drive * * ssd - solid state drive * ``` */ localStorageTypes?: string[]; /** * Block describing the minimum and maximum amount of memory (GiB) per vCPU. Default is no minimum or maximum. */ memoryGibPerVcpu?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsMemoryGibPerVcpu; /** * Block describing the minimum and maximum amount of memory (MiB). Default is no maximum. */ memoryMib?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsMemoryMib; /** * Block describing the minimum and maximum amount of network bandwidth, in gigabits per second (Gbps). Default is no minimum or maximum. */ networkBandwidthGbps?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsNetworkBandwidthGbps; /** * Block describing the minimum and maximum number of network interfaces. Default is no minimum or maximum. */ networkInterfaceCount?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsNetworkInterfaceCount; /** * The price protection threshold for On-Demand Instances. This is the maximum you’ll pay for an On-Demand Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 20. * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ onDemandMaxPricePercentageOverLowestPrice?: number; /** * Indicate whether instance types must support On-Demand Instance Hibernation, either `true` or `false`. Default is `false`. */ requireHibernateSupport?: boolean; /** * The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage higher than the cheapest M, C, or R instance type with your specified attributes. When Amazon EC2 Auto Scaling selects instance types with your attributes, we will exclude instance types whose price is higher than your threshold. The parameter accepts an integer, which Amazon EC2 Auto Scaling interprets as a percentage. To turn off price protection, specify a high value, such as 999999. Default is 100. * * If you set DesiredCapacityType to vcpu or memory-mib, the price protection threshold is applied based on the per vCPU or per memory price instead of the per instance price. */ spotMaxPricePercentageOverLowestPrice?: number; /** * Block describing the minimum and maximum total local storage (GB). Default is no minimum or maximum. */ totalLocalStorageGb?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsTotalLocalStorageGb; /** * Block describing the minimum and maximum number of vCPUs. Default is no maximum. */ vcpuCount?: outputs.ec2.SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsVcpuCount; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorCount { /** * Maximum. Set to `0` to exclude instance types with accelerators. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsAcceleratorTotalMemoryMib { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsBaselineEbsBandwidthMbps { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsMemoryGibPerVcpu { /** * Maximum. May be a decimal number, e.g. `0.5`. */ max?: number; /** * Minimum. May be a decimal number, e.g. `0.5`. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsMemoryMib { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsNetworkBandwidthGbps { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsNetworkInterfaceCount { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsTotalLocalStorageGb { /** * Maximum. May be a decimal number, e.g. `0.5`. */ max?: number; /** * Minimum. May be a decimal number, e.g. `0.5`. */ min?: number; } interface SpotFleetRequestLaunchTemplateConfigOverrideInstanceRequirementsVcpuCount { /** * Maximum. */ max?: number; /** * Minimum. */ min?: number; } interface SpotFleetRequestSpotMaintenanceStrategies { /** * Nested argument containing the capacity rebalance for your fleet request. Defined below. */ capacityRebalance?: outputs.ec2.SpotFleetRequestSpotMaintenanceStrategiesCapacityRebalance; } interface SpotFleetRequestSpotMaintenanceStrategiesCapacityRebalance { /** * The replacement strategy to use. Only available for spot fleets with `fleetType` set to `maintain`. Valid values: `launch`. */ replacementStrategy?: string; } interface SpotInstanceRequestCapacityReservationSpecification { /** * Indicates the instance's Capacity Reservation preferences. Can be `"open"` or `"none"`. (Default: `"open"`). */ capacityReservationPreference?: string; /** * Information about the target Capacity Reservation. See Capacity Reservation Target below for more details. * * For more information, see the documentation on [Capacity Reservations](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/capacity-reservations-using.html). */ capacityReservationTarget?: outputs.ec2.SpotInstanceRequestCapacityReservationSpecificationCapacityReservationTarget; } interface SpotInstanceRequestCapacityReservationSpecificationCapacityReservationTarget { /** * ID of the Capacity Reservation in which to run the instance. */ capacityReservationId?: string; /** * ARN of the Capacity Reservation resource group in which to run the instance. */ capacityReservationResourceGroupArn?: string; } interface SpotInstanceRequestCpuOptions { /** * Indicates whether to enable the instance for AMD SEV-SNP. AMD SEV-SNP is supported with M6a, R6a, and C6a instance types only. Valid values are `enabled` and `disabled`. */ amdSevSnp: string; /** * Sets the number of CPU cores for an instance. This option is only supported on creation of instance type that support CPU Options [CPU Cores and Threads Per CPU Core Per Instance Type](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html#cpu-options-supported-instances-values) - specifying this option for unsupported instance types will return an error from the EC2 API. */ coreCount: number; /** * Indicates whether to enable the instance for nested virtualization. Nested virtualization is supported on 8th generation Intel-based instance types (C8i, M8i, R8i, and their flex variants) only. When nested virtualization is enabled, Virtual Secure Mode (VSM) is automatically disabled for the instance. Valid values are `enabled` and `disabled`. */ nestedVirtualization: string; /** * If set to 1, hyperthreading is disabled on the launched instance. Defaults to 2 if not set. See [Optimizing CPU Options](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html) for more information. * * For more information, see the documentation on [Optimizing CPU options](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html). */ threadsPerCore: number; } interface SpotInstanceRequestCreditSpecification { /** * Credit option for CPU usage. Valid values include `standard` or `unlimited`. T3 instances are launched as unlimited by default. T2 instances are launched as standard by default. */ cpuCredits?: string; } interface SpotInstanceRequestEbsBlockDevice { /** * Whether the volume should be destroyed on instance termination. Defaults to `true`. */ deleteOnTermination?: boolean; /** * Name of the device to mount. */ deviceName: string; /** * Enables [EBS encryption](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html) on the volume. Defaults to `false`. Cannot be used with `snapshotId`. Must be configured to perform drift detection. */ encrypted: boolean; /** * Amount of provisioned [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). Only valid for volumeType of `io1`, `io2` or `gp3`. */ iops: number; /** * ARN of the KMS Key to use when encrypting the volume. Must be configured to perform drift detection. */ kmsKeyId: string; /** * Snapshot ID to mount. */ snapshotId: string; /** * Map of tags to assign to the device. **Note:** Tags specified here are applied after instance creation via a separate API call. This means they cannot be used with IAM policies that require tags during resource creation (e.g., ABAC policies with `ec2:CreateAction` conditions or SCPs requiring volume tags). For ABAC compliance, use `volumeTags` instead, which applies uniform tags to all volumes during instance creation. */ tags?: { [key: string]: string; }; /** * A map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll: { [key: string]: string; }; /** * Throughput to provision for a volume in mebibytes per second (MiB/s). This is only valid for `volumeType` of `gp3`. */ throughput: number; volumeId: string; /** * Size of the volume in gibibytes (GiB). */ volumeSize: number; /** * Type of volume. Valid values include `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1`, or `st1`. Defaults to `gp2`. * * > **NOTE:** Currently, changes to the `ebsBlockDevice` configuration of _existing_ resources cannot be automatically detected by this provider. To manage changes and attachments of an EBS block to an instance, use the `aws.ebs.Volume` and `aws.ec2.VolumeAttachment` resources instead. If you use `ebsBlockDevice` on an `aws.ec2.Instance`, this provider will assume management over the full set of non-root EBS block devices for the instance, treating additional block devices as drift. For this reason, `ebsBlockDevice` cannot be mixed with external `aws.ebs.Volume` and `aws.ec2.VolumeAttachment` resources for a given instance. */ volumeType: string; } interface SpotInstanceRequestEnclaveOptions { /** * Whether Nitro Enclaves will be enabled on the instance. Defaults to `false`. * * For more information, see the documentation on [Nitro Enclaves](https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html). */ enabled: boolean; } interface SpotInstanceRequestEphemeralBlockDevice { /** * Name of the block device to mount on the instance. */ deviceName: string; /** * Suppresses the specified device included in the AMI's block device mapping. */ noDevice?: boolean; /** * [Instance Store Device Name](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html#InstanceStoreDeviceNames) (e.g., `ephemeral0`). * * Each AWS Instance type has a different set of Instance Store block devices available for attachment. AWS [publishes a list](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html#StorageOnInstanceTypes) of which ephemeral devices are available on each type. The devices are always identified by the `virtualName` in the format `ephemeral{0..N}`. */ virtualName?: string; } interface SpotInstanceRequestLaunchTemplate { /** * ID of the launch template. Conflicts with `name`. */ id: string; /** * Name of the launch template. Conflicts with `id`. */ name: string; /** * Template version. Can be a specific version number, `$Latest` or `$Default`. The default value is `$Default`. */ version?: string; } interface SpotInstanceRequestMaintenanceOptions { /** * Automatic recovery behavior of the Instance. Can be `"default"` or `"disabled"`. See [Recover your instance](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-recover.html) for more details. */ autoRecovery: string; } interface SpotInstanceRequestMetadataOptions { /** * Whether the metadata service is available. Valid values include `enabled` or `disabled`. Defaults to `enabled`. */ httpEndpoint?: string; /** * Whether the IPv6 endpoint for the instance metadata service is enabled. Defaults to `disabled`. */ httpProtocolIpv6?: string; /** * Desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel. Valid values are integer from `1` to `64`. Defaults to `1`. */ httpPutResponseHopLimit: number; /** * Whether or not the metadata service requires session tokens, also referred to as _Instance Metadata Service Version 2 (IMDSv2)_. Valid values include `optional` or `required`. */ httpTokens: string; /** * Enables or disables access to instance tags from the instance metadata service. Valid values include `enabled` or `disabled`. Defaults to `disabled`. * * For more information, see the documentation on the [Instance Metadata Service](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html). */ instanceMetadataTags: string; } interface SpotInstanceRequestNetworkInterface { /** * Whether or not to delete the network interface on instance termination. Defaults to `false`. Currently, the only valid value is `false`, as this is only supported when creating new network interfaces when launching an instance. */ deleteOnTermination?: boolean; /** * Integer index of the network interface attachment. Limited by instance type. */ deviceIndex: number; /** * Integer index of the network card. Limited by instance type. The default index is `0`. */ networkCardIndex: number; /** * ID of the network interface to attach. */ networkInterfaceId: string; } interface SpotInstanceRequestPrimaryNetworkInterface { /** * Whether the network interface will be deleted when the instance terminates. */ deleteOnTermination: boolean; /** * ID of the network interface to attach. */ networkInterfaceId: string; } interface SpotInstanceRequestPrivateDnsNameOptions { /** * Indicates whether to respond to DNS queries for instance hostnames with DNS A records. */ enableResourceNameDnsARecord: boolean; /** * Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records. */ enableResourceNameDnsAaaaRecord: boolean; /** * Type of hostname for Amazon EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 native subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID. Valid values: `ip-name` and `resource-name`. */ hostnameType: string; } interface SpotInstanceRequestRootBlockDevice { /** * Whether the volume should be destroyed on instance termination. Defaults to `true`. */ deleteOnTermination?: boolean; deviceName: string; /** * Whether to enable volume encryption. Defaults to `false`. Must be configured to perform drift detection. */ encrypted: boolean; /** * Amount of provisioned [IOPS](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-io-characteristics.html). Only valid for volumeType of `io1`, `io2` or `gp3`. */ iops: number; /** * ARN of the KMS Key to use when encrypting the volume. Must be configured to perform drift detection. */ kmsKeyId: string; /** * Map of tags to assign to the device. **Note:** Tags specified here are applied after instance creation via a separate API call. This means they cannot be used with IAM policies that require tags during resource creation (e.g., ABAC policies with `ec2:CreateAction` conditions or SCPs requiring volume tags). For ABAC compliance, use `volumeTags` instead, which applies uniform tags to all volumes during instance creation. */ tags?: { [key: string]: string; }; /** * A map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll: { [key: string]: string; }; /** * Throughput to provision for a volume in mebibytes per second (MiB/s). This is only valid for `volumeType` of `gp3`. */ throughput: number; volumeId: string; /** * Size of the volume in gibibytes (GiB). */ volumeSize: number; /** * Type of volume. Valid values include `standard`, `gp2`, `gp3`, `io1`, `io2`, `sc1`, or `st1`. Defaults to the volume type that the AMI uses. * * Modifying the `encrypted` or `kmsKeyId` settings of the `rootBlockDevice` requires resource replacement. */ volumeType: string; } interface SpotInstanceRequestSecondaryNetworkInterface { /** * Whether the network interface should be destroyed when the instance is terminated. Defaults to `true`. Forces replacement. */ deleteOnTermination?: boolean; /** * Device index for the network interface attachment. Defaults to `0`. Forces replacement. */ deviceIndex?: number; /** * Type of network interface. Currently only `secondary` is supported. Defaults to `secondary`. Forces replacement. */ interfaceType?: string; macAddress: string; /** * Network card index for the interface. Each network card can have one secondary interface. Forces replacement. */ networkCardIndex: number; /** * Number of private IP addresses to assign to the network interface. Defaults to `1`. Forces replacement. */ privateIpAddressCount?: number; /** * List of private IP addresses to assign to the network interface. If not specified, AWS will automatically assign IP addresses based on `privateIpAddressCount`. Forces replacement. */ privateIpAddresses: string[]; secondaryInterfaceId: string; secondaryNetworkId: string; /** * ID of the secondary subnet in which to create the network interface. Forces replacement. */ secondarySubnetId: string; /** * Controls if traffic is routed to the instance when the destination address does not match the instance. Used for NAT or VPNs. Defaults true. */ sourceDestCheck: boolean; status: string; } interface TrafficMirrorFilterRuleDestinationPortRange { /** * Starting port of the range */ fromPort?: number; /** * Ending port of the range */ toPort?: number; } interface TrafficMirrorFilterRuleSourcePortRange { /** * Starting port of the range */ fromPort?: number; /** * Ending port of the range */ toPort?: number; } interface VpcBlockPublicAccessExclusionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface VpcBlockPublicAccessOptionsTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface VpcEncryptionControlResourceExclusions { /** * `state` and `stateMessage` describing encryption enforcement state for Egress-Only Internet Gateways. */ egressOnlyInternetGateway: outputs.ec2.VpcEncryptionControlResourceExclusionsEgressOnlyInternetGateway; /** * `state` and `stateMessage` describing encryption enforcement state for Elastic File System (EFS). */ elasticFileSystem: outputs.ec2.VpcEncryptionControlResourceExclusionsElasticFileSystem; /** * `state` and `stateMessage` describing encryption enforcement state for Internet Gateways. */ internetGateway: outputs.ec2.VpcEncryptionControlResourceExclusionsInternetGateway; /** * `state` and `stateMessage` describing encryption enforcement state for Lambda Functions. */ lambda: outputs.ec2.VpcEncryptionControlResourceExclusionsLambda; /** * `state` and `stateMessage` describing encryption enforcement state for NAT Gateways. */ natGateway: outputs.ec2.VpcEncryptionControlResourceExclusionsNatGateway; /** * `state` and `stateMessage` describing encryption enforcement state for Virtual Private Gateways. */ virtualPrivateGateway: outputs.ec2.VpcEncryptionControlResourceExclusionsVirtualPrivateGateway; /** * `state` and `stateMessage` describing encryption enforcement state for VPC Lattice. */ vpcLattice: outputs.ec2.VpcEncryptionControlResourceExclusionsVpcLattice; /** * `state` and `stateMessage` describing encryption enforcement state for peered VPCs. */ vpcPeering: outputs.ec2.VpcEncryptionControlResourceExclusionsVpcPeering; } interface VpcEncryptionControlResourceExclusionsEgressOnlyInternetGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsElasticFileSystem { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsInternetGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsLambda { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsNatGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsVirtualPrivateGateway { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsVpcLattice { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlResourceExclusionsVpcPeering { /** * The current state of the VPC Encryption Control. */ state: string; /** * A message providing additional information about the state of the VPC Encryption Control. */ stateMessage: string; } interface VpcEncryptionControlTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface VpcEndpointDnsEntry { /** * The DNS name. */ dnsName: string; /** * The ID of the private hosted zone. */ hostedZoneId: string; } interface VpcEndpointDnsOptions { /** * The DNS records created for the endpoint. Valid values are `ipv4`, `dualstack`, `service-defined`, and `ipv6`. */ dnsRecordIpType: string; /** * Boolean indicating whether to enable private DNS only for inbound endpoints. This option is available only for interface endpoints of services that support both gateway and interface endpoints. A gateway endpoint for the same service must be created before an interface endpoint is created. Traffic originating from the VPC is routed to the gateway endpoint, while traffic originating from on-premises is routed to the interface endpoint. Defaults to `false`. This argument can be specified only if `privateDnsEnabled` is `true`. */ privateDnsOnlyForInboundResolverEndpoint?: boolean; /** * Preference for which private domains have a private hosted zone created for and associated with the specified VPC. Valid values are `ALL_DOMAINS`, `VERIFIED_DOMAINS_ONLY`, `VERIFIED_DOMAINS_AND_SPECIFIED_DOMAINS`, and `SPECIFIED_DOMAINS_ONLY`. Only supported when `privateDnsEnabled` is `true` and when the `vpcEndpointType` is `ServiceNetwork` or `Resource`. */ privateDnsPreference: string; /** * List of private domains to create private hosted zones for and associate with the specified VPC. Must be specified when `privateDnsEnabled` is `true` and `privateDnsPreference` is set to either `VERIFIED_DOMAINS_AND_SPECIFIED_DOMAINS` or `SPECIFIED_DOMAINS_ONLY`. In all other cases, this argument must not be specified. */ privateDnsSpecifiedDomains: string[]; } interface VpcEndpointServicePrivateDnsNameConfiguration { /** * Name of the record subdomain the service provider needs to create. */ name: string; /** * Verification state of the VPC endpoint service. Consumers of the endpoint service can use the private name only when the state is `verified`. */ state: string; /** * Endpoint service verification type, for example `TXT`. */ type: string; /** * Value the service provider adds to the private DNS name domain record before verification. */ value: string; } interface VpcEndpointSubnetConfiguration { /** * The IPv4 address to assign to the endpoint network interface in the subnet. You must provide an IPv4 address if the VPC endpoint supports IPv4. */ ipv4?: string; /** * The IPv6 address to assign to the endpoint network interface in the subnet. You must provide an IPv6 address if the VPC endpoint supports IPv6. */ ipv6?: string; /** * The ID of the subnet. Must have a corresponding subnet in the `subnetIds` argument. */ subnetId?: string; } interface VpcIpamOperatingRegion { /** * The name of the Region you want to add to the IPAM. */ regionName: string; } interface VpcIpamPoolCidrCidrAuthorizationContext { /** * The plain-text authorization message for the prefix and account. */ message?: string; /** * The signed authorization message for the prefix and account. */ signature?: string; } interface VpcIpamPoolSourceResource { /** * ID of the resource. */ resourceId: string; /** * Owner of the resource. */ resourceOwner: string; /** * Region where the resource exists. Must match the `locale` of the parent IPAM Pool. */ resourceRegion: string; /** * Type of the resource. (`vpc`) */ resourceType: string; } interface VpcIpamResourceDiscoveryOperatingRegion { /** * The name of the Region you want to add to the IPAM. */ regionName: string; } interface VpcIpamResourceDiscoveryOrganizationalUnitExclusion { /** * AWS Organizations entity path. Build the path for the OU(s) using AWS Organizations IDs separated by a `/`. Include all child OUs by ending the path with `/*`. */ organizationsEntityPath: string; } interface VpcPeeringConnectionAccepter { /** * Allow a local VPC to resolve public DNS hostnames to * private IP addresses when queried from instances in the peer VPC. */ allowRemoteVpcDnsResolution?: boolean; } interface VpcPeeringConnectionAccepterAccepter { /** * Indicates whether a local VPC can resolve public DNS hostnames to * private IP addresses when queried from instances in a peer VPC. */ allowRemoteVpcDnsResolution?: boolean; } interface VpcPeeringConnectionAccepterRequester { /** * Indicates whether a local VPC can resolve public DNS hostnames to * private IP addresses when queried from instances in a peer VPC. */ allowRemoteVpcDnsResolution?: boolean; } interface VpcPeeringConnectionRequester { /** * Allow a local VPC to resolve public DNS hostnames to * private IP addresses when queried from instances in the peer VPC. */ allowRemoteVpcDnsResolution?: boolean; } interface VpnConnectionRoute { /** * The CIDR block associated with the local subnet of the customer data center. */ destinationCidrBlock: string; /** * Indicates how the routes were provided. */ source: string; /** * The current state of the static route. */ state: string; } interface VpnConnectionTunnel1LogOptions { /** * Options for sending VPN tunnel logs to CloudWatch. See CloudWatch Log Options below for more details. */ cloudwatchLogOptions: outputs.ec2.VpnConnectionTunnel1LogOptionsCloudwatchLogOptions; } interface VpnConnectionTunnel1LogOptionsCloudwatchLogOptions { /** * Enable or disable BGP logging feature. The default is `false`. */ bgpLogEnabled?: boolean; /** * ARN of the CloudWatch log group to send BGP logs to. */ bgpLogGroupArn?: string; /** * Set BGP log format. Default format is json. Possible values are: `json` and `text`. The default is `json`. */ bgpLogOutputFormat?: string; /** * Enable or disable VPN tunnel logging feature. The default is `false`. */ logEnabled?: boolean; /** * ARN of the CloudWatch log group to send logs to. */ logGroupArn?: string; /** * Set log format. Default format is json. Possible values are: `json` and `text`. The default is `json`. */ logOutputFormat?: string; } interface VpnConnectionTunnel2LogOptions { /** * Options for sending VPN tunnel logs to CloudWatch. See CloudWatch Log Options below for more details. */ cloudwatchLogOptions: outputs.ec2.VpnConnectionTunnel2LogOptionsCloudwatchLogOptions; } interface VpnConnectionTunnel2LogOptionsCloudwatchLogOptions { /** * Enable or disable BGP logging feature. The default is `false`. */ bgpLogEnabled?: boolean; /** * ARN of the CloudWatch log group to send BGP logs to. */ bgpLogGroupArn?: string; /** * Set BGP log format. Default format is json. Possible values are: `json` and `text`. The default is `json`. */ bgpLogOutputFormat?: string; /** * Enable or disable VPN tunnel logging feature. The default is `false`. */ logEnabled?: boolean; /** * ARN of the CloudWatch log group to send logs to. */ logGroupArn?: string; /** * Set log format. Default format is json. Possible values are: `json` and `text`. The default is `json`. */ logOutputFormat?: string; } interface VpnConnectionVgwTelemetry { /** * The number of accepted routes. */ acceptedRouteCount: number; /** * ARN of the VPN tunnel endpoint certificate. */ certificateArn: string; /** * The date and time of the last change in status. */ lastStatusChange: string; /** * The Internet-routable IP address of the virtual private gateway's outside interface. */ outsideIpAddress: string; /** * The status of the VPN tunnel. */ status: string; /** * If an error occurs, a description of the error. */ statusMessage: string; } } export declare namespace ec2clientvpn { interface EndpointAuthenticationOption { /** * The ID of the Active Directory to be used for authentication if type is `directory-service-authentication`. */ activeDirectoryId?: string; /** * The ARN of the client certificate. The certificate must be signed by a certificate authority (CA) and it must be provisioned in AWS Certificate Manager (ACM). Only necessary when type is set to `certificate-authentication`. */ rootCertificateChainArn?: string; /** * The ARN of the IAM SAML identity provider if type is `federated-authentication`. */ samlProviderArn?: string; /** * The ARN of the IAM SAML identity provider for the self service portal if type is `federated-authentication`. */ selfServiceSamlProviderArn?: string; /** * The type of client authentication to be used. Specify `certificate-authentication` to use certificate-based authentication, `directory-service-authentication` to use Active Directory authentication, or `federated-authentication` to use Federated Authentication via SAML 2.0. */ type: string; } interface EndpointClientConnectOptions { /** * Indicates whether client connect options are enabled. The default is `false` (not enabled). */ enabled: boolean; /** * ARN of the Lambda function used for connection authorization. */ lambdaFunctionArn: string; } interface EndpointClientLoginBannerOptions { /** * Customizable text that will be displayed in a banner on AWS provided clients when a VPN session is established. UTF-8 encoded characters only. Maximum of 1400 characters. */ bannerText: string; /** * Enable or disable a customizable text banner that will be displayed on AWS provided clients when a VPN session is established. The default is `false` (not enabled). */ enabled: boolean; } interface EndpointClientRouteEnforcementOptions { /** * Enable or disable Client Route Enforcement. The default is `false` (not enabled). */ enforced: boolean; } interface EndpointConnectionLogOptions { /** * The name of the CloudWatch Logs log group. */ cloudwatchLogGroup?: string; /** * The name of the CloudWatch Logs log stream to which the connection data is published. */ cloudwatchLogStream: string; /** * Indicates whether connection logging is enabled. */ enabled: boolean; } interface EndpointTransitGatewayConfiguration { /** * List of availability zone IDs in which the transit gateway is present. Conflicts with `availabilityZones`. */ availabilityZoneIds: string[]; /** * List of availability zones in which the transit gateway is present. Conflicts with `availabilityZoneIds`. */ availabilityZones?: string[]; /** * ID of the Transit Gateway attachment. */ transitGatewayAttachmentId: string; /** * ID of the Transit Gateway to which the Client VPN endpoint is associated. */ transitGatewayId?: string; } interface GetEndpointAuthenticationOption { activeDirectoryId: string; rootCertificateChainArn: string; samlProviderArn: string; selfServiceSamlProviderArn: string; type: string; } interface GetEndpointClientConnectOption { enabled: boolean; lambdaFunctionArn: string; } interface GetEndpointClientLoginBannerOption { bannerText: string; enabled: boolean; } interface GetEndpointClientRouteEnforcementOption { enforced: boolean; } interface GetEndpointConnectionLogOption { cloudwatchLogGroup: string; cloudwatchLogStream: string; enabled: boolean; } interface GetEndpointFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnEndpoints.html). */ name: string; /** * Set of values that are accepted for the given field. An endpoint will be selected if any one of the given values matches. */ values: string[]; } interface GetEndpointTransitGatewayConfiguration { availabilityZoneIds: string[]; availabilityZones: string[]; transitGatewayAttachmentId: string; transitGatewayId: string; } } export declare namespace ec2transitgateway { interface DefaultRouteTableAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DefaultRouteTablePropagationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GetAttachmentFilter { /** * Name of the field to filter by, as defined by the [underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html). */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetAttachmentsFilter { /** * Name of the filter check available value on [official documentation](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html) */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetConnectFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetConnectPeerFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetDirectConnectGatewayAttachmentFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeTransitGatewayAttachments API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetMulticastDomainAssociation { /** * The ID of the subnet associated with the transit gateway multicast domain. */ subnetId: string; /** * The ID of the transit gateway attachment. */ transitGatewayAttachmentId: string; } interface GetMulticastDomainFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayMulticastDomains.html). */ name: string; /** * Set of values that are accepted for the given field. A multicast domain will be selected if any one of the given values matches. */ values: string[]; } interface GetMulticastDomainMember { /** * The IP address assigned to the transit gateway multicast group. */ groupIpAddress: string; /** * The group members' network interface ID. */ networkInterfaceId: string; } interface GetMulticastDomainSource { /** * The IP address assigned to the transit gateway multicast group. */ groupIpAddress: string; /** * The group members' network interface ID. */ networkInterfaceId: string; } interface GetPeeringAttachmentFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayPeeringAttachments.html). */ name: string; /** * Set of values that are accepted for the given field. * An EC2 Transit Gateway Peering Attachment be selected if any one of the given values matches. */ values: string[]; } interface GetPeeringAttachmentsFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayPeeringAttachments.html) */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetRouteTableAssociationsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayRouteTableAssociations.html). */ name: string; /** * Set of values that are accepted for the given field. * A Transit Gateway Route Table will be selected if any one of the given values matches. */ values: string[]; } interface GetRouteTableFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetRouteTablePropagationsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayRouteTablePropagations.html). */ name: string; /** * Set of values that are accepted for the given field. * A Transit Gateway Route Table will be selected if any one of the given values matches. */ values: string[]; } interface GetRouteTableRoutesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayRoutes.html). */ name: string; /** * Set of values that are accepted for the given field. */ values: string[]; } interface GetRouteTableRoutesRoute { /** * The CIDR used for route destination matches. */ destinationCidrBlock: string; /** * The ID of the prefix list used for destination matches. */ prefixListId: string; /** * The current state of the route, can be `active`, `deleted`, `pending`, `blackhole`, `deleting`. */ state: string; /** * The id of the transit gateway route table announcement, most of the time it is an empty string. */ transitGatewayRouteTableAnnouncementId: string; /** * The type of the route, can be `propagated` or `static`. */ type: string; } interface GetTransitGatewayFilter { /** * Name of the field to filter by, as defined by the [underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGateways.html). */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetVpcAttachmentFilter { /** * Name of the filter. */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetVpcAttachmentsFilter { /** * Name of the filter check available value on [official documentation](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayVpcAttachments.html) */ name: string; /** * List of one or more values for the filter. */ values: string[]; } interface GetVpnAttachmentFilter { /** * Name of the filter field. Valid values can be found in the [EC2 DescribeTransitGatewayAttachments API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface InstanceConnectEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface MeteringPolicyEntryTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface MeteringPolicyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface PeeringAttachmentOptions { /** * Indicates whether dynamic routing is enabled or disabled.. Supports `enable` and `disable`. */ dynamicRouting?: string; } interface PolicyTableEntryPolicyRule { /** * Destination CIDR block to match. If not specified, all destination CIDR blocks are matched. */ destinationCidrBlock?: string; /** * Destination port or port range to match (e.g., `443` or `1024-65535`). Only valid when `protocol` is `6` (TCP) or `17` (UDP). */ destinationPortRange: string; /** * Metadata key/value tag associated with the policy rule. See below. */ metadata?: outputs.ec2transitgateway.PolicyTableEntryPolicyRuleMetadata; /** * Protocol number to match (e.g., `6` for TCP, `17` for UDP). If not specified, all protocols are matched. */ protocol?: string; /** * Source CIDR block to match. If not specified, all source CIDR blocks are matched. */ sourceCidrBlock?: string; /** * Source port or port range to match (e.g., `443` or `1024-65535`). Only valid when `protocol` is `6` (TCP) or `17` (UDP). */ sourcePortRange: string; } interface PolicyTableEntryPolicyRuleMetadata { /** * Metadata key name for the policy rule. */ key?: string; /** * Metadata key value for the policy rule. * * > **Note:** The EC2 API does not return policy rule metadata when describing transit gateway policy table entries, so Terraform cannot detect drift in `metadata` or recover its value when importing this resource. Configure `metadata` explicitly if you need it managed. */ value?: string; } } export declare namespace ecr { interface GetImagesImageId { /** * The sha256 digest of the image manifest. */ imageDigest: string; /** * The tag associated with the image. */ imageTag: string; } interface GetLifecyclePolicyDocumentRule { /** * Specifies the action to take. */ action?: outputs.ecr.GetLifecyclePolicyDocumentRuleAction; /** * Describes the purpose of a rule within a lifecycle policy. */ description?: string; /** * Sets the order in which rules are evaluated, lowest to highest. When you add rules to a lifecycle policy, you must give them each a unique value for `priority`. Values do not need to be sequential across rules in a policy. A rule with a `tagStatus` value of `any` must have the highest value for `priority` and be evaluated last. */ priority: number; /** * Collects parameters describing the selection criteria for the ECR lifecycle policy: */ selection: outputs.ecr.GetLifecyclePolicyDocumentRuleSelection; } interface GetLifecyclePolicyDocumentRuleAction { /** * The storage class you want the lifecycle policy to transition the image to. `archive` is the only supported value. */ targetStorageClass?: string; /** * Specify an action type. The supported values are `expire` (to delete images) and `transition` (to move images to archive storage). */ type: string; } interface GetLifecyclePolicyDocumentRuleSelection { /** * Specify a count number. If the `countType` used is `imageCountMoreThan`, then the value is the maximum number of images that you want to retain in your repository. If the `countType` used is `sinceImagePushed`, then the value is the maximum age limit for your images. If the `countType` used is `sinceImagePulled`, then the value is the maximum number of days since the image was last pulled. If the `countType` used is `sinceImageTransitioned`, then the value is the maximum number of days since the image was archived. */ countNumber: number; /** * Specify a count type to apply to the images. If `countType` is set to `imageCountMoreThan`, you also specify `countNumber` to create a rule that sets a limit on the number of images that exist in your repository. If `countType` is set to `sinceImagePushed`, `sinceImagePulled`, or `sinceImageTransitioned`, you also specify `countUnit` and `countNumber` to specify a time limit on the images that exist in your repository. */ countType: string; /** * Specify a count unit of `days` to indicate that as the unit of time, in addition to `countNumber`, which is the number of days. */ countUnit?: string; /** * The rule will only select images of this storage class. When using a `countType` of `imageCountMoreThan`, `sinceImagePushed`, or `sinceImagePulled`, the only supported value is `standard`. When using a `countType` of `sinceImageTransitioned`, this is required, and the only supported value is `archive`. If you omit this, the value of `standard` will be used. */ storageClass?: string; /** * You must specify a comma-separated list of image tag patterns that may contain wildcards (\*) on which to take action with your lifecycle policy. For example, if your images are tagged as `prod`, `prod1`, `prod2`, and so on, you would use the tag pattern list `["prod\*"]` to specify all of them. If you specify multiple tags, only the images with all specified tags are selected. There is a maximum limit of four wildcards (\*) per string. For example, `["*test*1*2*3", "test*1*2*3*"]` is valid but `["test*1*2*3*4*5*6"]` is invalid. */ tagPatternLists?: string[]; /** * You must specify a comma-separated list of image tag prefixes on which to take action with your lifecycle policy. For example, if your images are tagged as `prod`, `prod1`, `prod2`, and so on, you would use the tag prefix "prod" to specify all of them. If you specify multiple tags, only images with all specified tags are selected. */ tagPrefixLists?: string[]; /** * Determines whether the lifecycle policy rule that you are adding specifies a tag for an image. Acceptable options are `tagged`, `untagged`, or `any`. If you specify `any`, then all images have the rule evaluated against them. If you specify `tagged`, then you must also specify a `tagPrefixList` value or a `tagPatternList` value. If you specify `untagged`, then you must omit both `tagPrefixList` and `tagPatternList`. */ tagStatus: string; } interface GetRepositoryCreationTemplateEncryptionConfiguration { /** * Encryption type to use for any created repositories, either `AES256` or `KMS`. */ encryptionType: string; /** * If `encryptionType` is `KMS`, the ARN of the KMS key used. */ kmsKey: string; } interface GetRepositoryCreationTemplateImageTagMutabilityExclusionFilter { /** * The filter pattern to use for excluding image tags from the mutability setting. */ filter: string; /** * The type of filter to use. */ filterType: string; } interface GetRepositoryEncryptionConfiguration { /** * Encryption type to use for the repository, either `AES256` or `KMS`. */ encryptionType: string; /** * If `encryptionType` is `KMS`, the ARN of the KMS key used. */ kmsKey: string; } interface GetRepositoryImageScanningConfiguration { /** * Whether images are scanned after being pushed to the repository. */ scanOnPush: boolean; } interface GetRepositoryImageTagMutabilityExclusionFilter { /** * The filter pattern to use for excluding image tags from the mutability setting. */ filter: string; /** * The type of filter to use. */ filterType: string; } interface RegistryScanningConfigurationRule { /** * One or more repository filter blocks, containing a `filter` (required string filtering repositories, see pattern regex [here](https://docs.aws.amazon.com/AmazonECR/latest/APIReference/API_ScanningRepositoryFilter.html)) and a `filterType` (required string, currently only `WILDCARD` is supported). */ repositoryFilters: outputs.ecr.RegistryScanningConfigurationRuleRepositoryFilter[]; /** * The frequency that scans are performed at for a private registry. Can be `SCAN_ON_PUSH`, `CONTINUOUS_SCAN`, or `MANUAL`. */ scanFrequency: string; } interface RegistryScanningConfigurationRuleRepositoryFilter { filter: string; filterType: string; } interface ReplicationConfigurationReplicationConfiguration { /** * The replication rules for a replication configuration. A maximum of 10 are allowed per `replicationConfiguration`. See Rule */ rules: outputs.ecr.ReplicationConfigurationReplicationConfigurationRule[]; } interface ReplicationConfigurationReplicationConfigurationRule { /** * the details of a replication destination. A maximum of 25 are allowed per `rule`. See Destination. */ destinations: outputs.ecr.ReplicationConfigurationReplicationConfigurationRuleDestination[]; /** * filters for a replication rule. See Repository Filter. */ repositoryFilters?: outputs.ecr.ReplicationConfigurationReplicationConfigurationRuleRepositoryFilter[]; } interface ReplicationConfigurationReplicationConfigurationRuleDestination { /** * A Region to replicate to. */ region: string; /** * The account ID of the destination registry to replicate to. */ registryId: string; } interface ReplicationConfigurationReplicationConfigurationRuleRepositoryFilter { /** * The repository filter details. */ filter: string; /** * The repository filter type. The only supported value is `PREFIX_MATCH`, which is a repository name prefix specified with the filter parameter. */ filterType: string; } interface RepositoryCreationTemplateEncryptionConfiguration { /** * The encryption type to use for any created repositories. Valid values are `AES256` or `KMS`. Defaults to `AES256`. */ encryptionType?: string; /** * The ARN of the KMS key to use when `encryptionType` is `KMS`. If not specified, uses the default AWS managed key for ECR. */ kmsKey: string; } interface RepositoryCreationTemplateImageTagMutabilityExclusionFilter { /** * The filter pattern to use for excluding image tags from the mutability setting. Must contain only letters, numbers, and special characters (._*-). Each filter can be up to 128 characters long and can contain a maximum of 2 wildcards (*). */ filter: string; /** * The type of filter to use. Must be `WILDCARD`. */ filterType: string; } interface RepositoryEncryptionConfiguration { /** * The encryption type to use for the repository. Valid values are `AES256` or `KMS`. Defaults to `AES256`. */ encryptionType?: string; /** * The ARN of the KMS key to use when `encryptionType` is `KMS`. If not specified, uses the default AWS managed key for ECR. */ kmsKey: string; } interface RepositoryImageScanningConfiguration { /** * Indicates whether images are scanned after being pushed to the repository (true) or not scanned (false). */ scanOnPush: boolean; } interface RepositoryImageTagMutabilityExclusionFilter { /** * The filter pattern to use for excluding image tags from the mutability setting. Must contain only letters, numbers, and special characters (._*-). Each filter can be up to 128 characters long and can contain a maximum of 2 wildcards (*). */ filter: string; /** * The type of filter to use. Must be `WILDCARD`. */ filterType: string; } } export declare namespace ecrpublic { interface GetImagesImage { /** * Media type of the artifact. */ artifactMediaType: string; /** * Digest of the image manifest. */ imageDigest: string; /** * Media type of the image manifest. */ imageManifestMediaType: string; imagePushedAt: string; imageSizeInBytes: number; imageTags: string[]; /** * AWS account ID associated with the public registry that contains the repository. If not specified, the default public registry is assumed. */ registryId: string; /** * Name of the public repository. */ repositoryName: string; } interface GetImagesImageId { /** * Digest of the image manifest. */ imageDigest?: string; /** * Tag used for the image. */ imageTag?: string; } interface RepositoryCatalogData { /** * A detailed description of the contents of the repository. It is publicly visible in the Amazon ECR Public Gallery. The text must be in markdown format. */ aboutText?: string; /** * The system architecture that the images in the repository are compatible with. On the Amazon ECR Public Gallery, the following supported architectures will appear as badges on the repository and are used as search filters: `ARM`, `ARM 64`, `x86`, `x86-64` */ architectures?: string[]; /** * A short description of the contents of the repository. This text appears in both the image details and also when searching for repositories on the Amazon ECR Public Gallery. */ description?: string; /** * The base64-encoded repository logo payload. (Only visible for verified accounts) Note that drift detection is disabled for this attribute. */ logoImageBlob: string; /** * The operating systems that the images in the repository are compatible with. On the Amazon ECR Public Gallery, the following supported operating systems will appear as badges on the repository and are used as search filters: `Linux`, `Windows` */ operatingSystems?: string[]; /** * Detailed information on how to use the contents of the repository. It is publicly visible in the Amazon ECR Public Gallery. The usage text provides context, support information, and additional usage details for users of the repository. The text must be in markdown format. */ usageText?: string; } } export declare namespace ecs { interface CapacityProviderAutoScalingGroupProvider { /** * ARN of the associated auto scaling group. */ autoScalingGroupArn: string; /** * Enables or disables a graceful shutdown of instances without disturbing workloads. Valid values are `ENABLED` and `DISABLED`. The default value is `ENABLED` when a capacity provider is created. */ managedDraining: string; /** * Configuration block defining the parameters of the auto scaling. Detailed below. */ managedScaling: outputs.ecs.CapacityProviderAutoScalingGroupProviderManagedScaling; /** * Enables or disables container-aware termination of instances in the auto scaling group when scale-in happens. Valid values are `ENABLED` and `DISABLED`. */ managedTerminationProtection: string; } interface CapacityProviderAutoScalingGroupProviderManagedScaling { /** * Period of time, in seconds, after a newly launched Amazon EC2 instance can contribute to CloudWatch metrics for Auto Scaling group. If this parameter is omitted, the default value of 300 seconds is used. * * For more information on how the instance warmup period contributes to managed scale-out behavior, see [Control the instances Amazon ECS terminates](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/managed-termination-protection.html) in the _Amazon Elastic Container Service Developer Guide_. */ instanceWarmupPeriod: number; /** * Maximum step adjustment size. A number between 1 and 10,000. */ maximumScalingStepSize: number; /** * Minimum step adjustment size. A number between 1 and 10,000. */ minimumScalingStepSize: number; /** * Whether auto scaling is managed by ECS. Valid values are `ENABLED` and `DISABLED`. */ status: string; /** * Target utilization for the capacity provider. A number between 1 and 100. */ targetCapacity: number; } interface CapacityProviderManagedInstancesProvider { /** * Configuration block for the auto repair configuration. Detailed below. */ autoRepairConfiguration: outputs.ecs.CapacityProviderManagedInstancesProviderAutoRepairConfiguration; /** * Configuration block for how Amazon ECS Managed Instances optimizes the infrastructure in your capacity provider, including whether to turn optimization on or off and how long to delay optimizing idle EC2 instances. Detailed below. */ infrastructureOptimization?: outputs.ecs.CapacityProviderManagedInstancesProviderInfrastructureOptimization; /** * ARN of the infrastructure role that Amazon ECS uses to manage instances on your behalf. This role must have permissions to launch, terminate, and manage Amazon EC2 instances, as well as access to other AWS services required for Amazon ECS Managed Instances functionality. For more information, see [Amazon ECS infrastructure IAM role](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/infrastructure_IAM_role.html) in the Amazon ECS Developer Guide. */ infrastructureRoleArn: string; /** * Launch template configuration that specifies how Amazon ECS should launch Amazon EC2 instances. This includes the instance profile, network configuration, storage settings, and instance requirements for attribute-based instance type selection. For more information, see [Store instance launch parameters in Amazon EC2 launch templates](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html) in the Amazon EC2 User Guide. Detailed below. */ instanceLaunchTemplate: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplate; /** * Whether to propagate tags from the capacity provider to the Amazon ECS Managed Instances. When enabled, tags applied to the capacity provider are automatically applied to all instances launched by this provider. Valid values are `CAPACITY_PROVIDER` and `NONE`. */ propagateTags?: string; } interface CapacityProviderManagedInstancesProviderAutoRepairConfiguration { /** * Whether to use Amazon ECS managed auto repair. Valid values are `ENABLED` and `DISABLED`. */ actionsStatus: string; } interface CapacityProviderManagedInstancesProviderInfrastructureOptimization { /** * Number of seconds Amazon ECS Managed Instances waits before optimizing EC2 instances that have become idle or underutilized. A longer delay increases the likelihood of placing new tasks on idle instances, reducing startup time. A shorter delay helps reduce infrastructure costs by optimizing idle instances more quickly. Valid values are `-1` to disable automatic infrastructure optimization, `0` to `3600` (inclusive) to specify the number of seconds to wait before optimizing instances, or leave unset (null) to use the default optimization behavior. */ scaleInAfter?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplate { /** * Purchasing option for the EC2 instances used in the capacity provider. Determines whether to use On-Demand, Spot, or Capacity Reservation instances. Valid values are `ON_DEMAND`, `SPOT`, and `RESERVED`. Defaults to `ON_DEMAND` when not specified. Changing this value will trigger replacement of the capacity provider. For more information, see [Amazon EC2 billing and purchasing options](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-purchasing-options.html) in the Amazon EC2 User Guide. */ capacityOptionType: string; /** * Capacity Reservation configuration used to launch instances. Required when `capacityOptionType` is `RESERVED`. Detailed below. */ capacityReservations?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateCapacityReservations; /** * ARN of the instance profile that Amazon ECS applies to Amazon ECS Managed Instances. This instance profile must include the necessary permissions for your tasks to access AWS services and resources. For more information, see [Amazon ECS instance profile for Managed Instances](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/instance_IAM_role.html) in the Amazon ECS Developer Guide. */ ec2InstanceProfileArn: string; /** * Instance requirements. You can specify the instance types and instance requirements such as vCPU count, memory, network performance, and accelerator specifications. Amazon ECS automatically selects the instances that match the specified criteria. Detailed below. */ instanceRequirements?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirements; /** * Configuration block for the local storage settings applied to Amazon ECS Managed Instances. Detailed below. */ localStorageConfiguration?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateLocalStorageConfiguration; /** * CloudWatch provides two categories of monitoring: basic monitoring and detailed monitoring. By default, your managed instance is configured for basic monitoring. You can optionally enable detailed monitoring to help you more quickly identify and act on operational issues. You can enable or turn off detailed monitoring at launch or when the managed instance is running or stopped. For more information, see [Detailed monitoring for Amazon ECS Managed Instances](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/cloudwatch-metrics.html) in the Amazon ECS Developer Guide. Valid values are `BASIC` and `DETAILED`. */ monitoring?: string; /** * Network configuration for Amazon ECS Managed Instances. This specifies the subnets and security groups that instances use for network connectivity. Detailed below. */ networkConfiguration: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateNetworkConfiguration; /** * Storage configuration for Amazon ECS Managed Instances. This defines the root volume size and type for the instances. Detailed below. */ storageConfiguration?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateStorageConfiguration; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateCapacityReservations { /** * ARN of the Capacity Reservation resource group in which to run instances. Can only be set when `reservationPreference` is `RESERVATIONS_ONLY`. */ reservationGroupArn?: string; /** * Preference for when Capacity Reservations should be used. Valid values are `RESERVATIONS_ONLY`, `RESERVATIONS_FIRST`, and `RESERVATIONS_EXCLUDED`. `instanceRequirements` must be provided when set to `RESERVATIONS_ONLY` or `RESERVATIONS_FIRST`. */ reservationPreference: string; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirements { /** * Minimum and maximum number of accelerators for the instance types. This is used when you need instances with specific numbers of GPUs or other accelerators. Detailed below. */ acceleratorCount?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsAcceleratorCount; /** * Accelerator manufacturers to include. You can specify `nvidia`, `amd`, `amazon-web-services`, `xilinx`, or `habana` depending on your accelerator requirements. Valid values are `amazon-web-services`, `amd`, `nvidia`, `xilinx`, `habana`. */ acceleratorManufacturers?: string[]; /** * Specific accelerator names to include. For example, you can specify `a100`, `v100`, `k80`, or other specific accelerator models. Valid values are `a100`, `inferentia`, `k520`, `k80`, `m60`, `radeon-pro-v520`, `t4`, `vu9p`, `v100`, `a10g`, `h100`, `t4g`. */ acceleratorNames?: string[]; /** * Minimum and maximum total accelerator memory in mebibytes (MiB). This is important for GPU workloads that require specific amounts of video memory. Detailed below. */ acceleratorTotalMemoryMib?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsAcceleratorTotalMemoryMib; /** * Accelerator types to include. You can specify `gpu` for GPUs, `fpga` for field programmable gate arrays, or `inference` for machine learning inference accelerators. Valid values are `gpu`, `fpga`, `inference`. */ acceleratorTypes?: string[]; /** * Instance types to include in the selection. When specified, Amazon ECS only considers these instance types, subject to the other requirements specified. Maximum of 400 instance types. You can specify instance type patterns using wildcards (e.g., `m5.*`). */ allowedInstanceTypes?: string[]; /** * Whether to include bare metal instance types. Set to `included` to allow bare metal instances, `excluded` to exclude them, or `required` to use only bare metal instances. Valid values are `included`, `excluded`, `required`. */ bareMetal?: string; /** * Minimum and maximum baseline Amazon EBS bandwidth in megabits per second (Mbps). This is important for workloads with high storage I/O requirements. Detailed below. */ baselineEbsBandwidthMbps?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsBaselineEbsBandwidthMbps; /** * Whether to include burstable performance instance types (T2, T3, T3a, T4g). Set to `included` to allow burstable instances, `excluded` to exclude them, or `required` to use only burstable instances. Valid values are `included`, `excluded`, `required`. */ burstablePerformance?: string; /** * CPU manufacturers to include or exclude. You can specify `intel`, `amd`, or `amazon-web-services` to control which CPU types are used for your workloads. Valid values are `intel`, `amd`, `amazon-web-services`. */ cpuManufacturers?: string[]; /** * Instance types to exclude from selection. Use this to prevent Amazon ECS from selecting specific instance types that may not be suitable for your workloads. Maximum of 400 instance types. */ excludedInstanceTypes?: string[]; /** * Instance generations to include. You can specify `current` to use the latest generation instances, or `previous` to include previous generation instances for cost optimization. Valid values are `current`, `previous`. */ instanceGenerations?: string[]; /** * Whether to include instance types with local storage. Set to `included` to allow local storage, `excluded` to exclude it, or `required` to use only instances with local storage. Valid values are `included`, `excluded`, `required`. */ localStorage?: string; /** * Local storage types to include. You can specify `hdd` for hard disk drives, `ssd` for solid state drives, or both. Valid values are `hdd`, `ssd`. */ localStorageTypes?: string[]; /** * Maximum price for Spot instances as a percentage of the optimal On-Demand price. This provides more precise cost control for Spot instance selection. */ maxSpotPriceAsPercentageOfOptimalOnDemandPrice?: number; /** * Minimum and maximum amount of memory per vCPU in gibibytes (GiB). This helps ensure that instance types have the appropriate memory-to-CPU ratio for your workloads. Detailed below. */ memoryGibPerVcpu?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsMemoryGibPerVcpu; /** * Minimum and maximum amount of memory in mebibytes (MiB) for the instance types. Amazon ECS selects instance types that have memory within this range. Detailed below. */ memoryMib: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsMemoryMib; /** * Minimum and maximum network bandwidth in gigabits per second (Gbps). This is crucial for network-intensive workloads that require high throughput. Detailed below. */ networkBandwidthGbps?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsNetworkBandwidthGbps; /** * Minimum and maximum number of network interfaces for the instance types. This is useful for workloads that require multiple network interfaces. Detailed below. */ networkInterfaceCount?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsNetworkInterfaceCount; /** * Price protection threshold for On-Demand Instances, as a percentage higher than an identified On-Demand price. The identified On-Demand price is the price of the lowest priced current generation C, M, or R instance type with your specified attributes. When Amazon ECS selects instance types with your attributes, it will exclude instance types whose price exceeds your specified threshold. */ onDemandMaxPricePercentageOverLowestPrice?: number; /** * Whether the instance types must support hibernation. When set to `true`, only instance types that support hibernation are selected. */ requireHibernateSupport?: boolean; /** * Maximum price for Spot instances as a percentage over the lowest priced On-Demand instance. This helps control Spot instance costs while maintaining access to capacity. */ spotMaxPricePercentageOverLowestPrice?: number; /** * Minimum and maximum total local storage in gigabytes (GB) for instance types with local storage. Detailed below. */ totalLocalStorageGb?: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsTotalLocalStorageGb; /** * Minimum and maximum number of vCPUs for the instance types. Amazon ECS selects instance types that have vCPU counts within this range. Detailed below. */ vcpuCount: outputs.ecs.CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsVcpuCount; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsAcceleratorCount { /** * Maximum number of accelerators. */ max?: number; /** * Minimum number of accelerators. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsAcceleratorTotalMemoryMib { /** * Maximum total accelerator memory, in MiB. */ max?: number; /** * Minimum total accelerator memory, in MiB. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsBaselineEbsBandwidthMbps { /** * Maximum baseline Amazon EBS bandwidth, in Mbps. */ max?: number; /** * Minimum baseline Amazon EBS bandwidth, in Mbps. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsMemoryGibPerVcpu { /** * Maximum amount of memory per vCPU, in GiB. */ max?: number; /** * Minimum amount of memory per vCPU, in GiB. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsMemoryMib { /** * Maximum amount of memory, in MiB. */ max?: number; /** * Minimum amount of memory, in MiB. */ min: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsNetworkBandwidthGbps { /** * Maximum network bandwidth, in Gbps. */ max?: number; /** * Minimum network bandwidth, in Gbps. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsNetworkInterfaceCount { /** * Maximum number of network interfaces. */ max?: number; /** * Minimum number of network interfaces. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsTotalLocalStorageGb { /** * Maximum total local storage, in GB. */ max?: number; /** * Minimum total local storage, in GB. */ min?: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateInstanceRequirementsVcpuCount { /** * Maximum number of vCPUs. */ max?: number; /** * Minimum number of vCPUs. */ min: number; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateLocalStorageConfiguration { /** * Whether to use the local storage of the instance for Amazon ECS Managed Instances. */ useLocalStorage?: boolean; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateNetworkConfiguration { /** * List of security group IDs to apply to Amazon ECS Managed Instances. These security groups control the network traffic allowed to and from the instances. */ securityGroups?: string[]; /** * List of subnet IDs where Amazon ECS can launch Amazon ECS Managed Instances. Instances are distributed across the specified subnets for high availability. All subnets must be in the same VPC. */ subnets: string[]; } interface CapacityProviderManagedInstancesProviderInstanceLaunchTemplateStorageConfiguration { /** * Size of the tasks volume in GiB. Must be at least 1. */ storageSizeGib: number; } interface ClusterCapacityProvidersDefaultCapacityProviderStrategy { /** * Number of tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. Defaults to `0`. */ base?: number; /** * Name of the capacity provider. */ capacityProvider: string; /** * Relative percentage of the total number of launched tasks that should use the specified capacity provider. The `weight` value is taken into consideration after the `base` count of tasks has been satisfied. Defaults to `0`. */ weight?: number; } interface ClusterConfiguration { /** * Details of the execute command configuration. See `executeCommandConfiguration` Block for details. */ executeCommandConfiguration?: outputs.ecs.ClusterConfigurationExecuteCommandConfiguration; /** * Details of the managed storage configuration. See `managedStorageConfiguration` Block for details. */ managedStorageConfiguration?: outputs.ecs.ClusterConfigurationManagedStorageConfiguration; } interface ClusterConfigurationExecuteCommandConfiguration { /** * KMS key ID to encrypt the data between the local client and the container. */ kmsKeyId?: string; /** * Log configuration for the results of the execute command actions. Required when `logging` is `OVERRIDE`. See `logConfiguration` Block for details. */ logConfiguration?: outputs.ecs.ClusterConfigurationExecuteCommandConfigurationLogConfiguration; /** * Log setting to use for redirecting logs for your execute command results. Valid values: `NONE`, `DEFAULT`, `OVERRIDE`. */ logging?: string; } interface ClusterConfigurationExecuteCommandConfigurationLogConfiguration { /** * Whether to enable encryption on the CloudWatch logs. If not specified, encryption will be disabled. */ cloudWatchEncryptionEnabled?: boolean; /** * Name of the CloudWatch log group to send logs to. */ cloudWatchLogGroupName?: string; /** * Whether to enable encryption on the logs sent to S3. If not specified, encryption will be disabled. */ s3BucketEncryptionEnabled?: boolean; /** * Name of the S3 bucket to send logs to. */ s3BucketName?: string; /** * Optional folder in the S3 bucket to place logs in. */ s3KeyPrefix?: string; } interface ClusterConfigurationManagedStorageConfiguration { /** * KMS key ARN for the Fargate ephemeral storage. */ fargateEphemeralStorageKmsKeyId?: string; /** * KMS key ARN to encrypt the managed storage. */ kmsKeyId?: string; } interface ClusterServiceConnectDefaults { /** * ARN of the `aws.servicediscovery.HttpNamespace` that's used when you create a service and don't specify a Service Connect configuration. */ namespace: string; } interface ClusterSetting { /** * Name of the setting to manage. Valid values: `containerInsights`. */ name: string; /** * Value to assign to the setting. Valid values: `enhanced`, `enabled`, `disabled`. */ value: string; } interface DaemonDeploymentConfiguration { /** * Alarm configuration for deployment monitoring. See Alarms below. */ alarms?: outputs.ecs.DaemonDeploymentConfigurationAlarms; /** * Time in minutes to wait before considering a deployment successful. Valid values are between 0 and 1440. Defaults to `0`. */ bakeTimeInMinutes: number; /** * Percentage of tasks to drain during deployment. Valid values are between 0.0 and 100.0. */ drainPercent?: number; } interface DaemonDeploymentConfigurationAlarms { /** * List of CloudWatch alarm names to monitor during deployment. */ alarmNames?: string[]; /** * Whether to enable alarm monitoring for deployments. Defaults to `false`. */ enable: boolean; } interface DaemonTaskDefinitionContainerDefinition { /** * Command that is passed to the container. */ commands?: string[]; /** * Number of CPU units reserved for the container. */ cpu: number; /** * Dependencies defined for container startup and shutdown. Detailed below. */ dependsOns?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionDependsOn[]; /** * Entry point that is passed to the container. */ entryPoints?: string[]; /** * List of files containing the environment variables to pass to a container. Detailed below. */ environmentFiles?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionEnvironmentFile[]; /** * Environment variables to pass to a container. Detailed below. */ environments?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionEnvironment[]; /** * If the essential parameter of a container is marked as true, and that container fails or stops for any reason, all other containers that are part of the task are stopped. */ essential: boolean; /** * FireLens configuration for the container. Detailed below. */ firelensConfiguration?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionFirelensConfiguration; /** * Container health check command and associated configuration parameters for the container. Detailed below. */ healthCheck?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionHealthCheck; /** * Image used to start a container. */ image: string; /** * When this parameter is true, you can deploy containerized applications that require stdin or a tty to be allocated. */ interactive?: boolean; /** * Linux-specific modifications that are applied to the container. Detailed below. */ linuxParameters?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionLinuxParameters; /** * Log configuration specification for the container. Detailed below. */ logConfiguration?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionLogConfiguration; /** * Amount (in MiB) of memory to present to the container. */ memory?: number; /** * Soft limit (in MiB) of memory to reserve for the container. */ memoryReservation?: number; /** * Mount points for data volumes in your container. Detailed below. */ mountPoints?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionMountPoint[]; /** * Name of a container. */ name?: string; /** * When this parameter is true, the container is given elevated privileges on the host container instance. */ privileged?: boolean; /** * When this parameter is true, a TTY is allocated. */ pseudoTerminal?: boolean; /** * When this parameter is true, the container is given read-only access to its root file system. */ readonlyRootFilesystem?: boolean; /** * Private repository authentication credentials to use. Detailed below. */ repositoryCredentials?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionRepositoryCredentials; /** * Restart policy for a container. Detailed below. */ restartPolicy?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionRestartPolicy; /** * Secrets to pass to the container. Detailed below. */ secrets?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionSecret[]; /** * Time duration (in seconds) to wait before giving up on resolving dependencies for a container. */ startTimeout?: number; /** * Time duration (in seconds) to wait before the container is forcefully killed if it doesn't exit normally on its own. */ stopTimeout?: number; /** * List of namespaced kernel parameters to set in the container. Detailed below. */ systemControls?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionSystemControl[]; /** * List of ulimits to set in the container. Detailed below. */ ulimits?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionUlimit[]; /** * User to use inside the container. */ user: string; /** * Working directory to run commands inside the container. */ workingDirectory?: string; } interface DaemonTaskDefinitionContainerDefinitionDependsOn { /** * Dependency condition of the container. Valid values: `START`, `COMPLETE`, `SUCCESS`, `HEALTHY`. */ condition: string; /** * Name of a container. */ containerName: string; } interface DaemonTaskDefinitionContainerDefinitionEnvironment { /** * Name of the environment variable. */ name?: string; /** * Value of the environment variable. */ value?: string; } interface DaemonTaskDefinitionContainerDefinitionEnvironmentFile { /** * File type to use. The only supported value is `s3`. */ type: string; /** * ARN of the Amazon S3 object containing the environment variable file. */ value: string; } interface DaemonTaskDefinitionContainerDefinitionFirelensConfiguration { /** * Options to use when configuring the log router. */ options?: { [key: string]: string; }; /** * Log router to use. Valid values: `fluentd`, `fluentbit`. */ type: string; } interface DaemonTaskDefinitionContainerDefinitionHealthCheck { /** * String array representing the command that the container runs to determine if it is healthy. */ commands: string[]; /** * Time period in seconds between each health check execution. Valid range: 5–300. */ interval?: number; /** * Number of times to retry a failed health check. Valid range: 1–10. */ retries: number; /** * Grace period in seconds to provide containers time to bootstrap. Valid range: 0–300. */ startPeriod?: number; /** * Time period in seconds to wait for a health check to succeed. Valid range: 2–60. */ timeout: number; } interface DaemonTaskDefinitionContainerDefinitionLinuxParameters { /** * Linux capabilities for the container. Detailed below. */ capabilities?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionLinuxParametersCapabilities; /** * Any host devices to expose to the container. Detailed below. */ devices?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionLinuxParametersDevice[]; /** * Run an init process inside the container that forwards signals and reaps processes. */ initProcessEnabled?: boolean; /** * Container path, mount options, and size of the tmpfs mount. Detailed below. */ tmpfs?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionLinuxParametersTmpf[]; } interface DaemonTaskDefinitionContainerDefinitionLinuxParametersCapabilities { /** * Linux capabilities for the container that have been added to the default configuration provided by Docker. */ adds?: string[]; /** * Linux capabilities for the container that have been removed from the default configuration provided by Docker. */ drops?: string[]; } interface DaemonTaskDefinitionContainerDefinitionLinuxParametersDevice { /** * Path inside the container at which to expose the host device. */ containerPath?: string; /** * Path for the device on the host container instance. */ hostPath: string; /** * Explicit permissions to provide to the container for the device. Valid values: `read`, `write`, `mknod`. */ permissions?: string[]; } interface DaemonTaskDefinitionContainerDefinitionLinuxParametersTmpf { /** * Absolute file path where the tmpfs volume is to be mounted. */ containerPath: string; /** * List of tmpfs volume mount options. */ mountOptions?: string[]; /** * Maximum size (in MiB) of the tmpfs volume. */ size: number; } interface DaemonTaskDefinitionContainerDefinitionLogConfiguration { /** * Log driver to use for the container. Valid values: `json-file`, `syslog`, `journald`, `gelf`, `fluentd`, `awslogs`, `splunk`, `awsfirelens`. */ logDriver: string; /** * Configuration options to send to the log driver. */ options?: { [key: string]: string; }; /** * Secrets to pass to the log configuration. Detailed below. */ secretOptions?: outputs.ecs.DaemonTaskDefinitionContainerDefinitionLogConfigurationSecretOption[]; } interface DaemonTaskDefinitionContainerDefinitionLogConfigurationSecretOption { /** * Name of the secret. */ name: string; /** * Secret to expose to the log configuration. */ valueFrom: string; } interface DaemonTaskDefinitionContainerDefinitionMountPoint { /** * Path on the container to mount the host volume at. */ containerPath?: string; /** * If this value is true, the container has read-only access to the volume. */ readOnly?: boolean; /** * Name of the volume to mount. */ sourceVolume?: string; } interface DaemonTaskDefinitionContainerDefinitionRepositoryCredentials { /** * ARN of the secret containing the private repository credentials. */ credentialsParameter: string; } interface DaemonTaskDefinitionContainerDefinitionRestartPolicy { /** * Whether a restart policy is enabled for the container. */ enabled: boolean; /** * List of exit codes that Amazon ECS will ignore and not attempt a restart on. Maximum of 50. */ ignoredExitCodes?: number[]; /** * Period of time (in seconds) that the container must run for before a restart can be attempted. Valid range: 60–1800. */ restartAttemptPeriod?: number; } interface DaemonTaskDefinitionContainerDefinitionSecret { /** * Name of the secret. */ name: string; /** * Secret to expose to the container. The supported values are either the full ARN of the Secrets Manager secret or the full ARN of the parameter in the SSM Parameter Store. */ valueFrom: string; } interface DaemonTaskDefinitionContainerDefinitionSystemControl { /** * Namespaced kernel parameter to set a value for. */ namespace?: string; /** * Value for the namespaced kernel parameter. */ value?: string; } interface DaemonTaskDefinitionContainerDefinitionUlimit { /** * Hard limit for the ulimit type. */ hardLimit: number; /** * Type of the ulimit. */ name: string; /** * Soft limit for the ulimit type. */ softLimit: number; } interface DaemonTaskDefinitionVolume { /** * Configuration for a host volume. Detailed below. */ hosts?: outputs.ecs.DaemonTaskDefinitionVolumeHost[]; /** * Name of the volume. This name is referenced in the `sourceVolume` parameter of container definition in the `mountPoints` section. */ name: string; } interface DaemonTaskDefinitionVolumeHost { /** * Path on the host container instance that is presented to the container. If not set, ECS will create a non-persistent data volume that starts empty and is deleted after the task has finished. */ sourcePath?: string; } interface DaemonTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ExpressGatewayServiceIngressPath { /** * Access type for the ingress path. */ accessType: string; /** * Endpoint for the ingress path. */ endpoint: string; } interface ExpressGatewayServiceNetworkConfiguration { /** * Security groups associated with the task. If not specified, the default security group for the VPC is used. */ securityGroups: string[]; /** * Subnets associated with the task. At least 2 subnets must be specified when using network configuration. If not specified, default subnets will be used. */ subnets: string[]; } interface ExpressGatewayServicePrimaryContainer { /** * CloudWatch Logs configuration for the container. See `awsLogsConfiguration` Block below. */ awsLogsConfigurations: outputs.ecs.ExpressGatewayServicePrimaryContainerAwsLogsConfiguration[]; /** * Command to run in the container. Overrides the default command from the Docker image. */ commands?: string[]; /** * Port on which the container listens for connections. Defaults to `80`. */ containerPort: number; environments?: outputs.ecs.ExpressGatewayServicePrimaryContainerEnvironment[]; /** * Docker image to use for the container. */ image: string; repositoryCredentials?: outputs.ecs.ExpressGatewayServicePrimaryContainerRepositoryCredentials; secrets?: outputs.ecs.ExpressGatewayServicePrimaryContainerSecret[]; } interface ExpressGatewayServicePrimaryContainerAwsLogsConfiguration { /** * CloudWatch log group name. */ logGroup: string; /** * Prefix for log stream names. If not specified, a default prefix will be used. */ logStreamPrefix: string; } interface ExpressGatewayServicePrimaryContainerEnvironment { /** * Name of the environment variable. */ name: string; /** * Value of the environment variable. */ value: string; } interface ExpressGatewayServicePrimaryContainerRepositoryCredentials { /** * ARN of the AWS Systems Manager parameter containing the repository credentials. */ credentialsParameter: string; } interface ExpressGatewayServicePrimaryContainerSecret { /** * Name of the secret. */ name: string; /** * ARN of the AWS Secrets Manager secret or AWS Systems Manager parameter containing the secret value. */ valueFrom: string; } interface ExpressGatewayServiceScalingTarget { /** * Metric to use for auto-scaling. Valid values are `AVERAGE_CPU`, `AVERAGE_MEMORY` and `REQUEST_COUNT_PER_TARGET`. */ autoScalingMetric: string; /** * Target value for the auto-scaling metric (as a percentage). Defaults to `60`. */ autoScalingTargetValue: number; /** * Maximum number of tasks to run. Defaults to `20`. */ maxTaskCount: number; /** * Minimum number of tasks to run. Defaults to `1`. */ minTaskCount: number; } interface ExpressGatewayServiceTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GetClusterServiceConnectDefault { namespace: string; } interface GetClusterSetting { name: string; value: string; } interface GetServiceCapacityProviderStrategy { /** * Number of tasks using the specified capacity provider */ base: number; /** * Name of the capacity provider */ capacityProvider: string; /** * Relative percentage of total tasks to launch */ weight: number; } interface GetServiceDeployment { /** * Time when task set was created (RFC3339 format) */ createdAt: string; /** * Desired number of tasks */ desiredCount: number; /** * Task set ID */ id: string; /** * Number of pending tasks */ pendingCount: number; /** * Number of running tasks */ runningCount: number; /** * Task set status */ status: string; /** * Task definition ARN */ taskDefinition: string; /** * Time when task set was last updated (RFC3339 format) */ updatedAt: string; } interface GetServiceDeploymentConfiguration { /** * CloudWatch alarms configuration. See `alarms` Block for details. */ alarms: outputs.ecs.GetServiceDeploymentConfigurationAlarm[]; /** * Time to wait after deployment before terminating old tasks */ bakeTimeInMinutes: string; /** * Canary deployment configuration. See `canaryConfiguration` Block for details. */ canaryConfigurations: outputs.ecs.GetServiceDeploymentConfigurationCanaryConfiguration[]; /** * Circuit breaker configuration. See `deploymentCircuitBreaker` Block for details. */ deploymentCircuitBreakers: outputs.ecs.GetServiceDeploymentConfigurationDeploymentCircuitBreaker[]; /** * Lifecycle hooks for deployments. See `lifecycleHook` Block for details. */ lifecycleHooks: outputs.ecs.GetServiceDeploymentConfigurationLifecycleHook[]; /** * Linear deployment configuration. See `linearConfiguration` Block for details. */ linearConfigurations: outputs.ecs.GetServiceDeploymentConfigurationLinearConfiguration[]; /** * Upper limit on tasks during deployment */ maximumPercent: number; /** * Lower limit on healthy tasks during deployment */ minimumHealthyPercent: number; /** * Deployment strategy (ROLLING, BLUE_GREEN, LINEAR, or CANARY) */ strategy: string; } interface GetServiceDeploymentConfigurationAlarm { /** * List of CloudWatch alarm names */ alarmNames: string[]; /** * Whether circuit breaker is enabled */ enable: boolean; /** * Whether to rollback on failure */ rollback: boolean; } interface GetServiceDeploymentConfigurationCanaryConfiguration { /** * Time to wait before shifting remaining traffic */ canaryBakeTimeInMinutes: string; /** * Percentage of traffic to route to canary deployment */ canaryPercent: number; } interface GetServiceDeploymentConfigurationDeploymentCircuitBreaker { /** * Whether circuit breaker is enabled */ enable: boolean; /** * Whether to rollback on failure */ rollback: boolean; } interface GetServiceDeploymentConfigurationLifecycleHook { /** * Additional details for the hook */ hookDetails: string; /** * ARN of the Lambda function to invoke (empty for `PAUSE` hooks) */ hookTargetArn: string; /** * Deployment stages when hook is invoked */ lifecycleStages: string[]; /** * ARN of the IAM role that allows ECS to manage the target groups. */ roleArn: string; /** * Type of hook target (`AWS_LAMBDA` or `PAUSE`) */ targetType: string; /** * Timeout configuration for `PAUSE` hooks. See `timeoutConfiguration` Block for details. */ timeoutConfigurations: outputs.ecs.GetServiceDeploymentConfigurationLifecycleHookTimeoutConfiguration[]; } interface GetServiceDeploymentConfigurationLifecycleHookTimeoutConfiguration { /** * Action ECS takes when the pause hook times out (`CONTINUE` or `ROLLBACK`) */ action: string; /** * Time until ECS executes the timeout action */ timeoutInMinutes: string; } interface GetServiceDeploymentConfigurationLinearConfiguration { /** * Time to wait between deployment steps */ stepBakeTimeInMinutes: string; /** * Percentage of traffic to shift in each step */ stepPercent: number; } interface GetServiceDeploymentController { /** * Constraint type */ type: string; } interface GetServiceEvent { /** * Time when task set was created (RFC3339 format) */ createdAt: string; /** * Task set ID */ id: string; /** * Event message */ message: string; } interface GetServiceLoadBalancer { /** * Settings for Blue/Green deployment. See `advancedConfiguration` Block for details. */ advancedConfigurations: outputs.ecs.GetServiceLoadBalancerAdvancedConfiguration[]; /** * Name of the container to associate with the load balancer. */ containerName: string; /** * Port on the container to associate with the load balancer. */ containerPort: number; /** * Name of the load balancer. */ elbName: string; /** * ARN of the target group to associate with the load balancer. */ targetGroupArn: string; } interface GetServiceLoadBalancerAdvancedConfiguration { /** * ARN of the alternate target group to use for Blue/Green deployments. */ alternateTargetGroupArn: string; /** * ARN of the listener rule that routes production traffic. */ productionListenerRule: string; /** * ARN of the IAM role that allows ECS to manage the target groups. */ roleArn: string; /** * ARN of the listener rule that routes test traffic. */ testListenerRule: string; } interface GetServiceNetworkConfiguration { /** * Whether tasks receive public IP addresses */ assignPublicIp: boolean; /** * Security groups associated with tasks */ securityGroups: string[]; /** * Subnets associated with tasks */ subnets: string[]; } interface GetServiceOrderedPlacementStrategy { /** * Field to apply placement strategy against */ field: string; /** * Constraint type */ type: string; } interface GetServicePlacementConstraint { /** * Cluster query language expression */ expression: string; /** * Constraint type */ type: string; } interface GetServiceServiceRegistry { /** * Name of the container to associate with the load balancer. */ containerName: string; /** * Port on the container to associate with the load balancer. */ containerPort: number; /** * Port value for service discovery */ port: number; /** * ARN of the service registry */ registryArn: string; } interface GetServiceTaskSet { /** * ARN of the task set */ arn: string; /** * Time when task set was created (RFC3339 format) */ createdAt: string; /** * Task set ID */ id: string; /** * Number of pending tasks */ pendingCount: number; /** * Number of running tasks */ runningCount: number; /** * Stability status of the task set */ stabilityStatus: string; /** * Task set status */ status: string; /** * Task definition ARN */ taskDefinition: string; /** * Time when task set was last updated (RFC3339 format) */ updatedAt: string; } interface GetTaskDefinitionEphemeralStorage { /** * Total amount, in GiB, of ephemeral storage to set for the task. The minimum supported value is `21` GiB and the maximum supported value is `200` GiB. */ sizeInGib: number; } interface GetTaskDefinitionPlacementConstraint { /** * Cluster Query Language expression to apply to the constraint. For more information, see [Cluster Query Language in the Amazon EC2 Container Service Developer Guide](http://docs.aws.amazon.com/AmazonECS/latest/developerguide/cluster-query-language.html). */ expression: string; /** * Proxy type. The default value is `APPMESH`. The only supported value is `APPMESH`. */ type: string; } interface GetTaskDefinitionProxyConfiguration { /** * Name of the container that will serve as the App Mesh proxy. */ containerName: string; /** * Set of network configuration parameters to provide the Container Network Interface (CNI) plugin, specified a key-value mapping. */ properties: { [key: string]: string; }; /** * Proxy type. The default value is `APPMESH`. The only supported value is `APPMESH`. */ type: string; } interface GetTaskDefinitionRuntimePlatform { /** * Must be set to either `X86_64` or `ARM64`; see [cpu architecture](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_definition_parameters.html#runtime-platform) */ cpuArchitecture: string; /** * If the `requiresCompatibilities` is `FARGATE` this field is required; must be set to a valid option from the [operating system family in the runtime platform](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_definition_parameters.html#runtime-platform) setting */ operatingSystemFamily: string; } interface GetTaskDefinitionVolume { /** * Whether the volume is configured at launch time. */ configureAtLaunch: boolean; /** * Configuration block for a Docker volume. See `dockerVolumeConfiguration` Block for details. */ dockerVolumeConfigurations: outputs.ecs.GetTaskDefinitionVolumeDockerVolumeConfiguration[]; /** * Configuration block for an EFS volume. See `efsVolumeConfiguration` Block for details. */ efsVolumeConfigurations: outputs.ecs.GetTaskDefinitionVolumeEfsVolumeConfiguration[]; /** * Configuration block for an FSx for Windows File Server volume. See `fsxWindowsFileServerVolumeConfiguration` Block for details. */ fsxWindowsFileServerVolumeConfigurations: outputs.ecs.GetTaskDefinitionVolumeFsxWindowsFileServerVolumeConfiguration[]; /** * Path on the host container instance that is presented to the container. */ hostPath: string; /** * Name of the volume. */ name: string; /** * Configuration block for an S3 Files volume. See `s3filesVolumeConfiguration` Block for details. */ s3filesVolumeConfigurations: outputs.ecs.GetTaskDefinitionVolumeS3filesVolumeConfiguration[]; } interface GetTaskDefinitionVolumeDockerVolumeConfiguration { /** * Whether the Docker volume is created if it does not already exist. */ autoprovision: boolean; /** * Docker volume driver used. */ driver: string; /** * Map of Docker driver-specific options. */ driverOpts: { [key: string]: string; }; /** * Map of custom metadata added to the Docker volume. */ labels: { [key: string]: string; }; /** * Scope for the Docker volume, either `task` or `shared`. */ scope: string; } interface GetTaskDefinitionVolumeEfsVolumeConfiguration { /** * Configuration block for authorization for the Amazon FSx for Windows File Server file system. See `fsx_windows_file_server_volume_configuration.authorization_config` Block for details. */ authorizationConfigs: outputs.ecs.GetTaskDefinitionVolumeEfsVolumeConfigurationAuthorizationConfig[]; /** * Amazon FSx for Windows File Server file system ID used. */ fileSystemId: string; /** * Directory within the Amazon S3 Files file system to mount as the root directory. */ rootDirectory: string; /** * Whether encryption is enabled for Amazon EFS data in transit between the Amazon ECS host and the Amazon EFS server. */ transitEncryption: string; /** * Port used for sending encrypted data between the ECS host and the S3 Files file system. */ transitEncryptionPort: number; } interface GetTaskDefinitionVolumeEfsVolumeConfigurationAuthorizationConfig { /** * Access point ID used. */ accessPointId: string; /** * Whether the Amazon ECS task IAM role defined in a task definition is used when mounting the Amazon EFS file system. */ iam: string; } interface GetTaskDefinitionVolumeFsxWindowsFileServerVolumeConfiguration { /** * Configuration block for authorization for the Amazon FSx for Windows File Server file system. See `fsx_windows_file_server_volume_configuration.authorization_config` Block for details. */ authorizationConfigs: outputs.ecs.GetTaskDefinitionVolumeFsxWindowsFileServerVolumeConfigurationAuthorizationConfig[]; /** * Amazon FSx for Windows File Server file system ID used. */ fileSystemId: string; /** * Directory within the Amazon S3 Files file system to mount as the root directory. */ rootDirectory: string; } interface GetTaskDefinitionVolumeFsxWindowsFileServerVolumeConfigurationAuthorizationConfig { /** * Authorization credential option used. */ credentialsParameter: string; /** * Fully qualified domain name hosted by an AWS Directory Service Managed Microsoft AD (Active Directory) or self-hosted AD on Amazon EC2. */ domain: string; } interface GetTaskDefinitionVolumeS3filesVolumeConfiguration { /** * Full ARN of the S3 Files access point used. */ accessPointArn: string; /** * Full ARN of the S3 Files file system mounted. */ fileSystemArn: string; /** * Directory within the Amazon S3 Files file system to mount as the root directory. */ rootDirectory: string; /** * Port used for sending encrypted data between the ECS host and the S3 Files file system. */ transitEncryptionPort: number; } interface GetTaskExecutionCapacityProviderStrategy { /** * Number of tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. Defaults to `0`. */ base?: number; /** * Name of the capacity provider. */ capacityProvider: string; /** * Relative percentage of the total number of launched tasks that should use the specified capacity provider. The `weight` value is taken into consideration after the `base` count of tasks has been satisfied. Defaults to `0`. */ weight?: number; } interface GetTaskExecutionNetworkConfiguration { /** * Assign a public IP address to the ENI (Fargate launch type only). Valid values are `true` or `false`. Default `false`. */ assignPublicIp?: boolean; /** * Security groups associated with the task or service. If you do not specify a security group, the default security group for the VPC is used. */ securityGroups?: string[]; /** * Subnets associated with the task or service. */ subnets: string[]; } interface GetTaskExecutionOverrides { /** * One or more container overrides that are sent to a task. See below. */ containerOverrides?: outputs.ecs.GetTaskExecutionOverridesContainerOverride[]; /** * CPU override for the task. */ cpu?: string; /** * ARN of the task execution role override for the task. */ executionRoleArn?: string; /** * Memory override for the task. */ memory?: string; /** * ARN of the role that containers in this task can assume. */ taskRoleArn?: string; } interface GetTaskExecutionOverridesContainerOverride { /** * Command to send to the container that overrides the default command from the Docker image or the task definition. */ commands?: string[]; /** * Number of cpu units reserved for the container, instead of the default value from the task definition. */ cpu?: number; /** * Environment variables to send to the container. You can add new environment variables, which are added to the container at launch, or you can override the existing environment variables from the Docker image or the task definition. See below. */ environments?: outputs.ecs.GetTaskExecutionOverridesContainerOverrideEnvironment[]; /** * Hard limit (in MiB) of memory to present to the container, instead of the default value from the task definition. If your container attempts to exceed the memory specified here, the container is killed. */ memory?: number; /** * Soft limit (in MiB) of memory to reserve for the container, instead of the default value from the task definition. */ memoryReservation?: number; /** * Name of the container that receives the override. This parameter is required if any override is specified. */ name: string; /** * Type and amount of a resource to assign to a container, instead of the default value from the task definition. The only supported resource is a GPU. See below. */ resourceRequirements?: outputs.ecs.GetTaskExecutionOverridesContainerOverrideResourceRequirement[]; } interface GetTaskExecutionOverridesContainerOverrideEnvironment { /** * Name of the key-value pair. For environment variables, this is the name of the environment variable. */ key: string; /** * Value of the key-value pair. For environment variables, this is the value of the environment variable. */ value: string; } interface GetTaskExecutionOverridesContainerOverrideResourceRequirement { /** * Type of resource to assign to a container. Valid values are `GPU`. */ type: string; /** * Value for the specified resource type. If the `GPU` type is used, the value is the number of physical GPUs the Amazon ECS container agent reserves for the container. The number of GPUs that's reserved for all containers in a task can't exceed the number of available GPUs on the container instance that the task is launched on. */ value: string; } interface GetTaskExecutionPlacementConstraint { /** * Cluster query language expression to apply to the constraint. The expression can have a maximum length of 2000 characters. You can't specify an expression if the constraint type is `distinctInstance`. */ expression?: string; /** * Type of constraint. Valid values are `distinctInstance` or `memberOf`. Use `distinctInstance` to ensure that each task in a particular group is running on a different container instance. Use `memberOf` to restrict the selection to a group of valid candidates. */ type: string; } interface GetTaskExecutionPlacementStrategy { /** * Field to apply the placement strategy against. */ field?: string; /** * Type of placement strategy. Valid values are `random`, `spread`, and `binpack`. */ type: string; } interface ServiceAlarms { /** * One or more CloudWatch alarm names. */ alarmNames: string[]; /** * Whether to use the CloudWatch alarm option in the service deployment process. */ enable: boolean; /** * Whether to configure Amazon ECS to roll back the service if a service deployment fails. If rollback is used, when a service deployment fails, the service is rolled back to the last deployment that completed successfully. */ rollback: boolean; } interface ServiceCapacityProviderStrategy { /** * Number of tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. */ base?: number; /** * Short name of the capacity provider. */ capacityProvider: string; /** * Relative percentage of the total number of launched tasks that should use the specified capacity provider. */ weight?: number; } interface ServiceDeploymentCircuitBreaker { /** * Whether to enable the deployment circuit breaker logic for the service. */ enable: boolean; /** * Whether to enable Amazon ECS to roll back the service if a service deployment fails. If rollback is enabled, when a service deployment fails, the service is rolled back to the last deployment that completed successfully. */ rollback: boolean; } interface ServiceDeploymentConfiguration { /** * Number of minutes to wait after a new deployment is fully provisioned before terminating the old deployment. Valid range: 0-1440 minutes. Used with `BLUE_GREEN`, `LINEAR`, and `CANARY` strategies. */ bakeTimeInMinutes: string; /** * Configuration block for canary deployment strategy. Required when `strategy` is set to `CANARY`. See below. */ canaryConfiguration: outputs.ecs.ServiceDeploymentConfigurationCanaryConfiguration; /** * Configuration block for lifecycle hooks that are invoked during deployments. See below. */ lifecycleHooks?: outputs.ecs.ServiceDeploymentConfigurationLifecycleHook[]; /** * Configuration block for linear deployment strategy. Required when `strategy` is set to `LINEAR`. See below. */ linearConfiguration: outputs.ecs.ServiceDeploymentConfigurationLinearConfiguration; /** * Type of deployment strategy. Valid values: `ROLLING`, `BLUE_GREEN`, `LINEAR`, `CANARY`. Default: `ROLLING`. */ strategy: string; } interface ServiceDeploymentConfigurationCanaryConfiguration { /** * Number of minutes to wait before shifting all traffic to the new deployment. Valid range: 0-1440 minutes. */ canaryBakeTimeInMinutes: string; /** * Percentage of traffic to route to the canary deployment. Valid range: 0.1-100.0. */ canaryPercent: number; } interface ServiceDeploymentConfigurationLifecycleHook { /** * Custom parameters that Amazon ECS will pass to the hook target invocations (such as a Lambda function). */ hookDetails?: string; /** * ARN of the Lambda function to invoke for the lifecycle hook. Required when `targetType` is `AWS_LAMBDA`. Not used when `targetType` is `PAUSE`. */ hookTargetArn?: string; /** * Stages during the deployment when the hook should be invoked. Valid values: `RECONCILE_SERVICE`, `PRE_SCALE_UP`, `POST_SCALE_UP`, `TEST_TRAFFIC_SHIFT`, `POST_TEST_TRAFFIC_SHIFT`, `PRODUCTION_TRAFFIC_SHIFT`, `POST_PRODUCTION_TRAFFIC_SHIFT`. */ lifecycleStages: string[]; /** * ARN of the IAM role that grants the service permission to invoke the Lambda function. Required when `targetType` is `AWS_LAMBDA`. Not used when `targetType` is `PAUSE`. */ roleArn?: string; /** * Type of hook target. Valid values: `AWS_LAMBDA`, `PAUSE`. Default: `AWS_LAMBDA`. `PAUSE` hooks cannot use the `TEST_TRAFFIC_SHIFT` or `PRODUCTION_TRAFFIC_SHIFT` lifecycle stages. */ targetType?: string; /** * Configuration block defining the timeout behavior for a `PAUSE` hook. Only valid when `targetType` is `PAUSE`. See below. */ timeoutConfiguration: outputs.ecs.ServiceDeploymentConfigurationLifecycleHookTimeoutConfiguration; } interface ServiceDeploymentConfigurationLifecycleHookTimeoutConfiguration { /** * Action ECS takes when the pause hook times out. Valid values: `ROLLBACK`, `CONTINUE`. Default: `ROLLBACK`. */ action: string; /** * Number of minutes to wait before executing the timeout action. Valid range: 1-20160 minutes. Default: `1440` (24 hours). */ timeoutInMinutes: string; } interface ServiceDeploymentConfigurationLinearConfiguration { /** * Number of minutes to wait between each step during a linear deployment. Valid range: 0-1440 minutes. */ stepBakeTimeInMinutes: string; /** * Percentage of traffic to shift in each step during a linear deployment. Valid range: 3.0-100.0. */ stepPercent: number; } interface ServiceDeploymentController { /** * Type of deployment controller. Valid values: `CODE_DEPLOY`, `ECS`, `EXTERNAL`. Default: `ECS`. */ type?: string; } interface ServiceLoadBalancer { /** * Configuration block for Blue/Green deployment settings. Required when using `BLUE_GREEN` deployment strategy. See below. */ advancedConfiguration?: outputs.ecs.ServiceLoadBalancerAdvancedConfiguration; /** * Name of the container to associate with the load balancer (as it appears in a container definition). */ containerName: string; /** * Port on the container to associate with the load balancer. */ containerPort: number; /** * Name of the ELB (Classic) to associate with the service. Required for ELB Classic. */ elbName?: string; /** * ARN of the Load Balancer target group to associate with the service. Required for ALB/NLB. * * > **Version note:** Multiple `loadBalancer` configuration block support was added in version 2.22.0 of the provider. This allows configuration of [ECS service support for multiple target groups](https://aws.amazon.com/about-aws/whats-new/2019/07/amazon-ecs-services-now-support-multiple-load-balancer-target-groups/). */ targetGroupArn?: string; } interface ServiceLoadBalancerAdvancedConfiguration { /** * ARN of the alternate target group to use for Blue/Green deployments. */ alternateTargetGroupArn: string; /** * ARN of the listener rule that routes production traffic. */ productionListenerRule: string; /** * ARN of the IAM role that allows ECS to manage the target groups. */ roleArn: string; /** * ARN of the listener rule that routes test traffic. */ testListenerRule?: string; } interface ServiceNetworkConfiguration { /** * Assign a public IP address to the ENI (Fargate launch type only). Valid values are `true` or `false`. Default `false`. */ assignPublicIp?: boolean; /** * Security groups associated with the task or service. If you do not specify a security group, the default security group for the VPC is used. */ securityGroups?: string[]; /** * Subnets associated with the task or service. */ subnets: string[]; } interface ServiceOrderedPlacementStrategy { /** * For the `spread` placement strategy, valid values are `instanceId` (or `host`, which has the same effect), or any platform or custom attribute that is applied to a container instance. For the `binpack` type, valid values are `memory` and `cpu`. For the `random` type, this attribute is not needed. For more information, see [Placement Strategy](https://docs.aws.amazon.com/AmazonECS/latest/APIReference/API_PlacementStrategy.html). */ field?: string; /** * Type of placement strategy. Must be one of: `binpack`, `random`, or `spread` * * > **Note:** for `spread`, `host` and `instanceId` will be normalized, by AWS, to be `instanceId`. This means the statefile will show `instanceId` but your config will differ if you use `host`. */ type: string; } interface ServicePlacementConstraint { /** * Cluster Query Language expression to apply to the constraint. Does not need to be specified for the `distinctInstance` type. For more information, see [Cluster Query Language in the Amazon EC2 Container Service Developer Guide](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/cluster-query-language.html). */ expression?: string; /** * Type of constraint. The only valid values at this time are `memberOf` and `distinctInstance`. */ type: string; } interface ServiceServiceConnectConfiguration { /** * Configuration for Service Connect access logs. See below. */ accessLogConfiguration?: outputs.ecs.ServiceServiceConnectConfigurationAccessLogConfiguration; /** * Whether to use Service Connect with this service. */ enabled: boolean; /** * Log configuration for the container. See below. */ logConfiguration?: outputs.ecs.ServiceServiceConnectConfigurationLogConfiguration; /** * Namespace name or ARN of the `aws.servicediscovery.HttpNamespace` for use with Service Connect. */ namespace: string; /** * List of Service Connect service objects. See below. */ services?: outputs.ecs.ServiceServiceConnectConfigurationService[]; } interface ServiceServiceConnectConfigurationAccessLogConfiguration { /** * Format for Service Connect access log output. Valid values: `TEXT`, `JSON`. See [AWS documentation](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-connect-envoy-access-logs.html) for format details. */ format: string; /** * Whether to include query parameters in Service Connect access logs. Valid values: `ENABLED`, `DISABLED`. Default: `DISABLED`. Query parameters may contain sensitive information. * * > **NOTE:** Access logs are delivered to the destination log group specified in the `logConfiguration` block. You must configure `logConfiguration` to enable access logs. * * > **SECURITY WARNING:** When `includeQueryParameters` is set to `ENABLED`, query parameters (which may contain sensitive data such as request IDs, tokens, or session identifiers) will be included in access logs. */ includeQueryParameters: string; } interface ServiceServiceConnectConfigurationLogConfiguration { /** * Log driver to use for the container. */ logDriver: string; /** * Configuration options to send to the log driver. */ options: { [key: string]: string; }; /** * Secrets to pass to the log configuration. See below. */ secretOptions?: outputs.ecs.ServiceServiceConnectConfigurationLogConfigurationSecretOption[]; } interface ServiceServiceConnectConfigurationLogConfigurationSecretOption { /** * Name of the secret. */ name: string; /** * Secret to expose to the container. The supported values are either the full ARN of the AWS Secrets Manager secret or the full ARN of the parameter in the SSM Parameter Store. */ valueFrom: string; } interface ServiceServiceConnectConfigurationService { /** * List of client aliases for this Service Connect service. You use these to assign names that can be used by client applications. For each service block where enabled is true, exactly one `clientAlias` with one `port` should be specified. See below. */ clientAlias?: outputs.ecs.ServiceServiceConnectConfigurationServiceClientAlias[]; /** * Name of the new AWS Cloud Map service that Amazon ECS creates for this Amazon ECS service. */ discoveryName: string; /** * Port number for the Service Connect proxy to listen on. */ ingressPortOverride?: number; /** * Name of one of the `portMappings` from all the containers in the task definition of this Amazon ECS service. */ portName: string; /** * Configuration timeouts for Service Connect */ timeout?: outputs.ecs.ServiceServiceConnectConfigurationServiceTimeout; /** * Configuration for enabling TLS */ tls?: outputs.ecs.ServiceServiceConnectConfigurationServiceTls; } interface ServiceServiceConnectConfigurationServiceClientAlias { /** * Name that you use in the applications of client tasks to connect to this service. */ dnsName: string; /** * Listening port number for the Service Connect proxy. This port is available inside of all of the tasks within the same namespace. */ port: number; /** * Configuration block for test traffic routing rules. See below. */ testTrafficRules?: outputs.ecs.ServiceServiceConnectConfigurationServiceClientAliasTestTrafficRule[]; } interface ServiceServiceConnectConfigurationServiceClientAliasTestTrafficRule { /** * Configuration block for header-based routing rules. See below. */ header?: outputs.ecs.ServiceServiceConnectConfigurationServiceClientAliasTestTrafficRuleHeader; } interface ServiceServiceConnectConfigurationServiceClientAliasTestTrafficRuleHeader { /** * Name of the HTTP header to match. */ name: string; /** * Configuration block for header value matching criteria. See below. */ value: outputs.ecs.ServiceServiceConnectConfigurationServiceClientAliasTestTrafficRuleHeaderValue; } interface ServiceServiceConnectConfigurationServiceClientAliasTestTrafficRuleHeaderValue { /** * Exact string value to match in the header. */ exact: string; } interface ServiceServiceConnectConfigurationServiceTimeout { /** * Amount of time in seconds a connection will stay active while idle. A value of 0 can be set to disable idleTimeout. */ idleTimeoutSeconds?: number; /** * Amount of time in seconds for the upstream to respond with a complete response per request. A value of 0 can be set to disable perRequestTimeout. Can only be set when appProtocol isn't TCP. */ perRequestTimeoutSeconds?: number; } interface ServiceServiceConnectConfigurationServiceTls { /** * Details of the certificate authority which will issue the certificate. */ issuerCertAuthority: outputs.ecs.ServiceServiceConnectConfigurationServiceTlsIssuerCertAuthority; /** * KMS key used to encrypt the private key in Secrets Manager. */ kmsKey?: string; /** * ARN of the IAM Role that's associated with the Service Connect TLS. */ roleArn?: string; } interface ServiceServiceConnectConfigurationServiceTlsIssuerCertAuthority { /** * ARN of the `aws.acmpca.CertificateAuthority` used to create the TLS Certificates. */ awsPcaAuthorityArn: string; } interface ServiceServiceRegistries { /** * Container name value, already specified in the task definition, to be used for your service discovery service. */ containerName?: string; /** * Port value, already specified in the task definition, to be used for your service discovery service. */ containerPort?: number; /** * Port value used if your Service Discovery service specified an SRV record. */ port?: number; /** * ARN of the Service Registry. The currently supported service registry is Amazon Route 53 Auto Naming Service(`aws.servicediscovery.Service`). For more information, see [Service](https://docs.aws.amazon.com/Route53/latest/APIReference/API_autonaming_Service.html) */ registryArn: string; } interface ServiceVolumeConfiguration { /** * Configuration for the Amazon EBS volume that Amazon ECS creates and manages on your behalf. See below. */ managedEbsVolume: outputs.ecs.ServiceVolumeConfigurationManagedEbsVolume; /** * Name of the volume. */ name: string; } interface ServiceVolumeConfigurationManagedEbsVolume { /** * Whether the volume should be encrypted. Default value is `true`. */ encrypted?: boolean; /** * Linux filesystem type for the volume. For volumes created from a snapshot, same filesystem type must be specified that the volume was using when the snapshot was created. Valid values are `ext3`, `ext4`, `xfs`. Default value is `xfs`. */ fileSystemType?: string; /** * Number of I/O operations per second (IOPS). */ iops?: number; /** * ARN identifier of the Amazon Web Services KMS key to use for Amazon EBS encryption. */ kmsKeyId?: string; /** * Amazon ECS infrastructure IAM role that is used to manage your Amazon Web Services infrastructure. Recommended using the Amazon ECS-managed `AmazonECSInfrastructureRolePolicyForVolumes` IAM policy with this role. */ roleArn: string; /** * Size of the volume in GiB. You must specify either a `sizeInGb` or a `snapshotId`. You can optionally specify a volume size greater than or equal to the snapshot size. */ sizeInGb?: number; /** * Snapshot that Amazon ECS uses to create the volume. You must specify either a `sizeInGb` or a `snapshotId`. */ snapshotId?: string; /** * Tags to apply to the volume. See below. */ tagSpecifications?: outputs.ecs.ServiceVolumeConfigurationManagedEbsVolumeTagSpecification[]; /** * Throughput to provision for a volume, in MiB/s, with a maximum of 1,000 MiB/s. */ throughput?: number; /** * Volume Initialization Rate in MiB/s. You must also specify a `snapshotId`. */ volumeInitializationRate?: number; /** * Volume type. */ volumeType?: string; } interface ServiceVolumeConfigurationManagedEbsVolumeTagSpecification { /** * Whether to propagate the tags from the task definition to the Amazon EBS volume. */ propagateTags?: string; /** * Type of volume resource. Valid values, `volume`. */ resourceType: string; /** * Tags applied to this Amazon EBS volume. `AmazonECSCreated` and `AmazonECSManaged` are reserved tags that can't be used. */ tags?: { [key: string]: string; }; } interface ServiceVpcLatticeConfiguration { /** * Name of the port for a target group associated with the VPC Lattice configuration. */ portName: string; /** * ARN of the IAM role to associate with this volume. This is the Amazon ECS infrastructure IAM role that is used to manage your AWS infrastructure. */ roleArn: string; /** * Full ARN of the target group or groups associated with the VPC Lattice configuration. */ targetGroupArn: string; } interface TaskDefinitionEphemeralStorage { /** * Total amount, in GiB, of ephemeral storage to set for the task. The minimum supported value is `21` GiB and the maximum supported value is `200` GiB. */ sizeInGib: number; } interface TaskDefinitionPlacementConstraint { /** * Cluster Query Language expression to apply to the constraint. For more information, see [Cluster Query Language in the Amazon EC2 Container Service Developer Guide](http://docs.aws.amazon.com/AmazonECS/latest/developerguide/cluster-query-language.html). */ expression?: string; /** * Type of constraint. Use `memberOf` to restrict selection to a group of valid candidates. Note that `distinctInstance` is not supported in task definitions. */ type: string; } interface TaskDefinitionProxyConfiguration { /** * Name of the container that will serve as the App Mesh proxy. */ containerName: string; /** * Set of network configuration parameters to provide the Container Network Interface (CNI) plugin, specified a key-value mapping. */ properties?: { [key: string]: string; }; /** * Proxy type. The default value is `APPMESH`. The only supported value is `APPMESH`. */ type?: string; } interface TaskDefinitionRuntimePlatform { /** * Must be set to either `X86_64` or `ARM64`; see [cpu architecture](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_definition_parameters.html#runtime-platform) */ cpuArchitecture?: string; /** * If the `requiresCompatibilities` is `FARGATE` this field is required; must be set to a valid option from the [operating system family in the runtime platform](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_definition_parameters.html#runtime-platform) setting */ operatingSystemFamily?: string; } interface TaskDefinitionVolume { /** * Whether the volume should be configured at launch time. This is used to create Amazon EBS volumes for standalone tasks or tasks created as part of a service. Each task definition revision may only have one volume configured at launch in the volume configuration. */ configureAtLaunch: boolean; /** * Configuration block to configure a docker volume. Detailed below. */ dockerVolumeConfiguration?: outputs.ecs.TaskDefinitionVolumeDockerVolumeConfiguration; /** * Configuration block for an EFS volume. Detailed below. */ efsVolumeConfiguration?: outputs.ecs.TaskDefinitionVolumeEfsVolumeConfiguration; /** * Configuration block for an FSX Windows File Server volume. Detailed below. */ fsxWindowsFileServerVolumeConfiguration?: outputs.ecs.TaskDefinitionVolumeFsxWindowsFileServerVolumeConfiguration; /** * Path on the host container instance that is presented to the container. If not set, ECS will create a nonpersistent data volume that starts empty and is deleted after the task has finished. */ hostPath?: string; /** * Name of the volume. This name is referenced in the `sourceVolume` parameter of container definition in the `mountPoints` section. */ name: string; /** * Configuration block for an S3 Files volume. Detailed below. */ s3filesVolumeConfiguration?: outputs.ecs.TaskDefinitionVolumeS3filesVolumeConfiguration; } interface TaskDefinitionVolumeDockerVolumeConfiguration { /** * If this value is `true`, the Docker volume is created if it does not already exist. *Note*: This field is only used if the scope is `shared`. */ autoprovision?: boolean; /** * Docker volume driver to use. The driver value must match the driver name provided by Docker because it is used for task placement. */ driver: string; /** * Map of Docker driver specific options. */ driverOpts?: { [key: string]: string; }; /** * Map of custom metadata to add to your Docker volume. */ labels?: { [key: string]: string; }; /** * Scope for the Docker volume, which determines its lifecycle, either `task` or `shared`. Docker volumes that are scoped to a `task` are automatically provisioned when the task starts and destroyed when the task stops. Docker volumes that are scoped as `shared` persist after the task stops. */ scope: string; } interface TaskDefinitionVolumeEfsVolumeConfiguration { /** * Configuration block for authorization for the Amazon EFS file system. Detailed below. */ authorizationConfig?: outputs.ecs.TaskDefinitionVolumeEfsVolumeConfigurationAuthorizationConfig; /** * ID of the EFS File System. */ fileSystemId: string; /** * Directory within the Amazon EFS file system to mount as the root directory inside the host. If this parameter is omitted, the root of the Amazon EFS volume will be used. Specifying / will have the same effect as omitting this parameter. This argument is ignored when using `authorizationConfig`. */ rootDirectory?: string; /** * Whether or not to enable encryption for Amazon EFS data in transit between the Amazon ECS host and the Amazon EFS server. Transit encryption must be enabled if Amazon EFS IAM authorization is used. Valid values: `ENABLED`, `DISABLED`. If this parameter is omitted, the default value of `DISABLED` is used. */ transitEncryption?: string; /** * Port to use for transit encryption. If you do not specify a transit encryption port, it will use the port selection strategy that the Amazon EFS mount helper uses. */ transitEncryptionPort?: number; } interface TaskDefinitionVolumeEfsVolumeConfigurationAuthorizationConfig { /** * Access point ID to use. If an access point is specified, the root directory value will be relative to the directory set for the access point. If specified, transit encryption must be enabled in the EFSVolumeConfiguration. */ accessPointId?: string; /** * Whether or not to use the Amazon ECS task IAM role defined in a task definition when mounting the Amazon EFS file system. If enabled, transit encryption must be enabled in the EFSVolumeConfiguration. Valid values: `ENABLED`, `DISABLED`. If this parameter is omitted, the default value of `DISABLED` is used. */ iam?: string; } interface TaskDefinitionVolumeFsxWindowsFileServerVolumeConfiguration { /** * Configuration block for authorization for the Amazon FSx for Windows File Server file system detailed below. */ authorizationConfig: outputs.ecs.TaskDefinitionVolumeFsxWindowsFileServerVolumeConfigurationAuthorizationConfig; /** * Amazon FSx for Windows File Server file system ID to use. */ fileSystemId: string; /** * Directory within the Amazon FSx for Windows File Server file system to mount as the root directory inside the host. */ rootDirectory: string; } interface TaskDefinitionVolumeFsxWindowsFileServerVolumeConfigurationAuthorizationConfig { /** * Authorization credential option to use. The authorization credential options can be provided using either the ARN of an AWS Secrets Manager secret or AWS Systems Manager Parameter Store parameter. The ARNs refer to the stored credentials. */ credentialsParameter: string; /** * Fully qualified domain name hosted by an AWS Directory Service Managed Microsoft AD (Active Directory) or self-hosted AD on Amazon EC2. */ domain: string; } interface TaskDefinitionVolumeS3filesVolumeConfiguration { /** * Full ARN of the S3 Files access point to use. If configured, `rootDirectory` must either be omitted or set to `"/"`. */ accessPointArn?: string; /** * Full ARN of the S3 Files file system to mount. */ fileSystemArn: string; /** * Directory within the Amazon S3 Files file system to mount as the root directory. */ rootDirectory?: string; /** * Port to use for sending encrypted data between the ECS host and the S3 Files file system. */ transitEncryptionPort?: number; } interface TaskSetCapacityProviderStrategy { /** * Number of tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. */ base?: number; /** * Short name or full ARN of the capacity provider. */ capacityProvider: string; /** * Relative percentage of the total number of launched tasks that should use the specified capacity provider. */ weight: number; } interface TaskSetLoadBalancer { /** * Name of the container to associate with the load balancer (as it appears in a container definition). */ containerName: string; /** * Port on the container to associate with the load balancer. Defaults to `0` if not specified. */ containerPort?: number; /** * Name of the ELB (Classic) to associate with the service. */ loadBalancerName?: string; /** * ARN of the Load Balancer target group to associate with the service. * * > **Note:** Specifying multiple `loadBalancer` configurations is still not supported by AWS for ECS task set. */ targetGroupArn?: string; } interface TaskSetNetworkConfiguration { /** * Whether to assign a public IP address to the ENI (`FARGATE` launch type only). Valid values are `true` or `false`. Default `false`. */ assignPublicIp?: boolean; /** * Security groups associated with the task or service. If you do not specify a security group, the default security group for the VPC is used. Maximum of 5. */ securityGroups?: string[]; /** * Subnets associated with the task or service. Maximum of 16. */ subnets: string[]; } interface TaskSetScale { /** * Unit of measure for the scale value. Default: `PERCENT`. */ unit?: string; /** * Value, specified as a percent total of a service's `desiredCount`, to scale the task set. Defaults to `0` if not specified. Accepted values are numbers between 0.0 and 100.0. */ value?: number; } interface TaskSetServiceRegistries { /** * Container name value, already specified in the task definition, to be used for your service discovery service. */ containerName?: string; /** * Port value, already specified in the task definition, to be used for your service discovery service. */ containerPort?: number; /** * Port value used if your Service Discovery service specified an SRV record. */ port?: number; /** * ARN of the Service Registry. The currently supported service registry is Amazon Route 53 Auto Naming Service (`aws.servicediscovery.Service` resource). For more information, see [Service](https://docs.aws.amazon.com/Route53/latest/APIReference/API_autonaming_Service.html). */ registryArn: string; } } export declare namespace efs { interface AccessPointPosixUser { /** * POSIX group ID used for all file system operations using this access point. */ gid: number; /** * Secondary POSIX group IDs used for all file system operations using this access point. */ secondaryGids?: number[]; /** * POSIX user ID used for all file system operations using this access point. */ uid: number; } interface AccessPointRootDirectory { /** * POSIX IDs and permissions to apply to the access point's Root Directory. See Creation Info below. */ creationInfo: outputs.efs.AccessPointRootDirectoryCreationInfo; /** * Path on the EFS file system to expose as the root directory to NFS clients using the access point to access the EFS file system. A path can have up to four subdirectories. If the specified path does not exist, you are required to provide `creationInfo`. */ path: string; } interface AccessPointRootDirectoryCreationInfo { /** * POSIX group ID to apply to the `rootDirectory`. */ ownerGid: number; /** * POSIX user ID to apply to the `rootDirectory`. */ ownerUid: number; /** * POSIX permissions to apply to the RootDirectory, in the format of an octal number representing the file's mode bits. */ permissions: string; } interface BackupPolicyBackupPolicy { /** * A status of the backup policy. Valid values: `ENABLED`, `DISABLED`. */ status: string; } interface FileSystemLifecyclePolicy { /** * Indicates how long it takes to transition files to the archive storage class. Requires transition_to_ia, Elastic Throughput and General Purpose performance mode. Valid values: `AFTER_1_DAY`, `AFTER_7_DAYS`, `AFTER_14_DAYS`, `AFTER_30_DAYS`, `AFTER_60_DAYS`, `AFTER_90_DAYS`, `AFTER_180_DAYS`, `AFTER_270_DAYS`, or `AFTER_365_DAYS`. */ transitionToArchive?: string; /** * Indicates how long it takes to transition files to the IA storage class. Valid values: `AFTER_1_DAY`, `AFTER_7_DAYS`, `AFTER_14_DAYS`, `AFTER_30_DAYS`, `AFTER_60_DAYS`, `AFTER_90_DAYS`, `AFTER_180_DAYS`, `AFTER_270_DAYS`, or `AFTER_365_DAYS`. */ transitionToIa?: string; /** * Describes the policy used to transition a file from infequent access storage to primary storage. Valid values: `AFTER_1_ACCESS`. */ transitionToPrimaryStorageClass?: string; } interface FileSystemProtection { /** * Indicates whether replication overwrite protection is enabled. Valid values: `ENABLED` or `DISABLED`. */ replicationOverwrite: string; } interface FileSystemSizeInByte { /** * The latest known metered size (in bytes) of data stored in the file system. */ value: number; /** * The latest known metered size (in bytes) of data stored in the Infrequent Access storage class. */ valueInIa: number; /** * The latest known metered size (in bytes) of data stored in the Standard storage class. */ valueInStandard: number; } interface GetAccessPointPosixUser { /** * Group ID */ gid: number; /** * Secondary group IDs */ secondaryGids: number[]; /** * User Id */ uid: number; } interface GetAccessPointRootDirectory { /** * Single element list containing information on the creation permissions of the directory */ creationInfos: outputs.efs.GetAccessPointRootDirectoryCreationInfo[]; /** * Path exposed as the root directory */ path: string; } interface GetAccessPointRootDirectoryCreationInfo { /** * POSIX owner group ID */ ownerGid: number; /** * POSIX owner user ID */ ownerUid: number; /** * POSIX permissions mode */ permissions: string; } interface GetFileSystemLifecyclePolicy { transitionToArchive: string; transitionToIa: string; transitionToPrimaryStorageClass: string; } interface GetFileSystemProtection { replicationOverwrite: string; } interface ReplicationConfigurationDestination { /** * The availability zone in which the replica should be created. If specified, the replica will be created with One Zone storage. If omitted, regional storage will be used. */ availabilityZoneName?: string; /** * The ID of the destination file system for the replication. If no ID is provided, then EFS creates a new file system with the default settings. */ fileSystemId: string; /** * The Key ID, ARN, alias, or alias ARN of the KMS key that should be used to encrypt the replica file system. If omitted, the default KMS key for EFS `/aws/elasticfilesystem` will be used. */ kmsKeyId?: string; /** * The region in which the replica should be created. */ region: string; status: string; } } export declare namespace eks { interface AccessPolicyAssociationAccessScope { /** * The namespaces to which the access scope applies when type is namespace. */ namespaces?: string[]; /** * Valid values are `namespace` or `cluster`. */ type: string; } interface AddonNamespaceConfig { /** * Name of the Kubernetes namespace to install the add-on in. Once you install an add-on in a specific namespace, you must remove and re-create the add-on to change its namespace. For more details see the [Custom namespace for add-ons](https://docs.aws.amazon.com/eks/latest/userguide/eks-add-ons.html#custom-namespace). */ namespace: string; } interface AddonPodIdentityAssociation { /** * ARN of the IAM role to associate with the service account. The EKS Pod Identity agent manages credentials to assume this role for applications in the containers in the pods that use this service account. */ roleArn: string; /** * The name of the Kubernetes service account inside the cluster to associate the IAM credentials with. */ serviceAccount: string; } interface CapabilityConfiguration { /** * ArgoCD configuration. See `argoCd` below. */ argoCd?: outputs.eks.CapabilityConfigurationArgoCd; } interface CapabilityConfigurationArgoCd { /** * AWS IAM Identity Center configuration. See `awsIdc` below. */ awsIdc: outputs.eks.CapabilityConfigurationArgoCdAwsIdc; /** * Kubernetes namespace for ArgoCD. */ namespace: string; /** * Network access configuration. See `networkAccess` below. */ networkAccess?: outputs.eks.CapabilityConfigurationArgoCdNetworkAccess; /** * RBAC role mappings. See `rbacRoleMapping` below. */ rbacRoleMappings?: outputs.eks.CapabilityConfigurationArgoCdRbacRoleMapping[]; /** * URL of the Argo CD server. */ serverUrl: string; } interface CapabilityConfigurationArgoCdAwsIdc { /** * ARN of the IAM Identity Center instance. */ idcInstanceArn: string; idcManagedApplicationArn: string; /** * Region of the IAM Identity Center instance. */ idcRegion: string; } interface CapabilityConfigurationArgoCdNetworkAccess { /** * VPC Endpoint IDs. */ vpceIds?: string[]; } interface CapabilityConfigurationArgoCdRbacRoleMapping { /** * List of identities. See `identity` below. */ identities: outputs.eks.CapabilityConfigurationArgoCdRbacRoleMappingIdentity[]; /** * ArgoCD role. Valid values: `ADMIN`, `EDITOR`, `VIEWER`. */ role: string; } interface CapabilityConfigurationArgoCdRbacRoleMappingIdentity { /** * Identity ID. */ id: string; /** * Identity type. Valid values: `SSO_USER`, `SSO_GROUP`. */ type: string; } interface CapabilityTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ClusterAccessConfig { /** * The authentication mode for the cluster. Valid values are `CONFIG_MAP`, `API` or `API_AND_CONFIG_MAP` */ authenticationMode: string; /** * Whether or not to bootstrap the access config values to the cluster. Default is `true`. */ bootstrapClusterCreatorAdminPermissions?: boolean; } interface ClusterCertificateAuthority { /** * Base64 encoded certificate data required to communicate with your cluster. Add this to the `certificate-authority-data` section of the `kubeconfig` file for your cluster. */ data: string; } interface ClusterComputeConfig { /** * Request to enable or disable the compute capability on your EKS Auto Mode cluster. If the compute capability is enabled, EKS Auto Mode will create and delete EC2 Managed Instances in your Amazon Web Services account. */ enabled: boolean; /** * Configuration for node pools that defines the compute resources for your EKS Auto Mode cluster. Valid options are `general-purpose` and `system`. */ nodePools?: string[]; /** * The ARN of the IAM Role EKS will assign to EC2 Managed Instances in your EKS Auto Mode cluster. This value cannot be changed after the compute capability of EKS Auto Mode is enabled.. */ nodeRoleArn?: string; } interface ClusterControlPlaneScalingConfig { /** * The control plane scaling tier. Valid values are `standard`, `tier-xl`, `tier-2xl`, `tier-4xl`, or `tier-8xl`. Defaults to `standard`. For more information about each tier, see [EKS Provisioned Control Plane](https://docs.aws.amazon.com/eks/latest/userguide/eks-provisioned-control-plane-getting-started.html). */ tier: string; } interface ClusterEncryptionConfig { /** * Configuration block with provider for encryption. Detailed below. */ provider: outputs.eks.ClusterEncryptionConfigProvider; /** * List of strings with resources to be encrypted. Valid values: `secrets`. */ resources: string[]; } interface ClusterEncryptionConfigProvider { /** * ARN of the KMS customer master key (CMK). The CMK must be symmetric, created in the same region as the cluster, and if the CMK was created in a different account, the user must have access to the CMK. For more information, see [Allowing Users in Other Accounts to Use a CMK in the KMS Developer Guide](https://docs.aws.amazon.com/kms/latest/developerguide/key-policy-modifying-external-accounts.html). */ keyArn: string; } interface ClusterIdentity { /** * Nested block containing [OpenID Connect](https://openid.net/connect/) identity provider information for the cluster. Detailed below. */ oidcs: outputs.eks.ClusterIdentityOidc[]; } interface ClusterIdentityOidc { /** * Issuer URL for the OpenID Connect identity provider. */ issuer: string; } interface ClusterKubeApiServerConfig { /** * The duration that Kubernetes events are retained. Must be a single-unit duration (e.g., `30m`, `1h`). Valid range: `10m` to `60m`. Default is `1h`. */ eventTtl: string; /** * Configuration block for the port range available for NodePort services. Detailed below. */ serviceNodePortRange: outputs.eks.ClusterKubeApiServerConfigServiceNodePortRange; } interface ClusterKubeApiServerConfigServiceNodePortRange { /** * The maximum port number in the range. Valid range: `10260` to `32767`. Default is `32767`. Must be greater than or equal to `minPort`. */ maxPort: number; /** * The minimum port number in the range. Valid range: `10260` to `32767`. Default is `30000`. */ minPort: number; } interface ClusterKubeControllerManagerConfig { /** * Configuration block for the horizontal pod autoscaler controller. Detailed below. */ horizontalPodAutoscalerControllerConfig: outputs.eks.ClusterKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig; /** * Configuration block for the pod garbage collection controller. Detailed below. * * > **NOTE:** The `horizontalPodAutoscalerControllerConfig` requires a Provisioned Control Plane scaling tier (e.g., `tier-xl` or higher). It cannot be configured on clusters using the `standard` tier. */ podGcControllerConfig: outputs.eks.ClusterKubeControllerManagerConfigPodGcControllerConfig; } interface ClusterKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig { /** * The interval between each sync of the horizontal pod autoscaler. Must be a single-unit duration (e.g., `10s`, `15s`). Valid range: `10s` to `15s`. Default is `15s`. */ horizontalPodAutoscalerSyncPeriod: string; } interface ClusterKubeControllerManagerConfigPodGcControllerConfig { /** * The number of terminated pods that can exist before the pod garbage collector starts deleting them. Valid range: `0` to `12500`. Refer to the `aws.eks.getClusterVersions` data source for any version-specific constraints. */ terminatedPodGcThreshold: number; } interface ClusterKubeSchedulerConfig { /** * Configuration block for the NodeResourcesFit scheduler plugin. Detailed below. */ nodeResourcesFit: outputs.eks.ClusterKubeSchedulerConfigNodeResourcesFit; } interface ClusterKubeSchedulerConfigNodeResourcesFit { /** * Configuration block for the scoring strategy used to rank nodes during scheduling. Detailed below. */ scoringStrategy: outputs.eks.ClusterKubeSchedulerConfigNodeResourcesFitScoringStrategy; } interface ClusterKubeSchedulerConfigNodeResourcesFitScoringStrategy { /** * List of resource weight configuration blocks for scoring nodes. Detailed below. */ resources: outputs.eks.ClusterKubeSchedulerConfigNodeResourcesFitScoringStrategyResource[]; /** * The scoring strategy type. Valid values are `LeastAllocated` and `MostAllocated`. Default is `LeastAllocated`. */ type: string; } interface ClusterKubeSchedulerConfigNodeResourcesFitScoringStrategyResource { /** * The name of the resource (e.g., `cpu`, `memory`, `nvidia.com/gpu`). */ name: string; /** * The weight assigned to the resource for scoring. Must be between `1` and `100`. */ weight: number; } interface ClusterKubernetesNetworkConfig { /** * Configuration block with elastic load balancing configuration for the cluster. Detailed below. */ elasticLoadBalancing: outputs.eks.ClusterKubernetesNetworkConfigElasticLoadBalancing; /** * The IP family used to assign Kubernetes pod and service addresses. Valid values are `ipv4` (default) and `ipv6`. You can only specify an IP family when you create a cluster, changing this value will force a new cluster to be created. */ ipFamily: string; /** * The CIDR block to assign Kubernetes pod and service IP addresses from. If you don't specify a block, Kubernetes assigns addresses from either the 10.100.0.0/16 or 172.20.0.0/16 CIDR blocks. We recommend that you specify a block that does not overlap with resources in other networks that are peered or connected to your VPC. You can only specify a custom CIDR block when you create a cluster, changing this value will force a new cluster to be created. The block must meet the following requirements: * * * Within one of the following private IP address blocks: 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16. * * * Doesn't overlap with any CIDR block assigned to the VPC that you selected for VPC. * * * Between /24 and /12. */ serviceIpv4Cidr: string; /** * The CIDR block that Kubernetes pod and service IP addresses are assigned from if you specify `ipv6` for `ipFamily` when you create the cluster. Kubernetes assigns service addresses from the unique local address range (fc00::/7) because you can't specify a custom IPv6 CIDR block when you create the cluster. */ serviceIpv6Cidr: string; } interface ClusterKubernetesNetworkConfigElasticLoadBalancing { /** * Indicates if the load balancing capability is enabled on your EKS Auto Mode cluster. If the load balancing capability is enabled, EKS Auto Mode will create and delete load balancers in your Amazon Web Services account. */ enabled: boolean; } interface ClusterOutpostConfig { /** * The Amazon EC2 instance type that you want to use for your local Amazon EKS cluster on Outposts. The instance type that you specify is used for all Kubernetes control plane instances. The instance type can't be changed after cluster creation. Choose an instance type based on the number of nodes that your cluster will have. If your cluster will have: * * * 1–20 nodes, then we recommend specifying a large instance type. * * * 21–100 nodes, then we recommend specifying an xlarge instance type. * * * 101–250 nodes, then we recommend specifying a 2xlarge instance type. * * For a list of the available Amazon EC2 instance types, see Compute and storage in AWS Outposts rack features The control plane is not automatically scaled by Amazon EKS. */ controlPlaneInstanceType: string; /** * An object representing the placement configuration for all the control plane instances of your local Amazon EKS cluster on AWS Outpost. * The `controlPlanePlacement` configuration block supports the following arguments: */ controlPlanePlacement?: outputs.eks.ClusterOutpostConfigControlPlanePlacement; /** * Amazon EC2 instance type for etcd instances of your local Amazon EKS cluster on AWS Outposts. */ etcdInstanceType: string; /** * Placement configuration for the etcd instances of your local Amazon EKS cluster on an AWS Outpost. * The `etcdPlacement` configuration block supports the following arguments: */ etcdPlacement: outputs.eks.ClusterOutpostConfigEtcdPlacement; /** * The ARN of the Outpost that you want to use for your local Amazon EKS cluster on Outposts. This argument is a list of arns, but only a single Outpost ARN is supported currently. */ outpostArns: string[]; } interface ClusterOutpostConfigControlPlanePlacement { /** * Name of the placement group for the Kubernetes control plane instances. This setting can't be changed after cluster creation. */ groupName?: string; /** * Placement group spread level for control plane instances. Valid values: `host`, `rack`. */ spreadLevel: string; } interface ClusterOutpostConfigEtcdPlacement { /** * Placement group spread level for etcd instances. Valid values: `host`, `rack`. */ spreadLevel: string; } interface ClusterRemoteNetworkConfig { /** * Configuration block with remote node network configuration for EKS Hybrid Nodes. Detailed below. */ remoteNodeNetworks?: outputs.eks.ClusterRemoteNetworkConfigRemoteNodeNetworks; /** * Configuration block with remote pod network configuration for EKS Hybrid Nodes. Detailed below. */ remotePodNetworks?: outputs.eks.ClusterRemoteNetworkConfigRemotePodNetworks; } interface ClusterRemoteNetworkConfigRemoteNodeNetworks { /** * List of network CIDRs that can contain hybrid nodes. */ cidrs?: string[]; } interface ClusterRemoteNetworkConfigRemotePodNetworks { /** * List of network CIDRs that can contain pods that run Kubernetes webhooks on hybrid nodes. */ cidrs?: string[]; } interface ClusterStorageConfig { /** * Configuration block with block storage configuration for the cluster. Detailed below. */ blockStorage?: outputs.eks.ClusterStorageConfigBlockStorage; } interface ClusterStorageConfigBlockStorage { /** * Indicates if the block storage capability is enabled on your EKS Auto Mode cluster. If the block storage capability is enabled, EKS Auto Mode will create and delete block storage volumes in your Amazon Web Services account. */ enabled: boolean; } interface ClusterUpgradePolicy { /** * Support type to use for the cluster. If the cluster is set to `EXTENDED`, it will enter extended support at the end of standard support. If the cluster is set to `STANDARD`, it will be automatically upgraded at the end of standard support. Valid values are `EXTENDED`, `STANDARD` */ supportType: string; } interface ClusterVpcConfig { /** * Cluster security group that is created by Amazon EKS for the cluster. Managed node groups use this security group for control-plane-to-data-plane communication. */ clusterSecurityGroupId: string; /** * Egress mode for the EKS control plane. Valid values are `AWS_MANAGED` and `CUSTOMER_ROUTED`. Defaults to `AWS_MANAGED`. Changing from `CUSTOMER_ROUTED` back to `AWS_MANAGED` forces a new resource. */ controlPlaneEgressMode: string; /** * Whether the Amazon EKS private API server endpoint is enabled. Default is `false`. */ endpointPrivateAccess?: boolean; /** * Whether the Amazon EKS public API server endpoint is enabled. Default is `true`. */ endpointPublicAccess?: boolean; /** * List of CIDR blocks. Indicates which CIDR blocks can access the Amazon EKS public API server endpoint when enabled. EKS defaults this to a list with `0.0.0.0/0`. The provider will only perform drift detection of its value when present in a configuration. */ publicAccessCidrs: string[]; /** * List of security group IDs for the cross-account elastic network interfaces that Amazon EKS creates to use to allow communication between your worker nodes and the Kubernetes control plane. */ securityGroupIds?: string[]; /** * List of subnet IDs. Must be in at least two different availability zones. Amazon EKS creates cross-account elastic network interfaces in these subnets to allow communication between your worker nodes and the Kubernetes control plane. */ subnetIds: string[]; /** * ID of the VPC associated with your cluster. */ vpcId: string; } interface ClusterZonalShiftConfig { /** * Whether zonal shift is enabled for the cluster. */ enabled?: boolean; } interface FargateProfileSelector { /** * Key-value map of Kubernetes labels for selection. */ labels?: { [key: string]: string; }; /** * Kubernetes namespace for selection. * * The following arguments are optional: */ namespace: string; } interface GetAccessPoliciesAccessPolicy { /** * ARN of the access policy. */ arn: string; /** * Name of the access policy. */ name: string; } interface GetAddonPodIdentityAssociation { /** * ARN of the IAM role associated with the EKS add-on. */ roleArn: string; /** * Service account associated with the EKS add-on. */ serviceAccount: string; } interface GetClusterAccessConfig { /** * Values returned are `CONFIG_MAP`, `API` or `API_AND_CONFIG_MAP` */ authenticationMode: string; /** * Default to `true`. */ bootstrapClusterCreatorAdminPermissions: boolean; } interface GetClusterCertificateAuthority { /** * The base64 encoded certificate data required to communicate with your cluster. Add this to the `certificate-authority-data` section of the `kubeconfig` file for your cluster. */ data: string; } interface GetClusterComputeConfig { /** * Whether zonal shift is enabled. */ enabled: boolean; /** * List of node pools for the EKS Auto Mode compute capability. */ nodePools: string[]; /** * The ARN of the IAM Role EKS will assign to EC2 Managed Instances in your EKS Auto Mode cluster. */ nodeRoleArn: string; } interface GetClusterControlPlaneScalingConfig { /** * The control plane scaling tier. Valid values are `standard`, `tier-xl`, `tier-2xl`, `tier-4xl`, or `tier-8xl`. */ tier: string; } interface GetClusterIdentity { /** * Nested attribute containing [OpenID Connect](https://openid.net/connect/) identity provider information for the cluster. */ oidcs: outputs.eks.GetClusterIdentityOidc[]; } interface GetClusterIdentityOidc { /** * Issuer URL for the OpenID Connect identity provider. */ issuer: string; } interface GetClusterKubeApiServerConfig { /** * The duration that Kubernetes events are retained. */ eventTtl: string; /** * The port range for NodePort services. */ serviceNodePortRanges: outputs.eks.GetClusterKubeApiServerConfigServiceNodePortRange[]; } interface GetClusterKubeApiServerConfigServiceNodePortRange { /** * The maximum port number in the range. */ maxPort: number; /** * The minimum port number in the range. */ minPort: number; } interface GetClusterKubeControllerManagerConfig { /** * Configuration for the horizontal pod autoscaler controller. */ horizontalPodAutoscalerControllerConfigs: outputs.eks.GetClusterKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig[]; /** * Configuration for the pod garbage collection controller. */ podGcControllerConfigs: outputs.eks.GetClusterKubeControllerManagerConfigPodGcControllerConfig[]; } interface GetClusterKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig { /** * The interval between each sync of the horizontal pod autoscaler. */ horizontalPodAutoscalerSyncPeriod: string; } interface GetClusterKubeControllerManagerConfigPodGcControllerConfig { /** * The number of terminated pods that can exist before the pod garbage collector starts deleting them. */ terminatedPodGcThreshold: number; } interface GetClusterKubeSchedulerConfig { /** * Configuration for the NodeResourcesFit scheduler plugin. */ nodeResourcesFits: outputs.eks.GetClusterKubeSchedulerConfigNodeResourcesFit[]; } interface GetClusterKubeSchedulerConfigNodeResourcesFit { /** * The scoring strategy used to rank nodes during scheduling. */ scoringStrategies: outputs.eks.GetClusterKubeSchedulerConfigNodeResourcesFitScoringStrategy[]; } interface GetClusterKubeSchedulerConfigNodeResourcesFitScoringStrategy { /** * List of resource weights for scoring nodes. */ resources: outputs.eks.GetClusterKubeSchedulerConfigNodeResourcesFitScoringStrategyResource[]; /** * The scoring strategy type (`LeastAllocated` or `MostAllocated`). */ type: string; } interface GetClusterKubeSchedulerConfigNodeResourcesFitScoringStrategyResource { /** * Name of the cluster. */ name: string; /** * The weight assigned to the resource for scoring (1-100). */ weight: number; } interface GetClusterKubernetesNetworkConfig { /** * Contains Elastic Load Balancing configuration for EKS Auto Mode enabled cluster. */ elasticLoadBalancings: outputs.eks.GetClusterKubernetesNetworkConfigElasticLoadBalancing[]; /** * `ipv4` or `ipv6`. */ ipFamily: string; /** * The CIDR block to assign Kubernetes pod and service IP addresses from if `ipv4` was specified when the cluster was created. */ serviceIpv4Cidr: string; /** * The CIDR block to assign Kubernetes pod and service IP addresses from if `ipv6` was specified when the cluster was created. Kubernetes assigns service addresses from the unique local address range (fc00::/7) because you can't specify a custom IPv6 CIDR block when you create the cluster. */ serviceIpv6Cidr: string; } interface GetClusterKubernetesNetworkConfigElasticLoadBalancing { /** * Whether zonal shift is enabled. */ enabled: boolean; } interface GetClusterOutpostConfig { /** * The Amazon EC2 instance type for all Kubernetes control plane instances. */ controlPlaneInstanceType: string; /** * An object representing the placement configuration for all the control plane instances of your local Amazon EKS cluster on AWS Outpost. */ controlPlanePlacements: outputs.eks.GetClusterOutpostConfigControlPlanePlacement[]; /** * Amazon EC2 instance type for etcd instances. */ etcdInstanceType: string; /** * Placement configuration for the etcd instances. */ etcdPlacements: outputs.eks.GetClusterOutpostConfigEtcdPlacement[]; /** * List of ARNs of the Outposts hosting the EKS cluster. Only a single ARN is supported currently. */ outpostArns: string[]; } interface GetClusterOutpostConfigControlPlanePlacement { /** * The name of the placement group for the Kubernetes control plane instances. */ groupName: string; /** * Placement group spread level for etcd instances. */ spreadLevel: string; } interface GetClusterOutpostConfigEtcdPlacement { /** * Placement group spread level for etcd instances. */ spreadLevel: string; } interface GetClusterRemoteNetworkConfig { /** * The networks that can contain hybrid nodes. */ remoteNodeNetworks: outputs.eks.GetClusterRemoteNetworkConfigRemoteNodeNetwork[]; /** * The networks that can contain pods that run Kubernetes webhooks on hybrid nodes. */ remotePodNetworks: outputs.eks.GetClusterRemoteNetworkConfigRemotePodNetwork[]; } interface GetClusterRemoteNetworkConfigRemoteNodeNetwork { /** * List of network CIDRs that can contain pods that run Kubernetes webhooks on hybrid nodes. */ cidrs: string[]; } interface GetClusterRemoteNetworkConfigRemotePodNetwork { /** * List of network CIDRs that can contain pods that run Kubernetes webhooks on hybrid nodes. */ cidrs: string[]; } interface GetClusterStorageConfig { /** * Contains block storage configuration for EKS Auto Mode enabled cluster. */ blockStorages: outputs.eks.GetClusterStorageConfigBlockStorage[]; } interface GetClusterStorageConfigBlockStorage { /** * Whether zonal shift is enabled. */ enabled: boolean; } interface GetClusterUpgradePolicy { /** * Support type to use for the cluster. */ supportType: string; } interface GetClusterVersionsClusterVersion { /** * Type of clusters to filter by. * Currently, the only valid value is `eks`. */ clusterType: string; /** * Kubernetes version supported by EKS. */ clusterVersion: string; /** * Default control plane component configuration and constraints for this version. */ controlPlaneComponentConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfig[]; /** * Available provisioned control plane scaling tiers and their capabilities. */ controlPlaneScalingTiers: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTier[]; /** * Default eks platform version for the cluster version. */ defaultPlatformVersion: string; /** * Default Kubernetes version for the cluster version. */ defaultVersion: boolean; /** * End of extended support date for the cluster version. */ endOfExtendedSupportDate: string; /** * End of standard support date for the cluster version. */ endOfStandardSupportDate: string; /** * Kubernetes patch version for the cluster version. */ kubernetesPatchVersion: string; /** * Release date of the cluster version. */ releaseDate: string; /** * Status of the EKS cluster versions to list. * Valid values are `STANDARD_SUPPORT` or `UNSUPPORTED` or `EXTENDED_SUPPORT`. */ versionStatus: string; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfig { /** * Kubernetes API server configuration defaults and constraints. */ kubeApiServerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfig[]; /** * Kubernetes controller manager configuration defaults and constraints. */ kubeControllerManagerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfig[]; /** * Kubernetes scheduler configuration defaults and constraints. */ kubeSchedulerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfig[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfig { /** * Event TTL configuration with default value and constraints. */ eventTtls: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigEventTtl[]; /** * Service node port range configuration with default value and constraints. */ serviceNodePortRanges: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRange[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigEventTtl { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigEventTtlConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValue: string; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigEventTtlConstraint { /** * The maximum allowed duration. */ max: string; /** * The minimum allowed duration. */ min: string; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRange { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValues: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeDefaultValue[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeConstraint { /** * The allowed range for the maximum port (`min`, `max`). */ maxPorts: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeConstraintMaxPort[]; /** * The allowed range for the minimum port (`min`, `max`). */ minPorts: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeConstraintMinPort[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeConstraintMaxPort { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeConstraintMinPort { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeApiServerConfigServiceNodePortRangeDefaultValue { /** * The allowed range for the maximum port (`min`, `max`). */ maxPort: number; /** * The allowed range for the minimum port (`min`, `max`). */ minPort: number; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfig { /** * HPA controller configuration defaults and constraints. */ horizontalPodAutoscalerControllerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig[]; /** * Pod garbage collection controller configuration defaults and constraints. */ podGcControllerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigPodGcControllerConfig[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig { /** * HPA sync period configuration with default value and constraints. */ horizontalPodAutoscalerSyncPeriods: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriod[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriod { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriodConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValue: string; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriodConstraint { /** * The maximum allowed duration. */ max: string; /** * The minimum allowed duration. */ min: string; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigPodGcControllerConfig { /** * Terminated pod GC threshold configuration with default value and constraints. */ terminatedPodGcThresholds: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThreshold[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThreshold { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThresholdConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValue: number; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThresholdConstraint { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfig { /** * NodeResourcesFit plugin configuration with default value and constraints. */ nodeResourcesFits: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFit[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFit { /** * Allowed values for the strategy type. */ scoringStrategies: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategy[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategy { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValues: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValue[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraint { /** * Constraints for resource names and weights. */ resources: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResource[]; /** * Allowed values for the strategy type. */ scoringStrategies: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintScoringStrategy[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResource { names: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceName[]; weights: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceWeight[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceName { allowedValues: string[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceWeight { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintScoringStrategy { allowedValues: string[]; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValue { /** * Constraints for resource names and weights. */ resources: outputs.eks.GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValueResource[]; type: string; } interface GetClusterVersionsClusterVersionControlPlaneComponentConfigKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValueResource { name: string; weight: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTier { /** * Maximum API request concurrency supported by this tier. */ apiRequestConcurrency: number; /** * Maximum cluster database size in GB supported by this tier. */ clusterDatabaseSizeGb: number; /** * Control plane component configuration overrides specific to this tier (same structure as `controlPlaneComponentConfig`). */ controlPlaneComponentConfigOverrides: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverride[]; /** * Maximum pod scheduling rate per second supported by this tier. */ podSchedulingRatePerSecond: number; /** * The name of the scaling tier. */ tierName: string; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverride { /** * Kubernetes API server configuration defaults and constraints. */ kubeApiServerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfig[]; /** * Kubernetes controller manager configuration defaults and constraints. */ kubeControllerManagerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfig[]; /** * Kubernetes scheduler configuration defaults and constraints. */ kubeSchedulerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfig[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfig { /** * Event TTL configuration with default value and constraints. */ eventTtls: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigEventTtl[]; /** * Service node port range configuration with default value and constraints. */ serviceNodePortRanges: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRange[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigEventTtl { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigEventTtlConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValue: string; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigEventTtlConstraint { /** * The maximum allowed duration. */ max: string; /** * The minimum allowed duration. */ min: string; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRange { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValues: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeDefaultValue[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeConstraint { /** * The allowed range for the maximum port (`min`, `max`). */ maxPorts: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeConstraintMaxPort[]; /** * The allowed range for the minimum port (`min`, `max`). */ minPorts: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeConstraintMinPort[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeConstraintMaxPort { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeConstraintMinPort { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeApiServerConfigServiceNodePortRangeDefaultValue { /** * The allowed range for the maximum port (`min`, `max`). */ maxPort: number; /** * The allowed range for the minimum port (`min`, `max`). */ minPort: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfig { /** * HPA controller configuration defaults and constraints. */ horizontalPodAutoscalerControllerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig[]; /** * Pod garbage collection controller configuration defaults and constraints. */ podGcControllerConfigs: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigPodGcControllerConfig[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfig { /** * HPA sync period configuration with default value and constraints. */ horizontalPodAutoscalerSyncPeriods: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriod[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriod { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriodConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValue: string; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigHorizontalPodAutoscalerControllerConfigHorizontalPodAutoscalerSyncPeriodConstraint { /** * The maximum allowed duration. */ max: string; /** * The minimum allowed duration. */ min: string; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigPodGcControllerConfig { /** * Terminated pod GC threshold configuration with default value and constraints. */ terminatedPodGcThresholds: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThreshold[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThreshold { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThresholdConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValue: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeControllerManagerConfigPodGcControllerConfigTerminatedPodGcThresholdConstraint { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfig { /** * NodeResourcesFit plugin configuration with default value and constraints. */ nodeResourcesFits: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFit[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFit { /** * Allowed values for the strategy type. */ scoringStrategies: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategy[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategy { /** * Scoring strategy constraints. */ constraints: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraint[]; /** * Default scoring strategy (`type`, `resources`). */ defaultValues: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValue[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraint { /** * Constraints for resource names and weights. */ resources: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResource[]; /** * Allowed values for the strategy type. */ scoringStrategies: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintScoringStrategy[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResource { names: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceName[]; weights: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceWeight[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceName { allowedValues: string[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintResourceWeight { /** * The maximum allowed duration. */ max: number; /** * The minimum allowed duration. */ min: number; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyConstraintScoringStrategy { allowedValues: string[]; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValue { /** * Constraints for resource names and weights. */ resources: outputs.eks.GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValueResource[]; type: string; } interface GetClusterVersionsClusterVersionControlPlaneScalingTierControlPlaneComponentConfigOverrideKubeSchedulerConfigNodeResourcesFitScoringStrategyDefaultValueResource { name: string; weight: number; } interface GetClusterVpcConfig { /** * The cluster security group that was created by Amazon EKS for the cluster. */ clusterSecurityGroupId: string; /** * The egress mode for the EKS control plane. Possible values are `AWS_MANAGED` and `CUSTOMER_ROUTED`. */ controlPlaneEgressMode: string; /** * Indicates whether or not the Amazon EKS private API server endpoint is enabled. */ endpointPrivateAccess: boolean; /** * Indicates whether or not the Amazon EKS public API server endpoint is enabled. */ endpointPublicAccess: boolean; /** * List of CIDR blocks. Indicates which CIDR blocks can access the Amazon EKS public API server endpoint. */ publicAccessCidrs: string[]; /** * List of security group IDs */ securityGroupIds: string[]; /** * List of subnet IDs */ subnetIds: string[]; /** * The VPC associated with your cluster. */ vpcId: string; } interface GetClusterZonalShiftConfig { /** * Whether zonal shift is enabled. */ enabled: boolean; } interface GetNodeGroupLaunchTemplate { /** * The ID of the launch template. */ id: string; /** * Name of the AutoScaling Group. */ name: string; /** * Kubernetes version. */ version: string; } interface GetNodeGroupRemoteAccess { /** * EC2 Key Pair name that provides access for SSH communication with the worker nodes in the EKS Node Group. */ ec2SshKey: string; /** * Set of EC2 Security Group IDs to allow SSH access (port 22) from on the worker nodes. */ sourceSecurityGroupIds: string[]; } interface GetNodeGroupResource { /** * List of objects containing information about AutoScaling Groups. */ autoscalingGroups: outputs.eks.GetNodeGroupResourceAutoscalingGroup[]; /** * Identifier of the remote access EC2 Security Group. */ remoteAccessSecurityGroupId: string; } interface GetNodeGroupResourceAutoscalingGroup { /** * Name of the AutoScaling Group. */ name: string; } interface GetNodeGroupScalingConfig { /** * Desired number of worker nodes. */ desiredSize: number; /** * Maximum number of worker nodes. */ maxSize: number; /** * Minimum number of instances maintained in the warm pool. */ minSize: number; } interface GetNodeGroupTaint { /** * The effect of the taint. */ effect: string; /** * The key of the taint. */ key: string; /** * The value of the taint. */ value: string; } interface GetNodeGroupUpdateConfig { maxUnavailable: number; maxUnavailablePercentage: number; updateStrategy: string; } interface GetNodeGroupWarmPoolConfig { /** * Maximum number of instances allowed to be in the warm pool combined with the Auto Scaling Group. */ maxGroupPreparedCapacity: number; /** * Minimum number of instances maintained in the warm pool. */ minSize: number; /** * Instance state that warm pool instances are transitioned to. */ poolState: string; /** * Whether instances in the Auto Scaling Group are returned to the warm pool on scale in. */ reuseOnScaleIn: boolean; } interface IdentityProviderConfigOidc { /** * Client ID for the OpenID Connect identity provider. */ clientId: string; /** * The JWT claim that the provider will use to return groups. */ groupsClaim?: string; /** * A prefix that is prepended to group claims e.g., `oidc:`. */ groupsPrefix?: string; /** * The name of the identity provider config. */ identityProviderConfigName: string; /** * Issuer URL for the OpenID Connect identity provider. */ issuerUrl: string; /** * The key value pairs that describe required claims in the identity token. */ requiredClaims?: { [key: string]: string; }; /** * The JWT claim that the provider will use as the username. */ usernameClaim?: string; /** * A prefix that is prepended to username claims. */ usernamePrefix?: string; } interface NodeGroupLaunchTemplate { /** * Identifier of the EC2 Launch Template. Conflicts with `name`. */ id: string; /** * Name of the EC2 Launch Template. Conflicts with `id`. */ name: string; /** * EC2 Launch Template version number. While the API accepts values like `$Default` and `$Latest`, the API will convert the value to the associated version number (e.g., `1`) on read and the provider will show a difference on next plan. Using the `defaultVersion` or `latestVersion` attribute of the `aws.ec2.LaunchTemplate` resource or data source is recommended for this argument. */ version: string; } interface NodeGroupNodeRepairConfig { /** * Specifies whether to enable node auto repair for the node group. Node auto repair is disabled by default. Defaults to `false`. */ enabled?: boolean; /** * Maximum number of nodes that can be repaired concurrently or in parallel, expressed as a count of unhealthy nodes. Conflicts with `maxParallelNodesRepairedPercentage`. */ maxParallelNodesRepairedCount?: number; /** * Maximum number of nodes that can be repaired concurrently or in parallel, expressed as a percentage of unhealthy nodes. Conflicts with `maxParallelNodesRepairedCount`. */ maxParallelNodesRepairedPercentage?: number; /** * Count threshold of unhealthy nodes, above which node auto repair actions will stop. Conflicts with `maxUnhealthyNodeThresholdPercentage`. */ maxUnhealthyNodeThresholdCount?: number; /** * Percentage threshold of unhealthy nodes, above which node auto repair actions will stop. Conflicts with `maxUnhealthyNodeThresholdCount`. */ maxUnhealthyNodeThresholdPercentage?: number; /** * Granular overrides for specific repair actions. See `nodeRepairConfigOverrides` below for details. */ nodeRepairConfigOverrides?: outputs.eks.NodeGroupNodeRepairConfigNodeRepairConfigOverride[]; } interface NodeGroupNodeRepairConfigNodeRepairConfigOverride { /** * Minimum time in minutes to wait before attempting to repair a node with the specified `nodeMonitoringCondition` and `nodeUnhealthyReason`. */ minRepairWaitTimeMins: number; /** * Unhealthy condition reported by the node monitoring agent that this override applies to. */ nodeMonitoringCondition: string; /** * Reason reported by the node monitoring agent that this override applies to. */ nodeUnhealthyReason: string; /** * Repair action to take for nodes when all of the specified conditions are met. Valid values are defined by the EKS API. */ repairAction: string; } interface NodeGroupRemoteAccess { /** * EC2 Key Pair name that provides access for remote communication with the worker nodes in the EKS Node Group. If you specify this configuration, but do not specify `sourceSecurityGroupIds` when you create an EKS Node Group, either port 3389 for Windows, or port 22 for all other operating systems is opened on the worker nodes to the Internet (0.0.0.0/0). For Windows nodes, this will allow you to use RDP, for all others this allows you to SSH into the worker nodes. */ ec2SshKey?: string; /** * Set of EC2 Security Group IDs to allow SSH access (port 22) from on the worker nodes. If you specify `ec2SshKey`, but do not specify this configuration when you create an EKS Node Group, port 22 on the worker nodes is opened to the Internet (0.0.0.0/0). */ sourceSecurityGroupIds?: string[]; } interface NodeGroupResource { /** * List of objects containing information about AutoScaling Groups. */ autoscalingGroups: outputs.eks.NodeGroupResourceAutoscalingGroup[]; /** * Identifier of the remote access EC2 Security Group. */ remoteAccessSecurityGroupId: string; } interface NodeGroupResourceAutoscalingGroup { /** * Name of the AutoScaling Group. */ name: string; } interface NodeGroupScalingConfig { /** * Desired number of worker nodes. */ desiredSize: number; /** * Maximum number of worker nodes. */ maxSize: number; /** * Minimum number of worker nodes. */ minSize: number; } interface NodeGroupTaint { /** * The effect of the taint. Valid values: `NO_SCHEDULE`, `NO_EXECUTE`, `PREFER_NO_SCHEDULE`. */ effect: string; /** * The key of the taint. Maximum length of 63. */ key: string; /** * The value of the taint. Maximum length of 63. */ value?: string; } interface NodeGroupUpdateConfig { /** * Desired max number of unavailable worker nodes during node group update. */ maxUnavailable?: number; /** * Desired max percentage of unavailable worker nodes during node group update. */ maxUnavailablePercentage?: number; /** * Strategy to use for updating the node group. Valid values: `MINIMAL` and `DEFAULT`. */ updateStrategy?: string; } interface NodeGroupWarmPoolConfig { /** * Maximum number of instances that are allowed to be in the warm pool combined with the Auto Scaling Group. Use `-1` to specify an unlimited capacity. */ maxGroupPreparedCapacity: number; /** * Minimum number of instances to maintain in the warm pool. Defaults to `0`. */ minSize: number; /** * Instance state to transition warm pool instances to. Valid values: `STOPPED`, `RUNNING`, `HIBERNATED`. Defaults to `STOPPED`. */ poolState: string; /** * Whether to return instances in the Auto Scaling Group to the warm pool on scale in. Not supported on Bottlerocket. Defaults to `false`. */ reuseOnScaleIn: boolean; } } export declare namespace elasticache { interface ClusterCacheNode { address: string; /** * Availability Zone for the cache cluster. If you want to create cache nodes in multi-az, use `preferredAvailabilityZones` instead. Default: System chosen Availability Zone. Changing this value will re-create the resource. */ availabilityZone: string; id: string; outpostArn: string; /** * The port number on which each of the cache nodes will accept connections. For Memcached the default is 11211, and for Redis the default port is 6379. Cannot be provided with `replicationGroupId`. Changing this value will re-create the resource. */ port: number; } interface ClusterLogDeliveryConfiguration { /** * Name of either the CloudWatch Logs LogGroup or Kinesis Data Firehose resource. */ destination: string; /** * For CloudWatch Logs use `cloudwatch-logs` or for Kinesis Data Firehose use `kinesis-firehose`. */ destinationType: string; /** * Valid values are `json` or `text` */ logFormat: string; /** * Valid values are `slow-log` or `engine-log`. Max 1 of each. */ logType: string; } interface GetClusterCacheNode { address: string; /** * Availability Zone for the cache cluster. */ availabilityZone: string; id: string; outpostArn: string; /** * The port number on which each of the cache nodes will * accept connections. */ port: number; } interface GetClusterLogDeliveryConfiguration { destination: string; destinationType: string; logFormat: string; logType: string; } interface GetReplicationGroupLogDeliveryConfiguration { destination: string; destinationType: string; logFormat: string; logType: string; } interface GetReplicationGroupNodeGroupConfiguration { /** * ID of the node group. */ nodeGroupId: string; /** * Availability Zone for the primary node. */ primaryAvailabilityZone: string; /** * Outpost ARN of the primary node. */ primaryOutpostArn: string; /** * List of Availability Zones for the replica nodes. */ replicaAvailabilityZones: string[]; /** * Number of replica nodes in this node group. */ replicaCount: number; /** * List of outpost ARNs for the replica nodes. */ replicaOutpostArns: string[]; /** * Keyspace for this node group (shard). */ slots: string; } interface GetServerlessCacheCacheUsageLimits { /** * The maximum data storage limit in the cache, expressed in Gigabytes. See `dataStorage` Block for details. */ dataStorage: outputs.elasticache.GetServerlessCacheCacheUsageLimitsDataStorage; /** * The configured number of ElastiCache Processing Units (ECPU) the cache can consume per second. See `ecpuPerSecond` Block for details. */ ecpuPerSecond: outputs.elasticache.GetServerlessCacheCacheUsageLimitsEcpuPerSecond; } interface GetServerlessCacheCacheUsageLimitsDataStorage { /** * The maximum number of ECPUs the cache can consume per second. */ maximum: number; /** * The minimum number of ECPUs the cache can consume per second. */ minimum: number; /** * The unit that the storage is measured in. */ unit: string; } interface GetServerlessCacheCacheUsageLimitsEcpuPerSecond { /** * The maximum number of ECPUs the cache can consume per second. */ maximum: number; /** * The minimum number of ECPUs the cache can consume per second. */ minimum: number; } interface GetServerlessCacheEndpoint { /** * The DNS hostname of the cache node. */ address: string; /** * The port number that the cache engine is listening on. Set as integer. */ port: number; } interface GetServerlessCacheReaderEndpoint { /** * The DNS hostname of the cache node. */ address: string; /** * The port number that the cache engine is listening on. Set as integer. */ port: number; } interface GetServiceUpdateActionsUpdateAction { /** * ID of Cache Cluster to list updates for. If neither `cacheClusterId` nor `replicationGroupId` are specified, all service update actions will be listed. */ cacheClusterId: string; /** * Engine this update applies to. */ engine: string; /** * Estimated duration of update. */ estimatedUpdateTime: string; /** * Date the update should be applied by. */ recommendedApplyByDate: string; /** * Date the update was released. */ releaseDate: string; /** * ID of Replication Group to list updates for. If neither `replicationGroupId` nor `cacheClusterId` are specified, all service update actions will be listed. */ replicationGroupId: string; /** * Name of the update. */ serviceUpdateName: string; /** * Severity of the update. One of `critical`, `important`, `medium`, or `low`. */ serviceUpdateSeverity: string; /** * Service update statuses to include in list. Valid values are `available`, `cancelled`, and `expired`. If no value is specified, service updates in all statuses will be listed. */ serviceUpdateStatus: string; /** * Type of the update. */ serviceUpdateType: string; /** * Status of the update action. */ updateActionStatus: string; } interface GetServiceUpdatesServiceUpdate { /** * Whether the update will be applied after `recommendedApplyByDate`. */ autoUpdateAfterRecommendedApplyByDate: boolean; /** * Description of the update. */ description: string; /** * Date the update will no longer be available. */ endDate: string; /** * Engine this update applies to. */ engine: string; /** * Engine version this update applies to. */ engineVersion: string; /** * Estimated duration of update. */ estimatedUpdateTime: string; /** * Name of the update. */ name: string; /** * Date the update should be applied by. */ recommendedApplyByDate: string; /** * Date the update was released. */ releaseDate: string; /** * Severity of the update. One of `critical`, `important`, `medium`, or `low`. */ severity: string; /** * Set of one or more Service Update statuses. Elements must be one of `available`, `cancelled`, or `expired`. */ status: string; /** * Type of the update. */ type: string; } interface GetUserAuthenticationMode { passwordCount?: number; type?: string; } interface GlobalReplicationGroupGlobalNodeGroup { /** * The ID of the global node group. */ globalNodeGroupId: string; /** * The keyspace for this node group. */ slots: string; } interface ParameterGroupParameter { /** * The name of the ElastiCache parameter. */ name: string; /** * The value of the ElastiCache parameter. */ value: string; } interface ReplicationGroupLogDeliveryConfiguration { /** * Name of either the CloudWatch Logs LogGroup or Kinesis Data Firehose resource. */ destination: string; /** * For CloudWatch Logs use `cloudwatch-logs` or for Kinesis Data Firehose use `kinesis-firehose`. */ destinationType: string; /** * Valid values are `json` or `text` */ logFormat: string; /** * Valid values are `slow-log` or `engine-log`. Max 1 of each. */ logType: string; } interface ReplicationGroupNodeGroupConfiguration { /** * ID for the node group. Redis (cluster mode disabled) replication groups don't have node group IDs, so this value is ignored. For Redis (cluster mode enabled) replication groups, the node group ID is a 1 to 4 character alphanumeric string. */ nodeGroupId?: string; /** * Availability zone for the primary node. */ primaryAvailabilityZone: string; /** * ARN of the Outpost for the primary node. */ primaryOutpostArn: string; /** * List of availability zones for the replica nodes. */ replicaAvailabilityZones: string[]; /** * Number of replica nodes in this node group. Default AWS limit is 5. Higher values may be available with a quota increase. */ replicaCount?: number; /** * List of ARNs of the Outposts for the replica nodes. */ replicaOutpostArns: string[]; /** * Keyspace for this node group. Format is `start-end` (e.g., `0-5460`). For Redis (cluster mode disabled) replication groups, this value is ignored. */ slots?: string; } interface ReservedCacheNodeRecurringCharge { recurringChargeAmount: number; recurringChargeFrequency: string; } interface ReservedCacheNodeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ServerlessCacheCacheUsageLimits { /** * The maximum data storage limit in the cache, expressed in Gigabytes. See `dataStorage` Block for details. */ dataStorage?: outputs.elasticache.ServerlessCacheCacheUsageLimitsDataStorage; /** * The configuration for the number of ElastiCache Processing Units (ECPU) the cache can consume per second. See `ecpuPerSecond` Block for details. */ ecpuPerSeconds?: outputs.elasticache.ServerlessCacheCacheUsageLimitsEcpuPerSecond[]; } interface ServerlessCacheCacheUsageLimitsDataStorage { /** * The upper limit for data storage the cache is set to use. Must be between 1 and 5,000. */ maximum: number; /** * The lower limit for data storage the cache is set to use. Must be between 1 and 5,000. */ minimum: number; /** * The unit that the storage is measured in, in GB. */ unit: string; } interface ServerlessCacheCacheUsageLimitsEcpuPerSecond { /** * The maximum number of ECPUs the cache can consume per second. Must be between 1,000 and 15,000,000. */ maximum: number; /** * The minimum number of ECPUs the cache can consume per second. Must be between 1,000 and 15,000,000. */ minimum: number; } interface ServerlessCacheEndpoint { /** * The DNS hostname of the cache node. */ address: string; /** * The port number that the cache engine is listening on. Set as integer. */ port: number; } interface ServerlessCacheReaderEndpoint { /** * The DNS hostname of the cache node. */ address: string; /** * The port number that the cache engine is listening on. Set as integer. */ port: number; } interface ServerlessCacheTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface UserAuthenticationMode { passwordCount: number; /** * Specifies the passwords to use for authentication if `type` is set to `password`. */ passwords?: string[]; /** * Specifies the authentication type. Possible options are: `password`, `no-password-required` or `iam`. */ type: string; } } export declare namespace elasticbeanstalk { interface ApplicationAppversionLifecycle { /** * Set to `true` to delete a version's source bundle from S3 when the application version is deleted. */ deleteSourceFromS3?: boolean; /** * The number of days to retain an application version ('max_age_in_days' and 'max_count' cannot be enabled simultaneously.). */ maxAgeInDays?: number; /** * The maximum number of application versions to retain ('max_age_in_days' and 'max_count' cannot be enabled simultaneously.). */ maxCount?: number; /** * The ARN of an IAM service role under which the application version is deleted. Elastic Beanstalk must have permission to assume this role. */ serviceRole: string; } interface ConfigurationTemplateSetting { /** * Name of the configuration option */ name: string; /** * Unique namespace identifying the option's associated AWS resource */ namespace: string; /** * resource name for [scheduled action](https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/command-options-general.html#command-options-general-autoscalingscheduledaction) */ resource?: string; /** * Value for the configuration option */ value: string; } interface EnvironmentAllSetting { /** * Name of the configuration option */ name: string; /** * Unique namespace identifying the option's associated AWS resource */ namespace: string; /** * resource name for [scheduled action](https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/command-options-general.html#command-options-general-autoscalingscheduledaction) */ resource?: string; /** * Value for the configuration option */ value: string; } interface EnvironmentSetting { /** * Name of the configuration option */ name: string; /** * Unique namespace identifying the option's associated AWS resource */ namespace: string; /** * resource name for [scheduled action](https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/command-options-general.html#command-options-general-autoscalingscheduledaction) */ resource?: string; /** * Value for the configuration option */ value: string; } interface GetApplicationAppversionLifecycle { /** * Specifies whether delete a version's source bundle from S3 when the application version is deleted. */ deleteSourceFromS3: boolean; /** * Number of days to retain an application version. */ maxAgeInDays: number; /** * Maximum number of application versions to retain. */ maxCount: number; /** * ARN of an IAM service role under which the application version is deleted. Elastic Beanstalk must have permission to assume this role. */ serviceRole: string; } } export declare namespace elasticsearch { interface DomainAdvancedSecurityOptions { /** * Whether advanced security is enabled. */ enabled: boolean; /** * Whether the internal user database is enabled. If not set, defaults to `false` by the AWS API. */ internalUserDatabaseEnabled?: boolean; /** * Configuration block for the main user. Detailed below. */ masterUserOptions?: outputs.elasticsearch.DomainAdvancedSecurityOptionsMasterUserOptions; } interface DomainAdvancedSecurityOptionsMasterUserOptions { /** * ARN for the main user. Only specify if `internalUserDatabaseEnabled` is not set or set to `false`. */ masterUserArn?: string; /** * Main user's username, which is stored in the Amazon Elasticsearch Service domain's internal database. Only specify if `internalUserDatabaseEnabled` is set to `true`. */ masterUserName?: string; /** * Main user's password, which is stored in the Amazon Elasticsearch Service domain's internal database. Only specify if `internalUserDatabaseEnabled` is set to `true`. */ masterUserPassword?: string; } interface DomainAutoTuneOptions { /** * The Auto-Tune desired state for the domain. Valid values: `ENABLED` or `DISABLED`. */ desiredState: string; /** * Configuration block for Auto-Tune maintenance windows. Can be specified multiple times for each maintenance window. Detailed below. */ maintenanceSchedules: outputs.elasticsearch.DomainAutoTuneOptionsMaintenanceSchedule[]; /** * Whether to roll back to default Auto-Tune settings when disabling Auto-Tune. Valid values: `DEFAULT_ROLLBACK` or `NO_ROLLBACK`. */ rollbackOnDisable: string; } interface DomainAutoTuneOptionsMaintenanceSchedule { /** * A cron expression specifying the recurrence pattern for an Auto-Tune maintenance schedule. */ cronExpressionForRecurrence: string; /** * Configuration block for the duration of the Auto-Tune maintenance window. Detailed below. */ duration: outputs.elasticsearch.DomainAutoTuneOptionsMaintenanceScheduleDuration; /** * Date and time at which to start the Auto-Tune maintenance schedule in [RFC3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ startAt: string; } interface DomainAutoTuneOptionsMaintenanceScheduleDuration { /** * The unit of time specifying the duration of an Auto-Tune maintenance window. Valid values: `HOURS`. */ unit: string; /** * An integer specifying the value of the duration of an Auto-Tune maintenance window. */ value: number; } interface DomainClusterConfig { /** * Configuration block containing cold storage configuration. Detailed below. */ coldStorageOptions: outputs.elasticsearch.DomainClusterConfigColdStorageOptions; /** * Number of dedicated main nodes in the cluster. */ dedicatedMasterCount?: number; /** * Whether dedicated main nodes are enabled for the cluster. */ dedicatedMasterEnabled?: boolean; /** * Instance type of the dedicated main nodes in the cluster. */ dedicatedMasterType?: string; /** * Number of instances in the cluster. */ instanceCount?: number; /** * Instance type of data nodes in the cluster. */ instanceType?: string; /** * Number of warm nodes in the cluster. Valid values are between `2` and `150`. `warmCount` can be only and must be set when `warmEnabled` is set to `true`. */ warmCount?: number; /** * Whether to enable warm storage. */ warmEnabled?: boolean; /** * Instance type for the Elasticsearch cluster's warm nodes. Valid values are `ultrawarm1.medium.elasticsearch`, `ultrawarm1.large.elasticsearch` and `ultrawarm1.xlarge.elasticsearch`. `warmType` can be only and must be set when `warmEnabled` is set to `true`. */ warmType?: string; /** * Configuration block containing zone awareness settings. Detailed below. */ zoneAwarenessConfig?: outputs.elasticsearch.DomainClusterConfigZoneAwarenessConfig; /** * Whether zone awareness is enabled, set to `true` for multi-az deployment. To enable awareness with three Availability Zones, the `availabilityZoneCount` within the `zoneAwarenessConfig` must be set to `3`. */ zoneAwarenessEnabled?: boolean; } interface DomainClusterConfigColdStorageOptions { /** * Boolean to enable cold storage for an Elasticsearch domain. Defaults to `false`. Master and ultrawarm nodes must be enabled for cold storage. */ enabled: boolean; } interface DomainClusterConfigZoneAwarenessConfig { /** * Number of Availability Zones for the domain to use with `zoneAwarenessEnabled`. Defaults to `2`. Valid values: `2` or `3`. */ availabilityZoneCount?: number; } interface DomainCognitoOptions { /** * Whether Amazon Cognito authentication with Kibana is enabled or not. */ enabled?: boolean; /** * ID of the Cognito Identity Pool to use. */ identityPoolId: string; /** * ARN of the IAM role that has the AmazonESCognitoAccess policy attached. */ roleArn: string; /** * ID of the Cognito User Pool to use. */ userPoolId: string; } interface DomainDomainEndpointOptions { /** * Fully qualified domain for your custom endpoint. */ customEndpoint?: string; /** * ACM certificate ARN for your custom endpoint. */ customEndpointCertificateArn?: string; /** * Whether to enable custom endpoint for the Elasticsearch domain. */ customEndpointEnabled?: boolean; /** * Whether or not to require HTTPS. Defaults to `true`. */ enforceHttps?: boolean; /** * Name of the TLS security policy that needs to be applied to the HTTPS endpoint. Valid values: `Policy-Min-TLS-1-0-2019-07`, `Policy-Min-TLS-1-2-2019-07`, and `Policy-Min-TLS-1-2-PFS-2023-10`. Pulumi will only perform drift detection if a configuration value is provided. */ tlsSecurityPolicy: string; } interface DomainEbsOptions { /** * Whether EBS volumes are attached to data nodes in the domain. */ ebsEnabled: boolean; /** * Baseline input/output (I/O) performance of EBS volumes attached to data nodes. Applicable only for the GP3 and Provisioned IOPS EBS volume types. */ iops: number; /** * Specifies the throughput (in MiB/s) of the EBS volumes attached to data nodes. Applicable only for the gp3 volume type. */ throughput: number; /** * Size of EBS volumes attached to data nodes (in GiB). */ volumeSize?: number; /** * Type of EBS volumes attached to data nodes. */ volumeType: string; } interface DomainEncryptAtRest { /** * Whether to enable encryption at rest. If the `encryptAtRest` block is not provided then this defaults to `false`. Enabling encryption on new domains requires `elasticsearchVersion` 5.1 or greater. */ enabled: boolean; /** * KMS key ARN to encrypt the Elasticsearch domain with. If not specified then it defaults to using the `aws/es` service KMS key. Note that KMS will accept a KMS key ID but will return the key ARN. To prevent the provider detecting unwanted changes, use the key ARN instead. */ kmsKeyId: string; } interface DomainLogPublishingOption { /** * ARN of the Cloudwatch log group to which log needs to be published. */ cloudwatchLogGroupArn: string; /** * Whether given log publishing option is enabled or not. */ enabled?: boolean; /** * Type of Elasticsearch log. Valid values: `INDEX_SLOW_LOGS`, `SEARCH_SLOW_LOGS`, `ES_APPLICATION_LOGS`, `AUDIT_LOGS`. */ logType: string; } interface DomainNodeToNodeEncryption { /** * Whether to enable node-to-node encryption. If the `nodeToNodeEncryption` block is not provided then this defaults to `false`. Enabling node-to-node encryption of a new domain requires an `elasticsearchVersion` of `6.0` or greater. */ enabled: boolean; } interface DomainSamlOptionsSamlOptions { /** * Whether SAML authentication is enabled. */ enabled?: boolean; /** * Information from your identity provider. */ idp?: outputs.elasticsearch.DomainSamlOptionsSamlOptionsIdp; /** * This backend role from the SAML IdP receives full permissions to the cluster, equivalent to a new master user. */ masterBackendRole?: string; /** * This username from the SAML IdP receives full permissions to the cluster, equivalent to a new master user. */ masterUserName?: string; /** * Element of the SAML assertion to use for backend roles. Default is roles. */ rolesKey?: string; /** * Duration of a session in minutes after a user logs in. Default is 60. Maximum value is 1,440. */ sessionTimeoutMinutes?: number; /** * Custom SAML attribute to use for user names. Default is an empty string - `""`. This will cause Elasticsearch to use the `NameID` element of the `Subject`, which is the default location for name identifiers in the SAML specification. */ subjectKey?: string; } interface DomainSamlOptionsSamlOptionsIdp { /** * The unique Entity ID of the application in SAML Identity Provider. */ entityId: string; /** * The Metadata of the SAML application in xml format. */ metadataContent: string; } interface DomainSnapshotOptions { /** * Hour during which the service takes an automated daily snapshot of the indices in the domain. */ automatedSnapshotStartHour: number; } interface DomainVpcOptions { /** * If the domain was created inside a VPC, the names of the availability zones the configured `subnetIds` were created inside. */ availabilityZones: string[]; /** * List of VPC Security Group IDs to be applied to the Elasticsearch domain endpoints. If omitted, the default Security Group for the VPC will be used. */ securityGroupIds?: string[]; /** * List of VPC Subnet IDs for the Elasticsearch domain endpoints to be created in. */ subnetIds?: string[]; /** * If the domain was created inside a VPC, the ID of the VPC. */ vpcId: string; } interface GetDomainAdvancedSecurityOption { /** * Whether node to node encryption is enabled. */ enabled: boolean; /** * Whether the internal user database is enabled. */ internalUserDatabaseEnabled: boolean; } interface GetDomainAutoTuneOption { /** * The Auto-Tune desired state for the domain. */ desiredState: string; /** * A list of the nested configurations for the Auto-Tune maintenance windows of the domain. */ maintenanceSchedules: outputs.elasticsearch.GetDomainAutoTuneOptionMaintenanceSchedule[]; /** * Whether the domain is set to roll back to default Auto-Tune settings when disabling Auto-Tune. */ rollbackOnDisable: string; } interface GetDomainAutoTuneOptionMaintenanceSchedule { /** * Cron expression for an Auto-Tune maintenance schedule. */ cronExpressionForRecurrence: string; /** * Configuration block for the duration of the Auto-Tune maintenance window. */ durations: outputs.elasticsearch.GetDomainAutoTuneOptionMaintenanceScheduleDuration[]; /** * Date and time at which the Auto-Tune maintenance schedule starts in [RFC3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ startAt: string; } interface GetDomainAutoTuneOptionMaintenanceScheduleDuration { /** * Unit of time. */ unit: string; /** * Duration of an Auto-Tune maintenance window. */ value: number; } interface GetDomainClusterConfig { /** * Configuration block containing cold storage configuration. */ coldStorageOptions: outputs.elasticsearch.GetDomainClusterConfigColdStorageOption[]; /** * Number of dedicated master nodes in the cluster. */ dedicatedMasterCount: number; /** * Indicates whether dedicated master nodes are enabled for the cluster. */ dedicatedMasterEnabled: boolean; /** * Instance type of the dedicated master nodes in the cluster. */ dedicatedMasterType: string; /** * Number of instances in the cluster. */ instanceCount: number; /** * Instance type of data nodes in the cluster. */ instanceType: string; /** * The number of warm nodes in the cluster. */ warmCount: number; /** * Warm storage is enabled. */ warmEnabled: boolean; /** * The instance type for the Elasticsearch cluster's warm nodes. */ warmType: string; /** * Configuration block containing zone awareness settings. */ zoneAwarenessConfigs: outputs.elasticsearch.GetDomainClusterConfigZoneAwarenessConfig[]; /** * Indicates whether zone awareness is enabled. */ zoneAwarenessEnabled: boolean; } interface GetDomainClusterConfigColdStorageOption { /** * Whether node to node encryption is enabled. */ enabled: boolean; } interface GetDomainClusterConfigZoneAwarenessConfig { /** * Number of availability zones used. */ availabilityZoneCount: number; } interface GetDomainCognitoOption { /** * Whether node to node encryption is enabled. */ enabled: boolean; /** * The Cognito Identity pool used by the domain. */ identityPoolId: string; /** * The IAM Role with the AmazonESCognitoAccess policy attached. */ roleArn: string; /** * The Cognito User pool used by the domain. */ userPoolId: string; } interface GetDomainEbsOption { /** * Whether EBS volumes are attached to data nodes in the domain. */ ebsEnabled: boolean; /** * The baseline input/output (I/O) performance of EBS volumes attached to data nodes. */ iops: number; /** * The throughput (in MiB/s) of the EBS volumes attached to data nodes. */ throughput: number; /** * The size of EBS volumes attached to data nodes (in GB). */ volumeSize: number; /** * The type of EBS volumes attached to data nodes. */ volumeType: string; } interface GetDomainEncryptionAtRest { /** * Whether node to node encryption is enabled. */ enabled: boolean; /** * The KMS key id used to encrypt data at rest. */ kmsKeyId: string; } interface GetDomainLogPublishingOption { /** * The CloudWatch Log Group where the logs are published. */ cloudwatchLogGroupArn: string; /** * Whether node to node encryption is enabled. */ enabled: boolean; /** * The type of Elasticsearch log being published. */ logType: string; } interface GetDomainNodeToNodeEncryption { /** * Whether node to node encryption is enabled. */ enabled: boolean; } interface GetDomainSnapshotOption { /** * Hour during which the service takes an automated daily snapshot of the indices in the domain. */ automatedSnapshotStartHour: number; } interface GetDomainVpcOption { /** * The availability zones used by the domain. */ availabilityZones: string[]; /** * The security groups used by the domain. */ securityGroupIds: string[]; /** * The subnets used by the domain. */ subnetIds: string[]; /** * The VPC used by the domain. */ vpcId: string; } interface VpcEndpointVpcOptions { availabilityZones: string[]; /** * The list of security group IDs associated with the VPC endpoints for the domain. If you do not provide a security group ID, elasticsearch Service uses the default security group for the VPC. */ securityGroupIds: string[]; /** * A list of subnet IDs associated with the VPC endpoints for the domain. If your domain uses multiple Availability Zones, you need to provide two subnet IDs, one per zone. Otherwise, provide only one. */ subnetIds: string[]; vpcId: string; } } export declare namespace elastictranscoder { interface PipelineContentConfig { /** * The Amazon S3 bucket in which you want Elastic Transcoder to save transcoded files and playlists. */ bucket: string; /** * The Amazon S3 storage class, `Standard` or `ReducedRedundancy`, that you want Elastic Transcoder to assign to the files and playlists that it stores in your Amazon S3 bucket. */ storageClass?: string; } interface PipelineContentConfigPermission { /** * The permission that you want to give to the AWS user that you specified in `content_config_permissions.grantee`. Valid values are `Read`, `ReadAcp`, `WriteAcp` or `FullControl`. */ accesses?: string[]; /** * The AWS user or group that you want to have access to transcoded files and playlists. */ grantee?: string; /** * Specify the type of value that appears in the `content_config_permissions.grantee` object. Valid values are `Canonical`, `Email` or `Group`. */ granteeType?: string; } interface PipelineNotifications { /** * The topic ARN for the Amazon SNS topic that you want to notify when Elastic Transcoder has finished processing a job in this pipeline. */ completed?: string; /** * The topic ARN for the Amazon SNS topic that you want to notify when Elastic Transcoder encounters an error condition while processing a job in this pipeline. */ error?: string; /** * The topic ARN for the Amazon Simple Notification Service (Amazon SNS) topic that you want to notify when Elastic Transcoder has started to process a job in this pipeline. */ progressing?: string; /** * The topic ARN for the Amazon SNS topic that you want to notify when Elastic Transcoder encounters a warning condition while processing a job in this pipeline. * * The `thumbnailConfig` object specifies information about the Amazon S3 bucket in * which you want Elastic Transcoder to save thumbnail files: which bucket to use, * which users you want to have access to the files, the type of access you want * users to have, and the storage class that you want to assign to the files. If * you specify values for `contentConfig`, you must also specify values for * `thumbnailConfig` even if you don't want to create thumbnails. (You control * whether to create thumbnails when you create a job. For more information, see * ThumbnailPattern in the topic Create Job.) If you specify values for * `contentConfig` and `thumbnailConfig`, omit the OutputBucket object. */ warning?: string; } interface PipelineThumbnailConfig { /** * The Amazon S3 bucket in which you want Elastic Transcoder to save thumbnail files. */ bucket: string; /** * The Amazon S3 storage class, Standard or ReducedRedundancy, that you want Elastic Transcoder to assign to the thumbnails that it stores in your Amazon S3 bucket. */ storageClass?: string; } interface PipelineThumbnailConfigPermission { /** * The permission that you want to give to the AWS user that you specified in `thumbnail_config_permissions.grantee`. Valid values are `Read`, `ReadAcp`, `WriteAcp` or `FullControl`. */ accesses?: string[]; /** * The AWS user or group that you want to have access to thumbnail files. */ grantee?: string; /** * Specify the type of value that appears in the `thumbnail_config_permissions.grantee` object. Valid values are `Canonical`, `Email` or `Group`. */ granteeType?: string; } interface PresetAudio { /** * The method of organizing audio channels and tracks. Use Audio:Channels to specify the number of channels in your output, and Audio:AudioPackingMode to specify the number of tracks and their relation to the channels. If you do not specify an Audio:AudioPackingMode, Elastic Transcoder uses SingleTrack. */ audioPackingMode?: string; /** * The bit rate of the audio stream in the output file, in kilobits/second. Enter an integer between 64 and 320, inclusive. */ bitRate: string; /** * The number of audio channels in the output file */ channels?: string; /** * The audio codec for the output file. Valid values are `AAC`, `flac`, `mp2`, `mp3`, `pcm`, and `vorbis`. */ codec?: string; /** * The sample rate of the audio stream in the output file, in hertz. Valid values are: `auto`, `22050`, `32000`, `44100`, `48000`, `96000` */ sampleRate?: string; } interface PresetAudioCodecOptions { /** * The bit depth of a sample is how many bits of information are included in the audio samples. Valid values are `16` and `24`. (FLAC/PCM Only) */ bitDepth: string; /** * The order the bits of a PCM sample are stored in. The supported value is LittleEndian. (PCM Only) */ bitOrder: string; /** * If you specified AAC for Audio:Codec, choose the AAC profile for the output file. */ profile: string; /** * Whether audio samples are represented with negative and positive numbers (signed) or only positive numbers (unsigned). The supported value is Signed. (PCM Only) */ signed: string; } interface PresetThumbnails { /** * The aspect ratio of thumbnails. The following values are valid: auto, 1:1, 4:3, 3:2, 16:9 */ aspectRatio?: string; /** * The format of thumbnails, if any. Valid formats are jpg and png. */ format?: string; /** * The approximate number of seconds between thumbnails. The value must be an integer. The actual interval can vary by several seconds from one thumbnail to the next. */ interval?: string; /** * The maximum height of thumbnails, in pixels. If you specify auto, Elastic Transcoder uses 1080 (Full HD) as the default value. If you specify a numeric value, enter an even integer between 32 and 3072, inclusive. */ maxHeight?: string; /** * The maximum width of thumbnails, in pixels. If you specify auto, Elastic Transcoder uses 1920 (Full HD) as the default value. If you specify a numeric value, enter an even integer between 32 and 4096, inclusive. */ maxWidth?: string; /** * When you set PaddingPolicy to Pad, Elastic Transcoder might add black bars to the top and bottom and/or left and right sides of thumbnails to make the total size of the thumbnails match the values that you specified for thumbnail MaxWidth and MaxHeight settings. */ paddingPolicy?: string; /** * The width and height of thumbnail files in pixels, in the format WidthxHeight, where both values are even integers. The values cannot exceed the width and height that you specified in the Video:Resolution object. (To better control resolution and aspect ratio of thumbnails, we recommend that you use the thumbnail values `maxWidth`, `maxHeight`, `sizingPolicy`, and `paddingPolicy` instead of `resolution` and `aspectRatio`. The two groups of settings are mutually exclusive. Do not use them together) */ resolution?: string; /** * A value that controls scaling of thumbnails. Valid values are: `Fit`, `Fill`, `Stretch`, `Keep`, `ShrinkToFit`, and `ShrinkToFill`. */ sizingPolicy?: string; } interface PresetVideo { /** * The display aspect ratio of the video in the output file. Valid values are: `auto`, `1:1`, `4:3`, `3:2`, `16:9`. (Note; to better control resolution and aspect ratio of output videos, we recommend that you use the values `maxWidth`, `maxHeight`, `sizingPolicy`, `paddingPolicy`, and `displayAspectRatio` instead of `resolution` and `aspectRatio`.) */ aspectRatio?: string; /** * The bit rate of the video stream in the output file, in kilobits/second. You can configure variable bit rate or constant bit rate encoding. */ bitRate: string; /** * The video codec for the output file. Valid values are `gif`, `H.264`, `mpeg2`, `vp8`, and `vp9`. */ codec?: string; /** * The value that Elastic Transcoder adds to the metadata in the output file. If you set DisplayAspectRatio to auto, Elastic Transcoder chooses an aspect ratio that ensures square pixels. If you specify another option, Elastic Transcoder sets that value in the output file. */ displayAspectRatio?: string; /** * Whether to use a fixed value for Video:FixedGOP. Not applicable for containers of type gif. Valid values are true and false. Also known as, Fixed Number of Frames Between Keyframes. */ fixedGop?: string; /** * The frames per second for the video stream in the output file. The following values are valid: `auto`, `10`, `15`, `23.97`, `24`, `25`, `29.97`, `30`, `50`, `60`. */ frameRate?: string; /** * The maximum number of frames between key frames. Not applicable for containers of type gif. */ keyframesMaxDist?: string; /** * If you specify auto for FrameRate, Elastic Transcoder uses the frame rate of the input video for the frame rate of the output video, up to the maximum frame rate. If you do not specify a MaxFrameRate, Elastic Transcoder will use a default of 30. */ maxFrameRate: string; /** * The maximum height of the output video in pixels. If you specify auto, Elastic Transcoder uses 1080 (Full HD) as the default value. If you specify a numeric value, enter an even integer between 96 and 3072, inclusive. */ maxHeight?: string; /** * The maximum width of the output video in pixels. If you specify auto, Elastic Transcoder uses 1920 (Full HD) as the default value. If you specify a numeric value, enter an even integer between 128 and 4096, inclusive. */ maxWidth?: string; /** * When you set PaddingPolicy to Pad, Elastic Transcoder might add black bars to the top and bottom and/or left and right sides of the output video to make the total size of the output video match the values that you specified for `maxWidth` and `maxHeight`. */ paddingPolicy?: string; /** * The width and height of the video in the output file, in pixels. Valid values are `auto` and `widthxheight`. (see note for `aspectRatio`) */ resolution?: string; /** * A value that controls scaling of the output video. Valid values are: `Fit`, `Fill`, `Stretch`, `Keep`, `ShrinkToFit`, `ShrinkToFill`. */ sizingPolicy?: string; } interface PresetVideoWatermark { /** * The horizontal position of the watermark unless you specify a nonzero value for `horzontalOffset`. */ horizontalAlign?: string; /** * The amount by which you want the horizontal position of the watermark to be offset from the position specified by `horizontalAlign`. */ horizontalOffset?: string; /** * A unique identifier for the settings for one watermark. The value of Id can be up to 40 characters long. You can specify settings for up to four watermarks. */ id?: string; /** * The maximum height of the watermark. */ maxHeight?: string; /** * The maximum width of the watermark. */ maxWidth?: string; /** * A percentage that indicates how much you want a watermark to obscure the video in the location where it appears. */ opacity?: string; /** * A value that controls scaling of the watermark. Valid values are: `Fit`, `Stretch`, `ShrinkToFit` */ sizingPolicy?: string; /** * A value that determines how Elastic Transcoder interprets values that you specified for `video_watermarks.horizontal_offset`, `video_watermarks.vertical_offset`, `video_watermarks.max_width`, and `video_watermarks.max_height`. Valid values are `Content` and `Frame`. */ target?: string; /** * The vertical position of the watermark unless you specify a nonzero value for `verticalAlign`. Valid values are `Top`, `Bottom`, `Center`. */ verticalAlign?: string; /** * The amount by which you want the vertical position of the watermark to be offset from the position specified by `verticalAlign` */ verticalOffset?: string; } } export declare namespace elb { interface GetLoadBalancerAccessLogs { bucket: string; bucketPrefix: string; enabled: boolean; interval: number; } interface GetLoadBalancerHealthCheck { healthyThreshold: number; interval: number; target: string; timeout: number; unhealthyThreshold: number; } interface GetLoadBalancerListener { instancePort: number; instanceProtocol: string; lbPort: number; lbProtocol: string; sslCertificateId: string; } interface LoadBalancerAccessLogs { /** * The S3 bucket name to store the logs in. */ bucket: string; /** * The S3 bucket prefix. Logs are stored in the root if not configured. */ bucketPrefix?: string; /** * Boolean to enable / disable `accessLogs`. Default is `true` */ enabled?: boolean; /** * The publishing interval in minutes. Valid values: `5` and `60`. Default: `60` */ interval?: number; } interface LoadBalancerHealthCheck { /** * The number of checks before the instance is declared healthy. */ healthyThreshold: number; /** * The interval between checks. */ interval: number; /** * The target of the check. Valid pattern is "${PROTOCOL}:${PORT}${PATH}", where PROTOCOL * values are: * * `HTTP`, `HTTPS` - PORT and PATH are required * * `TCP`, `SSL` - PORT is required, PATH is not supported */ target: string; /** * The length of time before the check times out. * * > **Note:** If the ARN of the `sslCertificateId` references a certificate signed by an ECDSA key, ELB only supports the P256 and P384 curves. Using a certificate signed by a different curve could produce `ERR_SSL_VERSION_OR_CIPHER_MISMATCH` in your browser. */ timeout: number; /** * The number of checks before the instance is declared unhealthy. */ unhealthyThreshold: number; } interface LoadBalancerListener { /** * The port on the instance to route to */ instancePort: number; /** * The protocol to use to the instance. Valid * values are `HTTP`, `HTTPS`, `TCP`, or `SSL` */ instanceProtocol: string; /** * The port to listen on for the load balancer */ lbPort: number; /** * The protocol to listen on. Valid values are `HTTP`, * `HTTPS`, `TCP`, or `SSL` */ lbProtocol: string; /** * The ARN of an SSL certificate you have * uploaded to AWS IAM. **Note ECDSA-specific restrictions below. Only valid when `lbProtocol` is either HTTPS or SSL** */ sslCertificateId?: string; } interface LoadBalancerPolicyPolicyAttribute { name?: string; value?: string; } interface SslNegotiationPolicyAttribute { /** * The name of the attribute */ name: string; /** * The value of the attribute */ value: string; } } export declare namespace emr { interface BlockPublicAccessConfigurationPermittedPublicSecurityGroupRuleRange { /** * The final port in the range of TCP ports. */ maxRange: number; /** * The first port in the range of TCP ports. */ minRange: number; } interface ClusterAutoTerminationPolicy { /** * Specifies the amount of idle time in seconds after which the cluster automatically terminates. You can specify a minimum of `60` seconds and a maximum of `604800` seconds (seven days). */ idleTimeout?: number; } interface ClusterBootstrapAction { /** * List of command line arguments to pass to the bootstrap action script. */ args?: string[]; /** * Name of the bootstrap action. */ name: string; /** * Location of the script to run during a bootstrap action. Can be either a location in Amazon S3 or on a local file system. */ path: string; } interface ClusterCoreInstanceFleet { /** * ID of the cluster. */ id: string; /** * Configuration block for instance fleet. */ instanceTypeConfigs?: outputs.emr.ClusterCoreInstanceFleetInstanceTypeConfig[]; /** * Configuration block for launch specification. */ launchSpecifications?: outputs.emr.ClusterCoreInstanceFleetLaunchSpecifications; /** * Friendly name given to the instance fleet. */ name?: string; provisionedOnDemandCapacity: number; provisionedSpotCapacity: number; /** * The target capacity of On-Demand units for the instance fleet, which determines how many On-Demand instances to provision. */ targetOnDemandCapacity?: number; /** * Target capacity of Spot units for the instance fleet, which determines how many Spot instances to provision. */ targetSpotCapacity?: number; } interface ClusterCoreInstanceFleetInstanceTypeConfig { /** * Bid price for each EC2 Spot instance type as defined by `instanceType`. Expressed in USD. If neither `bidPrice` nor `bidPriceAsPercentageOfOnDemandPrice` is provided, `bidPriceAsPercentageOfOnDemandPrice` defaults to 100%. */ bidPrice?: string; /** * Bid price, as a percentage of On-Demand price, for each EC2 Spot instance as defined by `instanceType`. Expressed as a number (for example, 20 specifies 20%). If neither `bidPrice` nor `bidPriceAsPercentageOfOnDemandPrice` is provided, `bidPriceAsPercentageOfOnDemandPrice` defaults to 100%. */ bidPriceAsPercentageOfOnDemandPrice?: number; /** * Configuration classification that applies when provisioning cluster instances, which can include configurations for applications and software that run on the cluster. List of `configuration` blocks. */ configurations?: outputs.emr.ClusterCoreInstanceFleetInstanceTypeConfigConfiguration[]; /** * Configuration block(s) for EBS volumes attached to each instance in the instance group. Detailed below. */ ebsConfigs: outputs.emr.ClusterCoreInstanceFleetInstanceTypeConfigEbsConfig[]; /** * EC2 instance type, such as m4.xlarge. */ instanceType: string; /** * Number of units that a provisioned instance of this type provides toward fulfilling the target capacities defined in `aws.emr.InstanceFleet`. */ weightedCapacity?: number; } interface ClusterCoreInstanceFleetInstanceTypeConfigConfiguration { /** * Classification within a configuration. */ classification?: string; /** * Map of properties specified within a configuration classification. */ properties?: { [key: string]: string; }; } interface ClusterCoreInstanceFleetInstanceTypeConfigEbsConfig { /** * Number of I/O operations per second (IOPS) that the volume supports. */ iops?: number; /** * Volume size, in gibibytes (GiB). */ size: number; /** * Volume type. Valid options are `gp3`, `gp2`, `io1`, `io2`, `standard`, `st1` and `sc1`. See [EBS Volume Types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html). */ type: string; /** * Number of EBS volumes with this configuration to attach to each EC2 instance in the instance group (default is 1). */ volumesPerInstance?: number; } interface ClusterCoreInstanceFleetLaunchSpecifications { /** * Configuration block for on demand instances launch specifications. */ onDemandSpecifications?: outputs.emr.ClusterCoreInstanceFleetLaunchSpecificationsOnDemandSpecification[]; /** * Configuration block for spot instances launch specifications. */ spotSpecifications?: outputs.emr.ClusterCoreInstanceFleetLaunchSpecificationsSpotSpecification[]; } interface ClusterCoreInstanceFleetLaunchSpecificationsOnDemandSpecification { /** * Specifies the strategy to use in launching On-Demand instance fleets. Currently, the only option is `lowest-price` (the default), which launches the lowest price first. */ allocationStrategy: string; } interface ClusterCoreInstanceFleetLaunchSpecificationsSpotSpecification { /** * Specifies the strategy to use in launching Spot instance fleets. Valid values include `capacity-optimized`, `diversified`, `lowest-price`, `price-capacity-optimized`. See the [AWS documentation](https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-instance-fleet.html#emr-instance-fleet-allocation-strategy) for details on each strategy type. */ allocationStrategy: string; /** * Defined duration for Spot instances (also known as Spot blocks) in minutes. When specified, the Spot instance does not terminate before the defined duration expires, and defined duration pricing for Spot instances applies. Valid values are 60, 120, 180, 240, 300, or 360. The duration period starts as soon as a Spot instance receives its instance ID. At the end of the duration, Amazon EC2 marks the Spot instance for termination and provides a Spot instance termination notice, which gives the instance a two-minute warning before it terminates. */ blockDurationMinutes?: number; /** * Action to take when TargetSpotCapacity has not been fulfilled when the TimeoutDurationMinutes has expired; that is, when all Spot instances could not be provisioned within the Spot provisioning timeout. Valid values are `TERMINATE_CLUSTER` and `SWITCH_TO_ON_DEMAND`. SWITCH_TO_ON_DEMAND specifies that if no Spot instances are available, On-Demand Instances should be provisioned to fulfill any remaining Spot capacity. */ timeoutAction: string; /** * Spot provisioning timeout period in minutes. If Spot instances are not provisioned within this time period, the TimeOutAction is taken. Minimum value is 5 and maximum value is 1440. The timeout applies only during initial provisioning, when the cluster is first created. */ timeoutDurationMinutes: number; } interface ClusterCoreInstanceGroup { /** * String containing the [EMR Auto Scaling Policy](https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-automatic-scaling.html) JSON. */ autoscalingPolicy?: string; /** * Bid price for each EC2 instance in the instance group, expressed in USD. By setting this attribute, the instance group is being declared as a Spot Instance, and will implicitly create a Spot request. Leave this blank to use On-Demand Instances. */ bidPrice?: string; /** * Configuration block(s) for EBS volumes attached to each instance in the instance group. Detailed below. */ ebsConfigs: outputs.emr.ClusterCoreInstanceGroupEbsConfig[]; /** * Core node type Instance Group ID, if using Instance Group for this node type. */ id: string; /** * Target number of instances for the instance group. Must be at least 1. Defaults to 1. */ instanceCount?: number; /** * EC2 instance type for all instances in the instance group. */ instanceType: string; /** * Friendly name given to the instance group. */ name?: string; } interface ClusterCoreInstanceGroupEbsConfig { /** * Number of I/O operations per second (IOPS) that the volume supports. */ iops?: number; /** * Volume size, in gibibytes (GiB). */ size: number; /** * The throughput, in mebibyte per second (MiB/s). */ throughput?: number; /** * Volume type. Valid options are `gp3`, `gp2`, `io1`, `io2`, `standard`, `st1` and `sc1`. See [EBS Volume Types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html). */ type: string; /** * Number of EBS volumes with this configuration to attach to each EC2 instance in the instance group (default is 1). */ volumesPerInstance?: number; } interface ClusterEc2Attributes { /** * String containing a comma separated list of additional Amazon EC2 security group IDs for the master node. */ additionalMasterSecurityGroups?: string; /** * String containing a comma separated list of additional Amazon EC2 security group IDs for the slave nodes as a comma separated string. */ additionalSlaveSecurityGroups?: string; /** * Identifier of the Amazon EC2 EMR-Managed security group for the master node. */ emrManagedMasterSecurityGroup: string; /** * Identifier of the Amazon EC2 EMR-Managed security group for the slave nodes. */ emrManagedSlaveSecurityGroup: string; /** * Instance Profile for EC2 instances of the cluster assume this role. */ instanceProfile: string; /** * Amazon EC2 key pair that can be used to ssh to the master node as the user called `hadoop`. */ keyName?: string; /** * Identifier of the Amazon EC2 service-access security group - required when the cluster runs on a private subnet. */ serviceAccessSecurityGroup: string; /** * VPC subnet id where you want the job flow to launch. Cannot specify the `cc1.4xlarge` instance type for nodes of a job flow launched in an Amazon VPC. */ subnetId: string; /** * List of VPC subnet id-s where you want the job flow to launch. Amazon EMR identifies the best Availability Zone to launch instances according to your fleet specifications. * * > **NOTE on EMR-Managed security groups:** These security groups will have any missing inbound or outbound access rules added and maintained by AWS, to ensure proper communication between instances in a cluster. The EMR service will maintain these rules for groups provided in `emrManagedMasterSecurityGroup` and `emrManagedSlaveSecurityGroup`; attempts to remove the required rules may succeed, only for the EMR service to re-add them in a matter of minutes. This may cause this provider to fail to destroy an environment that contains an EMR cluster, because the EMR service does not revoke rules added on deletion, leaving a cyclic dependency between the security groups that prevents their deletion. To avoid this, use the `revokeRulesOnDelete` optional attribute for any Security Group used in `emrManagedMasterSecurityGroup` and `emrManagedSlaveSecurityGroup`. See [Amazon EMR-Managed Security Groups](http://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-man-sec-groups.html) for more information about the EMR-managed security group rules. */ subnetIds: string[]; } interface ClusterKerberosAttributes { /** * Active Directory password for `adDomainJoinUser`. This provider cannot perform drift detection of this configuration. */ adDomainJoinPassword?: string; /** * Required only when establishing a cross-realm trust with an Active Directory domain. A user with sufficient privileges to join resources to the domain. This provider cannot perform drift detection of this configuration. */ adDomainJoinUser?: string; /** * Required only when establishing a cross-realm trust with a KDC in a different realm. The cross-realm principal password, which must be identical across realms. This provider cannot perform drift detection of this configuration. */ crossRealmTrustPrincipalPassword?: string; /** * Password used within the cluster for the kadmin service on the cluster-dedicated KDC, which maintains Kerberos principals, password policies, and keytabs for the cluster. This provider cannot perform drift detection of this configuration. */ kdcAdminPassword: string; /** * Name of the Kerberos realm to which all nodes in a cluster belong. For example, `EC2.INTERNAL` */ realm: string; } interface ClusterMasterInstanceFleet { /** * ID of the cluster. */ id: string; /** * Configuration block for instance fleet. */ instanceTypeConfigs?: outputs.emr.ClusterMasterInstanceFleetInstanceTypeConfig[]; /** * Configuration block for launch specification. */ launchSpecifications?: outputs.emr.ClusterMasterInstanceFleetLaunchSpecifications; /** * Friendly name given to the instance fleet. */ name?: string; provisionedOnDemandCapacity: number; provisionedSpotCapacity: number; /** * Target capacity of On-Demand units for the instance fleet, which determines how many On-Demand instances to provision. */ targetOnDemandCapacity?: number; /** * Target capacity of Spot units for the instance fleet, which determines how many Spot instances to provision. */ targetSpotCapacity?: number; } interface ClusterMasterInstanceFleetInstanceTypeConfig { /** * Bid price for each EC2 Spot instance type as defined by `instanceType`. Expressed in USD. If neither `bidPrice` nor `bidPriceAsPercentageOfOnDemandPrice` is provided, `bidPriceAsPercentageOfOnDemandPrice` defaults to 100%. */ bidPrice?: string; /** * Bid price, as a percentage of On-Demand price, for each EC2 Spot instance as defined by `instanceType`. Expressed as a number (for example, 20 specifies 20%). If neither `bidPrice` nor `bidPriceAsPercentageOfOnDemandPrice` is provided, `bidPriceAsPercentageOfOnDemandPrice` defaults to 100%. */ bidPriceAsPercentageOfOnDemandPrice?: number; /** * Configuration classification that applies when provisioning cluster instances, which can include configurations for applications and software that run on the cluster. List of `configuration` blocks. */ configurations?: outputs.emr.ClusterMasterInstanceFleetInstanceTypeConfigConfiguration[]; /** * Configuration block(s) for EBS volumes attached to each instance in the instance group. Detailed below. */ ebsConfigs: outputs.emr.ClusterMasterInstanceFleetInstanceTypeConfigEbsConfig[]; /** * EC2 instance type, such as m4.xlarge. */ instanceType: string; /** * Number of units that a provisioned instance of this type provides toward fulfilling the target capacities defined in `aws.emr.InstanceFleet`. */ weightedCapacity?: number; } interface ClusterMasterInstanceFleetInstanceTypeConfigConfiguration { /** * Classification within a configuration. */ classification?: string; /** * Map of properties specified within a configuration classification. */ properties?: { [key: string]: string; }; } interface ClusterMasterInstanceFleetInstanceTypeConfigEbsConfig { /** * Number of I/O operations per second (IOPS) that the volume supports. */ iops?: number; /** * Volume size, in gibibytes (GiB). */ size: number; /** * Volume type. Valid options are `gp3`, `gp2`, `io1`, `io2`, `standard`, `st1` and `sc1`. See [EBS Volume Types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html). */ type: string; /** * Number of EBS volumes with this configuration to attach to each EC2 instance in the instance group (default is 1). */ volumesPerInstance?: number; } interface ClusterMasterInstanceFleetLaunchSpecifications { /** * Configuration block for on demand instances launch specifications. */ onDemandSpecifications?: outputs.emr.ClusterMasterInstanceFleetLaunchSpecificationsOnDemandSpecification[]; /** * Configuration block for spot instances launch specifications. */ spotSpecifications?: outputs.emr.ClusterMasterInstanceFleetLaunchSpecificationsSpotSpecification[]; } interface ClusterMasterInstanceFleetLaunchSpecificationsOnDemandSpecification { /** * Specifies the strategy to use in launching On-Demand instance fleets. Currently, the only option is `lowest-price` (the default), which launches the lowest price first. */ allocationStrategy: string; } interface ClusterMasterInstanceFleetLaunchSpecificationsSpotSpecification { /** * Specifies the strategy to use in launching Spot instance fleets. Valid values include `capacity-optimized`, `diversified`, `lowest-price`, `price-capacity-optimized`. See the [AWS documentation](https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-instance-fleet.html#emr-instance-fleet-allocation-strategy) for details on each strategy type. */ allocationStrategy: string; /** * Defined duration for Spot instances (also known as Spot blocks) in minutes. When specified, the Spot instance does not terminate before the defined duration expires, and defined duration pricing for Spot instances applies. Valid values are 60, 120, 180, 240, 300, or 360. The duration period starts as soon as a Spot instance receives its instance ID. At the end of the duration, Amazon EC2 marks the Spot instance for termination and provides a Spot instance termination notice, which gives the instance a two-minute warning before it terminates. */ blockDurationMinutes?: number; /** * Action to take when TargetSpotCapacity has not been fulfilled when the TimeoutDurationMinutes has expired; that is, when all Spot instances could not be provisioned within the Spot provisioning timeout. Valid values are `TERMINATE_CLUSTER` and `SWITCH_TO_ON_DEMAND`. SWITCH_TO_ON_DEMAND specifies that if no Spot instances are available, On-Demand Instances should be provisioned to fulfill any remaining Spot capacity. */ timeoutAction: string; /** * Spot provisioning timeout period in minutes. If Spot instances are not provisioned within this time period, the TimeOutAction is taken. Minimum value is 5 and maximum value is 1440. The timeout applies only during initial provisioning, when the cluster is first created. */ timeoutDurationMinutes: number; } interface ClusterMasterInstanceGroup { /** * Bid price for each EC2 instance in the instance group, expressed in USD. By setting this attribute, the instance group is being declared as a Spot Instance, and will implicitly create a Spot request. Leave this blank to use On-Demand Instances. */ bidPrice?: string; /** * Configuration block(s) for EBS volumes attached to each instance in the instance group. Detailed below. */ ebsConfigs: outputs.emr.ClusterMasterInstanceGroupEbsConfig[]; /** * Master node type Instance Group ID, if using Instance Group for this node type. */ id: string; /** * Target number of instances for the instance group. Must be 1 or 3. Defaults to 1. Launching with multiple master nodes is only supported in EMR version 5.23.0+, and requires this resource's `coreInstanceGroup` to be configured. Public (Internet accessible) instances must be created in VPC subnets that have map public IP on launch enabled. Termination protection is automatically enabled when launched with multiple master nodes and this provider must have the `terminationProtection = false` configuration applied before destroying this resource. */ instanceCount?: number; /** * EC2 instance type for all instances in the instance group. */ instanceType: string; /** * Friendly name given to the instance group. */ name?: string; } interface ClusterMasterInstanceGroupEbsConfig { /** * Number of I/O operations per second (IOPS) that the volume supports. */ iops?: number; /** * Volume size, in gibibytes (GiB). */ size: number; /** * The throughput, in mebibyte per second (MiB/s). */ throughput?: number; /** * Volume type. Valid options are `gp3`, `gp2`, `io1`, `io2`, `standard`, `st1` and `sc1`. See [EBS Volume Types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html). */ type: string; /** * Number of EBS volumes with this configuration to attach to each EC2 instance in the instance group (default is 1). */ volumesPerInstance?: number; } interface ClusterPlacementGroupConfig { /** * Role of the instance in the cluster. Valid Values: `MASTER`, `CORE`, `TASK`. */ instanceRole: string; /** * EC2 Placement Group strategy associated with instance role. Valid Values: `SPREAD`, `PARTITION`, `CLUSTER`, `NONE`. */ placementStrategy: string; } interface ClusterStep { /** * Action to take if the step fails. Valid values: `TERMINATE_JOB_FLOW`, `TERMINATE_CLUSTER`, `CANCEL_AND_WAIT`, and `CONTINUE` */ actionOnFailure: string; /** * JAR file used for the step. See below. */ hadoopJarStep: outputs.emr.ClusterStepHadoopJarStep; /** * Name of the step. */ name: string; } interface ClusterStepHadoopJarStep { /** * List of command line arguments passed to the JAR file's main function when executed. */ args?: string[]; /** * Path to a JAR file run during the step. */ jar: string; /** * Name of the main class in the specified Java file. If not specified, the JAR file should specify a Main-Class in its manifest file. */ mainClass?: string; /** * Key-Value map of Java properties that are set when the step runs. You can use these properties to pass key value pairs to your main function. */ properties?: { [key: string]: string; }; } interface GetReleaseLabelsFilters { /** * Optional release label application filter. For example, `Spark@2.1.0` or `Spark`. */ application?: string; /** * Optional release label version prefix filter. For example, `emr-5`. */ prefix?: string; } interface GetSupportedInstanceTypesSupportedInstanceType { /** * CPU architecture. */ architecture: string; /** * Indicates whether the instance type supports Amazon EBS optimization. */ ebsOptimizedAvailable: boolean; /** * Indicates whether the instance type uses Amazon EBS optimization by default. */ ebsOptimizedByDefault: boolean; /** * Indicates whether the instance type only supports Amazon EBS. */ ebsStorageOnly: boolean; /** * The Amazon EC2 family and generation for the instance type. */ instanceFamilyId: string; /** * Indicates whether the instance type only supports 64-bit architecture. */ is64BitsOnly: boolean; /** * Memory that is available to Amazon EMR from the instance type. */ memoryGb: number; /** * Number of disks for the instance type. */ numberOfDisks: number; /** * Storage capacity of the instance type. */ storageGb: number; /** * Amazon EC2 instance type. For example, `m5.xlarge`. */ type: string; /** * The number of vCPUs available for the instance type. */ vcpu: number; } interface InstanceFleetInstanceTypeConfig { /** * The bid price for each EC2 Spot instance type as defined by `instanceType`. Expressed in USD. If neither `bidPrice` nor `bidPriceAsPercentageOfOnDemandPrice` is provided, `bidPriceAsPercentageOfOnDemandPrice` defaults to 100%. */ bidPrice?: string; /** * The bid price, as a percentage of On-Demand price, for each EC2 Spot instance as defined by `instanceType`. Expressed as a number (for example, 20 specifies 20%). If neither `bidPrice` nor `bidPriceAsPercentageOfOnDemandPrice` is provided, `bidPriceAsPercentageOfOnDemandPrice` defaults to 100%. */ bidPriceAsPercentageOfOnDemandPrice?: number; /** * A configuration classification that applies when provisioning cluster instances, which can include configurations for applications and software that run on the cluster. List of `configuration` blocks. */ configurations?: outputs.emr.InstanceFleetInstanceTypeConfigConfiguration[]; /** * Configuration block(s) for EBS volumes attached to each instance in the instance group. Detailed below. */ ebsConfigs: outputs.emr.InstanceFleetInstanceTypeConfigEbsConfig[]; /** * An EC2 instance type, such as m4.xlarge. */ instanceType: string; /** * The number of units that a provisioned instance of this type provides toward fulfilling the target capacities defined in `aws.emr.InstanceFleet`. */ weightedCapacity?: number; } interface InstanceFleetInstanceTypeConfigConfiguration { /** * The classification within a configuration. */ classification?: string; /** * A map of properties specified within a configuration classification */ properties?: { [key: string]: string; }; } interface InstanceFleetInstanceTypeConfigEbsConfig { /** * The number of I/O operations per second (IOPS) that the volume supports */ iops?: number; /** * The volume size, in gibibytes (GiB). */ size: number; /** * The volume type. Valid options are `gp2`, `io1`, `standard` and `st1`. See [EBS Volume Types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html). */ type: string; /** * The number of EBS volumes with this configuration to attach to each EC2 instance in the instance group (default is 1) */ volumesPerInstance?: number; } interface InstanceFleetLaunchSpecifications { /** * Configuration block for on demand instances launch specifications */ onDemandSpecifications?: outputs.emr.InstanceFleetLaunchSpecificationsOnDemandSpecification[]; /** * Configuration block for spot instances launch specifications */ spotSpecifications?: outputs.emr.InstanceFleetLaunchSpecificationsSpotSpecification[]; } interface InstanceFleetLaunchSpecificationsOnDemandSpecification { /** * Specifies the strategy to use in launching On-Demand instance fleets. Currently, the only option is `lowest-price` (the default), which launches the lowest price first. */ allocationStrategy: string; } interface InstanceFleetLaunchSpecificationsSpotSpecification { /** * Specifies one of the following strategies to launch Spot Instance fleets: `price-capacity-optimized`, `capacity-optimized`, `lowest-price`, or `diversified`. For more information on the provisioning strategies, see [Allocation strategies for Spot Instances](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-allocation-strategy.html). */ allocationStrategy: string; /** * The defined duration for Spot instances (also known as Spot blocks) in minutes. When specified, the Spot instance does not terminate before the defined duration expires, and defined duration pricing for Spot instances applies. Valid values are 60, 120, 180, 240, 300, or 360. The duration period starts as soon as a Spot instance receives its instance ID. At the end of the duration, Amazon EC2 marks the Spot instance for termination and provides a Spot instance termination notice, which gives the instance a two-minute warning before it terminates. */ blockDurationMinutes?: number; /** * The action to take when TargetSpotCapacity has not been fulfilled when the TimeoutDurationMinutes has expired; that is, when all Spot instances could not be provisioned within the Spot provisioning timeout. Valid values are `TERMINATE_CLUSTER` and `SWITCH_TO_ON_DEMAND`. SWITCH_TO_ON_DEMAND specifies that if no Spot instances are available, On-Demand Instances should be provisioned to fulfill any remaining Spot capacity. */ timeoutAction: string; /** * The spot provisioning timeout period in minutes. If Spot instances are not provisioned within this time period, the TimeOutAction is taken. Minimum value is 5 and maximum value is 1440. The timeout applies only during initial provisioning, when the cluster is first created. */ timeoutDurationMinutes: number; } interface InstanceGroupEbsConfig { /** * The number of I/O operations per second (IOPS) that the volume supports. */ iops?: number; /** * The volume size, in gibibytes (GiB). This can be a number from 1 - 1024. If the volume type is EBS-optimized, the minimum value is 10. */ size: number; /** * The volume type. Valid options are 'gp2', 'io1' and 'standard'. */ type: string; /** * The number of EBS Volumes to attach per instance. */ volumesPerInstance?: number; } interface ManagedScalingPolicyComputeLimit { /** * The upper boundary of EC2 units. It is measured through VCPU cores or instances for instance groups and measured through units for instance fleets. Managed scaling activities are not allowed beyond this boundary. The limit only applies to the core and task nodes. The master node cannot be scaled after initial configuration. */ maximumCapacityUnits: number; /** * The upper boundary of EC2 units for core node type in a cluster. It is measured through VCPU cores or instances for instance groups and measured through units for instance fleets. The core units are not allowed to scale beyond this boundary. The parameter is used to split capacity allocation between core and task nodes. */ maximumCoreCapacityUnits?: number; /** * The upper boundary of On-Demand EC2 units. It is measured through VCPU cores or instances for instance groups and measured through units for instance fleets. The On-Demand units are not allowed to scale beyond this boundary. The parameter is used to split capacity allocation between On-Demand and Spot instances. */ maximumOndemandCapacityUnits?: number; /** * The lower boundary of EC2 units. It is measured through VCPU cores or instances for instance groups and measured through units for instance fleets. Managed scaling activities are not allowed beyond this boundary. The limit only applies to the core and task nodes. The master node cannot be scaled after initial configuration. */ minimumCapacityUnits: number; /** * The unit type used for specifying a managed scaling policy. Valid Values: `InstanceFleetUnits` | `Instances` | `VCPU` */ unitType: string; } } export declare namespace emrcontainers { interface GetVirtualClusterContainerProvider { /** * The name of the container provider that is running your EMR Containers cluster */ id: string; /** * Nested list containing information about the configuration of the container provider */ infos: outputs.emrcontainers.GetVirtualClusterContainerProviderInfo[]; /** * The type of the container provider */ type: string; } interface GetVirtualClusterContainerProviderInfo { /** * Nested list containing EKS-specific information about the cluster where the EMR Containers cluster is running */ eksInfos: outputs.emrcontainers.GetVirtualClusterContainerProviderInfoEksInfo[]; } interface GetVirtualClusterContainerProviderInfoEksInfo { /** * The namespace where the EMR Containers cluster is running */ namespace: string; } interface JobTemplateJobTemplateData { /** * The configuration settings that are used to override defaults configuration. */ configurationOverrides?: outputs.emrcontainers.JobTemplateJobTemplateDataConfigurationOverrides; /** * The execution role ARN of the job run. */ executionRoleArn: string; /** * Specify the driver that the job runs on. Exactly one of the two available job drivers is required, either sparkSqlJobDriver or sparkSubmitJobDriver. */ jobDriver: outputs.emrcontainers.JobTemplateJobTemplateDataJobDriver; /** * The tags assigned to jobs started using the job template. */ jobTags?: { [key: string]: string; }; /** * The release version of Amazon EMR. */ releaseLabel: string; } interface JobTemplateJobTemplateDataConfigurationOverrides { /** * The configurations for the application running by the job run. */ applicationConfigurations?: outputs.emrcontainers.JobTemplateJobTemplateDataConfigurationOverridesApplicationConfiguration[]; /** * The configurations for monitoring. */ monitoringConfiguration?: outputs.emrcontainers.JobTemplateJobTemplateDataConfigurationOverridesMonitoringConfiguration; } interface JobTemplateJobTemplateDataConfigurationOverridesApplicationConfiguration { /** * The classification within a configuration. */ classification: string; /** * A list of additional configurations to apply within a configuration object. */ configurations?: outputs.emrcontainers.JobTemplateJobTemplateDataConfigurationOverridesApplicationConfigurationConfiguration[]; /** * A set of properties specified within a configuration classification. */ properties?: { [key: string]: string; }; } interface JobTemplateJobTemplateDataConfigurationOverridesApplicationConfigurationConfiguration { /** * The classification within a configuration. */ classification?: string; /** * A set of properties specified within a configuration classification. */ properties?: { [key: string]: string; }; } interface JobTemplateJobTemplateDataConfigurationOverridesMonitoringConfiguration { /** * Monitoring configurations for CloudWatch. */ cloudWatchMonitoringConfiguration?: outputs.emrcontainers.JobTemplateJobTemplateDataConfigurationOverridesMonitoringConfigurationCloudWatchMonitoringConfiguration; /** * Monitoring configurations for the persistent application UI. */ persistentAppUi: string; /** * Amazon S3 configuration for monitoring log publishing. */ s3MonitoringConfiguration?: outputs.emrcontainers.JobTemplateJobTemplateDataConfigurationOverridesMonitoringConfigurationS3MonitoringConfiguration; } interface JobTemplateJobTemplateDataConfigurationOverridesMonitoringConfigurationCloudWatchMonitoringConfiguration { /** * The name of the log group for log publishing. */ logGroupName: string; /** * The specified name prefix for log streams. */ logStreamNamePrefix?: string; } interface JobTemplateJobTemplateDataConfigurationOverridesMonitoringConfigurationS3MonitoringConfiguration { /** * Amazon S3 destination URI for log publishing. */ logUri: string; } interface JobTemplateJobTemplateDataJobDriver { /** * The job driver for job type. */ sparkSqlJobDriver?: outputs.emrcontainers.JobTemplateJobTemplateDataJobDriverSparkSqlJobDriver; /** * The job driver parameters specified for spark submit. */ sparkSubmitJobDriver?: outputs.emrcontainers.JobTemplateJobTemplateDataJobDriverSparkSubmitJobDriver; } interface JobTemplateJobTemplateDataJobDriverSparkSqlJobDriver { /** * The SQL file to be executed. */ entryPoint?: string; /** * The Spark parameters to be included in the Spark SQL command. */ sparkSqlParameters?: string; } interface JobTemplateJobTemplateDataJobDriverSparkSubmitJobDriver { /** * The entry point of job application. */ entryPoint: string; /** * The arguments for job application. */ entryPointArguments?: string[]; /** * The Spark submit parameters that are used for job runs. */ sparkSubmitParameters?: string; } interface VirtualClusterContainerProvider { /** * The name of the container provider that is running your EMR Containers cluster */ id: string; /** * Nested list containing information about the configuration of the container provider */ info: outputs.emrcontainers.VirtualClusterContainerProviderInfo; /** * The type of the container provider */ type: string; } interface VirtualClusterContainerProviderInfo { /** * Nested list containing EKS-specific information about the cluster where the EMR Containers cluster is running */ eksInfo: outputs.emrcontainers.VirtualClusterContainerProviderInfoEksInfo; } interface VirtualClusterContainerProviderInfoEksInfo { /** * The namespace where the EMR Containers cluster is running */ namespace?: string; } } export declare namespace emrserverless { interface ApplicationAutoStartConfiguration { /** * Enables the application to automatically start on job submission. Defaults to `true`. */ enabled?: boolean; } interface ApplicationAutoStopConfiguration { /** * Enables the application to automatically stop after a certain amount of time being idle. Defaults to `true`. */ enabled?: boolean; /** * The amount of idle time in minutes after which your application will automatically stop. Defaults to `15` minutes. */ idleTimeoutMinutes?: number; } interface ApplicationImageConfiguration { /** * The image URI. */ imageUri: string; } interface ApplicationInitialCapacity { /** * The initial capacity configuration per worker. */ initialCapacityConfig?: outputs.emrserverless.ApplicationInitialCapacityInitialCapacityConfig; /** * The worker type for an analytics framework. For Spark applications, the key can either be set to `Driver` or `Executor`. For Hive applications, it can be set to `HiveDriver` or `TezTask`. */ initialCapacityType: string; } interface ApplicationInitialCapacityInitialCapacityConfig { /** * The resource configuration of the initial capacity configuration. */ workerConfiguration?: outputs.emrserverless.ApplicationInitialCapacityInitialCapacityConfigWorkerConfiguration; /** * The number of workers in the initial capacity configuration. */ workerCount: number; } interface ApplicationInitialCapacityInitialCapacityConfigWorkerConfiguration { /** * The CPU requirements for every worker instance of the worker type. */ cpu: string; /** * The disk requirements for every worker instance of the worker type. */ disk: string; /** * The memory requirements for every worker instance of the worker type. */ memory: string; } interface ApplicationInteractiveConfiguration { /** * Enables an Apache Livy endpoint that you can connect to and run interactive jobs. */ livyEndpointEnabled: boolean; /** * Enables you to connect an application to Amazon EMR Studio to run interactive workloads in a notebook. */ studioEnabled: boolean; } interface ApplicationJobLevelCostAllocationConfiguration { enabled: boolean; } interface ApplicationMaximumCapacity { /** * The maximum allowed CPU for an application. */ cpu: string; /** * The maximum allowed disk for an application. */ disk: string; /** * The maximum allowed resources for an application. */ memory: string; } interface ApplicationMonitoringConfiguration { /** * The Amazon CloudWatch configuration for monitoring logs. */ cloudwatchLoggingConfiguration?: outputs.emrserverless.ApplicationMonitoringConfigurationCloudwatchLoggingConfiguration; /** * The managed log persistence configuration for monitoring logs. */ managedPersistenceMonitoringConfiguration?: outputs.emrserverless.ApplicationMonitoringConfigurationManagedPersistenceMonitoringConfiguration; /** * The Prometheus configuration for monitoring metrics. */ prometheusMonitoringConfiguration?: outputs.emrserverless.ApplicationMonitoringConfigurationPrometheusMonitoringConfiguration; /** * The Amazon S3 configuration for monitoring log publishing. */ s3MonitoringConfiguration?: outputs.emrserverless.ApplicationMonitoringConfigurationS3MonitoringConfiguration; } interface ApplicationMonitoringConfigurationCloudwatchLoggingConfiguration { /** * Enables CloudWatch logging. */ enabled: boolean; /** * KMS key ARN to encrypt the logs that you store in CloudWatch Logs. */ encryptionKeyArn?: string; /** * The name of the log group in Amazon CloudWatch Logs where you want to publish your logs. */ logGroupName?: string; /** * Prefix for the CloudWatch log stream name. */ logStreamNamePrefix?: string; /** * The types of logs that you want to publish to CloudWatch. If you don't specify any log types, driver STDOUT and STDERR logs will be published to CloudWatch Logs by default. See logTypes for more details. */ logTypes?: outputs.emrserverless.ApplicationMonitoringConfigurationCloudwatchLoggingConfigurationLogType[]; } interface ApplicationMonitoringConfigurationCloudwatchLoggingConfigurationLogType { /** * The worker type. Valid values are `SPARK_DRIVER`, `SPARK_EXECUTOR`, `HIVE_DRIVER`, and `TEZ_TASK`. */ name: string; /** * The list of log types to publish. Valid values are `STDOUT`, `STDERR`, `HIVE_LOG`, `TEZ_AM`, and `SYSTEM_LOGS`. */ values: string[]; } interface ApplicationMonitoringConfigurationManagedPersistenceMonitoringConfiguration { /** * Enables managed log persistence for monitoring logs. */ enabled?: boolean; /** * The KMS key ARN to encrypt the logs stored in managed persistence. */ encryptionKeyArn?: string; } interface ApplicationMonitoringConfigurationPrometheusMonitoringConfiguration { /** * The Prometheus remote write URL for sending metrics. Only supported in EMR 7.1.0 and later versions. */ remoteWriteUrl?: string; } interface ApplicationMonitoringConfigurationS3MonitoringConfiguration { /** * The KMS key ARN to encrypt the logs published to the given Amazon S3 destination. */ encryptionKeyArn?: string; /** * The Amazon S3 destination URI for log publishing. */ logUri?: string; } interface ApplicationNetworkConfiguration { /** * The array of security group Ids for customer VPC connectivity. */ securityGroupIds?: string[]; /** * The array of subnet Ids for customer VPC connectivity. */ subnetIds?: string[]; } interface ApplicationRuntimeConfiguration { /** * The classification within a configuration. */ classification: string; /** * A set of properties specified within a configuration classification. */ properties?: { [key: string]: string; }; } interface ApplicationSchedulerConfiguration { /** * Maximum concurrent job runs on this application. Valid range is `1` to `1000`. Defaults to `15`. */ maxConcurrentRuns: number; /** * Maximum duration in minutes for the job in QUEUED state. Valid range is from `15` to `720`. Defaults to `360`. */ queueTimeoutMinutes: number; } } export declare namespace evidently { interface FeatureEvaluationRule { /** * The name for the new feature. Minimum length of `1`. Maximum length of `127`. */ name: string; /** * This value is `aws.evidently.splits` if this is an evaluation rule for a launch, and it is `aws.evidently.onlineab` if this is an evaluation rule for an experiment. */ type: string; } interface FeatureVariation { /** * The name of the variation. Minimum length of `1`. Maximum length of `127`. */ name: string; /** * A block that specifies the value assigned to this variation. Detailed below */ value: outputs.evidently.FeatureVariationValue; } interface FeatureVariationValue { /** * If this feature uses the Boolean variation type, this field contains the Boolean value of this variation. */ boolValue?: string; /** * If this feature uses the double integer variation type, this field contains the double integer value of this variation. */ doubleValue?: string; /** * If this feature uses the long variation type, this field contains the long value of this variation. Minimum value of `-9007199254740991`. Maximum value of `9007199254740991`. */ longValue?: string; /** * If this feature uses the string variation type, this field contains the string value of this variation. Minimum length of `0`. Maximum length of `512`. */ stringValue?: string; } interface LaunchExecution { /** * The date and time that the launch ended. */ endedTime: string; /** * The date and time that the launch started. */ startedTime: string; } interface LaunchGroup { /** * Specifies the description of the launch group. */ description?: string; /** * Specifies the name of the feature that the launch is using. */ feature: string; /** * Specifies the name of the lahnch group. */ name: string; /** * Specifies the feature variation to use for this launch group. */ variation: string; } interface LaunchMetricMonitor { /** * A block that defines the metric. Detailed below. */ metricDefinition: outputs.evidently.LaunchMetricMonitorMetricDefinition; } interface LaunchMetricMonitorMetricDefinition { /** * Specifies the entity, such as a user or session, that does an action that causes a metric value to be recorded. An example is `userDetails.userID`. */ entityIdKey: string; /** * Specifies The EventBridge event pattern that defines how the metric is recorded. */ eventPattern?: string; /** * Specifies the name for the metric. */ name: string; /** * Specifies a label for the units that the metric is measuring. */ unitLabel?: string; /** * Specifies the value that is tracked to produce the metric. */ valueKey: string; } interface LaunchScheduledSplitsConfig { /** * One or up to six blocks that define the traffic allocation percentages among the feature variations during each step of the launch. This also defines the start time of each step. Detailed below. */ steps: outputs.evidently.LaunchScheduledSplitsConfigStep[]; } interface LaunchScheduledSplitsConfigStep { /** * The traffic allocation percentages among the feature variations during one step of a launch. This is a set of key-value pairs. The keys are variation names. The values represent the percentage of traffic to allocate to that variation during this step. For more information, refer to the [AWS documentation for ScheduledSplitConfig groupWeights](https://docs.aws.amazon.com/cloudwatchevidently/latest/APIReference/API_ScheduledSplitConfig.html). */ groupWeights: { [key: string]: number; }; /** * One or up to six blocks that specify different traffic splits for one or more audience segments. A segment is a portion of your audience that share one or more characteristics. Examples could be Chrome browser users, users in Europe, or Firefox browser users in Europe who also fit other criteria that your application collects, such as age. Detailed below. */ segmentOverrides?: outputs.evidently.LaunchScheduledSplitsConfigStepSegmentOverride[]; /** * Specifies the date and time that this step of the launch starts. */ startTime: string; } interface LaunchScheduledSplitsConfigStepSegmentOverride { /** * Specifies a number indicating the order to use to evaluate segment overrides, if there are more than one. Segment overrides with lower numbers are evaluated first. */ evaluationOrder: number; /** * The name or ARN of the segment to use. */ segment: string; /** * The traffic allocation percentages among the feature variations to assign to this segment. This is a set of key-value pairs. The keys are variation names. The values represent the amount of traffic to allocate to that variation for this segment. This is expressed in thousandths of a percent, so a weight of 50000 represents 50% of traffic. */ weights: { [key: string]: number; }; } interface ProjectDataDelivery { /** * A block that defines the CloudWatch Log Group that stores the evaluation events. See below. */ cloudwatchLogs?: outputs.evidently.ProjectDataDeliveryCloudwatchLogs; /** * A block that defines the S3 bucket and prefix that stores the evaluation events. See below. */ s3Destination?: outputs.evidently.ProjectDataDeliveryS3Destination; } interface ProjectDataDeliveryCloudwatchLogs { /** * The name of the log group where the project stores evaluation events. */ logGroup?: string; } interface ProjectDataDeliveryS3Destination { /** * The name of the bucket in which Evidently stores evaluation events. */ bucket?: string; /** * The bucket prefix in which Evidently stores evaluation events. */ prefix?: string; } } export declare namespace finspace { interface KxClusterAutoScalingConfiguration { /** * Metric your cluster will track in order to scale in and out. For example, CPU_UTILIZATION_PERCENTAGE is the average CPU usage across all nodes in a cluster. */ autoScalingMetric: string; /** * Highest number of nodes to scale. Cannot be greater than 5. */ maxNodeCount: number; /** * Desired value of chosen `autoScalingMetric`. When metric drops below this value, cluster will scale in. When metric goes above this value, cluster will scale out. Can be set between 0 and 100 percent. */ metricTarget: number; /** * Lowest number of nodes to scale. Must be at least 1 and less than the `maxNodeCount`. If nodes in cluster belong to multiple availability zones, then `minNodeCount` must be at least 3. */ minNodeCount: number; /** * Duration in seconds that FinSpace will wait after a scale in event before initiating another scaling event. */ scaleInCooldownSeconds: number; /** * Duration in seconds that FinSpace will wait after a scale out event before initiating another scaling event. */ scaleOutCooldownSeconds: number; } interface KxClusterCacheStorageConfiguration { /** * Size of cache in Gigabytes. */ size: number; /** * Type of cache storage. Valid values are `CACHE_1000` (1000 MB/s disk access throughput), `CACHE_250` (250 MB/s disk access throughput), and `CACHE_12` (12 MB/s disk access throughput). */ type: string; } interface KxClusterCapacityConfiguration { /** * Number of instances running in a cluster. Must be at least 1 and at most 5. */ nodeCount: number; /** * Hardware of the host computer used for your cluster instance. Valid values are `kx.s.large`, `kx.s.xlarge`, `kx.s.2xlarge`, `kx.s.4xlarge`, `kx.s.8xlarge`, `kx.s.16xlarge`, and `kx.s.32xlarge`. */ nodeType: string; } interface KxClusterCode { /** * Unique name for the S3 bucket. */ s3Bucket: string; /** * Full S3 path (excluding bucket) to the .zip file that contains the code to be loaded onto the cluster when it’s started. */ s3Key: string; /** * Version of an S3 Object. */ s3ObjectVersion?: string; } interface KxClusterDatabase { /** * Configuration details for the disk cache to increase performance reading from a KX database mounted to the cluster. See `cacheConfigurations` Block. */ cacheConfigurations?: outputs.finspace.KxClusterDatabaseCacheConfiguration[]; /** * Unique identifier of the changeset that is associated with the cluster. */ changesetId?: string; /** * Name of the KX database. */ databaseName: string; /** * Name of the dataview to be used for caching historical data on disk. You cannot update to a different dataview name once a cluster is created. Use `lifecycle` `ignoreChanges` for database to prevent any undesirable behaviors. */ dataviewName?: string; } interface KxClusterDatabaseCacheConfiguration { /** * Type of disk cache. */ cacheType: string; /** * Paths within the database to cache. */ dbPaths?: string[]; } interface KxClusterSavedownStorageConfiguration { /** * Size of temporary storage in gigabytes. Must be between 10 and 16000. */ size?: number; /** * Type of writeable storage space for temporarily storing your savedown data. Valid value is `SDS01`, which represents 3000 IOPS and io2 ebs volume type. */ type?: string; /** * Name of the kdb volume that you want to use as writeable save-down storage for clusters. */ volumeName?: string; } interface KxClusterScalingGroupConfiguration { /** * Number of vCPUs that you want to reserve for each node of this kdb cluster on the scaling group host. */ cpu?: number; /** * Hard limit on the amount of memory a kdb cluster can use. */ memoryLimit?: number; /** * Reservation of the minimum amount of memory that should be available on the scaling group for a kdb cluster to be successfully placed in a scaling group. */ memoryReservation: number; /** * Number of kdb cluster nodes. */ nodeCount: number; /** * Unique identifier for the kdb scaling group. */ scalingGroupName: string; } interface KxClusterTickerplantLogConfiguration { /** * Names of the volumes for tickerplant logs. */ tickerplantLogVolumes: string[]; } interface KxClusterVpcConfiguration { /** * IP address type for cluster network configuration parameters. The following type is available: IP_V4 - IP address version 4. */ ipAddressType: string; /** * Unique identifier of the VPC security group applied to the VPC endpoint ENI for the cluster. */ securityGroupIds: string[]; /** * Identifier of the subnet that the Privatelink VPC endpoint uses to connect to the cluster. */ subnetIds: string[]; /** * Identifier of the VPC endpoint. */ vpcId: string; } interface KxDataviewSegmentConfiguration { /** * Database path of the data that you want to place on each selected volume. Each segment must have a unique database path for each volume. */ dbPaths: string[]; /** * Enables on-demand caching on the selected database path when a particular file or a column of the database is accessed. When on demand caching is **True**, dataviews perform minimal loading of files on the filesystem as needed. When it is set to **False**, everything is cached. The default value is **False**. */ onDemand?: boolean; /** * Name of the volume that you want to attach to a dataview. This volume must be in the same availability zone as the dataview that you are attaching to. */ volumeName: string; } interface KxEnvironmentCustomDnsConfiguration { /** * IP address of the DNS server. */ customDnsServerIp: string; /** * Name of the DNS server. */ customDnsServerName: string; } interface KxEnvironmentTransitGatewayConfiguration { /** * Rules that define how you manage outbound traffic from kdb network to your internal network. Defined below. */ attachmentNetworkAclConfigurations?: outputs.finspace.KxEnvironmentTransitGatewayConfigurationAttachmentNetworkAclConfiguration[]; /** * Routing CIDR on behalf of KX environment. It could be any “/26 range in the 100.64.0.0 CIDR space. After providing, it will be added to the customer’s transit gateway routing table so that the traffics could be routed to KX network. */ routableCidrSpace: string; /** * Identifier of the transit gateway created by the customer to connect outbound traffics from KX network to your internal network. */ transitGatewayId: string; } interface KxEnvironmentTransitGatewayConfigurationAttachmentNetworkAclConfiguration { /** * IPv4 network range to allow or deny, in CIDR notation. The specified CIDR block is modified to its canonical form. For example, `100.68.0.18/18` will be converted to `100.68.0.0/18`. */ cidrBlock: string; /** * ICMP protocol that consists of the ICMP type and code. Defined below. */ icmpTypeCode?: outputs.finspace.KxEnvironmentTransitGatewayConfigurationAttachmentNetworkAclConfigurationIcmpTypeCode; /** * Range of ports the rule applies to. Defined below. */ portRange?: outputs.finspace.KxEnvironmentTransitGatewayConfigurationAttachmentNetworkAclConfigurationPortRange; /** * Protocol number. A value of `1` means all the protocols. */ protocol: string; /** * Whether to `allow` or `deny` the traffic that matches the rule. */ ruleAction: string; /** * Rule number for the entry. All the network ACL entries are processed in ascending order by rule number. */ ruleNumber: number; } interface KxEnvironmentTransitGatewayConfigurationAttachmentNetworkAclConfigurationIcmpTypeCode { /** * ICMP code. A value of `-1` means all codes for the specified ICMP type. */ code: number; /** * ICMP type. A value of `-1` means all types. */ type: number; } interface KxEnvironmentTransitGatewayConfigurationAttachmentNetworkAclConfigurationPortRange { /** * First port in the range. */ from: number; /** * Last port in the range. */ to: number; } interface KxVolumeAttachedCluster { /** * Name of the KX cluster. */ clusterName: string; /** * Status of the KX cluster. */ clusterStatus: string; /** * Type of the KX cluster. */ clusterType: string; } interface KxVolumeNas1Configuration { /** * Size of the network attached storage. */ size: number; /** * Type of the network attached storage. */ type: string; } } export declare namespace fis { interface ExperimentTemplateAction { /** * ID of the action. To find out what actions are supported see [AWS FIS actions reference](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html). */ actionId: string; /** * Description of the action. */ description?: string; /** * Friendly name of the action. */ name: string; /** * Parameter(s) for the action, if applicable. See below. */ parameters?: outputs.fis.ExperimentTemplateActionParameter[]; /** * Set of action names that must complete before this action can be executed. */ startAfters?: string[]; /** * Action's target, if applicable. See below. */ target?: outputs.fis.ExperimentTemplateActionTarget; } interface ExperimentTemplateActionParameter { /** * Parameter name. */ key: string; /** * Parameter value. */ value: string; } interface ExperimentTemplateActionTarget { key: string; value: string; } interface ExperimentTemplateExperimentOptions { /** * Account targeting setting for experiment options. Supports `single-account` and `multi-account`. */ accountTargeting?: string; /** * Empty target resolution mode for experiment options. Supports `fail` and `skip`. */ emptyTargetResolutionMode?: string; } interface ExperimentTemplateExperimentReportConfiguration { /** * Data sources for the experiment report. See below. */ dataSources?: outputs.fis.ExperimentTemplateExperimentReportConfigurationDataSources; /** * Outputs for the experiment report. See below. */ outputs?: outputs.fis.ExperimentTemplateExperimentReportConfigurationOutputs; /** * Duration of the post-experiment period. Defaults to `PT20M`. */ postExperimentDuration?: string; /** * Duration of the pre-experiment period. Defaults to `PT20M`. */ preExperimentDuration?: string; } interface ExperimentTemplateExperimentReportConfigurationDataSources { /** * Data sources for the experiment report. See below. */ cloudwatchDashboards?: outputs.fis.ExperimentTemplateExperimentReportConfigurationDataSourcesCloudwatchDashboard[]; } interface ExperimentTemplateExperimentReportConfigurationDataSourcesCloudwatchDashboard { /** * ARN of the CloudWatch dashboard. */ dashboardArn?: string; } interface ExperimentTemplateExperimentReportConfigurationOutputs { /** * Data sources for the experiment report. See below. */ s3Configuration?: outputs.fis.ExperimentTemplateExperimentReportConfigurationOutputsS3Configuration; } interface ExperimentTemplateExperimentReportConfigurationOutputsS3Configuration { bucketName: string; prefix?: string; } interface ExperimentTemplateLogConfiguration { /** * Configuration for experiment logging to Amazon CloudWatch Logs. See below. */ cloudwatchLogsConfiguration?: outputs.fis.ExperimentTemplateLogConfigurationCloudwatchLogsConfiguration; /** * Schema version. See [documentation](https://docs.aws.amazon.com/fis/latest/userguide/monitoring-logging.html#experiment-log-schema) for the list of schema versions. */ logSchemaVersion: number; /** * Configuration for experiment logging to Amazon S3. See below. */ s3Configuration?: outputs.fis.ExperimentTemplateLogConfigurationS3Configuration; } interface ExperimentTemplateLogConfigurationCloudwatchLogsConfiguration { /** * ARN of the destination Amazon CloudWatch Logs log group. The ARN must end with `:*` */ logGroupArn: string; } interface ExperimentTemplateLogConfigurationS3Configuration { bucketName: string; prefix?: string; } interface ExperimentTemplateStopCondition { /** * Source of the condition. One of `none`, `aws:cloudwatch:alarm`. */ source: string; /** * ARN of the CloudWatch alarm. Required if the source is a CloudWatch alarm. */ value?: string; } interface ExperimentTemplateTarget { /** * Filter(s) for the target. Filters can be used to select resources based on specific attributes returned by the respective describe action of the resource type. For more information, see [Targets for AWS FIS](https://docs.aws.amazon.com/fis/latest/userguide/targets.html#target-filters). See below. */ filters?: outputs.fis.ExperimentTemplateTargetFilter[]; /** * Friendly name given to the target. */ name: string; /** * Resource type parameters. */ parameters?: { [key: string]: string; }; /** * Set of ARNs of the resources to target with an action. Conflicts with `resourceTag`. */ resourceArns?: string[]; /** * Tag(s) the resources need to have to be considered a valid target for an action. Conflicts with `resourceArns`. See below. */ resourceTags?: outputs.fis.ExperimentTemplateTargetResourceTag[]; /** * AWS resource type. The resource type must be supported for the specified action. To find out what resource types are supported, see [Targets for AWS FIS](https://docs.aws.amazon.com/fis/latest/userguide/targets.html#resource-types). */ resourceType: string; /** * Scopes the identified resources. Valid values are `ALL` (all identified resources), `COUNT(n)` (randomly select `n` of the identified resources), `PERCENT(n)` (randomly select `n` percent of the identified resources). * * > **NOTE:** The `target` configuration block requires either `resourceArns` or `resourceTag`. */ selectionMode: string; } interface ExperimentTemplateTargetFilter { /** * Attribute path for the filter. */ path: string; /** * Set of attribute values for the filter. * * > **NOTE:** Values specified in a `filter` are joined with an `OR` clause, while values across multiple `filter` blocks are joined with an `AND` clause. For more information, see [Targets for AWS FIS](https://docs.aws.amazon.com/fis/latest/userguide/targets.html#target-filters). */ values: string[]; } interface ExperimentTemplateTargetResourceTag { /** * Tag key. */ key: string; /** * Tag value. */ value: string; } interface SafetyLeverStateState { /** * Reason for the current status of the safety lever. */ reason: string; /** * Status of the safety lever. Valid values: `engaged`, `disengaged`. Engaging the lever immediately stops all running experiments in the account and Region, and prevents new ones from starting. */ status: string; } interface SafetyLeverStateTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace fms { interface PolicyExcludeMap { /** * List of AWS Organization member accounts to exclude from this AWS FMS Policy. */ accounts?: string[]; /** * List of IDs of the AWS Organizational Units to exclude from this AWS FMS Policy. Specifying an OU is equivalent to specifying all accounts in the OU and in any of its child OUs, including any child OUs and accounts that are added at a later time. */ orgunits?: string[]; } interface PolicyIncludeMap { /** * List of AWS Organization member accounts to include for this AWS FMS Policy. */ accounts?: string[]; /** * List of IDs of the AWS Organizational Units to include for this AWS FMS Policy. Specifying an OU is equivalent to specifying all accounts in the OU and in any of its child OUs, including any child OUs and accounts that are added at a later time. */ orgunits?: string[]; } interface PolicySecurityServicePolicyData { /** * Details about the service that are specific to the service type, in JSON format. For service type `SHIELD_ADVANCED`, this is an empty string. Examples depending on `type` can be found in the [AWS Firewall Manager SecurityServicePolicyData API Reference](https://docs.aws.amazon.com/fms/2018-01-01/APIReference/API_SecurityServicePolicyData.html). */ managedServiceData?: string; /** * Network Firewall firewall policy options to configure a centralized deployment model. See the `policyOption` block. */ policyOption?: outputs.fms.PolicySecurityServicePolicyDataPolicyOption; /** * Service that the policy uses to protect the resources. For the current list of supported types, refer to the [AWS Firewall Manager SecurityServicePolicyData API Type Reference](https://docs.aws.amazon.com/fms/2018-01-01/APIReference/API_SecurityServicePolicyData.html#fms-Type-SecurityServicePolicyData-Type). */ type: string; } interface PolicySecurityServicePolicyDataPolicyOption { /** * Network ACL rules applied across accounts in the AWS Organization. See the `networkAclCommonPolicy` block. */ networkAclCommonPolicy?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicy; /** * Network Firewall policy options that configure a centralized deployment model. See the `networkFirewallPolicy` block. */ networkFirewallPolicy?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkFirewallPolicy; /** * Third-party firewall policy options. See the `thirdPartyFirewallPolicy` block. */ thirdPartyFirewallPolicy?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionThirdPartyFirewallPolicy; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicy { /** * Network ACL entries for the Network ACL policy. See the `networkAclEntrySet` block. */ networkAclEntrySet?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySet; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySet { /** * Rules to run first in the Firewall Manager managed network ACLs. Firewall Manager creates entries with ID value between 1 and 5000. See the `firstEntry` block. */ firstEntries?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetFirstEntry[]; /** * Whether Firewall Manager applies this setting to first-entry policy violations that involve conflicts between the custom entries and the policy entries. If `false`, Firewall Manager marks the network ACL as noncompliant and does not try to remediate. */ forceRemediateForFirstEntries: boolean; /** * Whether Firewall Manager applies this setting to last-entry policy violations that involve conflicts between the custom entries and the policy entries. If `false`, Firewall Manager marks the network ACL as noncompliant and does not try to remediate. */ forceRemediateForLastEntries: boolean; /** * Rules to run last in the Firewall Manager managed network ACLs. Firewall Manager creates entries with ID value between 32000 and 32766. See the `lastEntry` block. */ lastEntries?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetLastEntry[]; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetFirstEntry { /** * IPv4 network range to allow or deny, in CIDR notation. */ cidrBlock?: string; /** * Whether Firewall Manager creates an egress rule. If `false`, Firewall Manager creates an ingress rule. */ egress: boolean; /** * ICMP protocol configuration specifying the ICMP type and code. See the `icmpTypeCode` block. */ icmpTypeCodes?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetFirstEntryIcmpTypeCode[]; /** * IPv6 network range to allow or deny, in CIDR notation. */ ipv6CidrBlock?: string; /** * Port range configuration for the rule. See the `portRange` block. */ portRanges?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetFirstEntryPortRange[]; /** * Protocol number. A value of `-1` means all protocols. */ protocol: string; /** * Whether to allow or deny the traffic that matches the rule. Valid values: `allow`, `deny`. */ ruleAction: string; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetFirstEntryIcmpTypeCode { /** * ICMP code. */ code?: number; /** * ICMP type. */ type?: number; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetFirstEntryPortRange { /** * Beginning port number of the range. */ from?: number; /** * Ending port number of the range. */ to?: number; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetLastEntry { /** * IPv4 network range to allow or deny, in CIDR notation. */ cidrBlock?: string; /** * Whether Firewall Manager creates an egress rule. If `false`, Firewall Manager creates an ingress rule. */ egress: boolean; /** * ICMP protocol configuration specifying the ICMP type and code. See the `icmpTypeCode` block. */ icmpTypeCodes?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetLastEntryIcmpTypeCode[]; /** * IPv6 network range to allow or deny, in CIDR notation. */ ipv6CidrBlock?: string; /** * Port range configuration for the rule. See the `portRange` block. */ portRanges?: outputs.fms.PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetLastEntryPortRange[]; /** * Protocol number. A value of `-1` means all protocols. */ protocol: string; /** * Whether to allow or deny the traffic that matches the rule. Valid values: `allow`, `deny`. */ ruleAction: string; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetLastEntryIcmpTypeCode { /** * ICMP code. */ code?: number; /** * ICMP type. */ type?: number; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkAclCommonPolicyNetworkAclEntrySetLastEntryPortRange { /** * Beginning port number of the range. */ from?: number; /** * Ending port number of the range. */ to?: number; } interface PolicySecurityServicePolicyDataPolicyOptionNetworkFirewallPolicy { /** * Deployment model for the firewall policy. To use a distributed model, remove the `policyOption` section. Valid values are `CENTRALIZED` and `DISTRIBUTED`. */ firewallDeploymentModel?: string; } interface PolicySecurityServicePolicyDataPolicyOptionThirdPartyFirewallPolicy { /** * Deployment model for the third-party firewall policy. Valid values are `CENTRALIZED` and `DISTRIBUTED`. */ firewallDeploymentModel?: string; } interface ResourceSetResourceSet { /** * Description of the resource set. */ description?: string; /** * Unique identifier for the resource set. It's returned in the responses to create and list commands. You provide it to operations like update and delete. */ id: string; /** * Last time that the resource set was changed. */ lastUpdateTime: string; /** * Descriptive name of the resource set. You can't change the name of a resource set after you create it. * * The following arguments are optional: */ name: string; /** * Whether the resource set is in or out of the admin's Region scope. Valid values are `ACTIVE` (Admin can manage and delete the resource set) or `OUT_OF_ADMIN_SCOPE` (Admin can view the resource set, but they can't edit or delete the resource set.) */ resourceSetStatus: string; /** * Resources that can be associated to the resource set. Depending on your setting for max results and the number of resource sets, a single call might not return the full list. */ resourceTypeLists?: string[]; /** * Unique identifier for each update to the resource set. */ updateToken: string; } interface ResourceSetTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace fsx { interface DataRepositoryAssociationS3 { /** * Type of updated objects that are automatically exported from your file system to the linked S3 bucket. See the `autoExportPolicy` Block below. */ autoExportPolicy: outputs.fsx.DataRepositoryAssociationS3AutoExportPolicy; /** * Type of updated objects that are automatically imported from the linked S3 bucket to your file system. See the `autoImportPolicy` Block below. */ autoImportPolicy: outputs.fsx.DataRepositoryAssociationS3AutoImportPolicy; } interface DataRepositoryAssociationS3AutoExportPolicy { /** * List of file event types to automatically export to your linked S3 bucket. Valid values are `NEW`, `CHANGED`, `DELETED`. Max of 3. */ events: string[]; } interface DataRepositoryAssociationS3AutoImportPolicy { /** * List of file event types to automatically import from the linked S3 bucket. Valid values are `NEW`, `CHANGED`, `DELETED`. Max of 3. */ events: string[]; } interface FileCacheDataRepositoryAssociation { /** * System-generated, unique ID of the data repository association. */ associationId: string; /** * Path to the S3 or NFS data repository that links to the cache. */ dataRepositoryPath: string; /** * NFS exports linked with this data repository association, in the format `/exportpath1`. Configure `dataRepositoryPath` as the domain name of the NFS file system to use this argument. Not supported for S3 data repositories. Maximum of 500. */ dataRepositorySubdirectories?: string[]; /** * System-generated, unique ID of the cache. */ fileCacheId: string; /** * Path on the cache that maps 1-1 with `dataRepositoryPath`. Must begin with a forward slash and cannot overlap the cache path of another data repository association. */ fileCachePath: string; /** * ID of the file system for an NFS data repository association. */ fileSystemId: string; /** * Path to the data repository on the file system. */ fileSystemPath: string; /** * Size, in mebibytes (MiB), of the data blocks used to represent imported files. */ importedFileChunkSize: number; /** * Configuration for a data repository association linked to an NFS file system. See `nfs` Block below. */ nfs?: outputs.fsx.FileCacheDataRepositoryAssociationNf[]; /** * ARN of the data repository association. */ resourceArn: string; /** * Map of tags to assign to the file cache. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags: { [key: string]: string; }; } interface FileCacheDataRepositoryAssociationNf { /** * Up to 2 IP addresses of DNS servers used to resolve the NFS file system domain name. */ dnsIps?: string[]; /** * Version of the NFS protocol of the NFS data repository. The only supported value is `NFS3`. */ version: string; } interface FileCacheLustreConfiguration { /** * Cache deployment type. The only supported value is `CACHE_1`. */ deploymentType: string; /** * Configuration for Lustre logging used to write the enabled logging events for the cache. See `logConfiguration` Block below. */ logConfigurations: outputs.fsx.FileCacheLustreConfigurationLogConfiguration[]; /** * Configuration for a Lustre MDT (Metadata Target) storage volume. See `metadataConfiguration` Block below. */ metadataConfigurations: outputs.fsx.FileCacheLustreConfigurationMetadataConfiguration[]; /** * Mount name of the cache. */ mountName: string; /** * Throughput provisioned for each 1 tebibyte (TiB) of cache storage capacity, in MB/s/TiB. The only supported value is `1000`. */ perUnitStorageThroughput: number; /** * Recurring weekly time to start maintenance, in the format `D:HH:MM`. `D` is the day of the week, where `1` represents Monday and `7` represents Sunday. `HH` is the zero-padded hour of the day (0-23), and `MM` is the zero-padded minute of the hour. See the [ISO week date](https://en.wikipedia.org/wiki/ISO_week_date) for more information. */ weeklyMaintenanceStartTime?: string; } interface FileCacheLustreConfigurationLogConfiguration { /** * ARN of the destination that receives the logs. */ destination: string; /** * Level of logging that Lustre logs write to the destination. */ level: string; } interface FileCacheLustreConfigurationMetadataConfiguration { /** * Storage capacity of the Lustre MDT (Metadata Target) storage volume in gibibytes (GiB). The only supported value is `2400` GiB. */ storageCapacity: number; } interface GetOntapFileSystemDiskIopsConfiguration { /** * Total number of SSD IOPS provisioned for the file system. */ iops: number; /** * Whether the file system is using the `AUTOMATIC` setting of SSD IOPS of 3 IOPS per GB of storage capacity, or if it using a `USER_PROVISIONED` value. */ mode: string; } interface GetOntapFileSystemEndpoint { /** * FileSystemEndpoint for managing your file system by setting up NetApp SnapMirror with other ONTAP systems. See FileSystemEndpoint below. */ interclusters: outputs.fsx.GetOntapFileSystemEndpointIntercluster[]; /** * FileSystemEndpoint for managing your file system using the NetApp ONTAP CLI and NetApp ONTAP API. See FileSystemEndpoint below. */ managements: outputs.fsx.GetOntapFileSystemEndpointManagement[]; } interface GetOntapFileSystemEndpointIntercluster { /** * DNS name for the file system. */ dnsName: string; ipAddresses: string[]; } interface GetOntapFileSystemEndpointManagement { /** * DNS name for the file system. */ dnsName: string; ipAddresses: string[]; } interface GetOntapStorageVirtualMachineActiveDirectoryConfiguration { /** * NetBIOS name of the AD computer object to which the SVM is joined. */ netbiosName: string; selfManagedActiveDirectoryConfigurations: outputs.fsx.GetOntapStorageVirtualMachineActiveDirectoryConfigurationSelfManagedActiveDirectoryConfiguration[]; } interface GetOntapStorageVirtualMachineActiveDirectoryConfigurationSelfManagedActiveDirectoryConfiguration { /** * List of up to three IP addresses of DNS servers or domain controllers in the self-managed AD directory. */ dnsIps: string[]; /** * Fully qualified domain name of the self-managed AD directory. */ domainName: string; /** * Name of the domain group whose members have administrative privileges for the FSx file system. */ fileSystemAdministratorsGroup: string; /** * Fully qualified distinguished name of the organizational unit within the self-managed AD directory to which the Windows File Server or ONTAP storage virtual machine (SVM) instance is joined. */ organizationalUnitDistinguishedName: string; /** * User name for the service account on your self-managed AD domain that FSx uses to join to your AD domain. */ username: string; } interface GetOntapStorageVirtualMachineEndpoint { iscsis: outputs.fsx.GetOntapStorageVirtualMachineEndpointIscsi[]; /** * Endpoint for managing SVMs using the NetApp ONTAP CLI, NetApp ONTAP API, or NetApp CloudManager. See SVM Endpoint below. */ managements: outputs.fsx.GetOntapStorageVirtualMachineEndpointManagement[]; /** * Endpoint for connecting using the Network File System (NFS) protocol. See SVM Endpoint below. */ nfs: outputs.fsx.GetOntapStorageVirtualMachineEndpointNf[]; /** * Endpoint for connecting using the Server Message Block (SMB) protocol. See SVM Endpoint below. */ smbs: outputs.fsx.GetOntapStorageVirtualMachineEndpointSmb[]; } interface GetOntapStorageVirtualMachineEndpointIscsi { dnsName: string; ipAddresses: string[]; } interface GetOntapStorageVirtualMachineEndpointManagement { dnsName: string; ipAddresses: string[]; } interface GetOntapStorageVirtualMachineEndpointNf { dnsName: string; ipAddresses: string[]; } interface GetOntapStorageVirtualMachineEndpointSmb { dnsName: string; ipAddresses: string[]; } interface GetOntapStorageVirtualMachineFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/fsx/latest/APIReference/API_StorageVirtualMachineFilter.html). */ name: string; /** * Set of values that are accepted for the given field. An SVM will be selected if any one of the given values matches. */ values: string[]; } interface GetOntapStorageVirtualMachineLifecycleTransitionReason { /** * Detailed message. */ message: string; } interface GetOntapStorageVirtualMachinesFilter { /** * Name of the field to filter by, as defined by [the underlying AWS API](https://docs.aws.amazon.com/fsx/latest/APIReference/API_StorageVirtualMachineFilter.html). */ name: string; /** * Set of values that are accepted for the given field. An SVM will be selected if any one of the given values matches. */ values: string[]; } interface GetOpenZfsSnapshotFilter { /** * Name of the field to filter by. */ name: string; /** * Set of values that are used to filter. A snapshot is returned only if it matches all of the specified filters. */ values: string[]; } interface GetWindowsFileSystemAuditLogConfiguration { auditLogDestination: string; fileAccessAuditLogLevel: string; fileShareAccessAuditLogLevel: string; } interface GetWindowsFileSystemDiskIopsConfiguration { iops: number; mode: string; } interface LustreFileSystemDataReadCacheConfiguration { /** * Size of the file system's SSD read cache, in gibibytes (GiB). Required when the `sizingMode` is `USER_PROVISIONED`. */ size: number; /** * Sizing mode for the cache. Valud values are `NO_CACHE`, `USER_PROVISIONED`, and `PROPORTIONAL_TO_THROUGHPUT_CAPACITY`. */ sizingMode: string; } interface LustreFileSystemLogConfiguration { /** * ARN that specifies the destination of the logs. The name of the Amazon CloudWatch Logs log group must begin with the `/aws/fsx` prefix. If you do not provide a destination, Amazon FSx will create and use a log stream in the CloudWatch Logs `/aws/fsx/lustre` log group. */ destination: string; /** * Sets which data repository events are logged by Amazon FSx. Valid values are `WARN_ONLY`, `FAILURE_ONLY`, `ERROR_ONLY`, `WARN_ERROR` and `DISABLED`. Default value is `DISABLED`. */ level?: string; } interface LustreFileSystemMetadataConfiguration { /** * Amount of IOPS provisioned for metadata. This parameter should only be used when the mode is set to `USER_PROVISIONED`. Valid Values are `1500`,`3000`,`6000` and `12000` through `192000` in increments of `12000`. Valid values for `INTELLIGENT_TIERING` storage type are `6000` or `12000`. */ iops: number; /** * Mode for the metadata configuration of the file system. Valid values are `AUTOMATIC`, and `USER_PROVISIONED`. Must be set to `USER_PROVISIONED` for `INTELLIGENT_TIERING` storage type. * * > **WARNING:** Updating the value of `iops` from a higher to a lower value will force a recreation of the resource. Any data on the file system will be lost when recreating. */ mode: string; } interface LustreFileSystemRootSquashConfiguration { /** * When root squash is enabled, you can optionally specify an array of NIDs of clients for which root squash does not apply. A client NID is a Lustre Network Identifier used to uniquely identify a client. You can specify the NID as either a single address or a range of addresses: 1. A single address is described in standard Lustre NID format by specifying the client’s IP address followed by the Lustre network ID (for example, 10.0.1.6@tcp). 2. An address range is described using a dash to separate the range (for example, 10.0.[2-10].[1-255]@tcp). */ noSquashNids?: string[]; /** * You enable root squash by setting a user ID (UID) and group ID (GID) for the file system in the format UID:GID (for example, 365534:65534). The UID and GID values can range from 0 to 4294967294. */ rootSquash?: string; } interface OntapFileSystemDiskIopsConfiguration { /** * Total number of SSD IOPS provisioned for the file system. */ iops: number; /** * Whether the number of IOPS for the file system is using the system. Valid values are `AUTOMATIC` and `USER_PROVISIONED`. Default value is `AUTOMATIC`. */ mode?: string; } interface OntapFileSystemEndpoint { /** * Endpoint for managing your file system by setting up NetApp SnapMirror with other ONTAP systems. See Endpoint. */ interclusters: outputs.fsx.OntapFileSystemEndpointIntercluster[]; /** * Endpoint for managing your file system using the NetApp ONTAP CLI and NetApp ONTAP API. See Endpoint. */ managements: outputs.fsx.OntapFileSystemEndpointManagement[]; } interface OntapFileSystemEndpointIntercluster { /** * Domain Name Service (DNS) name for the file system. You can mount your file system using its DNS name. */ dnsName: string; /** * IP addresses of the file system endpoint. */ ipAddresses: string[]; } interface OntapFileSystemEndpointManagement { /** * Domain Name Service (DNS) name for the file system. You can mount your file system using its DNS name. */ dnsName: string; /** * IP addresses of the file system endpoint. */ ipAddresses: string[]; } interface OntapStorageVirtualMachineActiveDirectoryConfiguration { /** * NetBIOS name of the Active Directory computer object that will be created for your SVM. This is often the same as the SVM name but can be different. AWS limits to 15 characters because of standard NetBIOS naming limits. */ netbiosName?: string; /** * Configuration block that Amazon FSx uses to join the SVM to your self-managed (including on-premises) Microsoft Active Directory (AD) directory. Detailed below. */ selfManagedActiveDirectoryConfiguration?: outputs.fsx.OntapStorageVirtualMachineActiveDirectoryConfigurationSelfManagedActiveDirectoryConfiguration; } interface OntapStorageVirtualMachineActiveDirectoryConfigurationSelfManagedActiveDirectoryConfiguration { /** * List of up to three IP addresses of DNS servers or domain controllers in the self-managed AD directory. */ dnsIps: string[]; /** * Fully qualified domain name of the self-managed AD directory. For example, `corp.example.com`. */ domainName: string; /** * Name of the domain group whose members are granted administrative privileges for the SVM. The group that you specify must already exist in your domain. Defaults to `Domain Admins`. */ fileSystemAdministratorsGroup?: string; /** * Fully qualified distinguished name of the organizational unit within your self-managed AD directory that the Windows File Server instance will join. For example, `OU=FSx,DC=yourdomain,DC=corp,DC=com`. Only accepts OU as the direct parent of the SVM. If none is provided, the SVM is created in the default location of your self-managed AD directory. To learn more, see [RFC 2253](https://tools.ietf.org/html/rfc2253). */ organizationalUnitDistinguishedName?: string; /** * Password for the service account on your self-managed AD domain that Amazon FSx will use to join to your AD domain. */ password: string; /** * User name for the service account on your self-managed AD domain that Amazon FSx will use to join to your AD domain. */ username: string; } interface OntapStorageVirtualMachineEndpoint { /** * Endpoint for accessing data on your storage virtual machine via iSCSI protocol. See Endpoint. */ iscsis: outputs.fsx.OntapStorageVirtualMachineEndpointIscsi[]; /** * Endpoint for managing your file system using the NetApp ONTAP CLI and NetApp ONTAP API. See Endpoint. */ managements: outputs.fsx.OntapStorageVirtualMachineEndpointManagement[]; /** * Endpoint for accessing data on your storage virtual machine via NFS protocol. See Endpoint. */ nfs: outputs.fsx.OntapStorageVirtualMachineEndpointNf[]; /** * Endpoint for accessing data on your storage virtual machine via SMB protocol. This is only set if an activeDirectoryConfiguration has been set. See Endpoint. */ smbs: outputs.fsx.OntapStorageVirtualMachineEndpointSmb[]; } interface OntapStorageVirtualMachineEndpointIscsi { /** * Domain Name Service (DNS) name for the storage virtual machine. You can mount your storage virtual machine using its DNS name. */ dnsName: string; /** * IP addresses of the storage virtual machine endpoint. */ ipAddresses: string[]; } interface OntapStorageVirtualMachineEndpointManagement { /** * Domain Name Service (DNS) name for the storage virtual machine. You can mount your storage virtual machine using its DNS name. */ dnsName: string; /** * IP addresses of the storage virtual machine endpoint. */ ipAddresses: string[]; } interface OntapStorageVirtualMachineEndpointNf { /** * Domain Name Service (DNS) name for the storage virtual machine. You can mount your storage virtual machine using its DNS name. */ dnsName: string; /** * IP addresses of the storage virtual machine endpoint. */ ipAddresses: string[]; } interface OntapStorageVirtualMachineEndpointSmb { /** * Domain Name Service (DNS) name for the storage virtual machine. You can mount your storage virtual machine using its DNS name. */ dnsName: string; /** * IP addresses of the storage virtual machine endpoint. */ ipAddresses: string[]; } interface OntapVolumeAggregateConfiguration { /** * Names of the aggregates on which the volume will be created. Each aggregate needs to be in the format aggrX where X is the number of the aggregate. */ aggregates: string[]; /** * Number of constituents within the FlexGroup per storage aggregate. the default value is `8`. */ constituentsPerAggregate: number; /** * Total amount of constituents for a `FLEXGROUP` volume. This would equal constituentsPerAggregate x aggregates. */ totalConstituents: number; } interface OntapVolumeSnaplockConfiguration { /** * Whether to enable the audit log volume for an FSx for ONTAP SnapLock volume. The default value is `false`. */ auditLogVolume?: boolean; /** * Configuration object for setting the autocommit period of files in an FSx for ONTAP SnapLock volume. See `autocommitPeriod` Block for details. */ autocommitPeriod: outputs.fsx.OntapVolumeSnaplockConfigurationAutocommitPeriod; /** * Whether privileged delete is enabled, disabled, or permanently disabled on an FSx for ONTAP SnapLock Enterprise volume. Valid values: `DISABLED`, `ENABLED`, `PERMANENTLY_DISABLED`. The default value is `DISABLED`. */ privilegedDelete?: string; /** * Retention period of an FSx for ONTAP SnapLock volume. See `retentionPeriod` Block for details. */ retentionPeriod: outputs.fsx.OntapVolumeSnaplockConfigurationRetentionPeriod; /** * Retention mode of an FSx for ONTAP SnapLock volume. After it is set, it can't be changed. Valid values: `COMPLIANCE`, `ENTERPRISE`. */ snaplockType: string; /** * Whether to enable volume-append mode on an FSx for ONTAP SnapLock volume. The default value is `false`. */ volumeAppendModeEnabled?: boolean; } interface OntapVolumeSnaplockConfigurationAutocommitPeriod { /** * Type of time for the autocommit period of a file in an FSx for ONTAP SnapLock volume. Setting this value to `NONE` disables autocommit. Valid values: `MINUTES`, `HOURS`, `DAYS`, `MONTHS`, `YEARS`, `NONE`. */ type: string; /** * Amount of time for the autocommit period of a file in an FSx for ONTAP SnapLock volume. */ value?: number; } interface OntapVolumeSnaplockConfigurationRetentionPeriod { /** * Retention period assigned to a write once, read many (WORM) file by default if an explicit retention period is not set for an FSx for ONTAP SnapLock volume. The default retention period must be greater than or equal to the minimum retention period and less than or equal to the maximum retention period. See `defaultRetention` Block for details. */ defaultRetention: outputs.fsx.OntapVolumeSnaplockConfigurationRetentionPeriodDefaultRetention; /** * Longest retention period that can be assigned to a WORM file on an FSx for ONTAP SnapLock volume. See `maximumRetention` Block for details. */ maximumRetention: outputs.fsx.OntapVolumeSnaplockConfigurationRetentionPeriodMaximumRetention; /** * Shortest retention period that can be assigned to a WORM file on an FSx for ONTAP SnapLock volume. See `minimumRetention` Block for details. */ minimumRetention: outputs.fsx.OntapVolumeSnaplockConfigurationRetentionPeriodMinimumRetention; } interface OntapVolumeSnaplockConfigurationRetentionPeriodDefaultRetention { /** * Type of time for the retention period of an FSx for ONTAP SnapLock volume. Set it to one of the valid types. If you set it to `INFINITE`, the files are retained forever. If you set it to `UNSPECIFIED`, the files are retained until you set an explicit retention period. Valid values: `SECONDS`, `MINUTES`, `HOURS`, `DAYS`, `MONTHS`, `YEARS`, `INFINITE`, `UNSPECIFIED`. */ type: string; /** * Amount of time for the autocommit period of a file in an FSx for ONTAP SnapLock volume. */ value?: number; } interface OntapVolumeSnaplockConfigurationRetentionPeriodMaximumRetention { /** * Type of time for the retention period of an FSx for ONTAP SnapLock volume. Set it to one of the valid types. If you set it to `INFINITE`, the files are retained forever. If you set it to `UNSPECIFIED`, the files are retained until you set an explicit retention period. Valid values: `SECONDS`, `MINUTES`, `HOURS`, `DAYS`, `MONTHS`, `YEARS`, `INFINITE`, `UNSPECIFIED`. */ type: string; /** * Amount of time for the autocommit period of a file in an FSx for ONTAP SnapLock volume. */ value?: number; } interface OntapVolumeSnaplockConfigurationRetentionPeriodMinimumRetention { /** * Type of time for the retention period of an FSx for ONTAP SnapLock volume. Set it to one of the valid types. If you set it to `INFINITE`, the files are retained forever. If you set it to `UNSPECIFIED`, the files are retained until you set an explicit retention period. Valid values: `SECONDS`, `MINUTES`, `HOURS`, `DAYS`, `MONTHS`, `YEARS`, `INFINITE`, `UNSPECIFIED`. */ type: string; /** * Amount of time for the autocommit period of a file in an FSx for ONTAP SnapLock volume. */ value?: number; } interface OntapVolumeTieringPolicy { /** * Number of days that user data in a volume must remain inactive before it is considered "cold" and moved to the capacity pool. Used with `AUTO` and `SNAPSHOT_ONLY` tiering policies only. Valid values are whole numbers between 2 and 183. Default values are 31 days for `AUTO` and 2 days for `SNAPSHOT_ONLY`. */ coolingPeriod: number; /** * Tiering policy for the ONTAP volume for moving data to the capacity pool storage. Valid values are `SNAPSHOT_ONLY`, `AUTO`, `ALL`, `NONE`. Default value is `SNAPSHOT_ONLY`. */ name: string; } interface OpenZfsFileSystemDiskIopsConfiguration { /** * Total number of SSD IOPS provisioned for the file system. */ iops: number; /** * How the number of IOPS for the file system is set. Valid values are `AUTOMATIC` and `USER_PROVISIONED`. Default value is `AUTOMATIC`. */ mode?: string; } interface OpenZfsFileSystemReadCacheConfiguration { /** * Size of the file system's SSD read cache, in gibibytes (GiB). Required when `sizingMode` is set to `USER_PROVISIONED`. Must not be set when any other `sizingMode` is used. */ size: number; /** * How the provisioned SSD read cache is sized. Valid values are `NO_CACHE`, `USER_PROVISIONED`, and `PROPORTIONAL_TO_THROUGHPUT_CAPACITY`. See the [AWS API documentation](https://docs.aws.amazon.com/fsx/latest/APIReference/API_OpenZFSReadCacheConfiguration.html) for more information. */ sizingMode?: string; } interface OpenZfsFileSystemRootVolumeConfiguration { /** * Whether tags for the file system should be copied to snapshots. Default value is false. */ copyTagsToSnapshots?: boolean; /** * Method used to compress the data on the volume. Valid values are `LZ4`, `NONE` or `ZSTD`. Child volumes that don't specify compression option will inherit from parent volume. This option on file system applies to the root volume. */ dataCompressionType?: string; /** * NFS export configuration for the root volume. Exactly 1 item. See `nfsExports` Block for details. */ nfsExports?: outputs.fsx.OpenZfsFileSystemRootVolumeConfigurationNfsExports; /** * specifies whether the volume is read-only. Default is false. */ readOnly: boolean; /** * Record size of an OpenZFS root volume, in kibibytes (KiB). Valid values are `4`, `8`, `16`, `32`, `64`, `128`, `256`, `512`, or `1024` KiB. Default is `128` KiB. */ recordSizeKib?: number; /** * Specify how much storage users or groups can use on the volume. Maximum of 100 items. See `userAndGroupQuotas` Block for details. */ userAndGroupQuotas: outputs.fsx.OpenZfsFileSystemRootVolumeConfigurationUserAndGroupQuota[]; } interface OpenZfsFileSystemRootVolumeConfigurationNfsExports { /** * List of configuration objects that contain the client and options for mounting the OpenZFS file system. Maximum of 25 items. See `clientConfigurations` Block for details. */ clientConfigurations: outputs.fsx.OpenZfsFileSystemRootVolumeConfigurationNfsExportsClientConfiguration[]; } interface OpenZfsFileSystemRootVolumeConfigurationNfsExportsClientConfiguration { /** * Value that specifies who can mount the file system. You can provide a wildcard character (*), an IP address (0.0.0.0), or a CIDR address (192.0.2.0/24. By default, Amazon FSx uses the wildcard character when specifying the client. */ clients: string; /** * Options to use when mounting the file system. Maximum of 20 items. See the [Linix NFS exports man page](https://linux.die.net/man/5/exports) for more information. `crossmount` and `sync` are used by default. */ options: string[]; } interface OpenZfsFileSystemRootVolumeConfigurationUserAndGroupQuota { /** * ID of the user or group. Valid values between `0` and `2147483647` */ id: number; /** * Amount of storage that the user or group can use in gibibytes (GiB). Valid values between `0` and `2147483647` */ storageCapacityQuotaGib: number; /** * Value that specifies whether the quota applies to a user or group. Valid values are `USER` or `GROUP`. */ type: string; } interface OpenZfsVolumeNfsExports { /** * A list of configuration objects that contain the client and options for mounting the OpenZFS file system. Maximum of 25 items. See `clientConfigurations` Block below for details. */ clientConfigurations: outputs.fsx.OpenZfsVolumeNfsExportsClientConfiguration[]; } interface OpenZfsVolumeNfsExportsClientConfiguration { /** * A value that specifies who can mount the file system. You can provide a wildcard character (*), an IP address (0.0.0.0), or a CIDR address (192.0.2.0/24. By default, Amazon FSx uses the wildcard character when specifying the client. */ clients: string; /** * The options to use when mounting the file system. Maximum of 20 items. See the [Linix NFS exports man page](https://linux.die.net/man/5/exports) for more information. `crossmount` and `sync` are used by default. */ options: string[]; } interface OpenZfsVolumeOriginSnapshot { /** * Specifies the strategy used when copying data from the snapshot to the new volume. Valid values are `CLONE`, `FULL_COPY`, `INCREMENTAL_COPY`. */ copyStrategy: string; /** * The ARN of the origin snapshot. */ snapshotArn: string; } interface OpenZfsVolumeUserAndGroupQuota { /** * The ID of the user or group. Valid values between `0` and `2147483647` */ id: number; /** * The amount of storage that the user or group can use in gibibytes (GiB). Valid values between `0` and `2147483647` */ storageCapacityQuotaGib: number; /** * A value that specifies whether the quota applies to a user or group. Valid values are `USER` or `GROUP`. */ type: string; } interface S3AccessPointAttachmentOpenzfsConfiguration { /** * File system user identity to use for authorizing file read and write requests that are made using the S3 access point. See `fileSystemIdentity` Block for details. */ fileSystemIdentity: outputs.fsx.S3AccessPointAttachmentOpenzfsConfigurationFileSystemIdentity; /** * ID of the FSx for OpenZFS volume to which the S3 access point is attached. */ volumeId: string; } interface S3AccessPointAttachmentOpenzfsConfigurationFileSystemIdentity { /** * UID and GIDs of the file system POSIX user. See `posixUser` Block for details. */ posixUser?: outputs.fsx.S3AccessPointAttachmentOpenzfsConfigurationFileSystemIdentityPosixUser; /** * FSx for OpenZFS user identity type. Valid values: `POSIX`. */ type: string; } interface S3AccessPointAttachmentOpenzfsConfigurationFileSystemIdentityPosixUser { /** * GID of the file system user. */ gid: number; /** * List of secondary GIDs for the file system user.. */ secondaryGids?: number[]; /** * UID of the file system user. */ uid: number; } interface S3AccessPointAttachmentS3AccessPoint { /** * Access policy associated with the S3 access point configuration. */ policy?: string; /** * Amazon S3 restricts access to the S3 access point to requests made from the specified VPC. See `vpcConfiguration` Block for details. */ vpcConfiguration?: outputs.fsx.S3AccessPointAttachmentS3AccessPointVpcConfiguration; } interface S3AccessPointAttachmentS3AccessPointVpcConfiguration { /** * VPC ID. */ vpcId?: string; } interface S3AccessPointAttachmentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface WindowsFileSystemAuditLogConfiguration { /** * ARN for the destination of the audit logs. The destination can be any Amazon CloudWatch Logs log group ARN or Amazon Kinesis Data Firehose delivery stream ARN. Can be specified when `fileAccessAuditLogLevel` and `fileShareAccessAuditLogLevel` are not set to `DISABLED`. The name of the Amazon CloudWatch Logs log group must begin with the `/aws/fsx` prefix. The name of the Amazon Kinesis Data Firehouse delivery stream must begin with the `aws-fsx` prefix. If you do not provide a destination in `auditLogDestionation`, Amazon FSx will create and use a log stream in the CloudWatch Logs /aws/fsx/windows log group. */ auditLogDestination: string; /** * Sets which attempt type is logged by Amazon FSx for file and folder accesses. Valid values are `SUCCESS_ONLY`, `FAILURE_ONLY`, `SUCCESS_AND_FAILURE`, and `DISABLED`. Default value is `DISABLED`. */ fileAccessAuditLogLevel?: string; /** * Sets which attempt type is logged by Amazon FSx for file share accesses. Valid values are `SUCCESS_ONLY`, `FAILURE_ONLY`, `SUCCESS_AND_FAILURE`, and `DISABLED`. Default value is `DISABLED`. */ fileShareAccessAuditLogLevel?: string; } interface WindowsFileSystemDiskIopsConfiguration { /** * Total number of SSD IOPS provisioned for the file system. */ iops: number; /** * Mode for the number of IOPS for the file system. Valid values are `AUTOMATIC` and `USER_PROVISIONED`. Default value is `AUTOMATIC`. */ mode?: string; } interface WindowsFileSystemSelfManagedActiveDirectory { /** * List of up to two IP addresses of DNS servers or domain controllers in the self-managed AD directory. The IP addresses need to be either in the same VPC CIDR range as the file system or in the private IP version 4 (IPv4) address ranges as specified in [RFC 1918](https://tools.ietf.org/html/rfc1918). */ dnsIps: string[]; /** * ARN for the AWS Secrets Manager secret that contains the credentials for the service account on your self-managed AD domain. Conflicts with `username` and `password`. */ domainJoinServiceAccountSecret?: string; /** * Fully qualified domain name of the self-managed AD directory. For example, `corp.example.com`. */ domainName: string; /** * Name of the domain group whose members are granted administrative privileges for the file system. Administrative privileges include taking ownership of files and folders, and setting audit controls (audit ACLs) on files and folders. The group that you specify must already exist in your domain. Defaults to `Domain Admins`. */ fileSystemAdministratorsGroup?: string; /** * Fully qualified distinguished name of the organizational unit within your self-managed AD directory that the Windows File Server instance will join. For example, `OU=FSx,DC=yourdomain,DC=corp,DC=com`. Only accepts OU as the direct parent of the file system. If none is provided, the FSx file system is created in the default location of your self-managed AD directory. To learn more, see [RFC 2253](https://tools.ietf.org/html/rfc2253). */ organizationalUnitDistinguishedName?: string; /** * Password for the service account on your self-managed AD domain that Amazon FSx will use to join to your AD domain. Conflicts with `domainJoinServiceAccountSecret` and `passwordWo`. */ password?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * Password for the service account on your self-managed AD domain that Amazon FSx will use to join to your AD domain. This argument is not persisted to state. Conflicts with `domainJoinServiceAccountSecret` and `password`. If set, requires `passwordWoVersion` to be set. */ passwordWo?: string; /** * Required when `passwordWo` is set. Changing this value triggers an update to `passwordWo`. */ passwordWoVersion?: number; /** * User name for the service account on your self-managed AD domain that Amazon FSx will use to join to your AD domain. Conflicts with `domainJoinServiceAccountSecret`. */ username: string; } } export declare namespace gamelift { interface AliasRoutingStrategy { /** * ID of the GameLift Fleet to point the alias to. */ fleetId?: string; /** * Message text to be used with the `TERMINAL` routing strategy. */ message?: string; /** * Type of routing strategyE.g., `SIMPLE` or `TERMINAL` */ type: string; } interface BuildStorageLocation { /** * Name of your S3 bucket. */ bucket: string; /** * Name of the zip file containing your build files. */ key: string; /** * A specific version of the file. If not set, the latest version of the file is retrieved. */ objectVersion?: string; /** * ARN of the access role that allows Amazon GameLift to access your S3 bucket. */ roleArn: string; } interface FleetCertificateConfiguration { /** * Indicates whether a TLS/SSL certificate is generated for a fleet. Valid values are `DISABLED` and `GENERATED`. Default value is `DISABLED`. */ certificateType?: string; } interface FleetEc2InboundPermission { /** * Starting value for a range of allowed port numbers. */ fromPort: number; /** * Range of allowed IP addresses expressed in CIDR notationE.g., `000.000.000.000/[subnet mask]` or `0.0.0.0/[subnet mask]`. */ ipRange: string; /** * Network communication protocol used by the fleetE.g., `TCP` or `UDP` */ protocol: string; /** * Ending value for a range of allowed port numbers. Port numbers are end-inclusive. This value must be higher than `fromPort`. */ toPort: number; } interface FleetResourceCreationLimitPolicy { /** * Maximum number of game sessions that an individual can create during the policy period. */ newGameSessionsPerCreator?: number; /** * Time span used in evaluating the resource creation limit policy. */ policyPeriodInMinutes?: number; } interface FleetRuntimeConfiguration { /** * Maximum amount of time (in seconds) that a game session can remain in status `ACTIVATING`. */ gameSessionActivationTimeoutSeconds?: number; /** * Maximum number of game sessions with status `ACTIVATING` to allow on an instance simultaneously. */ maxConcurrentGameSessionActivations?: number; /** * Collection of server process configurations that describe which server processes to run on each instance in a fleet. See below. */ serverProcesses?: outputs.gamelift.FleetRuntimeConfigurationServerProcess[]; } interface FleetRuntimeConfigurationServerProcess { /** * Number of server processes using this configuration to run concurrently on an instance. */ concurrentExecutions: number; /** * Location of the server executable in a game build. All game builds are installed on instances at the root : for Windows instances `C:\game`, and for Linux instances `/local/game`. */ launchPath: string; /** * Optional list of parameters to pass to the server executable on launch. */ parameters?: string; } interface GameServerGroupAutoScalingPolicy { /** * Length of time, in seconds, it takes for a new instance to start * new game server processes and register with GameLift FleetIQ. * Specifying a warm-up time can be useful, particularly with game servers that take a long time to start up, * because it avoids prematurely starting new instances. Defaults to `60`. */ estimatedInstanceWarmup: number; targetTrackingConfiguration: outputs.gamelift.GameServerGroupAutoScalingPolicyTargetTrackingConfiguration; } interface GameServerGroupAutoScalingPolicyTargetTrackingConfiguration { /** * Desired value to use with a game server group target-based scaling policy. */ targetValue: number; } interface GameServerGroupInstanceDefinition { /** * An EC2 instance type. */ instanceType: string; /** * Instance weighting that indicates how much this instance type contributes * to the total capacity of a game server group. * Instance weights are used by GameLift FleetIQ to calculate the instance type's cost per unit hour and better identify * the most cost-effective options. */ weightedCapacity?: string; } interface GameServerGroupLaunchTemplate { /** * A unique identifier for an existing EC2 launch template. */ id: string; /** * A readable identifier for an existing EC2 launch template. */ name: string; /** * The version of the EC2 launch template to use. If none is set, the default is the first version created. */ version?: string; } interface GameSessionQueuePlayerLatencyPolicy { /** * Maximum latency value that is allowed for any player. */ maximumIndividualPlayerLatencyMilliseconds: number; /** * Length of time that the policy is enforced while placing a new game session. Absence of value for this attribute means that the policy is enforced until the queue times out. */ policyDurationSeconds?: number; } interface ScriptStorageLocation { /** * Name of your S3 bucket. */ bucket: string; /** * Name of the zip file containing your script files. */ key: string; /** * A specific version of the file. If not set, the latest version of the file is retrieved. */ objectVersion?: string; /** * ARN of the access role that allows Amazon GameLift to access your S3 bucket. */ roleArn: string; } } export declare namespace glacier { interface VaultNotification { /** * You can configure a vault to publish a notification for `ArchiveRetrievalCompleted` and `InventoryRetrievalCompleted` events. */ events: string[]; /** * The SNS Topic ARN. */ snsTopic: string; } } export declare namespace globalaccelerator { interface AcceleratorAttributes { /** * Indicates whether flow logs are enabled. Defaults to `false`. Valid values: `true`, `false`. */ flowLogsEnabled?: boolean; /** * The name of the Amazon S3 bucket for the flow logs. Required if `flowLogsEnabled` is `true`. */ flowLogsS3Bucket?: string; /** * The prefix for the location in the Amazon S3 bucket for the flow logs. Required if `flowLogsEnabled` is `true`. */ flowLogsS3Prefix?: string; } interface AcceleratorIpSet { /** * The IP addresses to use for BYOIP accelerators. If not specified, the service assigns IP addresses. Valid values: 1 or 2 IPv4 addresses. */ ipAddresses: string[]; /** * The type of IP addresses included in this IP set. */ ipFamily: string; } interface CrossAccountAttachmentResource { /** * IP address range, in CIDR format, that is specified as resource. */ cidrBlock?: string; /** * The endpoint ID for the endpoint that is specified as a AWS resource. */ endpointId?: string; /** * The AWS Region where a shared endpoint resource is located. */ region?: string; } interface CustomRoutingAcceleratorAttributes { /** * Indicates whether flow logs are enabled. Defaults to `false`. Valid values: `true`, `false`. */ flowLogsEnabled?: boolean; /** * The name of the Amazon S3 bucket for the flow logs. Required if `flowLogsEnabled` is `true`. */ flowLogsS3Bucket?: string; /** * The prefix for the location in the Amazon S3 bucket for the flow logs. Required if `flowLogsEnabled` is `true`. */ flowLogsS3Prefix?: string; } interface CustomRoutingAcceleratorIpSet { /** * The IP addresses to use for BYOIP accelerators. If not specified, the service assigns IP addresses. Valid values: 1 or 2 IPv4 addresses. */ ipAddresses: string[]; /** * The type of IP addresses included in this IP set. */ ipFamily: string; } interface CustomRoutingEndpointGroupDestinationConfiguration { /** * The first port, inclusive, in the range of ports for the endpoint group that is associated with a custom routing accelerator. */ fromPort: number; /** * The protocol for the endpoint group that is associated with a custom routing accelerator. The protocol can be either `"TCP"` or `"UDP"`. */ protocols: string[]; /** * The last port, inclusive, in the range of ports for the endpoint group that is associated with a custom routing accelerator. */ toPort: number; } interface CustomRoutingEndpointGroupEndpointConfiguration { /** * ID for the endpoint. For custom routing accelerators, this is the VPC subnet ID. */ endpointId?: string; } interface CustomRoutingListenerPortRange { /** * The first port in the range of ports, inclusive. */ fromPort?: number; /** * The last port in the range of ports, inclusive. */ toPort?: number; } interface EndpointGroupEndpointConfiguration { /** * An ARN of an exposed cross-account attachment. See the [AWS documentation](https://docs.aws.amazon.com/global-accelerator/latest/dg/cross-account-resources.html) for more details. */ attachmentArn?: string; /** * Indicates whether client IP address preservation is enabled for an Application Load Balancer endpoint. See the [AWS documentation](https://docs.aws.amazon.com/global-accelerator/latest/dg/preserve-client-ip-address.html) for more details. The default value is `false`. * **Note:** When client IP address preservation is enabled, the Global Accelerator service creates an EC2 Security Group in the VPC named `GlobalAccelerator` that must be deleted (potentially outside of the provider) before the VPC will successfully delete. If this EC2 Security Group is not deleted, the provider will retry the VPC deletion for a few minutes before reporting a `DependencyViolation` error. This cannot be resolved by re-running the provider. */ clientIpPreservationEnabled: boolean; /** * ID for the endpoint. If the endpoint is a Network Load Balancer or Application Load Balancer, this is the ARN of the resource. If the endpoint is an Elastic IP address, this is the Elastic IP address allocation ID. */ endpointId?: string; /** * The weight associated with the endpoint. When you add weights to endpoints, you configure AWS Global Accelerator to route traffic based on proportions that you specify. */ weight?: number; } interface EndpointGroupPortOverride { /** * The endpoint port that you want a listener port to be mapped to. This is the port on the endpoint, such as the Application Load Balancer or Amazon EC2 instance. */ endpointPort: number; /** * The listener port that you want to map to a specific endpoint port. This is the port that user traffic arrives to the Global Accelerator on. */ listenerPort: number; } interface GetAcceleratorAttribute { flowLogsEnabled: boolean; flowLogsS3Bucket: string; flowLogsS3Prefix: string; } interface GetAcceleratorIpSet { ipAddresses: string[]; ipFamily: string; } interface GetCustomRoutingAcceleratorAttribute { flowLogsEnabled: boolean; flowLogsS3Bucket: string; flowLogsS3Prefix: string; } interface GetCustomRoutingAcceleratorIpSet { ipAddresses: string[]; ipFamily: string; } interface ListenerPortRange { /** * The first port in the range of ports, inclusive. */ fromPort?: number; /** * The last port in the range of ports, inclusive. */ toPort?: number; } } export declare namespace glue { interface CatalogCatalogProperties { /** * Map of custom key-value pairs for the catalog properties. */ customProperties: { [key: string]: string; }; /** * Configuration block for data lake access properties. See `dataLakeAccessProperties` below. */ dataLakeAccessProperties?: outputs.glue.CatalogCatalogPropertiesDataLakeAccessProperties; /** * Configuration block for Iceberg optimization properties. See `icebergOptimizationProperties` below. */ icebergOptimizationProperties?: outputs.glue.CatalogCatalogPropertiesIcebergOptimizationProperties; } interface CatalogCatalogPropertiesDataLakeAccessProperties { /** * Type of the catalog. */ catalogType: string; /** * Whether data lake access is enabled. */ dataLakeAccess: boolean; /** * ARN of the IAM role used for data transfer. */ dataTransferRole: string; /** * ARN of the KMS key used for encryption. */ kmsKey: string; /** * Managed workgroup name. */ managedWorkgroupName: string; /** * Managed workgroup status. */ managedWorkgroupStatus: string; /** * Redshift database name. */ redshiftDatabaseName: string; /** * Status message. */ statusMessage: string; } interface CatalogCatalogPropertiesIcebergOptimizationProperties { /** * Map of key-value pairs for compaction settings. */ compaction?: { [key: string]: string; }; /** * Map of key-value pairs for orphan file deletion settings. */ orphanFileDeletion?: { [key: string]: string; }; /** * Map of key-value pairs for retention settings. */ retention?: { [key: string]: string; }; /** * ARN of the IAM role for Iceberg optimization. */ roleArn?: string; } interface CatalogCreateDatabaseDefaultPermission { /** * Permissions that are granted to the principal. Valid values include `ALL`, `SELECT`, `ALTER`, `DROP`, `DELETE`, `INSERT`, `CREATE_DATABASE`, `CREATE_TABLE`, `DATA_LOCATION_ACCESS`. */ permissions?: string[]; /** * Principal who is granted permissions. See `principal` below. */ principal?: outputs.glue.CatalogCreateDatabaseDefaultPermissionPrincipal; } interface CatalogCreateDatabaseDefaultPermissionPrincipal { /** * Identifier for the Lake Formation principal. */ dataLakePrincipalIdentifier?: string; } interface CatalogCreateTableDefaultPermission { /** * Permissions that are granted to the principal. Valid values include `ALL`, `SELECT`, `ALTER`, `DROP`, `DELETE`, `INSERT`, `CREATE_DATABASE`, `CREATE_TABLE`, `DATA_LOCATION_ACCESS`. */ permissions?: string[]; /** * Principal who is granted permissions. See `principal` below. */ principal?: outputs.glue.CatalogCreateTableDefaultPermissionPrincipal; } interface CatalogCreateTableDefaultPermissionPrincipal { /** * Identifier for the Lake Formation principal. */ dataLakePrincipalIdentifier?: string; } interface CatalogDatabaseCreateTableDefaultPermission { /** * The permissions that are granted to the principal. */ permissions?: string[]; /** * The principal who is granted permissions.. See `principal` below. */ principal?: outputs.glue.CatalogDatabaseCreateTableDefaultPermissionPrincipal; } interface CatalogDatabaseCreateTableDefaultPermissionPrincipal { /** * An identifier for the Lake Formation principal. */ dataLakePrincipalIdentifier?: string; } interface CatalogDatabaseFederatedDatabase { /** * Name of the connection to the external metastore. */ connectionName?: string; /** * Unique identifier for the federated database. */ identifier?: string; } interface CatalogDatabaseTargetDatabase { /** * ID of the Data Catalog in which the database resides. */ catalogId: string; /** * Name of the catalog database. */ databaseName: string; /** * Region of the target database. */ region?: string; } interface CatalogFederatedCatalog { /** * Name of the connection to the external metastore. */ connectionName?: string; /** * Type of connection used to access the federated catalog. */ connectionType: string; /** * Unique identifier for the federated catalog. */ identifier?: string; } interface CatalogTableOpenTableFormatInput { /** * Configuration block for iceberg table config. See `icebergInput` below. */ icebergInput: outputs.glue.CatalogTableOpenTableFormatInputIcebergInput; } interface CatalogTableOpenTableFormatInputIcebergInput { /** * Configuration parameters, including table properties and metadata specifications. See `icebergTableInput` below. */ icebergTableInput?: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInput; /** * Required metadata operation. Can only be set to CREATE. */ metadataOperation: string; /** * Table version for the Iceberg table. Defaults to 2. */ version?: string; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInput { /** * S3 location where the Iceberg table data will be stored. Maximum length of 2056 characters. */ location: string; /** * Partitioning specification that defines how the Iceberg table data will be organized and partitioned for optimal query performance. See `partitionSpec` below. */ partitionSpec?: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputPartitionSpec; /** * Key-value pairs of additional table properties and configuration settings for the Iceberg table. */ properties?: { [key: string]: string; }; /** * Schema definition that specifies the structure, field types, and metadata for the Iceberg table. See `schema` below. */ schema: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSchema; /** * Sort order specification that defines how data should be ordered within each partition to optimize query performance. See `sortOrder` below. */ sortOrder?: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSortOrder; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputPartitionSpec { /** * List of partition fields that define how the table data should be partitioned. See `partition_spec.fields` below. */ fields: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputPartitionSpecField[]; /** * Unique identifier for this partition specification within the Iceberg table's metadata history. */ specId?: number; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputPartitionSpecField { /** * Unique identifier assigned to this partition field within the Iceberg table's partition specification. */ fieldId?: number; /** * Name of the table. For Hive compatibility, this must be entirely lowercase. * * The following arguments are optional: */ name: string; sourceId: number; transform: string; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSchema { /** * List of field definitions that make up the table schema. See `schema.fields` below. */ fields: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSchemaField[]; /** * List of field identifiers that uniquely identify records in the table, used for row-level operations and deduplication. */ identifierFieldIds?: number[]; /** * Unique identifier for this schema version within the Iceberg table's schema evolution history. */ schemaId?: number; /** * Data type definition for this field as a JSON string, specifying the structure and format of the data it contains. Examples: `"long"`, `"string"`, `"timestamp"`, `"decimal(10,2)"`. */ type?: string; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSchemaField { /** * Documentation or description text that provides additional context about the purpose and usage of this field. Length between 0 and 255 characters. */ doc?: string; /** * Catalog ID, database name, and table name, separated by colons (`:`). * * `partition_index[*].index_status` - Status of the partition index. */ id: number; /** * Default value as JSON used to populate the field's value for all records that were written before the field was added to the schema. */ initialDefault?: string; /** * Name of the table. For Hive compatibility, this must be entirely lowercase. * * The following arguments are optional: */ name: string; /** * Whether this field is required (non-nullable) or optional (nullable) in the table schema. */ required: boolean; type: string; /** * Default value as JSON used to populate the field's value for any records written after the field was added to the schema, if the writer does not supply the field's value. */ writeDefault?: string; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSortOrder { /** * List of fields and their sort directions that define the ordering criteria for the Iceberg table data. See `sort_order.fields` below. */ fields: outputs.glue.CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSortOrderField[]; /** * Unique identifier for this sort order specification within the Iceberg table's metadata. */ orderId: number; } interface CatalogTableOpenTableFormatInputIcebergInputIcebergTableInputSortOrderField { /** * Sort direction for this field. Valid values: `asc`, `desc`. */ direction: string; /** * Ordering behavior for null values in this field. Valid values: `nulls-first`, `nulls-last`. */ nullOrder: string; sourceId: number; transform: string; } interface CatalogTableOptimizerConfiguration { /** * The configuration block for a compaction optimizer. See Compaction Configuration for additional details. */ compactionConfiguration?: outputs.glue.CatalogTableOptimizerConfigurationCompactionConfiguration; /** * Indicates whether the table optimizer is enabled. */ enabled: boolean; /** * The configuration block for an orphan file deletion optimizer. See Orphan File Deletion Configuration for additional details. */ orphanFileDeletionConfiguration?: outputs.glue.CatalogTableOptimizerConfigurationOrphanFileDeletionConfiguration; /** * The configuration block for a snapshot retention optimizer. See Retention Configuration for additional details. */ retentionConfiguration?: outputs.glue.CatalogTableOptimizerConfigurationRetentionConfiguration; /** * The ARN of the IAM role to use for the table optimizer. */ roleArn: string; } interface CatalogTableOptimizerConfigurationCompactionConfiguration { /** * The configuration for an Iceberg compaction optimizer. */ icebergConfiguration?: outputs.glue.CatalogTableOptimizerConfigurationCompactionConfigurationIcebergConfiguration; } interface CatalogTableOptimizerConfigurationCompactionConfigurationIcebergConfiguration { /** * The minimum number of deletes that must be present in a data file to make it eligible for compaction. Defaults to `1`. */ deleteFileThreshold?: number; /** * The minimum number of data files that must be present in a partition before compaction will actually compact files. Defaults to `100`. */ minInputFiles?: number; /** * The strategy to use for compaction. Valid values are `binpack`, `sort` and `z-order` Defaults to `binpack`. */ strategy: string; } interface CatalogTableOptimizerConfigurationOrphanFileDeletionConfiguration { /** * The configuration for an Iceberg orphan file deletion optimizer. */ icebergConfiguration?: outputs.glue.CatalogTableOptimizerConfigurationOrphanFileDeletionConfigurationIcebergConfiguration; } interface CatalogTableOptimizerConfigurationOrphanFileDeletionConfigurationIcebergConfiguration { /** * Specifies a directory in which to look for files. You may choose a sub-directory rather than the top-level table location. Defaults to the table's location. */ location?: string; /** * The number of days that orphan files should be retained before file deletion. Defaults to `3`. */ orphanFileRetentionPeriodInDays?: number; /** * interval in hours between orphan file deletion job runs. Defaults to `24`. */ runRateInHours: number; } interface CatalogTableOptimizerConfigurationRetentionConfiguration { /** * The configuration for an Iceberg snapshot retention optimizer. */ icebergConfiguration?: outputs.glue.CatalogTableOptimizerConfigurationRetentionConfigurationIcebergConfiguration; } interface CatalogTableOptimizerConfigurationRetentionConfigurationIcebergConfiguration { /** * If set to `false`, snapshots are only deleted from table metadata, and the underlying data and metadata files are not deleted. Defaults to `false`. */ cleanExpiredFiles?: boolean; /** * The number of Iceberg snapshots to retain within the retention period. Defaults to `1` or the corresponding Iceberg table configuration field if it exists. */ numberOfSnapshotsToRetain?: number; /** * Interval in hours between retention job runs. Defaults to `24`. */ runRateInHours: number; /** * The number of days to retain the Iceberg snapshots. Defaults to `5`, or the corresponding Iceberg table configuration field if it exists. */ snapshotRetentionPeriodInDays?: number; } interface CatalogTablePartitionIndex { /** * Name of the partition index. */ indexName: string; indexStatus: string; /** * Keys for the partition index. */ keys: string[]; } interface CatalogTablePartitionKey { /** * Free-form text comment. */ comment?: string; /** * Name of the Partition Key. */ name: string; /** * Map of key-value pairs. */ parameters?: { [key: string]: string; }; /** * Datatype of data in the Partition Key. */ type?: string; } interface CatalogTableStorageDescriptor { /** * List of locations that point to the path where a Delta table is located. */ additionalLocations: string[]; /** * List of reducer grouping columns, clustering columns, and bucketing columns in the table. */ bucketColumns: string[]; /** * Configuration block for columns in the table. See `columns` below. */ columns: outputs.glue.CatalogTableStorageDescriptorColumn[]; /** * Whether the data in the table is compressed. */ compressed?: boolean; /** * Input format: SequenceFileInputFormat (binary), or TextInputFormat, or a custom format. */ inputFormat?: string; /** * Physical location of the table. By default this takes the form of the warehouse location, followed by the database location in the warehouse, followed by the table name. */ location?: string; /** * Must be specified if the table contains any dimension columns. */ numberOfBuckets?: number; /** * Output format: SequenceFileOutputFormat (binary), or IgnoreKeyTextOutputFormat, or a custom format. */ outputFormat?: string; /** * User-supplied properties in key-value form. */ parameters: { [key: string]: string; }; /** * Object that references a schema stored in the AWS Glue Schema Registry. When creating a table, you can pass an empty list of columns for the schema, and instead use a schema reference. See Schema Reference below. */ schemaReference?: outputs.glue.CatalogTableStorageDescriptorSchemaReference; /** * Configuration block for serialization and deserialization ("SerDe") information. See `serDeInfo` below. */ serDeInfo: outputs.glue.CatalogTableStorageDescriptorSerDeInfo; /** * Configuration block with information about values that appear very frequently in a column (skewed values). See `skewedInfo` below. */ skewedInfo?: outputs.glue.CatalogTableStorageDescriptorSkewedInfo; /** * Configuration block for the sort order of each bucket in the table. See `sortColumns` below. */ sortColumns?: outputs.glue.CatalogTableStorageDescriptorSortColumn[]; /** * Whether the table data is stored in subdirectories. */ storedAsSubDirectories?: boolean; } interface CatalogTableStorageDescriptorColumn { /** * Free-form text comment. */ comment?: string; /** * Name of the Column. */ name: string; /** * Key-value pairs defining properties associated with the column. */ parameters: { [key: string]: string; }; /** * Datatype of data in the Column. */ type?: string; } interface CatalogTableStorageDescriptorSchemaReference { /** * Configuration block that contains schema identity fields. Either this or the `schemaVersionId` has to be provided. See `schemaId` below. */ schemaId?: outputs.glue.CatalogTableStorageDescriptorSchemaReferenceSchemaId; /** * Unique ID assigned to a version of the schema. Either this or the `schemaId` has to be provided. */ schemaVersionId?: string; /** * Version number of the schema. */ schemaVersionNumber: number; } interface CatalogTableStorageDescriptorSchemaReferenceSchemaId { /** * Name of the schema registry that contains the schema. Must be provided when `schemaName` is specified and conflicts with `schemaArn`. */ registryName?: string; /** * ARN of the schema. One of `schemaArn` or `schemaName` has to be provided. */ schemaArn?: string; /** * Name of the schema. One of `schemaArn` or `schemaName` has to be provided. */ schemaName?: string; } interface CatalogTableStorageDescriptorSerDeInfo { /** * Name of the SerDe. */ name?: string; /** * Map of initialization parameters for the SerDe, in key-value form. */ parameters: { [key: string]: string; }; /** * Usually the class that implements the SerDe. An example is `org.apache.hadoop.hive.serde2.columnar.ColumnarSerDe`. */ serializationLibrary?: string; } interface CatalogTableStorageDescriptorSkewedInfo { /** * List of names of columns that contain skewed values. */ skewedColumnNames?: string[]; /** * List of values that appear so frequently as to be considered skewed. */ skewedColumnValueLocationMaps?: { [key: string]: string; }; /** * Map of skewed values to the columns that contain them. */ skewedColumnValues?: string[]; } interface CatalogTableStorageDescriptorSortColumn { /** * Name of the column. */ column: string; /** * Whether the column is sorted in ascending (`1`) or descending order (`0`). */ sortOrder: number; } interface CatalogTableTargetTable { /** * ID of the Data Catalog in which the table resides. */ catalogId: string; /** * Name of the catalog database that contains the target table. */ databaseName: string; /** * Name of the target table. */ name: string; /** * Region of the target table. */ region?: string; } interface CatalogTableViewDefinition { /** * Definer of a view in SQL. */ definer: string; /** * You can set this flag as true to instruct the engine not to push user-provided operations into the logical plan of the view during query planning. However, setting this flag does not guarantee that the engine will comply. Refer to the engine's documentation to understand the guarantees provided, if any. */ isProtected: boolean; /** * Type of the materialized view's last refresh. Valid values: `Full`, `Incremental`. */ lastRefreshType?: string; /** * Auto refresh interval in seconds for the materialized view. */ refreshSeconds?: number; /** * List of structures that contains the dialect of the view, and the query that defines the view. See `representations` below. */ representations?: outputs.glue.CatalogTableViewDefinitionRepresentation[]; /** * List of the Apache Iceberg table versions referenced by the materialized view. */ subObjectVersionIds: number[]; /** * List of base table ARNs that make up the view. */ subObjects: string[]; /** * ID value that identifies this view's version. For materialized views, the version ID is the Apache Iceberg table's snapshot ID. */ viewVersionId?: number; /** * Version ID of the Apache Iceberg table. */ viewVersionToken?: string; } interface CatalogTableViewDefinitionRepresentation { /** * Parameter that specifies the engine type of a specific representation. Valid values are `REDSHIFT`, `ATHENA`, and `SPARK`. */ dialect?: string; /** * Parameter that specifies the version of the engine of a specific representation. */ dialectVersion?: string; /** * Name of the connection to be used to validate the specific representation of the view. */ validationConnection: string; /** * String that represents the SQL query that describes the view with expanded resource ARNs. */ viewExpandedText: string; /** * String that represents the original SQL query that describes the view. */ viewOriginalText: string; } interface CatalogTargetRedshiftCatalog { /** * ARN of the target Redshift catalog. */ catalogArn: string; } interface CatalogTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ClassifierCsvClassifier { /** * Enables the processing of files that contain only one column. */ allowSingleColumn?: boolean; /** * Indicates whether the CSV file contains a header. This can be one of "ABSENT", "PRESENT", or "UNKNOWN". */ containsHeader?: string; /** * Enables the custom datatype to be configured. */ customDatatypeConfigured?: boolean; /** * A list of supported custom datatypes. Valid values are `BINARY`, `BOOLEAN`, `DATE`, `DECIMAL`, `DOUBLE`, `FLOAT`, `INT`, `LONG`, `SHORT`, `STRING`, `TIMESTAMP`. */ customDatatypes?: string[]; /** * The delimiter used in the CSV to separate columns. */ delimiter?: string; /** * Specifies whether to trim column values. */ disableValueTrimming?: boolean; /** * A list of strings representing column names. */ headers?: string[]; /** * A custom symbol to denote what combines content into a single column value. It must be different from the column delimiter. */ quoteSymbol?: string; /** * The SerDe for processing CSV. Valid values are `OpenCSVSerDe`, `LazySimpleSerDe`, `None`. */ serde: string; } interface ClassifierGrokClassifier { /** * An identifier of the data format that the classifier matches, such as Twitter, JSON, Omniture logs, Amazon CloudWatch Logs, and so on. */ classification: string; /** * Custom grok patterns used by this classifier. */ customPatterns?: string; /** * The grok pattern used by this classifier. */ grokPattern: string; } interface ClassifierJsonClassifier { /** * A `JsonPath` string defining the JSON data for the classifier to classify. AWS Glue supports a subset of `JsonPath`, as described in [Writing JsonPath Custom Classifiers](https://docs.aws.amazon.com/glue/latest/dg/custom-classifier.html#custom-classifier-json). */ jsonPath: string; } interface ClassifierXmlClassifier { /** * An identifier of the data format that the classifier matches. */ classification: string; /** * The XML tag designating the element that contains each record in an XML document being parsed. Note that this cannot identify a self-closing element (closed by `/>`). An empty row element that contains only attributes can be parsed as long as it ends with a closing tag (for example, `` is okay, but `` is not). */ rowTag: string; } interface ConnectionAuthenticationConfiguration { /** * Type of authentication. Valid values: `BASIC`, `CUSTOM`, `IAM`, `OAUTH2`. */ authenticationType: string; /** * Basic authentication credentials. See `basicAuthenticationCredentials` below. */ basicAuthenticationCredentials?: outputs.glue.ConnectionAuthenticationConfigurationBasicAuthenticationCredentials; /** * Map of custom authentication credentials. */ customAuthenticationCredentials?: { [key: string]: string; }; /** * ARN of the KMS key used for encryption. */ kmsKeyArn?: string; /** * OAuth2 properties. See `oauth2Properties` below. */ oauth2Properties?: outputs.glue.ConnectionAuthenticationConfigurationOauth2Properties; /** * ARN of the Secrets Manager secret containing credentials. */ secretArn?: string; } interface ConnectionAuthenticationConfigurationBasicAuthenticationCredentials { /** * Password for authentication. */ password: string; /** * Username for authentication. */ username: string; } interface ConnectionAuthenticationConfigurationOauth2Properties { /** * Authorization code properties. See `authorizationCodeProperties` below. */ authorizationCodeProperties?: outputs.glue.ConnectionAuthenticationConfigurationOauth2PropertiesAuthorizationCodeProperties; /** * OAuth2 client application details. See `oauth2ClientApplication` below. */ oauth2ClientApplication?: outputs.glue.ConnectionAuthenticationConfigurationOauth2PropertiesOauth2ClientApplication; /** * OAuth2 credentials. See `oauth2Credentials` below. */ oauth2Credentials?: outputs.glue.ConnectionAuthenticationConfigurationOauth2PropertiesOauth2Credentials; /** * OAuth2 grant type. Valid values: `AUTHORIZATION_CODE`, `CLIENT_CREDENTIALS`, `JWT_BEARER`. */ oauth2GrantType?: string; /** * Token URL for OAuth2 authentication. */ tokenUrl?: string; /** * Map of additional parameters for the token URL. */ tokenUrlParametersMap?: { [key: string]: string; }; } interface ConnectionAuthenticationConfigurationOauth2PropertiesAuthorizationCodeProperties { /** * Authorization code. */ authorizationCode: string; /** * Redirect URI for OAuth2 flow. */ redirectUri: string; } interface ConnectionAuthenticationConfigurationOauth2PropertiesOauth2ClientApplication { /** * Reference to an AWS-managed client application. */ awsManagedClientApplicationReference?: string; /** * Client ID for a user-managed client application. */ userManagedClientApplicationClientId?: string; } interface ConnectionAuthenticationConfigurationOauth2PropertiesOauth2Credentials { /** * OAuth2 access token. */ accessToken?: string; /** * JWT token. */ jwtToken?: string; /** * OAuth2 refresh token. */ refreshToken?: string; /** * Client secret for user-managed client application. */ userManagedClientApplicationClientSecret?: string; } interface ConnectionPhysicalConnectionRequirements { /** * Availability zone of the connection. This field is redundant and implied by `subnetId`, but is currently an API requirement. */ availabilityZone?: string; /** * Security group ID list used by the connection. */ securityGroupIdLists?: string[]; /** * Subnet ID used by the connection. */ subnetId?: string; } interface CrawlerCatalogTarget { /** * The name of the connection for an Amazon S3-backed Data Catalog table to be a target of the crawl when using a Catalog connection type paired with a `NETWORK` Connection type. */ connectionName?: string; /** * The name of the Glue database to be synchronized. */ databaseName: string; /** * A valid Amazon SQS ARN. * * > **Note:** `deletionBehavior` of catalog target doesn't support `DEPRECATE_IN_DATABASE`. * * > **Note:** `configuration` for catalog target crawlers will have `{ ... "Grouping": { "TableGroupingPolicy": "CombineCompatibleSchemas"} }` by default. */ dlqEventQueueArn?: string; /** * A valid Amazon SQS ARN. */ eventQueueArn?: string; /** * A list of catalog tables to be synchronized. */ tables: string[]; } interface CrawlerDeltaTarget { /** * The name of the connection to use to connect to the Delta table target. */ connectionName?: string; /** * Specifies whether the crawler will create native tables, to allow integration with query engines that support querying of the Delta transaction log directly. */ createNativeDeltaTable?: boolean; /** * A list of the Amazon S3 paths to the Delta tables. */ deltaTables: string[]; /** * Specifies whether to write the manifest files to the Delta table path. */ writeManifest: boolean; } interface CrawlerDynamodbTarget { /** * The name of the DynamoDB table to crawl. */ path: string; /** * Indicates whether to scan all the records, or to sample rows from the table. Scanning all the records can take a long time when the table is not a high throughput table. defaults to `true`. */ scanAll?: boolean; /** * The percentage of the configured read capacity units to use by the AWS Glue crawler. The valid values are null or a value between 0.1 to 1.5. */ scanRate?: number; } interface CrawlerHudiTarget { /** * The name of the connection to use to connect to the Hudi target. */ connectionName?: string; /** * A list of glob patterns used to exclude from the crawl. */ exclusions?: string[]; /** * The maximum depth of Amazon S3 paths that the crawler can traverse to discover the Hudi metadata folder in your Amazon S3 path. Used to limit the crawler run time. Valid values are between `1` and `20`. */ maximumTraversalDepth: number; /** * One or more Amazon S3 paths that contains Hudi metadata folders as s3://bucket/prefix. */ paths: string[]; } interface CrawlerIcebergTarget { /** * The name of the connection to use to connect to the Iceberg target. */ connectionName?: string; /** * A list of glob patterns used to exclude from the crawl. */ exclusions?: string[]; /** * The maximum depth of Amazon S3 paths that the crawler can traverse to discover the Iceberg metadata folder in your Amazon S3 path. Used to limit the crawler run time. Valid values are between `1` and `20`. */ maximumTraversalDepth: number; /** * One or more Amazon S3 paths that contains Iceberg metadata folders as s3://bucket/prefix. */ paths: string[]; } interface CrawlerJdbcTarget { /** * The name of the connection to use to connect to the JDBC target. */ connectionName: string; /** * Specify a value of `RAWTYPES` or `COMMENTS` to enable additional metadata intable responses. `RAWTYPES` provides the native-level datatype. `COMMENTS` provides comments associated with a column or table in the database. */ enableAdditionalMetadatas?: string[]; /** * A list of glob patterns used to exclude from the crawl. */ exclusions?: string[]; /** * The path of the JDBC target. */ path: string; } interface CrawlerLakeFormationConfiguration { /** * Required for cross account crawls. For same account crawls as the target data, this can omitted. */ accountId: string; /** * Specifies whether to use Lake Formation credentials for the crawler instead of the IAM role credentials. */ useLakeFormationCredentials?: boolean; } interface CrawlerLineageConfiguration { /** * Specifies whether data lineage is enabled for the crawler. Valid values are: `ENABLE` and `DISABLE`. Default value is `DISABLE`. */ crawlerLineageSettings?: string; } interface CrawlerMongodbTarget { /** * The name of the connection to use to connect to the Amazon DocumentDB or MongoDB target. */ connectionName: string; /** * The path of the Amazon DocumentDB or MongoDB target (database/collection). */ path: string; /** * Indicates whether to scan all the records, or to sample rows from the table. Scanning all the records can take a long time when the table is not a high throughput table. Default value is `true`. */ scanAll?: boolean; } interface CrawlerRecrawlPolicy { /** * Specifies whether to crawl the entire dataset again, crawl only folders that were added since the last crawler run, or crawl what S3 notifies the crawler of via SQS. Valid Values are: `CRAWL_EVENT_MODE`, `CRAWL_EVERYTHING` and `CRAWL_NEW_FOLDERS_ONLY`. Default value is `CRAWL_EVERYTHING`. */ recrawlBehavior?: string; } interface CrawlerS3Target { /** * The name of a connection which allows crawler to access data in S3 within a VPC. */ connectionName?: string; /** * The ARN of the dead-letter SQS queue. */ dlqEventQueueArn?: string; /** * The ARN of the SQS queue to receive S3 notifications from. */ eventQueueArn?: string; /** * A list of glob patterns used to exclude from the crawl. */ exclusions?: string[]; /** * The path to the Amazon S3 target. */ path: string; /** * Sets the number of files in each leaf folder to be crawled when crawling sample files in a dataset. If not set, all the files are crawled. A valid value is an integer between 1 and 249. */ sampleSize?: number; } interface CrawlerSchemaChangePolicy { /** * The deletion behavior when the crawler finds a deleted object. Valid values: `LOG`, `DELETE_FROM_DATABASE`, or `DEPRECATE_IN_DATABASE`. Defaults to `DEPRECATE_IN_DATABASE`. */ deleteBehavior?: string; /** * The update behavior when the crawler finds a changed schema. Valid values: `LOG` or `UPDATE_IN_DATABASE`. Defaults to `UPDATE_IN_DATABASE`. */ updateBehavior?: string; } interface DataCatalogEncryptionSettingsDataCatalogEncryptionSettings { /** * When connection password protection is enabled, the Data Catalog uses a customer-provided key to encrypt the password as part of CreateConnection or UpdateConnection and store it in the ENCRYPTED_PASSWORD field in the connection properties. You can enable catalog encryption or only password encryption. see Connection Password Encryption. */ connectionPasswordEncryption: outputs.glue.DataCatalogEncryptionSettingsDataCatalogEncryptionSettingsConnectionPasswordEncryption; /** * Specifies the encryption-at-rest configuration for the Data Catalog. see Encryption At Rest. */ encryptionAtRest: outputs.glue.DataCatalogEncryptionSettingsDataCatalogEncryptionSettingsEncryptionAtRest; } interface DataCatalogEncryptionSettingsDataCatalogEncryptionSettingsConnectionPasswordEncryption { /** * A KMS key ARN that is used to encrypt the connection password. If connection password protection is enabled, the caller of CreateConnection and UpdateConnection needs at least `kms:Encrypt` permission on the specified AWS KMS key, to encrypt passwords before storing them in the Data Catalog. */ awsKmsKeyId?: string; /** * When set to `true`, passwords remain encrypted in the responses of GetConnection and GetConnections. This encryption takes effect independently of the catalog encryption. */ returnConnectionPasswordEncrypted: boolean; } interface DataCatalogEncryptionSettingsDataCatalogEncryptionSettingsEncryptionAtRest { /** * The encryption-at-rest mode for encrypting Data Catalog data. Valid values: `DISABLED`, `SSE-KMS`, `SSE-KMS-WITH-SERVICE-ROLE`. */ catalogEncryptionMode: string; /** * The ARN of the AWS IAM role used for accessing encrypted Data Catalog data. */ catalogEncryptionServiceRole?: string; /** * The ARN of the AWS KMS key to use for encryption at rest. */ sseAwsKmsKeyId?: string; } interface DataQualityRulesetTargetTable { /** * The catalog id where the AWS Glue table exists. */ catalogId?: string; /** * Name of the database where the AWS Glue table exists. */ databaseName: string; /** * Name of the AWS Glue table. */ tableName: string; } interface GetCatalogCatalogProperty { /** * Map of custom key-value pairs for the catalog properties. */ customProperties: { [key: string]: string; }; /** * Data lake access properties. See `dataLakeAccessProperties` below. */ dataLakeAccessProperties: outputs.glue.GetCatalogCatalogPropertyDataLakeAccessProperty[]; /** * Iceberg optimization properties. See `icebergOptimizationProperties` below. */ icebergOptimizationProperties: outputs.glue.GetCatalogCatalogPropertyIcebergOptimizationProperty[]; } interface GetCatalogCatalogPropertyDataLakeAccessProperty { /** * Type of the catalog. */ catalogType: string; /** * Whether data lake access is enabled. */ dataLakeAccess: boolean; /** * ARN of the IAM role used for data transfer. */ dataTransferRole: string; /** * ARN of the KMS key used for encryption. */ kmsKey: string; /** * Managed workgroup name. */ managedWorkgroupName: string; /** * Managed workgroup status. */ managedWorkgroupStatus: string; /** * Redshift database name. */ redshiftDatabaseName: string; /** * Status message. */ statusMessage: string; } interface GetCatalogCatalogPropertyIcebergOptimizationProperty { compaction: { [key: string]: string; }; orphanFileDeletion: { [key: string]: string; }; retention: { [key: string]: string; }; roleArn: string; } interface GetCatalogCreateDatabaseDefaultPermission { /** * Permissions that are granted to the principal. */ permissions: string[]; /** * Principal who is granted permissions. See `principal` below. */ principals: outputs.glue.GetCatalogCreateDatabaseDefaultPermissionPrincipal[]; } interface GetCatalogCreateDatabaseDefaultPermissionPrincipal { /** * Identifier for the Lake Formation principal. */ dataLakePrincipalIdentifier: string; } interface GetCatalogCreateTableDefaultPermission { /** * Permissions that are granted to the principal. */ permissions: string[]; /** * Principal who is granted permissions. See `principal` below. */ principals: outputs.glue.GetCatalogCreateTableDefaultPermissionPrincipal[]; } interface GetCatalogCreateTableDefaultPermissionPrincipal { /** * Identifier for the Lake Formation principal. */ dataLakePrincipalIdentifier: string; } interface GetCatalogFederatedCatalog { /** * Name of the connection to the external metastore. */ connectionName: string; /** * Type of connection used to access the federated catalog. */ connectionType: string; /** * Unique identifier for the federated catalog. */ identifier: string; } interface GetCatalogTablePartitionIndex { /** * Name of the partition index. */ indexName: string; indexStatus: string; /** * Keys for the partition index. */ keys: string[]; } interface GetCatalogTablePartitionKey { /** * Free-form text comment. */ comment: string; /** * Name of the table. */ name: string; /** * Map of initialization parameters for the SerDe, in key-value form. */ parameters: { [key: string]: string; }; /** * Datatype of data in the Column. */ type: string; } interface GetCatalogTableStorageDescriptor { /** * List of locations that point to the path where a Delta table is located */ additionalLocations: string[]; /** * List of reducer grouping columns, clustering columns, and bucketing columns in the table. */ bucketColumns: string[]; /** * Configuration block for columns in the table. See `columns` below. */ columns: outputs.glue.GetCatalogTableStorageDescriptorColumn[]; /** * Whether the data in the table is compressed. */ compressed: boolean; /** * Input format: SequenceFileInputFormat (binary), or TextInputFormat, or a custom format. */ inputFormat: string; /** * Physical location of the table. By default, this takes the form of the warehouse location, followed by the database location in the warehouse, followed by the table name. */ location: string; /** * Is if the table contains any dimension columns. */ numberOfBuckets: number; /** * Output format: SequenceFileOutputFormat (binary), or IgnoreKeyTextOutputFormat, or a custom format. */ outputFormat: string; /** * Map of initialization parameters for the SerDe, in key-value form. */ parameters: { [key: string]: string; }; /** * Object that references a schema stored in the AWS Glue Schema Registry. See `schemaReference` below. */ schemaReferences: outputs.glue.GetCatalogTableStorageDescriptorSchemaReference[]; /** * Configuration block for serialization and deserialization ("SerDe") information. See `serDeInfo` below. */ serDeInfos: outputs.glue.GetCatalogTableStorageDescriptorSerDeInfo[]; /** * Configuration block with information about values that appear very frequently in a column (skewed values). See `skewedInfo` below. */ skewedInfos: outputs.glue.GetCatalogTableStorageDescriptorSkewedInfo[]; /** * Configuration block for the sort order of each bucket in the table. See `sortColumns` below. */ sortColumns: outputs.glue.GetCatalogTableStorageDescriptorSortColumn[]; /** * Whether the table data is stored in subdirectories. */ storedAsSubDirectories: boolean; } interface GetCatalogTableStorageDescriptorColumn { /** * Free-form text comment. */ comment: string; /** * Name of the table. */ name: string; /** * Map of initialization parameters for the SerDe, in key-value form. */ parameters: { [key: string]: string; }; /** * Datatype of data in the Column. */ type: string; } interface GetCatalogTableStorageDescriptorSchemaReference { /** * Configuration block that contains schema identity fields. See `schemaId` below. */ schemaIds: outputs.glue.GetCatalogTableStorageDescriptorSchemaReferenceSchemaId[]; /** * Unique ID assigned to a version of the schema. */ schemaVersionId: string; /** * Version number of the schema. */ schemaVersionNumber: number; } interface GetCatalogTableStorageDescriptorSchemaReferenceSchemaId { /** * Name of the schema registry that contains the schema. */ registryName: string; /** * ARN of the schema. */ schemaArn: string; /** * Name of the schema. */ schemaName: string; } interface GetCatalogTableStorageDescriptorSerDeInfo { /** * Name of the table. */ name: string; /** * Map of initialization parameters for the SerDe, in key-value form. */ parameters: { [key: string]: string; }; /** * Usually the class that implements the SerDe. An example is `org.apache.hadoop.hive.serde2.columnar.ColumnarSerDe`. */ serializationLibrary: string; } interface GetCatalogTableStorageDescriptorSkewedInfo { /** * List of names of columns that contain skewed values. */ skewedColumnNames: string[]; /** * List of values that appear so frequently as to be considered skewed. */ skewedColumnValueLocationMaps: { [key: string]: string; }; /** * Map of skewed values to the columns that contain them. */ skewedColumnValues: string[]; } interface GetCatalogTableStorageDescriptorSortColumn { /** * Name of the column. */ column: string; /** * Whether the column is sorted in ascending (`1`) or descending order (`0`). */ sortOrder: number; } interface GetCatalogTableTargetTable { /** * ID of the Glue Catalog and database where the table metadata resides. If omitted, this defaults to the current AWS Account ID. */ catalogId: string; /** * Name of the metadata database where the table metadata resides. */ databaseName: string; /** * Name of the table. */ name: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface GetCatalogTargetRedshiftCatalog { /** * ARN of the target Redshift catalog. */ catalogArn: string; } interface GetConnectionAuthenticationConfiguration { /** * Type of authentication used for the connection. */ authenticationType: string; /** * Basic authentication credentials. See `basicAuthenticationCredentials` Block for details. */ basicAuthenticationCredentials: outputs.glue.GetConnectionAuthenticationConfigurationBasicAuthenticationCredential[]; /** * Map of credentials used when the authentication type is custom authentication. */ customAuthenticationCredentials: { [key: string]: string; }; /** * ARN of the KMS key used to encrypt the connection. */ kmsKeyArn: string; /** * OAuth2 properties. See `oauth2Properties` Block for details. */ oauth2Properties: outputs.glue.GetConnectionAuthenticationConfigurationOauth2Property[]; /** * ARN of the secret used for authentication. */ secretArn: string; } interface GetConnectionAuthenticationConfigurationBasicAuthenticationCredential { /** * Password used for basic authentication. */ password: string; /** * Username used for basic authentication. */ username: string; } interface GetConnectionAuthenticationConfigurationOauth2Property { /** * Authorization code properties. See `authorizationCodeProperties` Block for details. */ authorizationCodeProperties: outputs.glue.GetConnectionAuthenticationConfigurationOauth2PropertyAuthorizationCodeProperty[]; /** * OAuth2 client application. See `oauth2ClientApplication` Block for details. */ oauth2ClientApplications: outputs.glue.GetConnectionAuthenticationConfigurationOauth2PropertyOauth2ClientApplication[]; /** * OAuth2 credentials. See `oauth2Credentials` Block for details. */ oauth2Credentials: outputs.glue.GetConnectionAuthenticationConfigurationOauth2PropertyOauth2Credential[]; /** * OAuth2 grant type. */ oauth2GrantType: string; /** * URL of the provider's authentication server used to exchange an authorization code for an access token. */ tokenUrl: string; /** * Map of parameters to add to the token request. */ tokenUrlParametersMap: { [key: string]: string; }; } interface GetConnectionAuthenticationConfigurationOauth2PropertyAuthorizationCodeProperty { /** * Authorization code used to obtain an access token. */ authorizationCode: string; /** * Redirect URI used in the authorization code request. */ redirectUri: string; } interface GetConnectionAuthenticationConfigurationOauth2PropertyOauth2ClientApplication { /** * Reference to the AWS managed client application. */ awsManagedClientApplicationReference: string; /** * Client ID of the user-managed client application. */ userManagedClientApplicationClientId: string; } interface GetConnectionAuthenticationConfigurationOauth2PropertyOauth2Credential { /** * Access token used for OAuth2 authentication. */ accessToken: string; /** * JWT token used for OAuth2 authentication. */ jwtToken: string; /** * Refresh token used for OAuth2 authentication. */ refreshToken: string; /** * Client secret of the user-managed client application. */ userManagedClientApplicationClientSecret: string; } interface GetConnectionPhysicalConnectionRequirement { /** * Availability Zone used by the connection. */ availabilityZone: string; /** * List of security group IDs used by the connection. */ securityGroupIdLists: string[]; /** * Subnet ID used by the connection. */ subnetId: string; } interface GetDataCatalogEncryptionSettingsDataCatalogEncryptionSetting { /** * When connection password protection is enabled, the Data Catalog uses a customer-provided key to encrypt the password as part of CreateConnection or UpdateConnection and store it in the ENCRYPTED_PASSWORD field in the connection properties. You can enable catalog encryption or only password encryption. see Connection Password Encryption. */ connectionPasswordEncryptions: outputs.glue.GetDataCatalogEncryptionSettingsDataCatalogEncryptionSettingConnectionPasswordEncryption[]; /** * Encryption-at-rest configuration for the Data Catalog. see Encryption At Rest. */ encryptionAtRests: outputs.glue.GetDataCatalogEncryptionSettingsDataCatalogEncryptionSettingEncryptionAtRest[]; } interface GetDataCatalogEncryptionSettingsDataCatalogEncryptionSettingConnectionPasswordEncryption { /** * KMS key ARN that is used to encrypt the connection password. */ awsKmsKeyId: string; /** * When set to `true`, passwords remain encrypted in the responses of GetConnection and GetConnections. This encryption takes effect independently of the catalog encryption. */ returnConnectionPasswordEncrypted: boolean; } interface GetDataCatalogEncryptionSettingsDataCatalogEncryptionSettingEncryptionAtRest { /** * The encryption-at-rest mode for encrypting Data Catalog data. */ catalogEncryptionMode: string; /** * The ARN of the AWS IAM role used for accessing encrypted Data Catalog data. */ catalogEncryptionServiceRole: string; /** * ARN of the AWS KMS key to use for encryption at rest. */ sseAwsKmsKeyId: string; } interface GetScriptDagEdge { /** * ID of the node at which the edge starts. */ source: string; /** * ID of the node at which the edge ends. */ target: string; /** * Target of the edge. */ targetParameter?: string; } interface GetScriptDagNode { /** * Nested configuration an argument or property of a node. Defined below. */ args: outputs.glue.GetScriptDagNodeArg[]; /** * Node identifier that is unique within the node's graph. */ id: string; /** * Line number of the node. */ lineNumber?: number; /** * Type of node this is. */ nodeType: string; } interface GetScriptDagNodeArg { /** * Name of the argument or property. */ name: string; /** * Boolean if the value is used as a parameter. Defaults to `false`. */ param?: boolean; /** * Value of the argument or property. */ value: string; } interface JobCommand { /** * The name of the job command. Defaults to `glueetl`. Use `pythonshell` for Python Shell Job Type, `glueray` for Ray Job Type, or `gluestreaming` for Streaming Job Type. `maxCapacity` needs to be set if `pythonshell` is chosen. */ name?: string; /** * The Python version being used to execute a Python shell job. Allowed values are 2, 3 or 3.9. Version 3 refers to Python 3.11 when `glueVersion` is set to 5.0. */ pythonVersion: string; /** * In Ray jobs, runtime is used to specify the versions of Ray, Python and additional libraries available in your environment. This field is not used in other job types. For supported runtime environment values, see [Working with Ray jobs](https://docs.aws.amazon.com/glue/latest/dg/ray-jobs-section.html#author-job-ray-runtimes) in the Glue Developer Guide. */ runtime: string; /** * Specifies the S3 path to a script that executes a job. */ scriptLocation: string; } interface JobExecutionProperty { /** * The maximum number of concurrent runs allowed for a job. The default is 1. */ maxConcurrentRuns?: number; } interface JobNotificationProperty { /** * After a job run starts, the number of minutes to wait before sending a job run delay notification. */ notifyDelayAfter?: number; } interface JobSourceControlDetails { /** * The type of authentication, which can be an authentication token stored in Amazon Web Services Secrets Manager, or a personal access token. Valid values are: `PERSONAL_ACCESS_TOKEN` and `AWS_SECRETS_MANAGER`. */ authStrategy?: string; /** * The value of an authorization token. */ authToken?: string; /** * A branch in the remote repository. */ branch?: string; /** * A folder in the remote repository. */ folder?: string; /** * The last commit ID for a commit in the remote repository. */ lastCommitId?: string; /** * The owner of the remote repository that contains the job artifacts. */ owner?: string; /** * The provider for the remote repository. Valid values are: `GITHUB`, `GITLAB`, `BITBUCKET`, and `AWS_CODE_COMMIT`. */ provider?: string; /** * The name of the remote repository that contains the job artifacts. */ repository?: string; } interface MLTransformInputRecordTable { /** * A unique identifier for the AWS Glue Data Catalog. */ catalogId?: string; /** * The name of the connection to the AWS Glue Data Catalog. */ connectionName?: string; /** * A database name in the AWS Glue Data Catalog. */ databaseName: string; /** * A table name in the AWS Glue Data Catalog. */ tableName: string; } interface MLTransformParameters { /** * The parameters for the find matches algorithm. see Find Matches Parameters. */ findMatchesParameters: outputs.glue.MLTransformParametersFindMatchesParameters; /** * The type of machine learning transform. For information about the types of machine learning transforms, see [Creating Machine Learning Transforms](http://docs.aws.amazon.com/glue/latest/dg/add-job-machine-learning-transform.html). */ transformType: string; } interface MLTransformParametersFindMatchesParameters { /** * The value that is selected when tuning your transform for a balance between accuracy and cost. */ accuracyCostTradeOff?: number; /** * The value to switch on or off to force the output to match the provided labels from users. */ enforceProvidedLabels?: boolean; /** * The value selected when tuning your transform for a balance between precision and recall. */ precisionRecallTradeOff?: number; /** * The name of a column that uniquely identifies rows in the source table. */ primaryKeyColumnName?: string; } interface MLTransformSchema { /** * The type of data in the column. */ dataType: string; /** * The name you assign to this ML Transform. It must be unique in your account. */ name: string; } interface PartitionIndexPartitionIndex { /** * Name of the partition index. */ indexName?: string; indexStatus: string; /** * Keys for the partition index. */ keys?: string[]; } interface PartitionStorageDescriptor { /** * List of locations that point to the path where a Delta table is located. */ additionalLocations?: string[]; /** * A list of reducer grouping columns, clustering columns, and bucketing columns in the table. */ bucketColumns?: string[]; /** * A list of the Columns in the table. */ columns?: outputs.glue.PartitionStorageDescriptorColumn[]; /** * True if the data in the table is compressed, or False if not. */ compressed?: boolean; /** * The input format: SequenceFileInputFormat (binary), or TextInputFormat, or a custom format. */ inputFormat?: string; /** * The physical location of the table. By default this takes the form of the warehouse location, followed by the database location in the warehouse, followed by the table name. */ location?: string; /** * Must be specified if the table contains any dimension columns. */ numberOfBuckets?: number; /** * The output format: SequenceFileOutputFormat (binary), or IgnoreKeyTextOutputFormat, or a custom format. */ outputFormat?: string; /** * User-supplied properties in key-value form. */ parameters?: { [key: string]: string; }; /** * Serialization/deserialization (SerDe) information. */ serDeInfo?: outputs.glue.PartitionStorageDescriptorSerDeInfo; /** * Information about values that appear very frequently in a column (skewed values). */ skewedInfo?: outputs.glue.PartitionStorageDescriptorSkewedInfo; /** * A list of Order objects specifying the sort order of each bucket in the table. */ sortColumns?: outputs.glue.PartitionStorageDescriptorSortColumn[]; /** * True if the table data is stored in subdirectories, or False if not. */ storedAsSubDirectories?: boolean; } interface PartitionStorageDescriptorColumn { /** * Free-form text comment. */ comment?: string; name: string; /** * The datatype of data in the Column. */ type?: string; } interface PartitionStorageDescriptorSerDeInfo { /** * Name of the SerDe. */ name?: string; /** * A map of initialization parameters for the SerDe, in key-value form. */ parameters?: { [key: string]: string; }; /** * Usually the class that implements the SerDe. An example is: org.apache.hadoop.hive.serde2.columnar.ColumnarSerDe. */ serializationLibrary?: string; } interface PartitionStorageDescriptorSkewedInfo { /** * A list of names of columns that contain skewed values. */ skewedColumnNames?: string[]; /** * A list of values that appear so frequently as to be considered skewed. */ skewedColumnValueLocationMaps?: { [key: string]: string; }; /** * A map of skewed values to the columns that contain them. */ skewedColumnValues?: string[]; } interface PartitionStorageDescriptorSortColumn { /** * The name of the column. */ column: string; /** * Indicates that the column is sorted in ascending order (== 1), or in descending order (==0). */ sortOrder: number; } interface SecurityConfigurationEncryptionConfiguration { cloudwatchEncryption: outputs.glue.SecurityConfigurationEncryptionConfigurationCloudwatchEncryption; jobBookmarksEncryption: outputs.glue.SecurityConfigurationEncryptionConfigurationJobBookmarksEncryption; /** * A ` s3Encryption ` block as described below, which contains encryption configuration for S3 data. */ s3Encryption: outputs.glue.SecurityConfigurationEncryptionConfigurationS3Encryption; } interface SecurityConfigurationEncryptionConfigurationCloudwatchEncryption { /** * Encryption mode to use for CloudWatch data. Valid values: `DISABLED`, `SSE-KMS`. Default value: `DISABLED`. */ cloudwatchEncryptionMode?: string; /** * ARN of the KMS key to be used to encrypt the data. */ kmsKeyArn?: string; } interface SecurityConfigurationEncryptionConfigurationJobBookmarksEncryption { /** * Encryption mode to use for job bookmarks data. Valid values: `CSE-KMS`, `DISABLED`. Default value: `DISABLED`. */ jobBookmarksEncryptionMode?: string; /** * ARN of the KMS key to be used to encrypt the data. */ kmsKeyArn?: string; } interface SecurityConfigurationEncryptionConfigurationS3Encryption { /** * ARN of the KMS key to be used to encrypt the data. */ kmsKeyArn?: string; /** * Encryption mode to use for S3 data. Valid values: `DISABLED`, `SSE-KMS`, `SSE-S3`. Default value: `DISABLED`. */ s3EncryptionMode?: string; } interface TriggerAction { /** * Arguments to be passed to the job. You can specify arguments here that your own job-execution script consumes, as well as arguments that AWS Glue itself consumes. */ arguments?: { [key: string]: string; }; /** * The name of the crawler to be executed. Conflicts with `jobName`. */ crawlerName?: string; /** * The name of a job to be executed. Conflicts with `crawlerName`. */ jobName?: string; /** * Specifies configuration properties of a job run notification. See Notification Property details below. */ notificationProperty?: outputs.glue.TriggerActionNotificationProperty; /** * The name of the Security Configuration structure to be used with this action. */ securityConfiguration?: string; /** * The job run timeout in minutes. It overrides the timeout value of the job. */ timeout?: number; } interface TriggerActionNotificationProperty { /** * After a job run starts, the number of minutes to wait before sending a job run delay notification. */ notifyDelayAfter?: number; } interface TriggerEventBatchingCondition { /** * Number of events that must be received from Amazon EventBridge before EventBridge event trigger fires. */ batchSize: number; /** * Window of time in seconds after which EventBridge event trigger fires. Window starts when first event is received. Default value is `900`. */ batchWindow?: number; } interface TriggerPredicate { /** * A list of the conditions that determine when the trigger will fire. See Conditions. */ conditions: outputs.glue.TriggerPredicateCondition[]; /** * How to handle multiple conditions. Defaults to `AND`. Valid values are `AND` or `ANY`. */ logical?: string; } interface TriggerPredicateCondition { /** * The condition crawl state. Currently, the values supported are `RUNNING`, `SUCCEEDED`, `CANCELLED`, and `FAILED`. If this is specified, `crawlerName` must also be specified. Conflicts with `state`. */ crawlState?: string; /** * The name of the crawler to watch. If this is specified, `crawlState` must also be specified. Conflicts with `jobName`. */ crawlerName?: string; /** * The name of the job to watch. If this is specified, `state` must also be specified. Conflicts with `crawlerName`. */ jobName?: string; /** * A logical operator. Defaults to `EQUALS`. */ logicalOperator?: string; /** * The condition job state. Currently, the values supported are `SUCCEEDED`, `STOPPED`, `TIMEOUT` and `FAILED`. If this is specified, `jobName` must also be specified. Conflicts with `crawlerState`. */ state?: string; } interface UserDefinedFunctionResourceUri { /** * The type of the resource. can be one of `JAR`, `FILE`, and `ARCHIVE`. */ resourceType: string; /** * The URI for accessing the resource. */ uri: string; } } export declare namespace grafana { interface WorkspaceNetworkAccessControl { /** * An array of prefix list IDs. */ prefixListIds: string[]; /** * An array of Amazon VPC endpoint IDs for the workspace. The only VPC endpoints that can be specified here are interface VPC endpoints for Grafana workspaces (using the com.amazonaws.[region].grafana-workspace service endpoint). Other VPC endpoints will be ignored. */ vpceIds: string[]; } interface WorkspaceVpcConfiguration { /** * The list of Amazon EC2 security group IDs attached to the Amazon VPC for your Grafana workspace to connect. */ securityGroupIds: string[]; /** * The list of Amazon EC2 subnet IDs created in the Amazon VPC for your Grafana workspace to connect. */ subnetIds: string[]; } } export declare namespace guardduty { interface DetectorDatasources { /** * Configures [Kubernetes protection](https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html). * See Kubernetes and Kubernetes Audit Logs below for more details. */ kubernetes: outputs.guardduty.DetectorDatasourcesKubernetes; /** * Configures [Malware Protection](https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html). * See Malware Protection, Scan EC2 instance with findings and EBS volumes below for more details. */ malwareProtection: outputs.guardduty.DetectorDatasourcesMalwareProtection; /** * Configures [S3 protection](https://docs.aws.amazon.com/guardduty/latest/ug/s3-protection.html). * See S3 Logs below for more details. */ s3Logs: outputs.guardduty.DetectorDatasourcesS3Logs; } interface DetectorDatasourcesKubernetes { /** * Configures Kubernetes audit logs as a data source for [Kubernetes protection](https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html). * See Kubernetes Audit Logs below for more details. */ auditLogs: outputs.guardduty.DetectorDatasourcesKubernetesAuditLogs; } interface DetectorDatasourcesKubernetesAuditLogs { /** * If true, enables Kubernetes audit logs as a data source for [Kubernetes protection](https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html). * Defaults to `true`. */ enable: boolean; } interface DetectorDatasourcesMalwareProtection { /** * Configure whether [Malware Protection](https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html) is enabled as data source for EC2 instances with findings for the detector. * See Scan EC2 instance with findings below for more details. */ scanEc2InstanceWithFindings: outputs.guardduty.DetectorDatasourcesMalwareProtectionScanEc2InstanceWithFindings; } interface DetectorDatasourcesMalwareProtectionScanEc2InstanceWithFindings { /** * Configure whether scanning EBS volumes is enabled as data source for the detector for instances with findings. * See EBS volumes below for more details. */ ebsVolumes: outputs.guardduty.DetectorDatasourcesMalwareProtectionScanEc2InstanceWithFindingsEbsVolumes; } interface DetectorDatasourcesMalwareProtectionScanEc2InstanceWithFindingsEbsVolumes { /** * If true, enables [Malware Protection](https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html) as data source for the detector. * Defaults to `true`. */ enable: boolean; } interface DetectorDatasourcesS3Logs { /** * If true, enables [S3 protection](https://docs.aws.amazon.com/guardduty/latest/ug/s3-protection.html). * Defaults to `true`. */ enable: boolean; } interface DetectorFeatureAdditionalConfiguration { /** * The name of the additional configuration for a feature. Valid values: `EKS_ADDON_MANAGEMENT`, `ECS_FARGATE_AGENT_MANAGEMENT`, `EC2_AGENT_MANAGEMENT`. Refer to the [AWS Documentation](https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DetectorAdditionalConfiguration.html) for the current list of supported values. */ name: string; /** * The status of the additional configuration. Valid values: `ENABLED`, `DISABLED`. */ status: string; } interface FilterFindingCriteria { criterions: outputs.guardduty.FilterFindingCriteriaCriterion[]; } interface FilterFindingCriteriaCriterion { /** * List of string values to be evaluated. */ equals?: string[]; /** * The name of the field to be evaluated. The full list of field names can be found in [AWS documentation](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_filter-findings.html#filter_criteria). */ field: string; /** * A value to be evaluated. Accepts either an integer given as a string (i.e., enclosed in quotations) or a date in [RFC 3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ greaterThan?: string; /** * A value to be evaluated. Accepts either an integer given as a string (i.e., enclosed in quotations) or a date in [RFC 3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ greaterThanOrEqual?: string; /** * A value to be evaluated. Accepts either an integer given as a string (i.e., enclosed in quotations) or a date in [RFC 3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ lessThan?: string; /** * A value to be evaluated. Accepts either an integer given as a string (i.e., enclosed in quotations) or a date in [RFC 3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ lessThanOrEqual?: string; /** * List of string values to be evaluated as matching conditions. */ matches?: string[]; /** * List of string values to be evaluated. */ notEquals?: string[]; /** * List of string values to be evaluated as non-matching conditions. */ notMatches?: string[]; } interface GetDetectorFeature { /** * Additional feature configuration. */ additionalConfigurations: outputs.guardduty.GetDetectorFeatureAdditionalConfiguration[]; /** * The name of the detector feature. */ name: string; /** * Current status of the detector. */ status: string; } interface GetDetectorFeatureAdditionalConfiguration { /** * The name of the detector feature. */ name: string; /** * Current status of the detector. */ status: string; } interface MalwareProtectionPlanAction { /** * Indicates whether the scanned S3 object will have tags about the scan result. See `tagging` below. */ taggings: outputs.guardduty.MalwareProtectionPlanActionTagging[]; } interface MalwareProtectionPlanActionTagging { /** * Indicates whether or not the tags will added. Valid values are `DISABLED` and `ENABLED`. Defaults to `DISABLED` */ status: string; } interface MalwareProtectionPlanProtectedResource { /** * Information about the protected S3 bucket resource. See `s3Bucket` below. */ s3Bucket: outputs.guardduty.MalwareProtectionPlanProtectedResourceS3Bucket; } interface MalwareProtectionPlanProtectedResourceS3Bucket { /** * Name of the S3 bucket. */ bucketName: string; /** * The list of object prefixes that specify the S3 objects that will be scanned. */ objectPrefixes: string[]; } interface MemberDetectorFeatureAdditionalConfiguration { /** * The name of the additional configuration. Valid values: `EKS_ADDON_MANAGEMENT`, `ECS_FARGATE_AGENT_MANAGEMENT`. */ name: string; /** * The status of the additional configuration. Valid values: `ENABLED`, `DISABLED`. */ status: string; } interface OrganizationConfigurationDatasources { /** * Enable Kubernetes Audit Logs Monitoring automatically for new member accounts. */ kubernetes: outputs.guardduty.OrganizationConfigurationDatasourcesKubernetes; /** * Enable Malware Protection automatically for new member accounts. */ malwareProtection: outputs.guardduty.OrganizationConfigurationDatasourcesMalwareProtection; /** * Enable S3 Protection automatically for new member accounts. */ s3Logs: outputs.guardduty.OrganizationConfigurationDatasourcesS3Logs; } interface OrganizationConfigurationDatasourcesKubernetes { /** * Enable Kubernetes Audit Logs Monitoring automatically for new member accounts. [Kubernetes protection](https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html). * See Kubernetes Audit Logs below for more details. */ auditLogs: outputs.guardduty.OrganizationConfigurationDatasourcesKubernetesAuditLogs; } interface OrganizationConfigurationDatasourcesKubernetesAuditLogs { /** * If true, enables Kubernetes audit logs as a data source for [Kubernetes protection](https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html). * Defaults to `true`. */ enable: boolean; } interface OrganizationConfigurationDatasourcesMalwareProtection { /** * Configure whether [Malware Protection](https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html) for EC2 instances with findings should be auto-enabled for new members joining the organization. * See Scan EC2 instance with findings below for more details. */ scanEc2InstanceWithFindings: outputs.guardduty.OrganizationConfigurationDatasourcesMalwareProtectionScanEc2InstanceWithFindings; } interface OrganizationConfigurationDatasourcesMalwareProtectionScanEc2InstanceWithFindings { /** * Configure whether scanning EBS volumes should be auto-enabled for new members joining the organization * See EBS volumes below for more details. */ ebsVolumes: outputs.guardduty.OrganizationConfigurationDatasourcesMalwareProtectionScanEc2InstanceWithFindingsEbsVolumes; } interface OrganizationConfigurationDatasourcesMalwareProtectionScanEc2InstanceWithFindingsEbsVolumes { /** * If true, enables [Malware Protection](https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html) for all new accounts joining the organization. * Defaults to `true`. */ autoEnable: boolean; } interface OrganizationConfigurationDatasourcesS3Logs { /** * Set to `true` if you want S3 data event logs to be automatically enabled for new members of the organization. Default: `false` */ autoEnable: boolean; } interface OrganizationConfigurationFeatureAdditionalConfiguration { /** * The status of the additional configuration that will be configured for the organization. Valid values: `NEW`, `ALL`, `NONE`. */ autoEnable: string; /** * The name of the additional configuration for a feature that will be configured for the organization. Valid values: `EKS_ADDON_MANAGEMENT`, `ECS_FARGATE_AGENT_MANAGEMENT`, `EC2_AGENT_MANAGEMENT`. Refer to the [AWS Documentation](https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DetectorAdditionalConfiguration.html) for the current list of supported values. */ name: string; } } export declare namespace iam { interface GetAccessKeysAccessKey { /** * Access key ID. */ accessKeyId: string; /** * Date and time in [RFC3339 format](https://tools.ietf.org/html/rfc3339#section-5.8) that the access key was created. */ createDate: string; /** * Access key status. Possible values are `Active` and `Inactive`. */ status: string; } interface GetGroupUser { /** * User ARN. */ arn: string; /** * Path to the IAM user. */ path: string; /** * Stable and unique string identifying the IAM user. */ userId: string; /** * Name of the IAM user. */ userName: string; } interface GetPolicyDocumentStatement { /** * List of actions that this statement either allows or denies. For example, `["ec2:RunInstances", "s3:*"]`. */ actions?: string[]; /** * Configuration block for a condition. Detailed below. */ conditions?: outputs.iam.GetPolicyDocumentStatementCondition[]; /** * Whether this statement allows or denies the given actions. Valid values are `Allow` and `Deny`. Defaults to `Allow`. */ effect?: string; /** * List of actions that this statement does *not* apply to. Use to apply a policy statement to all actions *except* those listed. */ notActions?: string[]; /** * Like `principals` except these are principals that the statement does *not* apply to. */ notPrincipals?: outputs.iam.GetPolicyDocumentStatementNotPrincipal[]; /** * List of resource ARNs that this statement does *not* apply to. Use to apply a policy statement to all resources *except* those listed. Conflicts with `resources`. */ notResources?: string[]; /** * Configuration block for principals. Detailed below. */ principals?: outputs.iam.GetPolicyDocumentStatementPrincipal[]; /** * List of resource ARNs that this statement applies to. This is required by AWS if used for an IAM policy. Conflicts with `notResources`. */ resources?: string[]; /** * Sid (statement ID) is an identifier for a policy statement. */ sid?: string; } interface GetPolicyDocumentStatementCondition { /** * Name of the [IAM condition operator](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html) to evaluate. */ test: string; /** * Values to evaluate the condition against. If multiple values are provided, the condition matches if at least one of them applies. That is, AWS evaluates multiple values as though using an "OR" boolean operation. */ values: string[]; /** * Name of a [Context Variable](http://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements.html#AvailableKeys) to apply the condition to. Context variables may either be standard AWS variables starting with `aws:` or service-specific variables prefixed with the service name. */ variable: string; } interface GetPolicyDocumentStatementNotPrincipal { /** * List of identifiers for principals. When `type` is `AWS`, these are IAM principal ARNs, e.g., `arn:aws:iam::12345678901:role/yak-role`. When `type` is `Service`, these are AWS Service roles, e.g., `lambda.amazonaws.com`. When `type` is `Federated`, these are web identity users or SAML provider ARNs, e.g., `accounts.google.com` or `arn:aws:iam::12345678901:saml-provider/yak-saml-provider`. When `type` is `CanonicalUser`, these are [canonical user IDs](https://docs.aws.amazon.com/general/latest/gr/acct-identifiers.html#FindingCanonicalId), e.g., `79a59df900b949e55d96a1e698fbacedfd6e09d98eacf8f8d5218e7cd47ef2be`. */ identifiers: string[]; /** * Type of principal. Valid values include `AWS`, `Service`, `Federated`, `CanonicalUser` and `*`. */ type: string; } interface GetPolicyDocumentStatementPrincipal { /** * List of identifiers for principals. When `type` is `AWS`, these are IAM principal ARNs, e.g., `arn:aws:iam::12345678901:role/yak-role`. When `type` is `Service`, these are AWS Service roles, e.g., `lambda.amazonaws.com`. When `type` is `Federated`, these are web identity users or SAML provider ARNs, e.g., `accounts.google.com` or `arn:aws:iam::12345678901:saml-provider/yak-saml-provider`. When `type` is `CanonicalUser`, these are [canonical user IDs](https://docs.aws.amazon.com/general/latest/gr/acct-identifiers.html#FindingCanonicalId), e.g., `79a59df900b949e55d96a1e698fbacedfd6e09d98eacf8f8d5218e7cd47ef2be`. */ identifiers: string[]; /** * Type of principal. Valid values include `AWS`, `Service`, `Federated`, `CanonicalUser` and `*`. */ type: string; } interface GetPrincipalPolicySimulationContext { /** * The context _condition key_ to set. * * If you have policies containing `Condition` elements or using dynamic interpolations then you will need to provide suitable values for each condition key your policies use. See [Actions, resources, and condition keys for AWS services](https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html) to find the various condition keys that are normally provided for real requests to each action of each AWS service. */ key: string; /** * An IAM value type that determines how the policy simulator will interpret the strings given in `values`. * * For more information, see the `ContextKeyType` field of [`iam.ContextEntry`](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ContextEntry.html) in the underlying API. */ type: string; /** * A set of one or more values for this context entry. */ values: string[]; } interface GetPrincipalPolicySimulationResult { /** * The name of the single IAM action used for this particular request. */ actionName: string; /** * `true` if `decision` is "allowed", and `false` otherwise. */ allowed: boolean; /** * The raw decision determined from all of the policies in scope; either "allowed", "explicitDeny", or "implicitDeny". */ decision: string; /** * A map of arbitrary metadata entries returned by the policy simulator for this request. */ decisionDetails: { [key: string]: string; }; /** * A nested set of objects describing which policies contained statements that were relevant to this simulation request. Each object has attributes `sourcePolicyId` and `sourcePolicyType` to identify one of the policies. */ matchedStatements: outputs.iam.GetPrincipalPolicySimulationResultMatchedStatement[]; /** * A set of context keys (or condition keys) that were needed by some of the policies contributing to this result but not specified using a `context` block in the configuration. Missing or incorrect context keys will typically cause a simulated request to be disallowed. */ missingContextKeys: string[]; /** * ARN of the resource that was used for this particular request. When you specify multiple actions and multiple resource ARNs, that causes a separate policy request for each combination of unique action and resource. */ resourceArn: string; } interface GetPrincipalPolicySimulationResultMatchedStatement { /** * Identifier of one of the policies used as input to the simulation. */ sourcePolicyId: string; /** * The type of the policy identified in source_policy_id. */ sourcePolicyType: string; } interface GetRolePolicyAttachmentsAttachedPolicy { /** * ARN of the attached managed policy. */ policyArn: string; /** * Name of the attached managed policy. */ policyName: string; } interface GetRoleRoleLastUsed { /** * The date and time, in RFC 3339 format, that the role was last used. */ lastUsedDate: string; /** * The name of the AWS Region in which the role was last used. */ region: string; } interface RoleInlinePolicy { /** * Name of the role policy. */ name: string; /** * Policy document as a JSON formatted string. */ policy?: string; } } export declare namespace identitystore { interface GetGroupAlternateIdentifier { /** * Configuration block for filtering by the identifier issued by an external identity provider. Detailed below. */ externalId?: outputs.identitystore.GetGroupAlternateIdentifierExternalId; /** * An entity attribute that's unique to a specific entity. Detailed below. * * > Exactly one of the above arguments must be provided. */ uniqueAttribute?: outputs.identitystore.GetGroupAlternateIdentifierUniqueAttribute; } interface GetGroupAlternateIdentifierExternalId { /** * The identifier issued to this resource by an external identity provider. */ id: string; /** * The issuer for an external identifier. */ issuer: string; } interface GetGroupAlternateIdentifierUniqueAttribute { /** * Attribute path that is used to specify which attribute name to search. For example: `DisplayName`. Refer to the [Group data type](https://docs.aws.amazon.com/singlesignon/latest/IdentityStoreAPIReference/API_Group.html). */ attributePath: string; /** * Value for an attribute. */ attributeValue: string; } interface GetGroupExternalId { /** * The identifier issued to this resource by an external identity provider. */ id: string; /** * The issuer for an external identifier. */ issuer: string; } interface GetGroupMembershipsGroupMembership { /** * The identifier for a group in the Identity Store. */ groupId: string; /** * Identity Store ID associated with the Single Sign-On Instance. */ identityStoreId: string; /** * An object containing the identifier of a group member. See `memberId` below. */ memberId: outputs.identitystore.GetGroupMembershipsGroupMembershipMemberId; membershipId: string; } interface GetGroupMembershipsGroupMembershipMemberId { /** * User identifier of the group member. */ userId: string; } interface GetGroupsGroup { /** * Description of the specified group. */ description: string; /** * Group's display name. */ displayName: string; /** * List of identifiers issued to this resource by an external identity provider. */ externalIds: outputs.identitystore.GetGroupsGroupExternalId[]; /** * Identifier of the group in the Identity Store. */ groupId: string; /** * Identity Store ID associated with the Single Sign-On (SSO) Instance. */ identityStoreId: string; } interface GetGroupsGroupExternalId { /** * Identifier issued to this resource by an external identity provider. */ id: string; /** * Issuer for an external identifier. */ issuer: string; } interface GetUserAddress { /** * The country that this address is in. */ country: string; /** * The name that is typically displayed when the name is shown for display. */ formatted: string; /** * The address locality. */ locality: string; /** * The postal code of the address. */ postalCode: string; /** * When `true`, this is the primary phone number associated with the user. */ primary: boolean; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * The street of the address. */ streetAddress: string; /** * The type of phone number. */ type: string; } interface GetUserAlternateIdentifier { /** * Configuration block for filtering by the identifier issued by an external identity provider. Detailed below. */ externalId?: outputs.identitystore.GetUserAlternateIdentifierExternalId; /** * An entity attribute that's unique to a specific entity. Detailed below. * * > Exactly one of the above arguments must be provided. */ uniqueAttribute?: outputs.identitystore.GetUserAlternateIdentifierUniqueAttribute; } interface GetUserAlternateIdentifierExternalId { /** * The identifier issued to this resource by an external identity provider. */ id: string; /** * The issuer for an external identifier. */ issuer: string; } interface GetUserAlternateIdentifierUniqueAttribute { /** * Attribute path that is used to specify which attribute name to search. For example: `UserName`. Refer to the [User data type](https://docs.aws.amazon.com/singlesignon/latest/IdentityStoreAPIReference/API_User.html). */ attributePath: string; /** * Value for an attribute. */ attributeValue: string; } interface GetUserEmail { /** * When `true`, this is the primary phone number associated with the user. */ primary: boolean; /** * The type of phone number. */ type: string; /** * The user's phone number. */ value: string; } interface GetUserExternalId { /** * The identifier issued to this resource by an external identity provider. */ id: string; /** * The issuer for an external identifier. */ issuer: string; } interface GetUserName { /** * The family name of the user. */ familyName: string; /** * The name that is typically displayed when the name is shown for display. */ formatted: string; /** * The given name of the user. */ givenName: string; /** * The honorific prefix of the user. */ honorificPrefix: string; /** * The honorific suffix of the user. */ honorificSuffix: string; /** * The middle name of the user. */ middleName: string; } interface GetUserPhoneNumber { /** * When `true`, this is the primary phone number associated with the user. */ primary: boolean; /** * The type of phone number. */ type: string; /** * The user's phone number. */ value: string; } interface GetUsersUser { /** * List of details about the user's address. */ addresses: outputs.identitystore.GetUsersUserAddress[]; /** * Name that is typically displayed when the user is referenced. */ displayName: string; /** * List of details about the user's email. */ emails: outputs.identitystore.GetUsersUserEmail[]; /** * List of identifiers issued to this resource by an external identity provider. */ externalIds: outputs.identitystore.GetUsersUserExternalId[]; /** * Identity Store ID associated with the Single Sign-On Instance. */ identityStoreId: string; /** * User's geographical region or location. */ locale: string; /** * Details about the user's full name. */ names: outputs.identitystore.GetUsersUserName[]; /** * An alternate name for the user. */ nickname: string; /** * List of details about the user's phone number. */ phoneNumbers: outputs.identitystore.GetUsersUserPhoneNumber[]; /** * Preferred language of the user. */ preferredLanguage: string; /** * An URL that may be associated with the user. */ profileUrl: string; /** * User's time zone. */ timezone: string; /** * User's title. */ title: string; /** * Identifier of the user in the Identity Store. */ userId: string; /** * User's user name value. */ userName: string; /** * Current status of the user account. */ userStatus: string; /** * User type. */ userType: string; } interface GetUsersUserAddress { /** * Country that this address is in. */ country: string; /** * Name that is typically displayed when the name is shown for display. */ formatted: string; /** * Address locality. */ locality: string; /** * Postal code of the address. */ postalCode: string; /** * When `true`, this is the primary phone number associated with the user. */ primary: boolean; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Street of the address. */ streetAddress: string; /** * Type of phone number. */ type: string; } interface GetUsersUserEmail { /** * When `true`, this is the primary phone number associated with the user. */ primary: boolean; /** * Type of phone number. */ type: string; /** * User's phone number. */ value: string; } interface GetUsersUserExternalId { /** * Identifier issued to this resource by an external identity provider. */ id: string; /** * Issuer for an external identifier. */ issuer: string; } interface GetUsersUserName { /** * Family name of the user. */ familyName: string; /** * Name that is typically displayed when the name is shown for display. */ formatted: string; /** * Given name of the user. */ givenName: string; /** * Honorific prefix of the user. */ honorificPrefix: string; /** * Honorific suffix of the user. */ honorificSuffix: string; /** * Middle name of the user. */ middleName: string; } interface GetUsersUserPhoneNumber { /** * When `true`, this is the primary phone number associated with the user. */ primary: boolean; /** * Type of phone number. */ type: string; /** * User's phone number. */ value: string; } interface GroupExternalId { /** * The identifier issued to this resource by an external identity provider. */ id: string; /** * The issuer for an external identifier. */ issuer: string; } interface UserAddresses { /** * The country that this address is in. */ country?: string; /** * The name that is typically displayed when the address is shown for display. */ formatted?: string; /** * The address locality. */ locality?: string; /** * The postal code of the address. */ postalCode?: string; /** * When `true`, this is the primary address associated with the user. */ primary?: boolean; /** * The region of the address. */ region?: string; /** * The street of the address. */ streetAddress?: string; /** * The type of address. */ type?: string; } interface UserEmails { /** * When `true`, this is the primary email associated with the user. */ primary?: boolean; /** * The type of email. */ type?: string; /** * The email address. This value must be unique across the identity store. */ value?: string; } interface UserExternalId { /** * The identifier issued to this resource by an external identity provider. */ id: string; /** * The issuer for an external identifier. */ issuer: string; } interface UserName { /** * The family name of the user. */ familyName: string; /** * The name that is typically displayed when the name is shown for display. */ formatted?: string; /** * The given name of the user. * * The following arguments are optional: */ givenName: string; /** * The honorific prefix of the user. */ honorificPrefix?: string; /** * The honorific suffix of the user. */ honorificSuffix?: string; /** * The middle name of the user. */ middleName?: string; } interface UserPhoneNumbers { /** * When `true`, this is the primary phone number associated with the user. */ primary?: boolean; /** * The type of phone number. */ type?: string; /** * The user's phone number. */ value?: string; } } export declare namespace imagebuilder { interface ContainerRecipeComponent { /** * ARN of the Image Builder Component to associate. */ componentArn: string; /** * Configuration block(s) for parameters to configure the component. Detailed below. */ parameters?: outputs.imagebuilder.ContainerRecipeComponentParameter[]; } interface ContainerRecipeComponentParameter { /** * The name of the component parameter. */ name: string; /** * The value for the named component parameter. */ value: string; } interface ContainerRecipeInstanceConfiguration { /** * Configuration block(s) with block device mappings for the container recipe. Detailed below. */ blockDeviceMappings?: outputs.imagebuilder.ContainerRecipeInstanceConfigurationBlockDeviceMapping[]; /** * The AMI ID to use as the base image for a container build and test instance. If not specified, Image Builder will use the appropriate ECS-optimized AMI as a base image. */ image?: string; } interface ContainerRecipeInstanceConfigurationBlockDeviceMapping { /** * Name of the device. For example, `/dev/sda` or `/dev/xvdb`. */ deviceName?: string; /** * Configuration block with Elastic Block Storage (EBS) block device mapping settings. Detailed below. */ ebs?: outputs.imagebuilder.ContainerRecipeInstanceConfigurationBlockDeviceMappingEbs; /** * Set to `true` to remove a mapping from the parent image. */ noDevice: boolean; /** * Virtual device name. For example, `ephemeral0`. Instance store volumes are numbered starting from 0. */ virtualName?: string; } interface ContainerRecipeInstanceConfigurationBlockDeviceMappingEbs { /** * Whether to delete the volume on termination. Defaults to unset, which is the value inherited from the parent image. */ deleteOnTermination?: string; /** * Whether to encrypt the volume. Defaults to unset, which is the value inherited from the parent image. */ encrypted?: string; /** * Number of Input/Output (I/O) operations per second to provision for an `io1` or `io2` volume. */ iops?: number; /** * ARN of the KMS Key for encryption. */ kmsKeyId?: string; /** * Identifier of the EC2 Volume Snapshot. */ snapshotId?: string; /** * For GP3 volumes only. The throughput in MiB/s that the volume supports. */ throughput?: number; /** * Size of the volume, in GiB. */ volumeSize?: number; /** * Type of the volume. For example, `gp2` or `io2`. */ volumeType?: string; } interface ContainerRecipeTargetRepository { /** * The name of the container repository where the output container image is stored. This name is prefixed by the repository location. */ repositoryName: string; /** * The service in which this image is registered. Valid values: `ECR`. */ service: string; } interface DistributionConfigurationDistribution { /** * Configuration block with AMI distribution settings. Detailed below. */ amiDistributionConfiguration?: outputs.imagebuilder.DistributionConfigurationDistributionAmiDistributionConfiguration; /** * Configuration block with container distribution settings. Detailed below. */ containerDistributionConfiguration?: outputs.imagebuilder.DistributionConfigurationDistributionContainerDistributionConfiguration; /** * Set of Windows faster-launching configurations to use for AMI distribution. Detailed below. */ fastLaunchConfigurations?: outputs.imagebuilder.DistributionConfigurationDistributionFastLaunchConfiguration[]; /** * Set of launch template configuration settings that apply to image distribution. Detailed below. */ launchTemplateConfigurations?: outputs.imagebuilder.DistributionConfigurationDistributionLaunchTemplateConfiguration[]; /** * Set of ARNs of License Manager License Configurations. */ licenseConfigurationArns?: string[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Configuration block with S3 export settings. Detailed below. */ s3ExportConfiguration?: outputs.imagebuilder.DistributionConfigurationDistributionS3ExportConfiguration; /** * Configuration block with SSM parameter configuration to use as AMI id output. Detailed below. */ ssmParameterConfigurations?: outputs.imagebuilder.DistributionConfigurationDistributionSsmParameterConfiguration[]; } interface DistributionConfigurationDistributionAmiDistributionConfiguration { /** * Key-value map of tags to apply to the distributed AMI. */ amiTags?: { [key: string]: string; }; /** * Description to apply to the distributed AMI. */ description?: string; /** * ARN of the KMS Key to encrypt the distributed AMI. */ kmsKeyId?: string; /** * Configuration block of EC2 launch permissions to apply to the distributed AMI. Detailed below. */ launchPermission?: outputs.imagebuilder.DistributionConfigurationDistributionAmiDistributionConfigurationLaunchPermission; /** * Name to apply to the distributed AMI. */ name?: string; /** * Set of AWS Account identifiers to distribute the AMI. */ targetAccountIds?: string[]; } interface DistributionConfigurationDistributionAmiDistributionConfigurationLaunchPermission { /** * Set of AWS Organization ARNs to assign. */ organizationArns?: string[]; /** * Set of AWS Organizational Unit ARNs to assign. */ organizationalUnitArns?: string[]; /** * Set of EC2 launch permission user groups to assign. Use `all` to distribute a public AMI. */ userGroups?: string[]; /** * Set of AWS Account identifiers to assign. */ userIds?: string[]; } interface DistributionConfigurationDistributionContainerDistributionConfiguration { /** * Set of tags that are attached to the container distribution configuration. */ containerTags?: string[]; /** * Description of the container distribution configuration. */ description?: string; /** * Configuration block with the destination repository for the container distribution configuration. */ targetRepository: outputs.imagebuilder.DistributionConfigurationDistributionContainerDistributionConfigurationTargetRepository; } interface DistributionConfigurationDistributionContainerDistributionConfigurationTargetRepository { /** * The name of the container repository where the output container image is stored. This name is prefixed by the repository location. */ repositoryName: string; /** * The service in which this image is registered. Valid values: `ECR`. */ service: string; } interface DistributionConfigurationDistributionFastLaunchConfiguration { /** * The owner account ID for the fast-launch enabled Windows AMI. */ accountId: string; /** * A Boolean that represents the current state of faster launching for the Windows AMI. Set to `true` to start using Windows faster launching, or `false` to stop using it. */ enabled: boolean; /** * Configuration block for the launch template that the fast-launch enabled Windows AMI uses when it launches Windows instances to create pre-provisioned snapshots. Detailed below. */ launchTemplate?: outputs.imagebuilder.DistributionConfigurationDistributionFastLaunchConfigurationLaunchTemplate; /** * The maximum number of parallel instances that are launched for creating resources. */ maxParallelLaunches?: number; /** * Configuration block for managing the number of snapshots that are created from pre-provisioned instances for the Windows AMI when faster launching is enabled. Detailed below. */ snapshotConfiguration?: outputs.imagebuilder.DistributionConfigurationDistributionFastLaunchConfigurationSnapshotConfiguration; } interface DistributionConfigurationDistributionFastLaunchConfigurationLaunchTemplate { /** * The ID of the launch template to use for faster launching for a Windows AMI. */ launchTemplateId?: string; /** * The name of the launch template to use for faster launching for a Windows AMI. */ launchTemplateName?: string; /** * The version of the launch template to use for faster launching for a Windows AMI. */ launchTemplateVersion?: string; } interface DistributionConfigurationDistributionFastLaunchConfigurationSnapshotConfiguration { /** * The number of pre-provisioned snapshots to keep on hand for a fast-launch enabled Windows AMI. */ targetResourceCount?: number; } interface DistributionConfigurationDistributionLaunchTemplateConfiguration { /** * The account ID that this configuration applies to. */ accountId?: string; /** * Indicates whether to set the specified Amazon EC2 launch template as the default launch template. Defaults to `true`. */ default?: boolean; /** * The ID of the Amazon EC2 launch template to use. */ launchTemplateId: string; } interface DistributionConfigurationDistributionS3ExportConfiguration { /** * The disk image format of the exported image (`RAW`, `VHD`, or `VMDK`) */ diskImageFormat: string; /** * The name of the IAM role to use for exporting. */ roleName: string; /** * The name of the S3 bucket to store the exported image in. The bucket needs to exist before the export configuration is created. */ s3Bucket: string; /** * The prefix for the exported image. */ s3Prefix?: string; } interface DistributionConfigurationDistributionSsmParameterConfiguration { /** * AWS account ID that will own the parameter in the given region. This account must be specified as a target account in the distribution settings. */ amiAccountId?: string; /** * Data type of the SSM parameter. Valid values are `text` and `aws:ec2:image`. AWS recommends using `aws:ec2:image`. */ dataType?: string; /** * Name of the SSM parameter that will store the AMI ID after distribution. */ parameterName: string; } interface GetComponentsFilter { /** * Name of the filter field. Valid values can be found in the [Image Builder ListComponents API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListComponents.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetContainerRecipeComponent { /** * ARN of the Image Builder Component. */ componentArn: string; /** * Set of parameters that are used to configure the component. */ parameters: outputs.imagebuilder.GetContainerRecipeComponentParameter[]; } interface GetContainerRecipeComponentParameter { /** * Name of the container recipe. */ name: string; /** * Value of the component parameter. */ value: string; } interface GetContainerRecipeInstanceConfiguration { /** * Set of objects with block device mappings for the instance configuration. */ blockDeviceMappings: outputs.imagebuilder.GetContainerRecipeInstanceConfigurationBlockDeviceMapping[]; /** * AMI ID of the base image for container build and test instance. */ image: string; } interface GetContainerRecipeInstanceConfigurationBlockDeviceMapping { /** * Name of the device. For example, `/dev/sda` or `/dev/xvdb`. */ deviceName: string; /** * Single list of object with Elastic Block Storage (EBS) block device mapping settings. */ ebs: outputs.imagebuilder.GetContainerRecipeInstanceConfigurationBlockDeviceMappingEb[]; /** * Whether to remove a mapping from the parent image. */ noDevice: string; /** * Virtual device name. For example, `ephemeral0`. Instance store volumes are numbered starting from 0. */ virtualName: string; } interface GetContainerRecipeInstanceConfigurationBlockDeviceMappingEb { /** * Whether to delete the volume on termination. Defaults to unset, which is the value inherited from the parent image. */ deleteOnTermination: boolean; /** * Whether to encrypt the volume. Defaults to unset, which is the value inherited from the parent image. */ encrypted: boolean; /** * Number of Input/Output (I/O) operations per second to provision for an `io1` or `io2` volume. */ iops: number; /** * KMS key used to encrypt the container image. */ kmsKeyId: string; /** * Identifier of the EC2 Volume Snapshot. */ snapshotId: string; /** * For GP3 volumes only. The throughput in MiB/s that the volume supports. */ throughput: number; /** * Size of the volume, in GiB. */ volumeSize: number; /** * Type of the volume. For example, `gp2` or `io2`. */ volumeType: string; } interface GetContainerRecipeTargetRepository { /** * Name of the container repository where the output container image is stored. The name is prefixed by the repository location. */ repositoryName: string; /** * Service in which this image is registered. */ service: string; } interface GetContainerRecipesFilter { /** * Name of the filter field. Valid values can be found in the [Image Builder ListContainerRecipes API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListContainerRecipes.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetDistributionConfigurationDistribution { /** * Nested list of AMI distribution configuration. */ amiDistributionConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionAmiDistributionConfiguration[]; /** * Nested list of container distribution configurations. */ containerDistributionConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionContainerDistributionConfiguration[]; /** * Nested list of Windows faster-launching configurations to use for AMI distribution. */ fastLaunchConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionFastLaunchConfiguration[]; /** * Nested list of launch template configurations. */ launchTemplateConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionLaunchTemplateConfiguration[]; /** * Set of ARNs of License Manager License Configurations. */ licenseConfigurationArns: string[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Nested list of S3 export configuration. */ s3ExportConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionS3ExportConfiguration[]; /** * Nested list of SSM parameter configuration. */ ssmParameterConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionSsmParameterConfiguration[]; } interface GetDistributionConfigurationDistributionAmiDistributionConfiguration { /** * Key-value map of tags to apply to distributed AMI. */ amiTags: { [key: string]: string; }; /** * Description of the container distribution configuration. */ description: string; /** * ARN of KMS Key to encrypt AMI. */ kmsKeyId: string; /** * Nested list of EC2 launch permissions. */ launchPermissions: outputs.imagebuilder.GetDistributionConfigurationDistributionAmiDistributionConfigurationLaunchPermission[]; /** * Name of the distribution configuration. */ name: string; /** * Set of target AWS Account identifiers. */ targetAccountIds: string[]; } interface GetDistributionConfigurationDistributionAmiDistributionConfigurationLaunchPermission { /** * Set of AWS Organization ARNs. */ organizationArns: string[]; /** * Set of AWS Organizational Unit ARNs. */ organizationalUnitArns: string[]; /** * Set of EC2 launch permission user groups. */ userGroups: string[]; /** * Set of AWS Account identifiers. */ userIds: string[]; } interface GetDistributionConfigurationDistributionContainerDistributionConfiguration { /** * Set of tags that are attached to the container distribution configuration. */ containerTags: string[]; /** * Description of the container distribution configuration. */ description: string; /** * Set of destination repositories for the container distribution configuration. */ targetRepositories: outputs.imagebuilder.GetDistributionConfigurationDistributionContainerDistributionConfigurationTargetRepository[]; } interface GetDistributionConfigurationDistributionContainerDistributionConfigurationTargetRepository { /** * Name of the container repository where the output container image is stored. */ repositoryName: string; /** * Service in which the image is registered. */ service: string; } interface GetDistributionConfigurationDistributionFastLaunchConfiguration { /** * The account ID that this configuration applies to. */ accountId: string; /** * A Boolean that represents the current state of faster launching for the Windows AMI. */ enabled: boolean; /** * Nested list of launch templates that the fast-launch enabled Windows AMI uses when it launches Windows instances to create pre-provisioned snapshots. */ launchTemplates: outputs.imagebuilder.GetDistributionConfigurationDistributionFastLaunchConfigurationLaunchTemplate[]; /** * The maximum number of parallel instances that are launched for creating resources. */ maxParallelLaunches: number; /** * Nested list of configurations for managing the number of snapshots that are created from pre-provisioned instances for the Windows AMI when faster launching is enabled. */ snapshotConfigurations: outputs.imagebuilder.GetDistributionConfigurationDistributionFastLaunchConfigurationSnapshotConfiguration[]; } interface GetDistributionConfigurationDistributionFastLaunchConfigurationLaunchTemplate { /** * ID of the Amazon EC2 launch template. */ launchTemplateId: string; /** * The name of the launch template to use for faster launching for a Windows AMI. */ launchTemplateName: string; /** * The version of the launch template to use for faster launching for a Windows AMI. */ launchTemplateVersion: string; } interface GetDistributionConfigurationDistributionFastLaunchConfigurationSnapshotConfiguration { /** * The number of pre-provisioned snapshots to keep on hand for a fast-launch enabled Windows AMI. */ targetResourceCount: number; } interface GetDistributionConfigurationDistributionLaunchTemplateConfiguration { /** * The account ID that this configuration applies to. */ accountId: string; /** * Whether the specified Amazon EC2 launch template is set as the default launch template. */ default: boolean; /** * ID of the Amazon EC2 launch template. */ launchTemplateId: string; } interface GetDistributionConfigurationDistributionS3ExportConfiguration { /** * The disk image format of the exported image (`RAW`, `VHD`, or `VMDK`) */ diskImageFormat: string; /** * The name of the IAM role to use for exporting. */ roleName: string; /** * The name of the S3 bucket to store the exported image in. */ s3Bucket: string; /** * The prefix for the exported image. */ s3Prefix: string; } interface GetDistributionConfigurationDistributionSsmParameterConfiguration { /** * The AWS account ID that own the parameter in the given region. */ amiAccountId: string; /** * The data type of the SSM parameter. */ dataType: string; /** * Name of the SSM parameter used to store the AMI ID after distribution. */ parameterName: string; } interface GetDistributionConfigurationsFilter { /** * Name of the filter field. Valid values can be found in the [Image Builder ListDistributionConfigurations API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListDistributionConfigurations.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetImageImageScanningConfiguration { /** * Configuration block with ECR configuration. */ ecrConfigurations: outputs.imagebuilder.GetImageImageScanningConfigurationEcrConfiguration[]; /** * Indicates whether Image Builder keeps a snapshot of the vulnerability scans that Amazon Inspector runs against the build instance when you create a new image. */ imageScanningEnabled: boolean; } interface GetImageImageScanningConfigurationEcrConfiguration { /** * Set of tags for Image Builder to apply to the output container image that that Amazon Inspector scans. */ containerTags: string[]; /** * The name of the container repository that Amazon Inspector scans to identify findings for your container images. */ repositoryName: string; } interface GetImageImageTestsConfiguration { /** * Whether image tests are enabled. */ imageTestsEnabled: boolean; /** * Number of minutes before image tests time out. */ timeoutMinutes: number; } interface GetImageOutputResource { /** * Set of objects with each AMI created. */ amis: outputs.imagebuilder.GetImageOutputResourceAmi[]; /** * Set of objects with each container image created and stored in the output repository. */ containers: outputs.imagebuilder.GetImageOutputResourceContainer[]; } interface GetImageOutputResourceAmi { /** * Account identifier of the AMI. */ accountId: string; /** * Description of the AMI. */ description: string; /** * Identifier of the AMI. */ image: string; /** * Name of the AMI. */ name: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface GetImageOutputResourceContainer { /** * Set of URIs for created containers. */ imageUris: string[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface GetImagePipelineImageScanningConfiguration { /** * List if an object with ecr configuration for image scanning */ ecrConfigurations: outputs.imagebuilder.GetImagePipelineImageScanningConfigurationEcrConfiguration[]; /** * Whether image scanning is enabled. */ imageScanningEnabled: boolean; } interface GetImagePipelineImageScanningConfigurationEcrConfiguration { /** * Tags that are added to the output containers that are scanned */ containerTags: string[]; /** * The name of the container repository that Amazon Inspector scans */ repositoryName: string; } interface GetImagePipelineImageTestsConfiguration { /** * Whether image tests are enabled. */ imageTestsEnabled: boolean; /** * Number of minutes before image tests time out. */ timeoutMinutes: number; } interface GetImagePipelineSchedule { /** * Condition when the pipeline should trigger a new image build. */ pipelineExecutionStartCondition: string; /** * Cron expression of how often the pipeline start condition is evaluated. */ scheduleExpression: string; } interface GetImagePipelinesFilter { /** * Name of the filter field. Valid values can be found in the [Image Builder ListImagePipelines API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePipelines.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetImageRecipeBlockDeviceMapping { /** * Name of the device. For example, `/dev/sda` or `/dev/xvdb`. */ deviceName: string; /** * Single list of object with Elastic Block Storage (EBS) block device mapping settings. */ ebs: outputs.imagebuilder.GetImageRecipeBlockDeviceMappingEb[]; /** * Whether to remove a mapping from the parent image. */ noDevice: string; /** * Virtual device name. For example, `ephemeral0`. Instance store volumes are numbered starting from 0. */ virtualName: string; } interface GetImageRecipeBlockDeviceMappingEb { /** * Whether to delete the volume on termination. Defaults to unset, which is the value inherited from the parent image. */ deleteOnTermination: string; /** * Whether to encrypt the volume. Defaults to unset, which is the value inherited from the parent image. */ encrypted: string; /** * Number of Input/Output (I/O) operations per second to provision for an `io1` or `io2` volume. */ iops: number; /** * ARN of the KMS Key for encryption. */ kmsKeyId: string; /** * Identifier of the EC2 Volume Snapshot. */ snapshotId: string; /** * For GP3 volumes only. The throughput in MiB/s that the volume supports. */ throughput: number; /** * Size of the volume, in GiB. */ volumeSize: number; /** * Type of the volume. For example, `gp2` or `io2`. */ volumeType: string; } interface GetImageRecipeComponent { /** * ARN of the Image Builder Component. */ componentArn: string; /** * Set of parameters that are used to configure the component. */ parameters: outputs.imagebuilder.GetImageRecipeComponentParameter[]; } interface GetImageRecipeComponentParameter { /** * Name of the image recipe. */ name: string; /** * Value of the component parameter. */ value: string; } interface GetImageRecipesFilter { /** * Name of the filter field. Valid values can be found in the [Image Builder ListImageRecipes API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageRecipes.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetInfrastructureConfigurationInstanceMetadataOption { /** * Number of hops that an instance can traverse to reach its destonation. */ httpPutResponseHopLimit: number; /** * Whether a signed token is required for instance metadata retrieval requests. */ httpTokens: string; } interface GetInfrastructureConfigurationLogging { /** * Nested list of S3 logs settings. */ s3Logs: outputs.imagebuilder.GetInfrastructureConfigurationLoggingS3Log[]; } interface GetInfrastructureConfigurationLoggingS3Log { /** * Name of the S3 Bucket for logging. */ s3BucketName: string; /** * Key prefix for S3 Bucket logging. */ s3KeyPrefix: string; } interface GetInfrastructureConfigurationPlacement { /** * Availability Zone where your build and test instances will launch. */ availabilityZone: string; /** * ID of the Dedicated Host on which build and test instances run. */ hostId: string; /** * ARN of the host resource group in which to launch build and test instances. */ hostResourceGroupArn: string; /** * Placement tenancy of the instance. */ tenancy: string; } interface GetInfrastructureConfigurationsFilter { /** * Name of the filter field. Valid values can be found in the [Image Builder ListInfrastructureConfigurations API Reference](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListInfrastructureConfigurations.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface ImageImageScanningConfiguration { /** * Configuration block with ECR configuration. Detailed below. */ ecrConfiguration: outputs.imagebuilder.ImageImageScanningConfigurationEcrConfiguration; /** * Indicates whether Image Builder keeps a snapshot of the vulnerability scans that Amazon Inspector runs against the build instance when you create a new image. Defaults to `false`. */ imageScanningEnabled?: boolean; } interface ImageImageScanningConfigurationEcrConfiguration { /** * Set of tags for Image Builder to apply to the output container image that that Amazon Inspector scans. */ containerTags?: string[]; /** * The name of the container repository that Amazon Inspector scans to identify findings for your container images. */ repositoryName?: string; } interface ImageImageTestsConfiguration { /** * Whether image tests are enabled. Defaults to `true`. */ imageTestsEnabled?: boolean; /** * Number of minutes before image tests time out. Valid values are between `60` and `1440`. Defaults to `720`. */ timeoutMinutes?: number; } interface ImageLoggingConfiguration { /** * Name of the CloudWatch Log Group to send logs to. */ logGroupName: string; } interface ImageOutputResource { /** * Set of objects with each AMI created. */ amis: outputs.imagebuilder.ImageOutputResourceAmi[]; /** * Set of objects with each container image created and stored in the output repository. */ containers: outputs.imagebuilder.ImageOutputResourceContainer[]; } interface ImageOutputResourceAmi { /** * Account identifier of the AMI. */ accountId: string; /** * Description of the AMI. */ description: string; /** * Identifier of the AMI. */ image: string; /** * Name of the AMI. */ name: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface ImageOutputResourceContainer { /** * Set of URIs for created containers. */ imageUris: string[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface ImagePipelineImageScanningConfiguration { /** * Configuration block with ECR configuration for image scanning. Detailed below. */ ecrConfiguration: outputs.imagebuilder.ImagePipelineImageScanningConfigurationEcrConfiguration; /** * Whether image scans are enabled. Defaults to `false`. */ imageScanningEnabled?: boolean; } interface ImagePipelineImageScanningConfigurationEcrConfiguration { containerTags?: string[]; /** * The name of the repository to scan */ repositoryName?: string; } interface ImagePipelineImageTestsConfiguration { /** * Whether image tests are enabled. Defaults to `true`. */ imageTestsEnabled?: boolean; /** * Number of minutes before image tests time out. Valid values are between `60` and `1440`. Defaults to `720`. */ timeoutMinutes?: number; } interface ImagePipelineLoggingConfiguration { /** * Name of the CloudWatch Log Group to send image logs to. */ imageLogGroupName?: string; /** * Name of the CloudWatch Log Group to send pipeline logs to. */ pipelineLogGroupName?: string; } interface ImagePipelineSchedule { /** * Condition when the pipeline should trigger a new image build. Valid values are `EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE` and `EXPRESSION_MATCH_ONLY`. Defaults to `EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE`. */ pipelineExecutionStartCondition?: string; /** * Cron expression of how often the pipeline start condition is evaluated. For example, `cron(0 0 * * ? *)` is evaluated every day at midnight UTC. Configurations using the five field syntax that was previously accepted by the API, such as `cron(0 0 * * *)`, must be updated to the six field syntax. For more information, see the [Image Builder User Guide](https://docs.aws.amazon.com/imagebuilder/latest/userguide/cron-expressions.html). * * The following arguments are optional: */ scheduleExpression: string; /** * The timezone that applies to the scheduling expression. For example, "Etc/UTC", "America/Los_Angeles" in the [IANA timezone format](https://www.joda.org/joda-time/timezones.html). If not specified this defaults to UTC. */ timezone: string; } interface ImagePipelineWorkflow { /** * The action to take if the workflow fails. Must be one of `CONTINUE` or `ABORT`. */ onFailure?: string; /** * The parallel group in which to run a test Workflow. */ parallelGroup?: string; /** * Configuration block for the workflow parameters. Detailed below. */ parameters?: outputs.imagebuilder.ImagePipelineWorkflowParameter[]; /** * ARN of the Image Builder Workflow. * * The following arguments are optional: */ workflowArn: string; } interface ImagePipelineWorkflowParameter { /** * The name of the Workflow parameter. */ name: string; /** * The value of the Workflow parameter. */ value: string; } interface ImageRecipeBlockDeviceMapping { /** * Name of the device. For example, `/dev/sda` or `/dev/xvdb`. */ deviceName?: string; /** * Configuration block with Elastic Block Storage (EBS) block device mapping settings. Detailed below. */ ebs?: outputs.imagebuilder.ImageRecipeBlockDeviceMappingEbs; /** * Set to `true` to remove a mapping from the parent image. */ noDevice: boolean; /** * Virtual device name. For example, `ephemeral0`. Instance store volumes are numbered starting from 0. */ virtualName?: string; } interface ImageRecipeBlockDeviceMappingEbs { /** * Whether to delete the volume on termination. Defaults to unset, which is the value inherited from the parent image. */ deleteOnTermination?: string; /** * Whether to encrypt the volume. Defaults to unset, which is the value inherited from the parent image. */ encrypted?: string; /** * Number of Input/Output (I/O) operations per second to provision for an `io1` or `io2` volume. */ iops?: number; /** * ARN of the KMS Key for encryption. */ kmsKeyId?: string; /** * Identifier of the EC2 Volume Snapshot. */ snapshotId?: string; /** * For GP3 volumes only. The throughput in MiB/s that the volume supports. */ throughput?: number; /** * Size of the volume, in GiB. */ volumeSize?: number; /** * Type of the volume. For example, `gp2` or `io2`. */ volumeType?: string; } interface ImageRecipeComponent { /** * ARN of the Image Builder Component to associate. */ componentArn: string; /** * Configuration block(s) for parameters to configure the component. Detailed below. */ parameters?: outputs.imagebuilder.ImageRecipeComponentParameter[]; } interface ImageRecipeComponentParameter { /** * The name of the component parameter. */ name: string; /** * The value for the named component parameter. */ value: string; } interface ImageRecipeSystemsManagerAgent { /** * Whether to remove the Systems Manager Agent after the image has been built. */ uninstallAfterBuild: boolean; } interface ImageWorkflow { /** * The action to take if the workflow fails. Must be one of `CONTINUE` or `ABORT`. */ onFailure?: string; /** * The parallel group in which to run a test Workflow. */ parallelGroup?: string; /** * Configuration block for the workflow parameters. Detailed below. */ parameters?: outputs.imagebuilder.ImageWorkflowParameter[]; /** * ARN of the Image Builder Workflow. * * The following arguments are optional: */ workflowArn: string; } interface ImageWorkflowParameter { /** * The name of the Workflow parameter. */ name: string; /** * The value of the Workflow parameter. */ value: string; } interface InfrastructureConfigurationInstanceMetadataOptions { /** * The number of hops that an instance can traverse to reach its destonation. */ httpPutResponseHopLimit?: number; /** * Whether a signed token is required for instance metadata retrieval requests. Valid values: `required`, `optional`. */ httpTokens?: string; } interface InfrastructureConfigurationLogging { /** * Configuration block with S3 logging settings. Detailed below. */ s3Logs: outputs.imagebuilder.InfrastructureConfigurationLoggingS3Logs; } interface InfrastructureConfigurationLoggingS3Logs { /** * Name of the S3 Bucket. * * The following arguments are optional: */ s3BucketName: string; /** * Prefix to use for S3 logs. Defaults to `/`. */ s3KeyPrefix?: string; } interface InfrastructureConfigurationPlacement { /** * Availability Zone where your build and test instances will launch. */ availabilityZone?: string; /** * ID of the Dedicated Host on which build and test instances run. Conflicts with `hostResourceGroupArn`. */ hostId?: string; /** * ARN of the host resource group in which to launch build and test instances. Conflicts with `hostId`. */ hostResourceGroupArn?: string; /** * Placement tenancy of the instance. Valid values: `default`, `dedicated` and `host`. */ tenancy?: string; } interface LifecyclePolicyPolicyDetail { /** * Configuration details for the policy action. */ action: outputs.imagebuilder.LifecyclePolicyPolicyDetailAction; /** * Additional rules to specify resources that should be exempt from policy actions. */ exclusionRules?: outputs.imagebuilder.LifecyclePolicyPolicyDetailExclusionRules; /** * Specifies the resources that the lifecycle policy applies to. * * The following arguments are optional: */ filter: outputs.imagebuilder.LifecyclePolicyPolicyDetailFilter; } interface LifecyclePolicyPolicyDetailAction { /** * Specifies the resources that the lifecycle policy applies to. Detailed below. */ includeResources?: outputs.imagebuilder.LifecyclePolicyPolicyDetailActionIncludeResources; /** * Specifies the lifecycle action to take. Valid values: `DELETE`, `DEPRECATE` or `DISABLE`. * * The following arguments are optional: */ type: string; } interface LifecyclePolicyPolicyDetailActionIncludeResources { /** * Specifies whether the lifecycle action should apply to distributed AMIs. */ amis: boolean; /** * Specifies whether the lifecycle action should apply to distributed containers. */ containers: boolean; /** * Specifies whether the lifecycle action should apply to snapshots associated with distributed AMIs. */ snapshots: boolean; } interface LifecyclePolicyPolicyDetailExclusionRules { /** * Lists configuration values that apply to AMIs that Image Builder should exclude from the lifecycle action. Detailed below. */ amis?: outputs.imagebuilder.LifecyclePolicyPolicyDetailExclusionRulesAmis; /** * Contains a list of tags that Image Builder uses to skip lifecycle actions for Image Builder image resources that have them. */ tagMap?: { [key: string]: string; }; } interface LifecyclePolicyPolicyDetailExclusionRulesAmis { /** * Configures whether public AMIs are excluded from the lifecycle action. */ isPublic: boolean; /** * Specifies configuration details for Image Builder to exclude the most recent resources from lifecycle actions. Detailed below. */ lastLaunched?: outputs.imagebuilder.LifecyclePolicyPolicyDetailExclusionRulesAmisLastLaunched; /** * Configures AWS Regions that are excluded from the lifecycle action. */ regions?: string[]; /** * Specifies AWS accounts whose resources are excluded from the lifecycle action. */ sharedAccounts?: string[]; /** * Lists tags that should be excluded from lifecycle actions for the AMIs that have them. */ tagMap?: { [key: string]: string; }; } interface LifecyclePolicyPolicyDetailExclusionRulesAmisLastLaunched { /** * Defines the unit of time that the lifecycle policy uses to calculate elapsed time since the last instance launched from the AMI. For example: days, weeks, months, or years. Valid values: `DAYS`, `WEEKS`, `MONTHS` or `YEARS`. */ unit: string; /** * The integer number of units for the time period. For example 6 (months). */ value: number; } interface LifecyclePolicyPolicyDetailFilter { /** * For age-based filters, this is the number of resources to keep on hand after the lifecycle DELETE action is applied. Impacted resources are only deleted if you have more than this number of resources. If you have fewer resources than this number, the impacted resource is not deleted. */ retainAtLeast?: number; /** * Filter resources based on either age or count. Valid values: `AGE` or `COUNT`. */ type: string; /** * Defines the unit of time that the lifecycle policy uses to determine impacted resources. This is required for age-based rules. Valid values: `DAYS`, `WEEKS`, `MONTHS` or `YEARS`. */ unit?: string; /** * The number of units for the time period or for the count. For example, a value of 6 might refer to six months or six AMIs. * * The following arguments are optional: */ value: number; } interface LifecyclePolicyResourceSelection { /** * A list of recipe that are used as selection criteria for the output images that the lifecycle policy applies to. Detailed below. */ recipes?: outputs.imagebuilder.LifecyclePolicyResourceSelectionRecipe[]; /** * A list of tags that are used as selection criteria for the Image Builder image resources that the lifecycle policy applies to. */ tagMap?: { [key: string]: string; }; } interface LifecyclePolicyResourceSelectionRecipe { /** * The name of an Image Builder recipe that the lifecycle policy uses for resource selection. */ name: string; /** * The version of the Image Builder recipe specified by the `name` field. Wildcard semantic version is supported (e.g. `1.0.x`, `1.x.x`, `x.x.x`). */ semanticVersion: string; } } export declare namespace inspector { interface AssessmentTemplateEventSubscription { /** * The event for which you want to receive SNS notifications. Valid values are `ASSESSMENT_RUN_STARTED`, `ASSESSMENT_RUN_COMPLETED`, `ASSESSMENT_RUN_STATE_CHANGED`, and `FINDING_REPORTED`. */ event: string; /** * The ARN of the SNS topic to which notifications are sent. */ topicArn: string; } } export declare namespace inspector2 { interface FilterFilterCriteria { /** * (Optional) The AWS account ID in which the finding was generated. Documented below. */ awsAccountIds?: outputs.inspector2.FilterFilterCriteriaAwsAccountId[]; /** * (Optional) The project name in a code repository. Documented below. */ codeRepositoryProjectNames?: outputs.inspector2.FilterFilterCriteriaCodeRepositoryProjectName[]; /** * (Optional) The repository provider type (such as GitHub, GitLab, etc.) Documented below. */ codeRepositoryProviderTypes?: outputs.inspector2.FilterFilterCriteriaCodeRepositoryProviderType[]; /** * (Optional) The ID of the component. Documented below. */ codeVulnerabilityDetectorNames?: outputs.inspector2.FilterFilterCriteriaCodeVulnerabilityDetectorName[]; /** * (Optional) The ID of the component. Documented below. */ codeVulnerabilityDetectorTags?: outputs.inspector2.FilterFilterCriteriaCodeVulnerabilityDetectorTag[]; /** * (Optional) The ID of the component. Documented below. */ codeVulnerabilityFilePaths?: outputs.inspector2.FilterFilterCriteriaCodeVulnerabilityFilePath[]; /** * (Optional) The ID of the component. Documented below. */ componentIds?: outputs.inspector2.FilterFilterCriteriaComponentId[]; /** * (Optional) The type of the component. Documented below. */ componentTypes?: outputs.inspector2.FilterFilterCriteriaComponentType[]; /** * (Optional) ID of the AMI. Documented below. */ ec2InstanceImageIds?: outputs.inspector2.FilterFilterCriteriaEc2InstanceImageId[]; /** * (Optional) The ID of the subnet. Documented below. */ ec2InstanceSubnetIds?: outputs.inspector2.FilterFilterCriteriaEc2InstanceSubnetId[]; /** * (Optional) The ID of the VPC. Documented below. */ ec2InstanceVpcIds?: outputs.inspector2.FilterFilterCriteriaEc2InstanceVpcId[]; /** * (Optional) The architecture of the ECR image. Documented below. */ ecrImageArchitectures?: outputs.inspector2.FilterFilterCriteriaEcrImageArchitecture[]; /** * (Optional) The SHA256 hash of the ECR image. Documented below. */ ecrImageHashes?: outputs.inspector2.FilterFilterCriteriaEcrImageHash[]; /** * (Optional) The number of the ECR images in use. Documented below. */ ecrImageInUseCounts?: outputs.inspector2.FilterFilterCriteriaEcrImageInUseCount[]; /** * (Optional) The date range when an ECR image was last used in an ECS cluster task or EKS cluster pod. Documented below. */ ecrImageLastInUseAts?: outputs.inspector2.FilterFilterCriteriaEcrImageLastInUseAt[]; /** * (Optional) The date range when the image was pushed. Documented below. */ ecrImagePushedAts?: outputs.inspector2.FilterFilterCriteriaEcrImagePushedAt[]; /** * (Optional) The registry of the ECR image. Documented below. */ ecrImageRegistries?: outputs.inspector2.FilterFilterCriteriaEcrImageRegistry[]; /** * (Optional) The name of the ECR repository. Documented below. */ ecrImageRepositoryNames?: outputs.inspector2.FilterFilterCriteriaEcrImageRepositoryName[]; /** * (Optional) The tags associated with the ECR image. Documented below. */ ecrImageTags?: outputs.inspector2.FilterFilterCriteriaEcrImageTag[]; /** * (Optional) EPSS (Exploit Prediction Scoring System) Score of the finding. Documented below. */ epssScores?: outputs.inspector2.FilterFilterCriteriaEpssScore[]; /** * (Optional) Availability of exploits. Documented below. */ exploitAvailables?: outputs.inspector2.FilterFilterCriteriaExploitAvailable[]; /** * (Optional) The ARN of the finding. Documented below. */ findingArns?: outputs.inspector2.FilterFilterCriteriaFindingArn[]; /** * (Optional) The status of the finding. Documented below. */ findingStatuses?: outputs.inspector2.FilterFilterCriteriaFindingStatus[]; /** * (Optional) The type of the finding. Documented below. */ findingTypes?: outputs.inspector2.FilterFilterCriteriaFindingType[]; /** * (Optional) When the finding was first observed. Documented below. */ firstObservedAts?: outputs.inspector2.FilterFilterCriteriaFirstObservedAt[]; /** * (Optional) Availability of the fix. Documented below. */ fixAvailables?: outputs.inspector2.FilterFilterCriteriaFixAvailable[]; /** * (Optional) The Inspector score given to the finding. Documented below. */ inspectorScores?: outputs.inspector2.FilterFilterCriteriaInspectorScore[]; /** * (Optional) Lambda execution role ARN. Documented below. */ lambdaFunctionExecutionRoleArns?: outputs.inspector2.FilterFilterCriteriaLambdaFunctionExecutionRoleArn[]; /** * (Optional) Last modified timestamp of the lambda function. Documented below. */ lambdaFunctionLastModifiedAts?: outputs.inspector2.FilterFilterCriteriaLambdaFunctionLastModifiedAt[]; /** * (Optional) Lambda function layers. Documented below. */ lambdaFunctionLayers?: outputs.inspector2.FilterFilterCriteriaLambdaFunctionLayer[]; /** * (Optional) Lambda function name. Documented below. */ lambdaFunctionNames?: outputs.inspector2.FilterFilterCriteriaLambdaFunctionName[]; /** * (Optional) Lambda function runtime. Documented below. */ lambdaFunctionRuntimes?: outputs.inspector2.FilterFilterCriteriaLambdaFunctionRuntime[]; /** * (Optional) When the finding was last observed. Documented below. */ lastObservedAts?: outputs.inspector2.FilterFilterCriteriaLastObservedAt[]; /** * (Optional) The network protocol of the finding. Documented below. */ networkProtocols?: outputs.inspector2.FilterFilterCriteriaNetworkProtocol[]; /** * (Optional) The port range of the finding. Documented below. */ portRanges?: outputs.inspector2.FilterFilterCriteriaPortRange[]; /** * (Optional) Related vulnerabilities. Documented below. */ relatedVulnerabilities?: outputs.inspector2.FilterFilterCriteriaRelatedVulnerability[]; /** * (Optional) The ID of the resource. Documented below. */ resourceIds?: outputs.inspector2.FilterFilterCriteriaResourceId[]; /** * (Optional) The tags of the resource. Documented below. */ resourceTags?: outputs.inspector2.FilterFilterCriteriaResourceTag[]; /** * (Optional) The type of the resource. Documented below. */ resourceTypes?: outputs.inspector2.FilterFilterCriteriaResourceType[]; /** * (Optional) The severity of the finding. Documented below. */ severities?: outputs.inspector2.FilterFilterCriteriaSeverity[]; /** * (Optional) The title of the finding. Documented below. */ titles?: outputs.inspector2.FilterFilterCriteriaTitle[]; /** * (Optional) When the finding was last updated. Documented below. */ updatedAts?: outputs.inspector2.FilterFilterCriteriaUpdatedAt[]; /** * (Optional) The severity as reported by the vendor. Documented below. */ vendorSeverities?: outputs.inspector2.FilterFilterCriteriaVendorSeverity[]; /** * (Optional) The ID of the vulnerability. Documented below. */ vulnerabilityIds?: outputs.inspector2.FilterFilterCriteriaVulnerabilityId[]; /** * (Optional) The source of the vulnerability. Documented below. */ vulnerabilitySources?: outputs.inspector2.FilterFilterCriteriaVulnerabilitySource[]; /** * (Optional) Details about vulnerable packages. Documented below. */ vulnerablePackages?: outputs.inspector2.FilterFilterCriteriaVulnerablePackage[]; } interface FilterFilterCriteriaAwsAccountId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaCodeRepositoryProjectName { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaCodeRepositoryProviderType { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaCodeVulnerabilityDetectorName { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaCodeVulnerabilityDetectorTag { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaCodeVulnerabilityFilePath { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaComponentId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaComponentType { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEc2InstanceImageId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEc2InstanceSubnetId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEc2InstanceVpcId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEcrImageArchitecture { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEcrImageHash { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEcrImageInUseCount { /** * (Optional) Lower bound of the range, inclusive. */ lowerInclusive: number; /** * (Optional) Upper bound of the range, inclusive. */ upperInclusive: number; } interface FilterFilterCriteriaEcrImageLastInUseAt { /** * (Required) The end of the port range, inclusive. */ endInclusive?: string; /** * (Optional) Start of the date range in RFC 3339 format, inclusive. Set the timezone to UTC. */ startInclusive?: string; } interface FilterFilterCriteriaEcrImagePushedAt { /** * (Required) The end of the port range, inclusive. */ endInclusive?: string; /** * (Optional) Start of the date range in RFC 3339 format, inclusive. Set the timezone to UTC. */ startInclusive?: string; } interface FilterFilterCriteriaEcrImageRegistry { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEcrImageRepositoryName { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEcrImageTag { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaEpssScore { /** * (Optional) Lower bound of the range, inclusive. */ lowerInclusive: number; /** * (Optional) Upper bound of the range, inclusive. */ upperInclusive: number; } interface FilterFilterCriteriaExploitAvailable { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaFindingArn { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaFindingStatus { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaFindingType { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaFirstObservedAt { /** * (Required) The end of the port range, inclusive. */ endInclusive?: string; /** * (Optional) Start of the date range in RFC 3339 format, inclusive. Set the timezone to UTC. */ startInclusive?: string; } interface FilterFilterCriteriaFixAvailable { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaInspectorScore { /** * (Optional) Lower bound of the range, inclusive. */ lowerInclusive: number; /** * (Optional) Upper bound of the range, inclusive. */ upperInclusive: number; } interface FilterFilterCriteriaLambdaFunctionExecutionRoleArn { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaLambdaFunctionLastModifiedAt { /** * (Required) The end of the port range, inclusive. */ endInclusive?: string; /** * (Optional) Start of the date range in RFC 3339 format, inclusive. Set the timezone to UTC. */ startInclusive?: string; } interface FilterFilterCriteriaLambdaFunctionLayer { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaLambdaFunctionName { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaLambdaFunctionRuntime { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaLastObservedAt { /** * (Required) The end of the port range, inclusive. */ endInclusive?: string; /** * (Optional) Start of the date range in RFC 3339 format, inclusive. Set the timezone to UTC. */ startInclusive?: string; } interface FilterFilterCriteriaNetworkProtocol { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaPortRange { /** * (Required) The beginning of the port range, inclusive. */ beginInclusive: number; /** * (Required) The end of the port range, inclusive. */ endInclusive: number; } interface FilterFilterCriteriaRelatedVulnerability { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaResourceId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaResourceTag { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The key to filter on. */ key: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaResourceType { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaSeverity { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaTitle { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaUpdatedAt { /** * (Required) The end of the port range, inclusive. */ endInclusive?: string; /** * (Optional) Start of the date range in RFC 3339 format, inclusive. Set the timezone to UTC. */ startInclusive?: string; } interface FilterFilterCriteriaVendorSeverity { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerabilityId { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerabilitySource { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackage { /** * (Optional) The architecture of the package. Documented below. */ architecture?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageArchitecture; /** * (Optional) The epoch of the package. Documented below. */ epoches?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageEpoch[]; /** * (Optional) The name of the package. Documented below. */ filePath?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageFilePath; /** * Name of the filter. */ name?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageName; /** * (Optional) The release of the package. Documented below. */ release?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageRelease; /** * (Optional) The ARN of the package's source lambda layer. Documented below. */ sourceLambdaLayerArn?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageSourceLambdaLayerArn; /** * (Optional) The source layer hash of the package. Documented below. */ sourceLayerHash?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageSourceLayerHash; /** * (Optional) The version of the package. Documented below. */ version?: outputs.inspector2.FilterFilterCriteriaVulnerablePackageVersion; } interface FilterFilterCriteriaVulnerablePackageArchitecture { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackageEpoch { /** * (Optional) Lower bound of the range, inclusive. */ lowerInclusive: number; /** * (Optional) Upper bound of the range, inclusive. */ upperInclusive: number; } interface FilterFilterCriteriaVulnerablePackageFilePath { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackageName { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackageRelease { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackageSourceLambdaLayerArn { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackageSourceLayerHash { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface FilterFilterCriteriaVulnerablePackageVersion { /** * (Required) The comparison operator. Valid values: `EQUALS`. */ comparison: string; /** * (Required) The value to filter on. */ value: string; } interface OrganizationConfigurationAutoEnable { /** * Whether code repository scans are automatically enabled for new members of your Amazon Inspector organization. */ codeRepository?: boolean; /** * Whether Amazon EC2 scans are automatically enabled for new members of your Amazon Inspector organization. */ ec2: boolean; /** * Whether Amazon ECR scans are automatically enabled for new members of your Amazon Inspector organization. */ ecr: boolean; /** * Whether Lambda Function scans are automatically enabled for new members of your Amazon Inspector organization. */ lambda?: boolean; /** * Whether AWS Lambda code scans are automatically enabled for new members of your Amazon Inspector organization. **Note:** Lambda code scanning requires Lambda standard scanning to be activated. Consequently, if you are setting this argument to `true`, you must also set the `lambda` argument to `true`. See [Scanning AWS Lambda functions with Amazon Inspector](https://docs.aws.amazon.com/inspector/latest/user/scanning-lambda.html#lambda-code-scans) for more information. */ lambdaCode?: boolean; } } export declare namespace invoicing { interface InvoiceUnitRule { /** * Set of AWS account IDs included in this invoice unit. */ linkedAccounts: string[]; } interface InvoiceUnitTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace iot { interface BillingGroupMetadata { creationDate: string; } interface BillingGroupProperties { /** * A description of the Billing Group. */ description?: string; } interface CaCertificateRegistrationConfig { /** * The ARN of the role. */ roleArn?: string; /** * The template body. */ templateBody?: string; /** * The name of the provisioning template. */ templateName?: string; } interface CaCertificateValidity { /** * The certificate is not valid after this date. */ notAfter: string; /** * The certificate is not valid before this date. */ notBefore: string; } interface DomainConfigurationAuthorizerConfig { /** * A Boolean that specifies whether the domain configuration's authorization service can be overridden. */ allowAuthorizerOverride?: boolean; /** * The name of the authorization service for a domain configuration. */ defaultAuthorizerName?: string; } interface DomainConfigurationTlsConfig { /** * The security policy for a domain configuration. */ securityPolicy: string; } interface IndexingConfigurationThingGroupIndexingConfiguration { /** * A list of thing group fields to index. This list cannot contain any managed fields. See below. */ customFields?: outputs.iot.IndexingConfigurationThingGroupIndexingConfigurationCustomField[]; /** * Contains fields that are indexed and whose types are already known by the Fleet Indexing service. See below. */ managedFields: outputs.iot.IndexingConfigurationThingGroupIndexingConfigurationManagedField[]; /** * Thing group indexing mode. Valid values: `OFF`, `ON`. */ thingGroupIndexingMode: string; } interface IndexingConfigurationThingGroupIndexingConfigurationCustomField { /** * The name of the field. */ name?: string; /** * The data type of the field. Valid values: `Number`, `String`, `Boolean`. */ type?: string; } interface IndexingConfigurationThingGroupIndexingConfigurationManagedField { /** * The name of the field. */ name?: string; /** * The data type of the field. Valid values: `Number`, `String`, `Boolean`. */ type?: string; } interface IndexingConfigurationThingIndexingConfiguration { /** * Contains custom field names and their data type. See below. */ customFields?: outputs.iot.IndexingConfigurationThingIndexingConfigurationCustomField[]; /** * Device Defender indexing mode. Valid values: `VIOLATIONS`, `OFF`. Default: `OFF`. */ deviceDefenderIndexingMode?: string; /** * Required if `namedShadowIndexingMode` is `ON`. Enables to add named shadows filtered by `filter` to fleet indexing configuration. */ filter: outputs.iot.IndexingConfigurationThingIndexingConfigurationFilter; /** * Contains fields that are indexed and whose types are already known by the Fleet Indexing service. See below. */ managedFields: outputs.iot.IndexingConfigurationThingIndexingConfigurationManagedField[]; /** * [Named shadow](https://docs.aws.amazon.com/iot/latest/developerguide/iot-device-shadows.html) indexing mode. Valid values: `ON`, `OFF`. Default: `OFF`. */ namedShadowIndexingMode?: string; /** * Thing connectivity indexing mode. Valid values: `STATUS`, `OFF`. Default: `OFF`. */ thingConnectivityIndexingMode?: string; /** * Thing indexing mode. Valid values: `REGISTRY`, `REGISTRY_AND_SHADOW`, `OFF`. */ thingIndexingMode: string; } interface IndexingConfigurationThingIndexingConfigurationCustomField { /** * The name of the field. */ name?: string; /** * The data type of the field. Valid values: `Number`, `String`, `Boolean`. */ type?: string; } interface IndexingConfigurationThingIndexingConfigurationFilter { /** * List of shadow names that you select to index. */ namedShadowNames?: string[]; } interface IndexingConfigurationThingIndexingConfigurationManagedField { /** * The name of the field. */ name?: string; /** * The data type of the field. Valid values: `Number`, `String`, `Boolean`. */ type?: string; } interface ProvisioningTemplatePreProvisioningHook { /** * The version of the payload that was sent to the target function. The only valid (and the default) payload version is `"2020-04-01"`. */ payloadVersion?: string; /** * The ARN of the target function. */ targetArn: string; } interface ThingGroupMetadata { creationDate: string; /** * The name of the parent Thing Group. */ parentGroupName: string; rootToParentGroups: outputs.iot.ThingGroupMetadataRootToParentGroup[]; } interface ThingGroupMetadataRootToParentGroup { groupArn: string; groupName: string; } interface ThingGroupProperties { /** * The Thing Group attributes. Defined below. */ attributePayload?: outputs.iot.ThingGroupPropertiesAttributePayload; /** * A description of the Thing Group. */ description?: string; } interface ThingGroupPropertiesAttributePayload { /** * Key-value map. */ attributes?: { [key: string]: string; }; } interface ThingTypeProperties { /** * The description of the thing type. */ description?: string; /** * A list of searchable thing attribute names. */ searchableAttributes: string[]; } interface TopicRuleCloudwatchAlarm { /** * The CloudWatch alarm name. */ alarmName: string; /** * The IAM role ARN that allows access to the CloudWatch alarm. */ roleArn: string; /** * The reason for the alarm change. */ stateReason: string; /** * The value of the alarm state. Acceptable values are: OK, ALARM, INSUFFICIENT_DATA. */ stateValue: string; } interface TopicRuleCloudwatchLog { /** * The payload that contains a JSON array of records will be sent to CloudWatch via a batch call. */ batchMode?: boolean; /** * The CloudWatch log group name. */ logGroupName: string; /** * The IAM role ARN that allows access to the CloudWatch alarm. */ roleArn: string; } interface TopicRuleCloudwatchMetric { /** * The CloudWatch metric name. */ metricName: string; /** * The CloudWatch metric namespace name. */ metricNamespace: string; /** * An optional Unix timestamp (http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/cloudwatch_concepts.html#about_timestamp). */ metricTimestamp?: string; /** * The metric unit (supported units can be found here: http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/cloudwatch_concepts.html#Unit) */ metricUnit: string; /** * The CloudWatch metric value. */ metricValue: string; /** * The IAM role ARN that allows access to the CloudWatch metric. */ roleArn: string; } interface TopicRuleDestinationVpcConfiguration { /** * The ARN of a role that has permission to create and attach to elastic network interfaces (ENIs). */ roleArn: string; /** * The security groups of the VPC destination. */ securityGroups?: string[]; /** * The subnet IDs of the VPC destination. */ subnetIds: string[]; /** * The ID of the VPC. */ vpcId: string; } interface TopicRuleDynamodb { /** * The hash key name. */ hashKeyField: string; /** * The hash key type. Valid values are "STRING" or "NUMBER". */ hashKeyType?: string; /** * The hash key value. */ hashKeyValue: string; /** * The operation. Valid values are "INSERT", "UPDATE", or "DELETE". */ operation?: string; /** * The action payload. */ payloadField?: string; /** * The range key name. */ rangeKeyField?: string; /** * The range key type. Valid values are "STRING" or "NUMBER". */ rangeKeyType?: string; /** * The range key value. */ rangeKeyValue?: string; /** * The ARN of the IAM role that grants access to the DynamoDB table. */ roleArn: string; /** * The name of the DynamoDB table. */ tableName: string; } interface TopicRuleDynamodbv2 { /** * Configuration block with DynamoDB Table to which the message will be written. Nested arguments below. */ putItem?: outputs.iot.TopicRuleDynamodbv2PutItem; /** * The ARN of the IAM role that grants access to the DynamoDB table. */ roleArn: string; } interface TopicRuleDynamodbv2PutItem { /** * The name of the DynamoDB table. */ tableName: string; } interface TopicRuleElasticsearch { /** * The endpoint of your Elasticsearch domain. */ endpoint: string; /** * The unique identifier for the document you are storing. */ id: string; /** * The Elasticsearch index where you want to store your data. */ index: string; /** * The IAM role ARN that has access to Elasticsearch. */ roleArn: string; /** * The type of document you are storing. */ type: string; } interface TopicRuleErrorAction { cloudwatchAlarm?: outputs.iot.TopicRuleErrorActionCloudwatchAlarm; cloudwatchLogs?: outputs.iot.TopicRuleErrorActionCloudwatchLogs; cloudwatchMetric?: outputs.iot.TopicRuleErrorActionCloudwatchMetric; dynamodb?: outputs.iot.TopicRuleErrorActionDynamodb; dynamodbv2?: outputs.iot.TopicRuleErrorActionDynamodbv2; elasticsearch?: outputs.iot.TopicRuleErrorActionElasticsearch; firehose?: outputs.iot.TopicRuleErrorActionFirehose; http?: outputs.iot.TopicRuleErrorActionHttp; iotAnalytics?: outputs.iot.TopicRuleErrorActionIotAnalytics; iotEvents?: outputs.iot.TopicRuleErrorActionIotEvents; kafka?: outputs.iot.TopicRuleErrorActionKafka; kinesis?: outputs.iot.TopicRuleErrorActionKinesis; lambda?: outputs.iot.TopicRuleErrorActionLambda; republish?: outputs.iot.TopicRuleErrorActionRepublish; s3?: outputs.iot.TopicRuleErrorActionS3; sns?: outputs.iot.TopicRuleErrorActionSns; sqs?: outputs.iot.TopicRuleErrorActionSqs; stepFunctions?: outputs.iot.TopicRuleErrorActionStepFunctions; timestream?: outputs.iot.TopicRuleErrorActionTimestream; } interface TopicRuleErrorActionCloudwatchAlarm { /** * The CloudWatch alarm name. */ alarmName: string; /** * The IAM role ARN that allows access to the CloudWatch alarm. */ roleArn: string; /** * The reason for the alarm change. */ stateReason: string; /** * The value of the alarm state. Acceptable values are: OK, ALARM, INSUFFICIENT_DATA. */ stateValue: string; } interface TopicRuleErrorActionCloudwatchLogs { /** * The payload that contains a JSON array of records will be sent to CloudWatch via a batch call. */ batchMode?: boolean; /** * The CloudWatch log group name. */ logGroupName: string; /** * The IAM role ARN that allows access to the CloudWatch alarm. */ roleArn: string; } interface TopicRuleErrorActionCloudwatchMetric { /** * The CloudWatch metric name. */ metricName: string; /** * The CloudWatch metric namespace name. */ metricNamespace: string; /** * An optional Unix timestamp (http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/cloudwatch_concepts.html#about_timestamp). */ metricTimestamp?: string; /** * The metric unit (supported units can be found here: http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/cloudwatch_concepts.html#Unit) */ metricUnit: string; /** * The CloudWatch metric value. */ metricValue: string; /** * The IAM role ARN that allows access to the CloudWatch metric. */ roleArn: string; } interface TopicRuleErrorActionDynamodb { /** * The hash key name. */ hashKeyField: string; /** * The hash key type. Valid values are "STRING" or "NUMBER". */ hashKeyType?: string; /** * The hash key value. */ hashKeyValue: string; /** * The operation. Valid values are "INSERT", "UPDATE", or "DELETE". */ operation?: string; /** * The action payload. */ payloadField?: string; /** * The range key name. */ rangeKeyField?: string; /** * The range key type. Valid values are "STRING" or "NUMBER". */ rangeKeyType?: string; /** * The range key value. */ rangeKeyValue?: string; /** * The ARN of the IAM role that grants access to the DynamoDB table. */ roleArn: string; /** * The name of the DynamoDB table. */ tableName: string; } interface TopicRuleErrorActionDynamodbv2 { /** * Configuration block with DynamoDB Table to which the message will be written. Nested arguments below. */ putItem?: outputs.iot.TopicRuleErrorActionDynamodbv2PutItem; /** * The ARN of the IAM role that grants access to the DynamoDB table. */ roleArn: string; } interface TopicRuleErrorActionDynamodbv2PutItem { /** * The name of the DynamoDB table. */ tableName: string; } interface TopicRuleErrorActionElasticsearch { /** * The endpoint of your Elasticsearch domain. */ endpoint: string; /** * The unique identifier for the document you are storing. */ id: string; /** * The Elasticsearch index where you want to store your data. */ index: string; /** * The IAM role ARN that has access to Elasticsearch. */ roleArn: string; /** * The type of document you are storing. */ type: string; } interface TopicRuleErrorActionFirehose { /** * The payload that contains a JSON array of records will be sent to Kinesis Firehose via a batch call. */ batchMode?: boolean; /** * The delivery stream name. */ deliveryStreamName: string; /** * The IAM role ARN that grants access to the Amazon Kinesis Firehose stream. */ roleArn: string; /** * A character separator that is used to separate records written to the Firehose stream. Valid values are: '\n' (newline), '\t' (tab), '\r\n' (Windows newline), ',' (comma). */ separator?: string; } interface TopicRuleErrorActionHttp { /** * The HTTPS URL used to verify ownership of `url`. */ confirmationUrl?: string; /** * Custom HTTP header IoT Core should send. It is possible to define more than one custom header. */ httpHeaders?: outputs.iot.TopicRuleErrorActionHttpHttpHeader[]; /** * The HTTPS URL. */ url: string; } interface TopicRuleErrorActionHttpHttpHeader { /** * The name of the HTTP header. */ key: string; /** * The value of the HTTP header. */ value: string; } interface TopicRuleErrorActionIotAnalytics { /** * The payload that contains a JSON array of records will be sent to IoT Analytics via a batch call. */ batchMode?: boolean; /** * Name of AWS IOT Analytics channel. */ channelName: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; } interface TopicRuleErrorActionIotEvents { /** * The payload that contains a JSON array of records will be sent to IoT Events via a batch call. */ batchMode?: boolean; /** * The name of the AWS IoT Events input. */ inputName: string; /** * Use this to ensure that only one input (message) with a given messageId is processed by an AWS IoT Events detector. */ messageId?: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; } interface TopicRuleErrorActionKafka { /** * Properties of the Apache Kafka producer client. For more info, see the [AWS documentation](https://docs.aws.amazon.com/iot/latest/developerguide/apache-kafka-rule-action.html). */ clientProperties: { [key: string]: string; }; /** * The ARN of Kafka action's VPC `aws.iot.TopicRuleDestination`. */ destinationArn: string; /** * The list of Kafka headers that you specify. Nested arguments below. */ headers?: outputs.iot.TopicRuleErrorActionKafkaHeader[]; /** * The Kafka message key. */ key?: string; /** * The Kafka message partition. */ partition?: string; /** * The Kafka topic for messages to be sent to the Kafka broker. */ topic: string; } interface TopicRuleErrorActionKafkaHeader { /** * The key of the Kafka header. */ key: string; /** * The value of the Kafka header. */ value: string; } interface TopicRuleErrorActionKinesis { /** * The partition key. */ partitionKey?: string; /** * The ARN of the IAM role that grants access to the Amazon Kinesis stream. */ roleArn: string; /** * The name of the Amazon Kinesis stream. */ streamName: string; } interface TopicRuleErrorActionLambda { /** * The ARN of the Lambda function. */ functionArn: string; } interface TopicRuleErrorActionRepublish { /** * The Quality of Service (QoS) level to use when republishing messages. Valid values are 0 or 1. The default value is 0. */ qos?: number; /** * The ARN of the IAM role that grants access. */ roleArn: string; /** * The name of the MQTT topic the message should be republished to. */ topic: string; } interface TopicRuleErrorActionS3 { /** * The Amazon S3 bucket name. */ bucketName: string; /** * The Amazon S3 canned ACL that controls access to the object identified by the object key. [Valid values](https://docs.aws.amazon.com/AmazonS3/latest/userguide/acl-overview.html#canned-acl). */ cannedAcl?: string; /** * The object key. */ key: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; } interface TopicRuleErrorActionSns { /** * The message format of the message to publish. Accepted values are "JSON" and "RAW". */ messageFormat?: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; /** * The ARN of the SNS topic. */ targetArn: string; } interface TopicRuleErrorActionSqs { /** * The URL of the Amazon SQS queue. */ queueUrl: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; /** * Specifies whether to use Base64 encoding. */ useBase64: boolean; } interface TopicRuleErrorActionStepFunctions { /** * The prefix used to generate, along with a UUID, the unique state machine execution name. */ executionNamePrefix?: string; /** * The ARN of the IAM role that grants access to start execution of the state machine. */ roleArn: string; /** * The name of the Step Functions state machine whose execution will be started. */ stateMachineName: string; } interface TopicRuleErrorActionTimestream { /** * The name of an Amazon Timestream database. */ databaseName: string; /** * Configuration blocks with metadata attributes of the time series that are written in each measure record. Nested arguments below. */ dimensions: outputs.iot.TopicRuleErrorActionTimestreamDimension[]; /** * The ARN of the role that grants permission to write to the Amazon Timestream database table. */ roleArn: string; /** * The name of the database table into which to write the measure records. */ tableName: string; /** * Configuration block specifying an application-defined value to replace the default value assigned to the Timestream record's timestamp in the time column. Nested arguments below. */ timestamp?: outputs.iot.TopicRuleErrorActionTimestreamTimestamp; } interface TopicRuleErrorActionTimestreamDimension { /** * The metadata dimension name. This is the name of the column in the Amazon Timestream database table record. */ name: string; /** * The value to write in this column of the database record. */ value: string; } interface TopicRuleErrorActionTimestreamTimestamp { /** * The precision of the timestamp value that results from the expression described in value. Valid values: `SECONDS`, `MILLISECONDS`, `MICROSECONDS`, `NANOSECONDS`. */ unit: string; /** * An expression that returns a long epoch time value. */ value: string; } interface TopicRuleFirehose { /** * The payload that contains a JSON array of records will be sent to Kinesis Firehose via a batch call. */ batchMode?: boolean; /** * The delivery stream name. */ deliveryStreamName: string; /** * The IAM role ARN that grants access to the Amazon Kinesis Firehose stream. */ roleArn: string; /** * A character separator that is used to separate records written to the Firehose stream. Valid values are: '\n' (newline), '\t' (tab), '\r\n' (Windows newline), ',' (comma). */ separator?: string; } interface TopicRuleHttp { /** * The HTTPS URL used to verify ownership of `url`. */ confirmationUrl?: string; /** * Custom HTTP header IoT Core should send. It is possible to define more than one custom header. */ httpHeaders?: outputs.iot.TopicRuleHttpHttpHeader[]; /** * The HTTPS URL. */ url: string; } interface TopicRuleHttpHttpHeader { /** * The name of the HTTP header. */ key: string; /** * The value of the HTTP header. */ value: string; } interface TopicRuleIotAnalytic { /** * The payload that contains a JSON array of records will be sent to IoT Analytics via a batch call. */ batchMode?: boolean; /** * Name of AWS IOT Analytics channel. */ channelName: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; } interface TopicRuleIotEvent { /** * The payload that contains a JSON array of records will be sent to IoT Events via a batch call. */ batchMode?: boolean; /** * The name of the AWS IoT Events input. */ inputName: string; /** * Use this to ensure that only one input (message) with a given messageId is processed by an AWS IoT Events detector. */ messageId?: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; } interface TopicRuleKafka { /** * Properties of the Apache Kafka producer client. For more info, see the [AWS documentation](https://docs.aws.amazon.com/iot/latest/developerguide/apache-kafka-rule-action.html). */ clientProperties: { [key: string]: string; }; /** * The ARN of Kafka action's VPC `aws.iot.TopicRuleDestination`. */ destinationArn: string; /** * The list of Kafka headers that you specify. Nested arguments below. */ headers?: outputs.iot.TopicRuleKafkaHeader[]; /** * The Kafka message key. */ key?: string; /** * The Kafka message partition. */ partition?: string; /** * The Kafka topic for messages to be sent to the Kafka broker. */ topic: string; } interface TopicRuleKafkaHeader { /** * The key of the Kafka header. */ key: string; /** * The value of the Kafka header. */ value: string; } interface TopicRuleKinesis { /** * The partition key. */ partitionKey?: string; /** * The ARN of the IAM role that grants access to the Amazon Kinesis stream. */ roleArn: string; /** * The name of the Amazon Kinesis stream. */ streamName: string; } interface TopicRuleLambda { /** * The ARN of the Lambda function. */ functionArn: string; } interface TopicRuleRepublish { /** * The Quality of Service (QoS) level to use when republishing messages. Valid values are 0 or 1. The default value is 0. */ qos?: number; /** * The ARN of the IAM role that grants access. */ roleArn: string; /** * The name of the MQTT topic the message should be republished to. */ topic: string; } interface TopicRuleS3 { /** * The Amazon S3 bucket name. */ bucketName: string; /** * The Amazon S3 canned ACL that controls access to the object identified by the object key. [Valid values](https://docs.aws.amazon.com/AmazonS3/latest/userguide/acl-overview.html#canned-acl). */ cannedAcl?: string; /** * The object key. */ key: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; } interface TopicRuleSns { /** * The message format of the message to publish. Accepted values are "JSON" and "RAW". */ messageFormat?: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; /** * The ARN of the SNS topic. */ targetArn: string; } interface TopicRuleSqs { /** * The URL of the Amazon SQS queue. */ queueUrl: string; /** * The ARN of the IAM role that grants access. */ roleArn: string; /** * Specifies whether to use Base64 encoding. */ useBase64: boolean; } interface TopicRuleStepFunction { /** * The prefix used to generate, along with a UUID, the unique state machine execution name. */ executionNamePrefix?: string; /** * The ARN of the IAM role that grants access to start execution of the state machine. */ roleArn: string; /** * The name of the Step Functions state machine whose execution will be started. */ stateMachineName: string; } interface TopicRuleTimestream { /** * The name of an Amazon Timestream database. */ databaseName: string; /** * Configuration blocks with metadata attributes of the time series that are written in each measure record. Nested arguments below. */ dimensions: outputs.iot.TopicRuleTimestreamDimension[]; /** * The ARN of the role that grants permission to write to the Amazon Timestream database table. */ roleArn: string; /** * The name of the database table into which to write the measure records. */ tableName: string; /** * Configuration block specifying an application-defined value to replace the default value assigned to the Timestream record's timestamp in the time column. Nested arguments below. */ timestamp?: outputs.iot.TopicRuleTimestreamTimestamp; } interface TopicRuleTimestreamDimension { /** * The metadata dimension name. This is the name of the column in the Amazon Timestream database table record. */ name: string; /** * The value to write in this column of the database record. */ value: string; } interface TopicRuleTimestreamTimestamp { /** * The precision of the timestamp value that results from the expression described in value. Valid values: `SECONDS`, `MILLISECONDS`, `MICROSECONDS`, `NANOSECONDS`. */ unit: string; /** * An expression that returns a long epoch time value. */ value: string; } } export declare namespace ivs { interface RecordingConfigurationDestinationConfiguration { /** * S3 destination configuration where recorded videos will be stored. */ s3: outputs.ivs.RecordingConfigurationDestinationConfigurationS3; } interface RecordingConfigurationDestinationConfigurationS3 { /** * S3 bucket name where recorded videos will be stored. * * The following arguments are optional: */ bucketName: string; } interface RecordingConfigurationThumbnailConfiguration { /** * Thumbnail recording mode. Valid values: `DISABLED`, `INTERVAL`. */ recordingMode: string; /** * The targeted thumbnail-generation interval in seconds. */ targetIntervalSeconds: number; } } export declare namespace ivschat { interface LoggingConfigurationDestinationConfiguration { /** * An Amazon CloudWatch Logs destination configuration where chat activity will be logged. */ cloudwatchLogs?: outputs.ivschat.LoggingConfigurationDestinationConfigurationCloudwatchLogs; /** * An Amazon Kinesis Data Firehose destination configuration where chat activity will be logged. */ firehose?: outputs.ivschat.LoggingConfigurationDestinationConfigurationFirehose; /** * An Amazon S3 destination configuration where chat activity will be logged. */ s3?: outputs.ivschat.LoggingConfigurationDestinationConfigurationS3; } interface LoggingConfigurationDestinationConfigurationCloudwatchLogs { /** * Name of the Amazon Cloudwatch Logs destination where chat activity will be logged. */ logGroupName: string; } interface LoggingConfigurationDestinationConfigurationFirehose { /** * Name of the Amazon Kinesis Firehose delivery stream where chat activity will be logged. */ deliveryStreamName: string; } interface LoggingConfigurationDestinationConfigurationS3 { /** * Name of the Amazon S3 bucket where chat activity will be logged. * * The following arguments are optional: */ bucketName: string; } interface RoomMessageReviewHandler { /** * The fallback behavior (whether the message * is allowed or denied) if the handler does not return a valid response, * encounters an error, or times out. Valid values: `ALLOW`, `DENY`. */ fallbackResult: string; /** * ARN of the lambda message review handler function. */ uri?: string; } } export declare namespace kendra { interface DataSourceConfiguration { /** * A block that provides the configuration information to connect to an Amazon S3 bucket as your data source. Detailed below. * * @deprecated s3_configuration is deprecated. Use templateConfiguration instead. */ s3Configuration?: outputs.kendra.DataSourceConfigurationS3Configuration; /** * A block that provides the configuration information required for Amazon Kendra Web Crawler. Detailed below. */ templateConfiguration?: outputs.kendra.DataSourceConfigurationTemplateConfiguration; /** * A block that provides the configuration information required for Amazon Kendra Web Crawler. Detailed below. * * @deprecated web_crawler_configuration is deprecated. Use templateConfiguration instead. */ webCrawlerConfiguration?: outputs.kendra.DataSourceConfigurationWebCrawlerConfiguration; } interface DataSourceConfigurationS3Configuration { /** * A block that provides the path to the S3 bucket that contains the user context filtering files for the data source. For the format of the file, see [Access control for S3 data sources](https://docs.aws.amazon.com/kendra/latest/dg/s3-acl.html). Detailed below. */ accessControlListConfiguration?: outputs.kendra.DataSourceConfigurationS3ConfigurationAccessControlListConfiguration; /** * The name of the bucket that contains the documents. */ bucketName: string; /** * A block that defines the Document metadata files that contain information such as the document access control information, source URI, document author, and custom attributes. Each metadata file contains metadata about a single document. Detailed below. */ documentsMetadataConfiguration?: outputs.kendra.DataSourceConfigurationS3ConfigurationDocumentsMetadataConfiguration; /** * A list of glob patterns for documents that should not be indexed. If a document that matches an inclusion prefix or inclusion pattern also matches an exclusion pattern, the document is not indexed. Refer to [Exclusion Patterns for more examples](https://docs.aws.amazon.com/kendra/latest/dg/API_S3DataSourceConfiguration.html#Kendra-Type-S3DataSourceConfiguration-ExclusionPatterns). */ exclusionPatterns?: string[]; /** * A list of glob patterns for documents that should be indexed. If a document that matches an inclusion pattern also matches an exclusion pattern, the document is not indexed. Refer to [Inclusion Patterns for more examples](https://docs.aws.amazon.com/kendra/latest/dg/API_S3DataSourceConfiguration.html#Kendra-Type-S3DataSourceConfiguration-InclusionPatterns). */ inclusionPatterns?: string[]; /** * A list of S3 prefixes for the documents that should be included in the index. */ inclusionPrefixes?: string[]; } interface DataSourceConfigurationS3ConfigurationAccessControlListConfiguration { /** * Path to the AWS S3 bucket that contains the ACL files. */ keyPath?: string; } interface DataSourceConfigurationS3ConfigurationDocumentsMetadataConfiguration { /** * A prefix used to filter metadata configuration files in the AWS S3 bucket. The S3 bucket might contain multiple metadata files. Use `s3Prefix` to include only the desired metadata files. */ s3Prefix?: string; } interface DataSourceConfigurationTemplateConfiguration { /** * JSON string containing a [data source template schema](https://docs.aws.amazon.com/kendra/latest/dg/ds-schemas.html). */ template: string; } interface DataSourceConfigurationWebCrawlerConfiguration { /** * A block with the configuration information required to connect to websites using authentication. You can connect to websites using basic authentication of user name and password. You use a secret in AWS Secrets Manager to store your authentication credentials. You must provide the website host name and port number. For example, the host name of `https://a.example.com/page1.html` is `"a.example.com"` and the port is `443`, the standard port for HTTPS. Detailed below. */ authenticationConfiguration?: outputs.kendra.DataSourceConfigurationWebCrawlerConfigurationAuthenticationConfiguration; /** * Specifies the number of levels in a website that you want to crawl. The first level begins from the website seed or starting point URL. For example, if a website has 3 levels - index level (i.e. seed in this example), sections level, and subsections level - and you are only interested in crawling information up to the sections level (i.e. levels 0-1), you can set your depth to 1. The default crawl depth is set to `2`. Minimum value of `0`. Maximum value of `10`. */ crawlDepth?: number; /** * The maximum size (in MB) of a webpage or attachment to crawl. Files larger than this size (in MB) are skipped/not crawled. The default maximum size of a webpage or attachment is set to `50` MB. Minimum value of `1.0e-06`. Maximum value of `50`. */ maxContentSizePerPageInMegaBytes?: number; /** * The maximum number of URLs on a webpage to include when crawling a website. This number is per webpage. As a website’s webpages are crawled, any URLs the webpages link to are also crawled. URLs on a webpage are crawled in order of appearance. The default maximum links per page is `100`. Minimum value of `1`. Maximum value of `1000`. */ maxLinksPerPage?: number; /** * The maximum number of URLs crawled per website host per minute. The default maximum number of URLs crawled per website host per minute is `300`. Minimum value of `1`. Maximum value of `300`. */ maxUrlsPerMinuteCrawlRate?: number; /** * Configuration information required to connect to your internal websites via a web proxy. You must provide the website host name and port number. For example, the host name of `https://a.example.com/page1.html` is `"a.example.com"` and the port is `443`, the standard port for HTTPS. Web proxy credentials are optional and you can use them to connect to a web proxy server that requires basic authentication. To store web proxy credentials, you use a secret in [AWS Secrets Manager](https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html). Detailed below. */ proxyConfiguration?: outputs.kendra.DataSourceConfigurationWebCrawlerConfigurationProxyConfiguration; /** * A list of regular expression patterns to exclude certain URLs to crawl. URLs that match the patterns are excluded from the index. URLs that don't match the patterns are included in the index. If a URL matches both an inclusion and exclusion pattern, the exclusion pattern takes precedence and the URL file isn't included in the index. Array Members: Minimum number of `0` items. Maximum number of `100` items. Length Constraints: Minimum length of `1`. Maximum length of `150`. */ urlExclusionPatterns?: string[]; /** * A list of regular expression patterns to include certain URLs to crawl. URLs that match the patterns are included in the index. URLs that don't match the patterns are excluded from the index. If a URL matches both an inclusion and exclusion pattern, the exclusion pattern takes precedence and the URL file isn't included in the index. Array Members: Minimum number of `0` items. Maximum number of `100` items. Length Constraints: Minimum length of `1`. Maximum length of `150`. */ urlInclusionPatterns?: string[]; /** * Block that specifies the seed or starting point URLs of the websites or the sitemap URLs of the websites you want to crawl. You can include website subdomains. You can list up to `100` seed URLs and up to `3` sitemap URLs. You can only crawl websites that use the secure communication protocol, HTTPS. If you receive an error when crawling a website, it could be that the website is blocked from crawling. When selecting websites to index, you must adhere to the [Amazon Acceptable Use Policy](https://aws.amazon.com/aup/) and all other Amazon terms. Remember that you must only use Amazon Kendra Web Crawler to index your own webpages, or webpages that you have authorization to index. Detailed below. */ urls: outputs.kendra.DataSourceConfigurationWebCrawlerConfigurationUrls; } interface DataSourceConfigurationWebCrawlerConfigurationAuthenticationConfiguration { /** * The list of configuration information that's required to connect to and crawl a website host using basic authentication credentials. The list includes the name and port number of the website host. Detailed below. */ basicAuthentications?: outputs.kendra.DataSourceConfigurationWebCrawlerConfigurationAuthenticationConfigurationBasicAuthentication[]; } interface DataSourceConfigurationWebCrawlerConfigurationAuthenticationConfigurationBasicAuthentication { /** * Your secret ARN, which you can create in AWS Secrets Manager. You use a secret if basic authentication credentials are required to connect to a website. The secret stores your credentials of user name and password. */ credentials: string; /** * The name of the website host you want to connect to using authentication credentials. For example, the host name of `https://a.example.com/page1.html` is `"a.example.com"`. */ host: string; /** * The port number of the website host you want to connect to using authentication credentials. For example, the port for `https://a.example.com/page1.html` is `443`, the standard port for HTTPS. */ port: number; } interface DataSourceConfigurationWebCrawlerConfigurationProxyConfiguration { /** * Your secret ARN, which you can create in AWS Secrets Manager. The credentials are optional. You use a secret if web proxy credentials are required to connect to a website host. Amazon Kendra currently support basic authentication to connect to a web proxy server. The secret stores your credentials. */ credentials?: string; /** * The name of the website host you want to connect to via a web proxy server. For example, the host name of `https://a.example.com/page1.html` is `"a.example.com"`. */ host: string; /** * The port number of the website host you want to connect to via a web proxy server. For example, the port for `https://a.example.com/page1.html` is `443`, the standard port for HTTPS. */ port: number; } interface DataSourceConfigurationWebCrawlerConfigurationUrls { /** * A block that specifies the configuration of the seed or starting point URLs of the websites you want to crawl. You can choose to crawl only the website host names, or the website host names with subdomains, or the website host names with subdomains and other domains that the webpages link to. You can list up to `100` seed URLs. Detailed below. */ seedUrlConfiguration?: outputs.kendra.DataSourceConfigurationWebCrawlerConfigurationUrlsSeedUrlConfiguration; /** * A block that specifies the configuration of the sitemap URLs of the websites you want to crawl. Only URLs belonging to the same website host names are crawled. You can list up to `3` sitemap URLs. Detailed below. */ siteMapsConfiguration?: outputs.kendra.DataSourceConfigurationWebCrawlerConfigurationUrlsSiteMapsConfiguration; } interface DataSourceConfigurationWebCrawlerConfigurationUrlsSeedUrlConfiguration { /** * The list of seed or starting point URLs of the websites you want to crawl. The list can include a maximum of `100` seed URLs. Array Members: Minimum number of `0` items. Maximum number of `100` items. Length Constraints: Minimum length of `1`. Maximum length of `2048`. */ seedUrls: string[]; /** * The default mode is set to `HOST_ONLY`. You can choose one of the following modes: * * `HOST_ONLY` - crawl only the website host names. For example, if the seed URL is `"abc.example.com"`, then only URLs with host name `"abc.example.com"` are crawled. * * `SUBDOMAINS` - crawl the website host names with subdomains. For example, if the seed URL is `"abc.example.com"`, then `"a.abc.example.com"` and `"b.abc.example.com"` are also crawled. * * `EVERYTHING` - crawl the website host names with subdomains and other domains that the webpages link to. */ webCrawlerMode?: string; } interface DataSourceConfigurationWebCrawlerConfigurationUrlsSiteMapsConfiguration { /** * The list of sitemap URLs of the websites you want to crawl. The list can include a maximum of `3` sitemap URLs. */ siteMaps: string[]; } interface DataSourceCustomDocumentEnrichmentConfiguration { /** * Configuration information to alter document attributes or metadata fields and content when ingesting documents into Amazon Kendra. Minimum number of `0` items. Maximum number of `100` items. Detailed below. */ inlineConfigurations?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationInlineConfiguration[]; /** * A block that specifies the configuration information for invoking a Lambda function in AWS Lambda on the structured documents with their metadata and text extracted. You can use a Lambda function to apply advanced logic for creating, modifying, or deleting document metadata and content. For more information, see [Advanced data manipulation](https://docs.aws.amazon.com/kendra/latest/dg/custom-document-enrichment.html#advanced-data-manipulation). Detailed below. */ postExtractionHookConfiguration?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationPostExtractionHookConfiguration; /** * Configuration information for invoking a Lambda function in AWS Lambda on the original or raw documents before extracting their metadata and text. You can use a Lambda function to apply advanced logic for creating, modifying, or deleting document metadata and content. For more information, see [Advanced data manipulation](https://docs.aws.amazon.com/kendra/latest/dg/custom-document-enrichment.html#advanced-data-manipulation). Detailed below. */ preExtractionHookConfiguration?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationPreExtractionHookConfiguration; /** * ARN of a role with permission to run `preExtractionHookConfiguration` and `postExtractionHookConfiguration` for altering document metadata and content during the document ingestion process. For more information, see [IAM roles for Amazon Kendra](https://docs.aws.amazon.com/kendra/latest/dg/iam-roles.html). */ roleArn?: string; } interface DataSourceCustomDocumentEnrichmentConfigurationInlineConfiguration { /** * Configuration of the condition used for the target document attribute or metadata field when ingesting documents into Amazon Kendra. See condition. */ condition?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationCondition; /** * `TRUE` to delete content if the condition used for the target attribute is met. */ documentContentDeletion?: boolean; /** * Configuration of the target document attribute or metadata field when ingesting documents into Amazon Kendra. You can also include a value. Detailed below. */ target?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationTarget; } interface DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationCondition { /** * The identifier of the document attribute used for the condition. For example, `_source_uri` could be an identifier for the attribute or metadata field that contains source URIs associated with the documents. Amazon Kendra currently does not support `_document_body` as an attribute key used for the condition. */ conditionDocumentAttributeKey: string; /** * The value used by the operator. For example, you can specify the value 'financial' for strings in the `_source_uri` field that partially match or contain this value. See condition_on_value. */ conditionOnValue?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationConditionConditionOnValue; /** * The condition operator. For example, you can use `Contains` to partially match a string. Valid Values: `GreaterThan` | `GreaterThanOrEquals` | `LessThan` | `LessThanOrEquals` | `Equals` | `NotEquals` | `Contains` | `NotContains` | `Exists` | `NotExists` | `BeginsWith`. */ operator: string; } interface DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationConditionConditionOnValue { /** * A date expressed as an ISO 8601 string. It is important for the time zone to be included in the ISO 8601 date-time format. As of this writing only UTC is supported. For example, `2012-03-25T12:30:10+00:00`. */ dateValue?: string; /** * A long integer value. */ longValue?: number; /** * A list of strings. */ stringListValues?: string[]; stringValue?: string; } interface DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationTarget { /** * The identifier of the target document attribute or metadata field. For example, 'Department' could be an identifier for the target attribute or metadata field that includes the department names associated with the documents. */ targetDocumentAttributeKey?: string; /** * The target value you want to create for the target attribute. For example, 'Finance' could be the target value for the target attribute key 'Department'. See target_document_attribute_value. */ targetDocumentAttributeValue?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationTargetTargetDocumentAttributeValue; /** * `TRUE` to delete the existing target value for your specified target attribute key. You cannot create a target value and set this to `TRUE`. To create a target value (`TargetDocumentAttributeValue`), set this to `FALSE`. */ targetDocumentAttributeValueDeletion?: boolean; } interface DataSourceCustomDocumentEnrichmentConfigurationInlineConfigurationTargetTargetDocumentAttributeValue { /** * A date expressed as an ISO 8601 string. It is important for the time zone to be included in the ISO 8601 date-time format. As of this writing only UTC is supported. For example, `2012-03-25T12:30:10+00:00`. */ dateValue?: string; /** * A long integer value. */ longValue?: number; /** * A list of strings. */ stringListValues?: string[]; stringValue?: string; } interface DataSourceCustomDocumentEnrichmentConfigurationPostExtractionHookConfiguration { /** * A block that specifies the condition used for when a Lambda function should be invoked. For example, you can specify a condition that if there are empty date-time values, then Amazon Kendra should invoke a function that inserts the current date-time. See invocation_condition. */ invocationCondition?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationPostExtractionHookConfigurationInvocationCondition; /** * ARN of a Lambda Function that can manipulate your document metadata fields or attributes and content. */ lambdaArn: string; /** * Stores the original, raw documents or the structured, parsed documents before and after altering them. For more information, see [Data contracts for Lambda functions](https://docs.aws.amazon.com/kendra/latest/dg/custom-document-enrichment.html#cde-data-contracts-lambda). */ s3Bucket: string; } interface DataSourceCustomDocumentEnrichmentConfigurationPostExtractionHookConfigurationInvocationCondition { /** * The identifier of the document attribute used for the condition. For example, `_source_uri` could be an identifier for the attribute or metadata field that contains source URIs associated with the documents. Amazon Kendra currently does not support `_document_body` as an attribute key used for the condition. */ conditionDocumentAttributeKey: string; /** * The value used by the operator. For example, you can specify the value 'financial' for strings in the `_source_uri` field that partially match or contain this value. See condition_on_value. */ conditionOnValue?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationPostExtractionHookConfigurationInvocationConditionConditionOnValue; /** * The condition operator. For example, you can use `Contains` to partially match a string. Valid Values: `GreaterThan` | `GreaterThanOrEquals` | `LessThan` | `LessThanOrEquals` | `Equals` | `NotEquals` | `Contains` | `NotContains` | `Exists` | `NotExists` | `BeginsWith`. */ operator: string; } interface DataSourceCustomDocumentEnrichmentConfigurationPostExtractionHookConfigurationInvocationConditionConditionOnValue { /** * A date expressed as an ISO 8601 string. It is important for the time zone to be included in the ISO 8601 date-time format. As of this writing only UTC is supported. For example, `2012-03-25T12:30:10+00:00`. */ dateValue?: string; /** * A long integer value. */ longValue?: number; /** * A list of strings. */ stringListValues?: string[]; stringValue?: string; } interface DataSourceCustomDocumentEnrichmentConfigurationPreExtractionHookConfiguration { /** * A block that specifies the condition used for when a Lambda function should be invoked. For example, you can specify a condition that if there are empty date-time values, then Amazon Kendra should invoke a function that inserts the current date-time. See invocation_condition. */ invocationCondition?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationPreExtractionHookConfigurationInvocationCondition; /** * ARN of a Lambda Function that can manipulate your document metadata fields or attributes and content. */ lambdaArn: string; /** * Stores the original, raw documents or the structured, parsed documents before and after altering them. For more information, see [Data contracts for Lambda functions](https://docs.aws.amazon.com/kendra/latest/dg/custom-document-enrichment.html#cde-data-contracts-lambda). */ s3Bucket: string; } interface DataSourceCustomDocumentEnrichmentConfigurationPreExtractionHookConfigurationInvocationCondition { /** * The identifier of the document attribute used for the condition. For example, `_source_uri` could be an identifier for the attribute or metadata field that contains source URIs associated with the documents. Amazon Kendra currently does not support `_document_body` as an attribute key used for the condition. */ conditionDocumentAttributeKey: string; /** * The value used by the operator. For example, you can specify the value 'financial' for strings in the `_source_uri` field that partially match or contain this value. See condition_on_value. */ conditionOnValue?: outputs.kendra.DataSourceCustomDocumentEnrichmentConfigurationPreExtractionHookConfigurationInvocationConditionConditionOnValue; /** * The condition operator. For example, you can use `Contains` to partially match a string. Valid Values: `GreaterThan` | `GreaterThanOrEquals` | `LessThan` | `LessThanOrEquals` | `Equals` | `NotEquals` | `Contains` | `NotContains` | `Exists` | `NotExists` | `BeginsWith`. */ operator: string; } interface DataSourceCustomDocumentEnrichmentConfigurationPreExtractionHookConfigurationInvocationConditionConditionOnValue { /** * A date expressed as an ISO 8601 string. It is important for the time zone to be included in the ISO 8601 date-time format. As of this writing only UTC is supported. For example, `2012-03-25T12:30:10+00:00`. */ dateValue?: string; /** * A long integer value. */ longValue?: number; /** * A list of strings. */ stringListValues?: string[]; stringValue?: string; } interface ExperienceConfiguration { /** * The identifiers of your data sources and FAQs. Or, you can specify that you want to use documents indexed via the `BatchPutDocument API`. The provider will only perform drift detection of its value when present in a configuration. Detailed below. */ contentSourceConfiguration: outputs.kendra.ExperienceConfigurationContentSourceConfiguration; /** * The AWS SSO field name that contains the identifiers of your users, such as their emails. Detailed below. */ userIdentityConfiguration?: outputs.kendra.ExperienceConfigurationUserIdentityConfiguration; } interface ExperienceConfigurationContentSourceConfiguration { /** * The identifiers of the data sources you want to use for your Amazon Kendra experience. Maximum number of 100 items. */ dataSourceIds?: string[]; /** * Whether to use documents you indexed directly using the `BatchPutDocument API`. Defaults to `false`. */ directPutContent?: boolean; /** * The identifier of the FAQs that you want to use for your Amazon Kendra experience. Maximum number of 100 items. */ faqIds?: string[]; } interface ExperienceConfigurationUserIdentityConfiguration { /** * The AWS SSO field name that contains the identifiers of your users, such as their emails. */ identityAttributeName: string; } interface ExperienceEndpoint { /** * The endpoint of your Amazon Kendra experience. */ endpoint: string; /** * The type of endpoint for your Amazon Kendra experience. */ endpointType: string; } interface FaqS3Path { /** * The name of the S3 bucket that contains the file. */ bucket: string; /** * The name of the file. * * The following arguments are optional: */ key: string; } interface GetExperienceConfiguration { /** * The identifiers of your data sources and FAQs. This is the content you want to use for your Amazon Kendra Experience. Documented below. */ contentSourceConfigurations: outputs.kendra.GetExperienceConfigurationContentSourceConfiguration[]; /** * The AWS SSO field name that contains the identifiers of your users, such as their emails. Documented below. */ userIdentityConfigurations: outputs.kendra.GetExperienceConfigurationUserIdentityConfiguration[]; } interface GetExperienceConfigurationContentSourceConfiguration { /** * Identifiers of the data sources you want to use for your Amazon Kendra Experience. */ dataSourceIds: string[]; /** * Whether to use documents you indexed directly using the `BatchPutDocument API`. */ directPutContent: boolean; /** * Identifier of the FAQs that you want to use for your Amazon Kendra Experience. */ faqIds: string[]; } interface GetExperienceConfigurationUserIdentityConfiguration { /** * The AWS SSO field name that contains the identifiers of your users, such as their emails. */ identityAttributeName: string; } interface GetExperienceEndpoint { /** * Endpoint of your Amazon Kendra Experience. */ endpoint: string; /** * Type of endpoint for your Amazon Kendra Experience. */ endpointType: string; } interface GetFaqS3Path { /** * Name of the S3 bucket that contains the file. */ bucket: string; /** * Name of the file. */ key: string; } interface GetIndexCapacityUnit { /** * The amount of extra query capacity for an index and GetQuerySuggestions capacity. For more information, refer to [QueryCapacityUnits](https://docs.aws.amazon.com/kendra/latest/APIReference/API_CapacityUnitsConfiguration.html#Kendra-Type-CapacityUnitsConfiguration-QueryCapacityUnits). */ queryCapacityUnits: number; /** * The amount of extra storage capacity for an index. A single capacity unit provides 30 GB of storage space or 100,000 documents, whichever is reached first. Minimum value of 0. */ storageCapacityUnits: number; } interface GetIndexDocumentMetadataConfigurationUpdate { /** * Name of the index field. Minimum length of 1. Maximum length of 30. */ name: string; /** * Block that provides manual tuning parameters to determine how the field affects the search results. Documented below. */ relevances: outputs.kendra.GetIndexDocumentMetadataConfigurationUpdateRelevance[]; /** * Block that provides information about how the field is used during a search. Documented below. */ searches: outputs.kendra.GetIndexDocumentMetadataConfigurationUpdateSearch[]; /** * Data type of the index field. Valid values are `STRING_VALUE`, `STRING_LIST_VALUE`, `LONG_VALUE`, `DATE_VALUE`. */ type: string; } interface GetIndexDocumentMetadataConfigurationUpdateRelevance { /** * Time period that the boost applies to. For more information, refer to [Duration](https://docs.aws.amazon.com/kendra/latest/APIReference/API_Relevance.html#Kendra-Type-Relevance-Duration). */ duration: string; /** * How "fresh" a document is. For more information, refer to [Freshness](https://docs.aws.amazon.com/kendra/latest/APIReference/API_Relevance.html#Kendra-Type-Relevance-Freshness). */ freshness: boolean; /** * Relative importance of the field in the search. Larger numbers provide more of a boost than smaller numbers. Minimum value of 1. Maximum value of 10. */ importance: number; /** * Determines how values should be interpreted. For more information, refer to [RankOrder](https://docs.aws.amazon.com/kendra/latest/APIReference/API_Relevance.html#Kendra-Type-Relevance-RankOrder). */ rankOrder: string; /** * A list of values that should be given a different boost when they appear in the result list. For more information, refer to [ValueImportanceMap](https://docs.aws.amazon.com/kendra/latest/APIReference/API_Relevance.html#Kendra-Type-Relevance-ValueImportanceMap). */ valuesImportanceMap: { [key: string]: number; }; } interface GetIndexDocumentMetadataConfigurationUpdateSearch { /** * Determines whether the field is returned in the query response. The default is `true`. */ displayable: boolean; /** * Whether the field can be used to create search facets, a count of results for each value in the field. The default is `false`. */ facetable: boolean; /** * Determines whether the field is used in the search. If the Searchable field is true, you can use relevance tuning to manually tune how Amazon Kendra weights the field in the search. The default is `true` for `string` fields and `false` for `number` and `date` fields. */ searchable: boolean; /** * Determines whether the field can be used to sort the results of a query. If you specify sorting on a field that does not have Sortable set to true, Amazon Kendra returns an exception. The default is `false`. */ sortable: boolean; } interface GetIndexIndexStatistic { /** * Block that specifies the number of question and answer topics in the index. Documented below. */ faqStatistics: outputs.kendra.GetIndexIndexStatisticFaqStatistic[]; /** * A block that specifies the number of text documents indexed. */ textDocumentStatistics: outputs.kendra.GetIndexIndexStatisticTextDocumentStatistic[]; } interface GetIndexIndexStatisticFaqStatistic { /** * The total number of FAQ questions and answers contained in the index. */ indexedQuestionAnswersCount: number; } interface GetIndexIndexStatisticTextDocumentStatistic { /** * Total size, in bytes, of the indexed documents. */ indexedTextBytes: number; /** * The number of text documents indexed. */ indexedTextDocumentsCount: number; } interface GetIndexServerSideEncryptionConfiguration { /** * Identifier of the AWS KMScustomer master key (CMK). Amazon Kendra doesn't support asymmetric CMKs. */ kmsKeyId: string; } interface GetIndexUserGroupResolutionConfiguration { /** * The identity store provider (mode) you want to use to fetch access levels of groups and users. AWS Single Sign-On is currently the only available mode. Your users and groups must exist in an AWS SSO identity source in order to use this mode. Valid Values are `AWS_SSO` or `NONE`. */ userGroupResolutionMode: string; } interface GetIndexUserTokenConfiguration { /** * A block that specifies the information about the JSON token type configuration. */ jsonTokenTypeConfigurations: outputs.kendra.GetIndexUserTokenConfigurationJsonTokenTypeConfiguration[]; /** * A block that specifies the information about the JWT token type configuration. */ jwtTokenTypeConfigurations: outputs.kendra.GetIndexUserTokenConfigurationJwtTokenTypeConfiguration[]; } interface GetIndexUserTokenConfigurationJsonTokenTypeConfiguration { /** * The group attribute field. */ groupAttributeField: string; /** * The user name attribute field. */ userNameAttributeField: string; } interface GetIndexUserTokenConfigurationJwtTokenTypeConfiguration { /** * Regular expression that identifies the claim. */ claimRegex: string; /** * The group attribute field. */ groupAttributeField: string; /** * Issuer of the token. */ issuer: string; /** * Location of the key. Valid values are `URL` or `SECRET_MANAGER` */ keyLocation: string; /** * ARN of the secret. */ secretsManagerArn: string; /** * Signing key URL. */ url: string; /** * The user name attribute field. */ userNameAttributeField: string; } interface GetQuerySuggestionsBlockListSourceS3Path { /** * Name of the S3 bucket that contains the file. */ bucket: string; /** * Name of the file. */ key: string; } interface GetThesaurusSourceS3Path { /** * Name of the S3 bucket that contains the file. */ bucket: string; /** * Name of the file. */ key: string; } interface IndexCapacityUnits { /** * The amount of extra query capacity for an index and GetQuerySuggestions capacity. For more information, refer to [QueryCapacityUnits](https://docs.aws.amazon.com/kendra/latest/dg/API_CapacityUnitsConfiguration.html#Kendra-Type-CapacityUnitsConfiguration-QueryCapacityUnits). */ queryCapacityUnits: number; /** * The amount of extra storage capacity for an index. A single capacity unit provides 30 GB of storage space or 100,000 documents, whichever is reached first. Minimum value of 0. */ storageCapacityUnits: number; } interface IndexDocumentMetadataConfigurationUpdate { /** * The name of the index field. Minimum length of 1. Maximum length of 30. */ name: string; /** * A block that provides manual tuning parameters to determine how the field affects the search results. Detailed below */ relevance: outputs.kendra.IndexDocumentMetadataConfigurationUpdateRelevance; /** * A block that provides information about how the field is used during a search. Documented below. Detailed below */ search: outputs.kendra.IndexDocumentMetadataConfigurationUpdateSearch; /** * The data type of the index field. Valid values are `STRING_VALUE`, `STRING_LIST_VALUE`, `LONG_VALUE`, `DATE_VALUE`. */ type: string; } interface IndexDocumentMetadataConfigurationUpdateRelevance { /** * Specifies the time period that the boost applies to. For more information, refer to [Duration](https://docs.aws.amazon.com/kendra/latest/dg/API_Relevance.html#Kendra-Type-Relevance-Duration). */ duration: string; /** * Indicates that this field determines how "fresh" a document is. For more information, refer to [Freshness](https://docs.aws.amazon.com/kendra/latest/dg/API_Relevance.html#Kendra-Type-Relevance-Freshness). */ freshness: boolean; /** * The relative importance of the field in the search. Larger numbers provide more of a boost than smaller numbers. Minimum value of 1. Maximum value of 10. */ importance: number; /** * Determines how values should be interpreted. For more information, refer to [RankOrder](https://docs.aws.amazon.com/kendra/latest/dg/API_Relevance.html#Kendra-Type-Relevance-RankOrder). */ rankOrder: string; /** * A list of values that should be given a different boost when they appear in the result list. For more information, refer to [ValueImportanceMap](https://docs.aws.amazon.com/kendra/latest/dg/API_Relevance.html#Kendra-Type-Relevance-ValueImportanceMap). */ valuesImportanceMap: { [key: string]: number; }; } interface IndexDocumentMetadataConfigurationUpdateSearch { /** * Determines whether the field is returned in the query response. The default is `true`. */ displayable: boolean; /** * Indicates that the field can be used to create search facets, a count of results for each value in the field. The default is `false`. */ facetable: boolean; /** * Determines whether the field is used in the search. If the Searchable field is true, you can use relevance tuning to manually tune how Amazon Kendra weights the field in the search. The default is `true` for `string` fields and `false` for `number` and `date` fields. */ searchable: boolean; /** * Determines whether the field can be used to sort the results of a query. If you specify sorting on a field that does not have Sortable set to true, Amazon Kendra returns an exception. The default is `false`. */ sortable: boolean; } interface IndexIndexStatistic { /** * A block that specifies the number of question and answer topics in the index. Detailed below. */ faqStatistics: outputs.kendra.IndexIndexStatisticFaqStatistic[]; /** * A block that specifies the number of text documents indexed. Detailed below. */ textDocumentStatistics: outputs.kendra.IndexIndexStatisticTextDocumentStatistic[]; } interface IndexIndexStatisticFaqStatistic { /** * The total number of FAQ questions and answers contained in the index. */ indexedQuestionAnswersCount: number; } interface IndexIndexStatisticTextDocumentStatistic { /** * The total size, in bytes, of the indexed documents. */ indexedTextBytes: number; /** * The number of text documents indexed. */ indexedTextDocumentsCount: number; } interface IndexServerSideEncryptionConfiguration { /** * The identifier of the AWS KMScustomer master key (CMK). Amazon Kendra doesn't support asymmetric CMKs. */ kmsKeyId?: string; } interface IndexUserGroupResolutionConfiguration { /** * The identity store provider (mode) you want to use to fetch access levels of groups and users. AWS Single Sign-On is currently the only available mode. Your users and groups must exist in an AWS SSO identity source in order to use this mode. Valid Values are `AWS_SSO` or `NONE`. */ userGroupResolutionMode: string; } interface IndexUserTokenConfigurations { /** * A block that specifies the information about the JSON token type configuration. Detailed below. */ jsonTokenTypeConfiguration?: outputs.kendra.IndexUserTokenConfigurationsJsonTokenTypeConfiguration; /** * A block that specifies the information about the JWT token type configuration. Detailed below. */ jwtTokenTypeConfiguration?: outputs.kendra.IndexUserTokenConfigurationsJwtTokenTypeConfiguration; } interface IndexUserTokenConfigurationsJsonTokenTypeConfiguration { /** * The group attribute field. Minimum length of 1. Maximum length of 2048. */ groupAttributeField: string; /** * The user name attribute field. Minimum length of 1. Maximum length of 2048. */ userNameAttributeField: string; } interface IndexUserTokenConfigurationsJwtTokenTypeConfiguration { /** * The regular expression that identifies the claim. Minimum length of 1. Maximum length of 100. */ claimRegex?: string; /** * The group attribute field. Minimum length of 1. Maximum length of 100. */ groupAttributeField?: string; /** * The issuer of the token. Minimum length of 1. Maximum length of 65. */ issuer?: string; /** * The location of the key. Valid values are `URL` or `SECRET_MANAGER` */ keyLocation: string; /** * ARN of the secret. */ secretsManagerArn?: string; /** * The signing key URL. Valid pattern is `^(https?|ftp|file):\/\/([^\s]*)` */ url?: string; /** * The user name attribute field. Minimum length of 1. Maximum length of 100. */ userNameAttributeField?: string; } interface QuerySuggestionsBlockListSourceS3Path { /** * Name of the S3 bucket that contains the file. */ bucket: string; /** * Name of the file. * * The following arguments are optional: */ key: string; } interface ThesaurusSourceS3Path { /** * The name of the S3 bucket that contains the file. */ bucket: string; /** * The name of the file. * * The following arguments are optional: */ key: string; } } export declare namespace keyspaces { interface KeyspaceReplicationSpecification { /** * Replication regions. If `replicationStrategy` is `MULTI_REGION`, `regionList` requires the current Region and at least one additional AWS Region where the keyspace is going to be replicated in. */ regionLists?: string[]; /** * Replication strategy. Valid values: `SINGLE_REGION` and `MULTI_REGION`. */ replicationStrategy: string; } interface TableCapacitySpecification { /** * The throughput capacity specified for read operations defined in read capacity units (RCUs). */ readCapacityUnits?: number; /** * The read/write throughput capacity mode for a table. Valid values: `PAY_PER_REQUEST`, `PROVISIONED`. The default value is `PAY_PER_REQUEST`. */ throughputMode: string; /** * The throughput capacity specified for write operations defined in write capacity units (WCUs). */ writeCapacityUnits?: number; } interface TableClientSideTimestamps { /** * Shows how to enable client-side timestamps settings for the specified table. Valid values: `ENABLED`. */ status: string; } interface TableComment { /** * A description of the table. */ message: string; } interface TableEncryptionSpecification { /** * ARN of the customer managed KMS key. */ kmsKeyIdentifier?: string; /** * The encryption option specified for the table. Valid values: `AWS_OWNED_KMS_KEY`, `CUSTOMER_MANAGED_KMS_KEY`. The default value is `AWS_OWNED_KMS_KEY`. */ type: string; } interface TablePointInTimeRecovery { /** * Valid values: `ENABLED`, `DISABLED`. The default value is `DISABLED`. */ status: string; } interface TableSchemaDefinition { /** * The columns that are part of the clustering key of the table. */ clusteringKeys?: outputs.keyspaces.TableSchemaDefinitionClusteringKey[]; /** * The regular columns of the table. */ columns: outputs.keyspaces.TableSchemaDefinitionColumn[]; /** * The columns that are part of the partition key of the table . */ partitionKeys: outputs.keyspaces.TableSchemaDefinitionPartitionKey[]; /** * The columns that have been defined as `STATIC`. Static columns store values that are shared by all rows in the same partition. */ staticColumns?: outputs.keyspaces.TableSchemaDefinitionStaticColumn[]; } interface TableSchemaDefinitionClusteringKey { /** * The name of the clustering key column. */ name: string; /** * The order modifier. Valid values: `ASC`, `DESC`. */ orderBy: string; } interface TableSchemaDefinitionColumn { /** * The name of the column. */ name: string; /** * The data type of the column. See the [Developer Guide](https://docs.aws.amazon.com/keyspaces/latest/devguide/cql.elements.html#cql.data-types) for a list of available data types. */ type: string; } interface TableSchemaDefinitionPartitionKey { /** * The name of the partition key column. */ name: string; } interface TableSchemaDefinitionStaticColumn { /** * The name of the static column. */ name: string; } interface TableTtl { /** * Valid values: `ENABLED`. */ status: string; } } export declare namespace kinesis { interface AccountSettingsMinimumThroughputBillingCommitment { earliestAllowedEndAt: string; endedAt: string; startedAt: string; /** * Desired status of the minimum throughput billing commitment. Valid values: `ENABLED`, `DISABLED`. */ status: string; statusActual: string; } interface AnalyticsApplicationCloudwatchLoggingOptions { /** * The ARN of the Kinesis Analytics Application. */ id: string; /** * The ARN of the CloudWatch Log Stream. */ logStreamArn: string; /** * The ARN of the IAM Role used to send application messages. */ roleArn: string; } interface AnalyticsApplicationInputs { /** * The ARN of the Kinesis Analytics Application. */ id: string; /** * The Kinesis Firehose configuration for the streaming source. Conflicts with `kinesisStream`. * See Kinesis Firehose below for more details. */ kinesisFirehose?: outputs.kinesis.AnalyticsApplicationInputsKinesisFirehose; /** * The Kinesis Stream configuration for the streaming source. Conflicts with `kinesisFirehose`. * See Kinesis Stream below for more details. */ kinesisStream?: outputs.kinesis.AnalyticsApplicationInputsKinesisStream; /** * The Name Prefix to use when creating an in-application stream. */ namePrefix: string; /** * The number of Parallel in-application streams to create. * See Parallelism below for more details. */ parallelism: outputs.kinesis.AnalyticsApplicationInputsParallelism; /** * The Processing Configuration to transform records as they are received from the stream. * See Processing Configuration below for more details. */ processingConfiguration?: outputs.kinesis.AnalyticsApplicationInputsProcessingConfiguration; /** * The Schema format of the data in the streaming source. See Source Schema below for more details. */ schema: outputs.kinesis.AnalyticsApplicationInputsSchema; /** * The point at which the application starts processing records from the streaming source. * See Starting Position Configuration below for more details. */ startingPositionConfigurations: outputs.kinesis.AnalyticsApplicationInputsStartingPositionConfiguration[]; streamNames: string[]; } interface AnalyticsApplicationInputsKinesisFirehose { /** * The ARN of the Kinesis Firehose delivery stream. */ resourceArn: string; /** * The ARN of the IAM Role used to access the stream. */ roleArn: string; } interface AnalyticsApplicationInputsKinesisStream { /** * The ARN of the Kinesis Stream. */ resourceArn: string; /** * The ARN of the IAM Role used to access the stream. */ roleArn: string; } interface AnalyticsApplicationInputsParallelism { /** * The Count of streams. */ count: number; } interface AnalyticsApplicationInputsProcessingConfiguration { /** * The Lambda function configuration. See Lambda below for more details. */ lambda: outputs.kinesis.AnalyticsApplicationInputsProcessingConfigurationLambda; } interface AnalyticsApplicationInputsProcessingConfigurationLambda { /** * The ARN of the Lambda function. */ resourceArn: string; /** * The ARN of the IAM Role used to access the Lambda function. */ roleArn: string; } interface AnalyticsApplicationInputsSchema { /** * The Record Column mapping for the streaming source data element. * See Record Columns below for more details. */ recordColumns: outputs.kinesis.AnalyticsApplicationInputsSchemaRecordColumn[]; /** * The Encoding of the record in the streaming source. */ recordEncoding?: string; /** * The Record Format and mapping information to schematize a record. * See Record Format below for more details. */ recordFormat: outputs.kinesis.AnalyticsApplicationInputsSchemaRecordFormat; } interface AnalyticsApplicationInputsSchemaRecordColumn { /** * The Mapping reference to the data element. */ mapping?: string; /** * Name of the column. */ name: string; /** * The SQL Type of the column. */ sqlType: string; } interface AnalyticsApplicationInputsSchemaRecordFormat { /** * The Mapping Information for the record format. * See Mapping Parameters below for more details. */ mappingParameters?: outputs.kinesis.AnalyticsApplicationInputsSchemaRecordFormatMappingParameters; /** * The type of Record Format. Can be `CSV` or `JSON`. */ recordFormatType: string; } interface AnalyticsApplicationInputsSchemaRecordFormatMappingParameters { /** * Mapping information when the record format uses delimiters. * See CSV Mapping Parameters below for more details. */ csv?: outputs.kinesis.AnalyticsApplicationInputsSchemaRecordFormatMappingParametersCsv; /** * Mapping information when JSON is the record format on the streaming source. * See JSON Mapping Parameters below for more details. */ json?: outputs.kinesis.AnalyticsApplicationInputsSchemaRecordFormatMappingParametersJson; } interface AnalyticsApplicationInputsSchemaRecordFormatMappingParametersCsv { /** * The Column Delimiter. */ recordColumnDelimiter: string; /** * The Row Delimiter. */ recordRowDelimiter: string; } interface AnalyticsApplicationInputsSchemaRecordFormatMappingParametersJson { /** * Path to the top-level parent that contains the records. */ recordRowPath: string; } interface AnalyticsApplicationInputsStartingPositionConfiguration { /** * The starting position on the stream. Valid values: `LAST_STOPPED_POINT`, `NOW`, `TRIM_HORIZON`. */ startingPosition: string; } interface AnalyticsApplicationOutput { /** * The ARN of the Kinesis Analytics Application. */ id: string; /** * The Kinesis Firehose configuration for the destination stream. Conflicts with `kinesisStream`. * See Kinesis Firehose below for more details. */ kinesisFirehose?: outputs.kinesis.AnalyticsApplicationOutputKinesisFirehose; /** * The Kinesis Stream configuration for the destination stream. Conflicts with `kinesisFirehose`. * See Kinesis Stream below for more details. */ kinesisStream?: outputs.kinesis.AnalyticsApplicationOutputKinesisStream; /** * The Lambda function destination. See Lambda below for more details. */ lambda?: outputs.kinesis.AnalyticsApplicationOutputLambda; /** * The Name of the in-application stream. */ name: string; /** * The Schema format of the data written to the destination. See Destination Schema below for more details. */ schema: outputs.kinesis.AnalyticsApplicationOutputSchema; } interface AnalyticsApplicationOutputKinesisFirehose { /** * The ARN of the Kinesis Firehose delivery stream. */ resourceArn: string; /** * The ARN of the IAM Role used to access the stream. */ roleArn: string; } interface AnalyticsApplicationOutputKinesisStream { /** * The ARN of the Kinesis Stream. */ resourceArn: string; /** * The ARN of the IAM Role used to access the stream. */ roleArn: string; } interface AnalyticsApplicationOutputLambda { /** * The ARN of the Lambda function. */ resourceArn: string; /** * The ARN of the IAM Role used to access the Lambda function. */ roleArn: string; } interface AnalyticsApplicationOutputSchema { /** * The Format Type of the records on the output stream. Can be `CSV` or `JSON`. */ recordFormatType: string; } interface AnalyticsApplicationReferenceDataSources { /** * The ARN of the Kinesis Analytics Application. */ id: string; /** * The S3 configuration for the reference data source. See S3 Reference below for more details. */ s3: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesS3; /** * The Schema format of the data in the streaming source. See Source Schema below for more details. */ schema: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesSchema; /** * The in-application Table Name. */ tableName: string; } interface AnalyticsApplicationReferenceDataSourcesS3 { /** * The S3 Bucket ARN. */ bucketArn: string; /** * The File Key name containing reference data. */ fileKey: string; /** * The IAM Role ARN to read the data. */ roleArn: string; } interface AnalyticsApplicationReferenceDataSourcesSchema { /** * The Record Column mapping for the streaming source data element. * See Record Columns below for more details. */ recordColumns: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesSchemaRecordColumn[]; /** * The Encoding of the record in the streaming source. */ recordEncoding?: string; /** * The Record Format and mapping information to schematize a record. * See Record Format below for more details. */ recordFormat: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesSchemaRecordFormat; } interface AnalyticsApplicationReferenceDataSourcesSchemaRecordColumn { /** * The Mapping reference to the data element. */ mapping?: string; /** * Name of the column. */ name: string; /** * The SQL Type of the column. */ sqlType: string; } interface AnalyticsApplicationReferenceDataSourcesSchemaRecordFormat { /** * The Mapping Information for the record format. * See Mapping Parameters below for more details. */ mappingParameters?: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesSchemaRecordFormatMappingParameters; /** * The type of Record Format. Can be `CSV` or `JSON`. */ recordFormatType: string; } interface AnalyticsApplicationReferenceDataSourcesSchemaRecordFormatMappingParameters { /** * Mapping information when the record format uses delimiters. * See CSV Mapping Parameters below for more details. */ csv?: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesSchemaRecordFormatMappingParametersCsv; /** * Mapping information when JSON is the record format on the streaming source. * See JSON Mapping Parameters below for more details. */ json?: outputs.kinesis.AnalyticsApplicationReferenceDataSourcesSchemaRecordFormatMappingParametersJson; } interface AnalyticsApplicationReferenceDataSourcesSchemaRecordFormatMappingParametersCsv { /** * The Column Delimiter. */ recordColumnDelimiter: string; /** * The Row Delimiter. */ recordRowDelimiter: string; } interface AnalyticsApplicationReferenceDataSourcesSchemaRecordFormatMappingParametersJson { /** * Path to the top-level parent that contains the records. */ recordRowPath: string; } interface FirehoseDeliveryStreamElasticsearchConfiguration { /** * Buffer incoming data for the specified period of time, in seconds between 0 to 900, before delivering it to the destination. The default value is 300s. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs between 1 to 100, before delivering it to the destination. The default value is 5MB. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationCloudwatchLoggingOptions; /** * The endpoint to use when communicating with the cluster. Conflicts with `domainArn`. */ clusterEndpoint?: string; /** * The ARN of the Amazon ES domain. The pattern needs to be `arn:.*`. Conflicts with `clusterEndpoint`. */ domainArn?: string; /** * The Elasticsearch index name. */ indexName: string; /** * The Elasticsearch index rotation period. Index rotation appends a timestamp to the IndexName to facilitate expiration of old data. Valid values are `NoRotation`, `OneHour`, `OneDay`, `OneWeek`, and `OneMonth`. The default value is `OneDay`. */ indexRotationPeriod?: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationProcessingConfiguration; /** * After an initial failure to deliver to Amazon Elasticsearch, the total amount of time, in seconds between 0 to 7200, during which Firehose re-attempts delivery (including the first attempt). After this time has elapsed, the failed documents are written to Amazon S3. The default value is 300s. There will be no retry if the value is 0. */ retryDuration?: number; /** * The ARN of the IAM role to be assumed by Firehose for calling the Amazon ES Configuration API and for indexing documents. The IAM role must have permission for `DescribeElasticsearchDomain`, `DescribeElasticsearchDomains`, and `DescribeElasticsearchDomainConfig`. The pattern needs to be `arn:.*`. */ roleArn: string; /** * Defines how documents should be delivered to Amazon S3. Valid values are `FailedDocumentsOnly` and `AllDocuments`. Default value is `FailedDocumentsOnly`. */ s3BackupMode?: string; /** * The S3 Configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationS3Configuration; /** * The Elasticsearch type name with maximum length of 100 characters. */ typeName?: string; /** * The VPC configuration for the delivery stream to connect to Elastic Search associated with the VPC. See `vpcConfig` block below for details. */ vpcConfig?: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationVpcConfig; } interface FirehoseDeliveryStreamElasticsearchConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamElasticsearchConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamElasticsearchConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamElasticsearchConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamElasticsearchConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamElasticsearchConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamElasticsearchConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamElasticsearchConfigurationVpcConfig { /** * The ARN of the IAM role to be assumed by Firehose for calling the Amazon EC2 configuration API and for creating network interfaces. Make sure role has necessary [IAM permissions](https://docs.aws.amazon.com/firehose/latest/dev/controlling-access.html#using-iam-es-vpc) */ roleArn: string; /** * A list of security group IDs to associate with Kinesis Firehose. */ securityGroupIds: string[]; /** * A list of subnet IDs to associate with Kinesis Firehose. */ subnetIds: string[]; vpcId: string; } interface FirehoseDeliveryStreamExtendedS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; bufferingInterval?: number; bufferingSize?: number; cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * The time zone you prefer. Valid values are `UTC` or a non-3-letter IANA time zones (for example, `America/Los_Angeles`). Default value is `UTC`. */ customTimeZone?: string; /** * Nested argument for the serializer, deserializer, and schema for converting data from the JSON format to the Parquet or ORC format before writing it to Amazon S3. See `dataFormatConversionConfiguration` block below for details. */ dataFormatConversionConfiguration?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfiguration; /** * The configuration for dynamic partitioning. Required when using [dynamic partitioning](https://docs.aws.amazon.com/firehose/latest/dev/dynamic-partitioning.html). See `dynamicPartitioningConfiguration` block below for details. */ dynamicPartitioningConfiguration?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDynamicPartitioningConfiguration; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * The file extension to override the default file extension (for example, `.json`). */ fileExtension?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationProcessingConfiguration; roleArn: string; /** * The configuration for backup in Amazon S3. Required if `s3BackupMode` is `Enabled`. Supports the same fields as `s3Configuration` object. */ s3BackupConfiguration?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationS3BackupConfiguration; /** * The Amazon S3 backup mode. Valid values are `Disabled` and `Enabled`. Default value is `Disabled`. */ s3BackupMode?: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfiguration { /** * Defaults to `true`. Set it to `false` if you want to disable format conversion while preserving the configuration details. */ enabled?: boolean; /** * Specifies the deserializer that you want Kinesis Data Firehose to use to convert the format of your data from JSON. See `inputFormatConfiguration` block below for details. */ inputFormatConfiguration: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfiguration; /** * Specifies the serializer that you want Kinesis Data Firehose to use to convert the format of your data to the Parquet or ORC format. See `outputFormatConfiguration` block below for details. */ outputFormatConfiguration: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfiguration; /** * Specifies the AWS Glue Data Catalog table that contains the column information. See `schemaConfiguration` block below for details. */ schemaConfiguration: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationSchemaConfiguration; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfiguration { /** * Specifies which deserializer to use. You can choose either the Apache Hive JSON SerDe or the OpenX JSON SerDe. See `deserializer` block below for details. */ deserializer: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfigurationDeserializer; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfigurationDeserializer { /** * Specifies the native Hive / HCatalog JsonSerDe. More details below. See `hiveJsonSerDe` block below for details. */ hiveJsonSerDe?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfigurationDeserializerHiveJsonSerDe; /** * Specifies the OpenX SerDe. See `openXJsonSerDe` block below for details. */ openXJsonSerDe?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfigurationDeserializerOpenXJsonSerDe; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfigurationDeserializerHiveJsonSerDe { /** * A list of how you want Kinesis Data Firehose to parse the date and time stamps that may be present in your input data JSON. To specify these format strings, follow the pattern syntax of JodaTime's DateTimeFormat format strings. For more information, see [Class DateTimeFormat](https://www.joda.org/joda-time/apidocs/org/joda/time/format/DateTimeFormat.html). You can also use the special value millis to parse time stamps in epoch milliseconds. If you don't specify a format, Kinesis Data Firehose uses java.sql.Timestamp::valueOf by default. */ timestampFormats?: string[]; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationInputFormatConfigurationDeserializerOpenXJsonSerDe { /** * When set to true, which is the default, Kinesis Data Firehose converts JSON keys to lowercase before deserializing them. */ caseInsensitive?: boolean; /** * A map of column names to JSON keys that aren't identical to the column names. This is useful when the JSON contains keys that are Hive keywords. For example, timestamp is a Hive keyword. If you have a JSON key named timestamp, set this parameter to `{ ts = "timestamp" }` to map this key to a column named ts. */ columnToJsonKeyMappings?: { [key: string]: string; }; /** * When set to `true`, specifies that the names of the keys include dots and that you want Kinesis Data Firehose to replace them with underscores. This is useful because Apache Hive does not allow dots in column names. For example, if the JSON contains a key whose name is "a.b", you can define the column name to be "aB" when using this option. Defaults to `false`. */ convertDotsInJsonKeysToUnderscores?: boolean; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfiguration { /** * Specifies which serializer to use. You can choose either the ORC SerDe or the Parquet SerDe. See `serializer` block below for details. */ serializer: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfigurationSerializer; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfigurationSerializer { /** * Specifies converting data to the ORC format before storing it in Amazon S3. For more information, see [Apache ORC](https://orc.apache.org/docs/). See `orcSerDe` block below for details. */ orcSerDe?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfigurationSerializerOrcSerDe; /** * Specifies converting data to the Parquet format before storing it in Amazon S3. For more information, see [Apache Parquet](https://parquet.apache.org/docs/). More details below. */ parquetSerDe?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfigurationSerializerParquetSerDe; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfigurationSerializerOrcSerDe { /** * The Hadoop Distributed File System (HDFS) block size. This is useful if you intend to copy the data from Amazon S3 to HDFS before querying. The default is 256 MiB and the minimum is 64 MiB. Kinesis Data Firehose uses this value for padding calculations. */ blockSizeBytes?: number; /** * A list of column names for which you want Kinesis Data Firehose to create bloom filters. */ bloomFilterColumns?: string[]; /** * The Bloom filter false positive probability (FPP). The lower the FPP, the bigger the Bloom filter. The default value is `0.05`, the minimum is `0`, and the maximum is `1`. */ bloomFilterFalsePositiveProbability?: number; /** * The compression code to use over data blocks. The default is `SNAPPY`. */ compression?: string; /** * A float that represents the fraction of the total number of non-null rows. To turn off dictionary encoding, set this fraction to a number that is less than the number of distinct keys in a dictionary. To always use dictionary encoding, set this threshold to `1`. */ dictionaryKeyThreshold?: number; /** * Set this to `true` to indicate that you want stripes to be padded to the HDFS block boundaries. This is useful if you intend to copy the data from Amazon S3 to HDFS before querying. The default is `false`. */ enablePadding?: boolean; /** * The version of the file to write. The possible values are `V0_11` and `V0_12`. The default is `V0_12`. */ formatVersion?: string; /** * A float between 0 and 1 that defines the tolerance for block padding as a decimal fraction of stripe size. The default value is `0.05`, which means 5 percent of stripe size. For the default values of 64 MiB ORC stripes and 256 MiB HDFS blocks, the default block padding tolerance of 5 percent reserves a maximum of 3.2 MiB for padding within the 256 MiB block. In such a case, if the available size within the block is more than 3.2 MiB, a new, smaller stripe is inserted to fit within that space. This ensures that no stripe crosses block boundaries and causes remote reads within a node-local task. Kinesis Data Firehose ignores this parameter when `enablePadding` is `false`. */ paddingTolerance?: number; /** * The number of rows between index entries. The default is `10000` and the minimum is `1000`. */ rowIndexStride?: number; /** * The number of bytes in each stripe. The default is 64 MiB and the minimum is 8 MiB. */ stripeSizeBytes?: number; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationOutputFormatConfigurationSerializerParquetSerDe { /** * The Hadoop Distributed File System (HDFS) block size. This is useful if you intend to copy the data from Amazon S3 to HDFS before querying. The default is 256 MiB and the minimum is 64 MiB. Kinesis Data Firehose uses this value for padding calculations. */ blockSizeBytes?: number; /** * The compression code to use over data blocks. The possible values are `UNCOMPRESSED`, `SNAPPY`, and `GZIP`, with the default being `SNAPPY`. Use `SNAPPY` for higher decompression speed. Use `GZIP` if the compression ratio is more important than speed. */ compression?: string; /** * Indicates whether to enable dictionary compression. */ enableDictionaryCompression?: boolean; /** * The maximum amount of padding to apply. This is useful if you intend to copy the data from Amazon S3 to HDFS before querying. The default is `0`. */ maxPaddingBytes?: number; /** * The Parquet page size. Column chunks are divided into pages. A page is conceptually an indivisible unit (in terms of compression and encoding). The minimum value is 64 KiB and the default is 1 MiB. */ pageSizeBytes?: number; /** * Indicates the version of row format to output. The possible values are `V1` and `V2`. The default is `V1`. */ writerVersion?: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDataFormatConversionConfigurationSchemaConfiguration { /** * The ID of the AWS Glue Data Catalog. If you don't supply this, the AWS account ID is used by default. */ catalogId: string; /** * Specifies the name of the AWS Glue database that contains the schema for the output data. */ databaseName: string; /** * If you don't specify an AWS Region, the default is the current region. */ region: string; /** * The role that Kinesis Data Firehose can use to access AWS Glue. This role must be in the same account you use for Kinesis Data Firehose. Cross-account roles aren't allowed. */ roleArn: string; /** * Specifies the AWS Glue table that contains the column information that constitutes your data schema. */ tableName: string; /** * Specifies the table version for the output data schema. Defaults to `LATEST`. */ versionId?: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationDynamicPartitioningConfiguration { /** * Enables or disables dynamic partitioning. Defaults to `false`. */ enabled?: boolean; /** * Total amount of seconds Firehose spends on retries. Valid values between 0 and 7200. Default is 300. * * > **NOTE:** You can enable dynamic partitioning only when you create a new delivery stream. Once you enable dynamic partitioning on a delivery stream, it cannot be disabled on this delivery stream. Therefore, the provider will recreate the resource whenever dynamic partitioning is enabled or disabled. */ retryDuration?: number; } interface FirehoseDeliveryStreamExtendedS3ConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamExtendedS3ConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationS3BackupConfiguration { /** * The ARN of the S3 bucket */ bucketArn: string; bufferingInterval?: number; bufferingSize?: number; cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamExtendedS3ConfigurationS3BackupConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; roleArn: string; } interface FirehoseDeliveryStreamExtendedS3ConfigurationS3BackupConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamHttpEndpointConfiguration { /** * The access key required for Kinesis Firehose to authenticate with the HTTP endpoint selected as the destination. */ accessKey?: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300 (5 minutes). */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationCloudwatchLoggingOptions; /** * The HTTP endpoint name. */ name?: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationProcessingConfiguration; /** * The request configuration. See `requestConfiguration` block below for details. */ requestConfiguration: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationRequestConfiguration; /** * Total amount of seconds Firehose spends on retries. This duration starts after the initial attempt fails, It does not include the time periods during which Firehose waits for acknowledgment from the specified destination after each attempt. Valid values between `0` and `7200`. Default is `300`. */ retryDuration?: number; /** * Kinesis Data Firehose uses this IAM role for all the permissions that the delivery stream needs. The pattern needs to be `arn:.*`. */ roleArn?: string; /** * Defines how documents should be delivered to Amazon S3. Valid values are `FailedDataOnly` and `AllData`. Default value is `FailedDataOnly`. */ s3BackupMode?: string; /** * The S3 Configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationS3Configuration; /** * The Secret Manager Configuration. See `secretsManagerConfiguration` block below for details. */ secretsManagerConfiguration: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationSecretsManagerConfiguration; /** * The HTTP endpoint URL to which Kinesis Firehose sends your data. Refer to the target vendor's documentation for the correct intake URL (for example, [New Relic](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/connect/aws-firehose/) or [Datadog](https://docs.datadoghq.com/integrations/amazon_kinesis_data_firehose/)). */ url: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamHttpEndpointConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationRequestConfiguration { /** * Describes the metadata sent to the HTTP endpoint destination. See `commonAttributes` block below for details. */ commonAttributes?: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationRequestConfigurationCommonAttribute[]; /** * Kinesis Data Firehose uses the content encoding to compress the body of a request before sending the request to the destination. Valid values are `NONE` and `GZIP`. Default value is `NONE`. */ contentEncoding?: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationRequestConfigurationCommonAttribute { /** * The name of the HTTP endpoint common attribute. */ name: string; /** * The value of the HTTP endpoint common attribute. */ value: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamHttpEndpointConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamHttpEndpointConfigurationSecretsManagerConfiguration { /** * Enables or disables the Secrets Manager configuration. */ enabled: boolean; /** * The ARN of the role the stream assumes. */ roleArn?: string; /** * The ARN of the Secrets Manager secret. This value is required if `enabled` is true. */ secretArn?: string; } interface FirehoseDeliveryStreamIcebergConfiguration { appendOnly: boolean; /** * Buffer incoming data for the specified period of time, in seconds between 0 and 900, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs between 1 and 128, before delivering it to the destination. The default value is 5. */ bufferingSize?: number; /** * Glue catalog ARN identifier of the destination Apache Iceberg Tables. You must specify the ARN in the format `arn:aws:glue:region:account-id:catalog` */ catalogArn: string; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationCloudwatchLoggingOptions; /** * Destination table configurations which Firehose uses to deliver data to Apache Iceberg Tables. Firehose will write data with insert if table specific configuration is not provided. See `destinationTableConfiguration` block below for details. */ destinationTableConfigurations?: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationDestinationTableConfiguration[]; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationProcessingConfiguration; /** * The period of time, in seconds between 0 to 7200, during which Firehose retries to deliver data to the specified destination. */ retryDuration?: number; /** * The ARN of the IAM role to be assumed by Firehose for calling Apache Iceberg Tables. */ roleArn: string; s3BackupMode?: string; /** * The S3 Configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationS3Configuration; } interface FirehoseDeliveryStreamIcebergConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamIcebergConfigurationDestinationTableConfiguration { /** * The name of the Apache Iceberg database. */ databaseName: string; /** * The table specific S3 error output prefix. All the errors that occurred while delivering to this table will be prefixed with this value in S3 destination. */ s3ErrorOutputPrefix?: string; /** * The name of the Apache Iceberg Table. */ tableName: string; /** * A list of unique keys for a given Apache Iceberg table. Firehose will use these for running Create, Update, or Delete operations on the given Iceberg table. */ uniqueKeys?: string[]; } interface FirehoseDeliveryStreamIcebergConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamIcebergConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamIcebergConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamIcebergConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamIcebergConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamIcebergConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamKinesisSourceConfiguration { /** * The kinesis stream used as the source of the firehose delivery stream. */ kinesisStreamArn: string; /** * The ARN of the role that provides access to the source Kinesis stream. */ roleArn: string; } interface FirehoseDeliveryStreamMskSourceConfiguration { /** * The authentication configuration of the Amazon MSK cluster. See `authenticationConfiguration` block below for details. */ authenticationConfiguration: outputs.kinesis.FirehoseDeliveryStreamMskSourceConfigurationAuthenticationConfiguration; /** * The ARN of the Amazon MSK cluster. */ mskClusterArn: string; /** * The start date and time in UTC for the offset position within your MSK topic from where Firehose begins to read. By default, this is set to timestamp when Firehose becomes Active. If you want to create a Firehose stream with Earliest start position set the `readFromTimestamp` parameter to Epoch (1970-01-01T00:00:00Z). */ readFromTimestamp?: string; /** * The topic name within the Amazon MSK cluster. */ topicName: string; } interface FirehoseDeliveryStreamMskSourceConfigurationAuthenticationConfiguration { /** * The type of connectivity used to access the Amazon MSK cluster. Valid values: `PUBLIC`, `PRIVATE`. */ connectivity: string; /** * The ARN of the role used to access the Amazon MSK cluster. */ roleArn: string; } interface FirehoseDeliveryStreamOpensearchConfiguration { /** * Buffer incoming data for the specified period of time, in seconds between 0 to 900, before delivering it to the destination. The default value is 300s. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs between 1 to 100, before delivering it to the destination. The default value is 5MB. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationCloudwatchLoggingOptions; /** * The endpoint to use when communicating with the cluster. Conflicts with `domainArn`. */ clusterEndpoint?: string; /** * The method for setting up document ID. See [`documentIdOptions` block] below for details. */ documentIdOptions?: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationDocumentIdOptions; /** * The ARN of the Amazon ES domain. The pattern needs to be `arn:.*`. Conflicts with `clusterEndpoint`. */ domainArn?: string; /** * The OpenSearch index name. */ indexName: string; /** * The OpenSearch index rotation period. Index rotation appends a timestamp to the IndexName to facilitate expiration of old data. Valid values are `NoRotation`, `OneHour`, `OneDay`, `OneWeek`, and `OneMonth`. The default value is `OneDay`. */ indexRotationPeriod?: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationProcessingConfiguration; /** * After an initial failure to deliver to Amazon OpenSearch, the total amount of time, in seconds between 0 to 7200, during which Firehose re-attempts delivery (including the first attempt). After this time has elapsed, the failed documents are written to Amazon S3. The default value is 300s. There will be no retry if the value is 0. */ retryDuration?: number; /** * The ARN of the IAM role to be assumed by Firehose for calling the Amazon ES Configuration API and for indexing documents. The IAM role must have permission for `DescribeDomain`, `DescribeDomains`, and `DescribeDomainConfig`. The pattern needs to be `arn:.*`. */ roleArn: string; /** * Defines how documents should be delivered to Amazon S3. Valid values are `FailedDocumentsOnly` and `AllDocuments`. Default value is `FailedDocumentsOnly`. */ s3BackupMode?: string; /** * The S3 Configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationS3Configuration; /** * The Elasticsearch type name with maximum length of 100 characters. Types are deprecated in OpenSearch_1.1. TypeName must be empty. */ typeName?: string; /** * The VPC configuration for the delivery stream to connect to OpenSearch associated with the VPC. See `vpcConfig` block below for details. */ vpcConfig?: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationVpcConfig; } interface FirehoseDeliveryStreamOpensearchConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamOpensearchConfigurationDocumentIdOptions { /** * The method for setting up document ID. Valid values: `FIREHOSE_DEFAULT`, `NO_DOCUMENT_ID`. */ defaultDocumentIdFormat: string; } interface FirehoseDeliveryStreamOpensearchConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamOpensearchConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamOpensearchConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamOpensearchConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamOpensearchConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamOpensearchConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamOpensearchConfigurationVpcConfig { /** * The ARN of the IAM role to be assumed by Firehose for calling the Amazon EC2 configuration API and for creating network interfaces. Make sure role has necessary [IAM permissions](https://docs.aws.amazon.com/firehose/latest/dev/controlling-access.html#using-iam-es-vpc) */ roleArn: string; /** * A list of security group IDs to associate with Kinesis Firehose. */ securityGroupIds: string[]; /** * A list of subnet IDs to associate with Kinesis Firehose. */ subnetIds: string[]; vpcId: string; } interface FirehoseDeliveryStreamOpensearchserverlessConfiguration { /** * Buffer incoming data for the specified period of time, in seconds between 0 to 900, before delivering it to the destination. The default value is 300s. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs between 1 to 100, before delivering it to the destination. The default value is 5MB. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationCloudwatchLoggingOptions; /** * The endpoint to use when communicating with the collection in the Serverless offering for Amazon OpenSearch Service. */ collectionEndpoint: string; /** * The Serverless offering for Amazon OpenSearch Service index name. */ indexName: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationProcessingConfiguration; /** * After an initial failure to deliver to the Serverless offering for Amazon OpenSearch Service, the total amount of time, in seconds between 0 to 7200, during which Kinesis Data Firehose retries delivery (including the first attempt). After this time has elapsed, the failed documents are written to Amazon S3. The default value is 300s. There will be no retry if the value is 0. */ retryDuration?: number; /** * ARN of the IAM role to be assumed by Kinesis Data Firehose for calling the Serverless offering for Amazon OpenSearch Service Configuration API and for indexing documents. The pattern needs to be `arn:.*`. */ roleArn: string; /** * Defines how documents should be delivered to Amazon S3. Valid values are `FailedDocumentsOnly` and `AllDocuments`. Default value is `FailedDocumentsOnly`. */ s3BackupMode?: string; /** * The S3 Configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationS3Configuration; /** * The VPC configuration for the delivery stream to connect to OpenSearch Serverless associated with the VPC. See `vpcConfig` block below for details. */ vpcConfig?: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationVpcConfig; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamOpensearchserverlessConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamOpensearchserverlessConfigurationVpcConfig { /** * The ARN of the IAM role to be assumed by Firehose for calling the Amazon EC2 configuration API and for creating network interfaces. Make sure role has necessary [IAM permissions](https://docs.aws.amazon.com/firehose/latest/dev/controlling-access.html#using-iam-es-vpc) */ roleArn: string; /** * A list of security group IDs to associate with Kinesis Firehose. */ securityGroupIds: string[]; /** * A list of subnet IDs to associate with Kinesis Firehose. */ subnetIds: string[]; vpcId: string; } interface FirehoseDeliveryStreamRedshiftConfiguration { /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationCloudwatchLoggingOptions; /** * The jdbcurl of the redshift cluster. */ clusterJdbcurl: string; /** * Copy options for copying the data from the s3 intermediate bucket into redshift, for example to change the default delimiter. For valid values, see the [AWS documentation](http://docs.aws.amazon.com/firehose/latest/APIReference/API_CopyCommand.html) */ copyOptions?: string; /** * The data table columns that will be targeted by the copy command. */ dataTableColumns?: string; /** * The name of the table in the redshift cluster that the s3 bucket will copy to. */ dataTableName: string; /** * The password for the username above. This value is required if `secretsManagerConfiguration` is not provided. */ password?: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationProcessingConfiguration; /** * The length of time during which Firehose retries delivery after a failure, starting from the initial request and including the first attempt. The default value is 3600 seconds (60 minutes). Firehose does not retry if the value of DurationInSeconds is 0 (zero) or if the first delivery attempt takes longer than the current value. */ retryDuration?: number; /** * The arn of the role the stream assumes. */ roleArn: string; /** * The configuration for backup in Amazon S3. Required if `s3BackupMode` is `Enabled`. Supports the same fields as `s3Configuration` object. * `secretsManagerConfiguration` - (Optional) The Secrets Manager configuration. See `secretsManagerConfiguration` block below for details. This value is required if `username` and `password` are not provided. */ s3BackupConfiguration?: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationS3BackupConfiguration; /** * The Amazon S3 backup mode. Valid values are `Disabled` and `Enabled`. Default value is `Disabled`. */ s3BackupMode?: string; /** * The S3 Configuration. See s3Configuration below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationS3Configuration; secretsManagerConfiguration: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationSecretsManagerConfiguration; /** * The username that the firehose delivery stream will assume. It is strongly recommended that the username and password provided is used exclusively for Amazon Kinesis Firehose purposes, and that the permissions for the account are restricted for Amazon Redshift INSERT permissions. This value is required if `secretsManagerConfiguration` is not provided. */ username?: string; } interface FirehoseDeliveryStreamRedshiftConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamRedshiftConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamRedshiftConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamRedshiftConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamRedshiftConfigurationS3BackupConfiguration { /** * The ARN of the S3 bucket */ bucketArn: string; bufferingInterval?: number; bufferingSize?: number; cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationS3BackupConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; roleArn: string; } interface FirehoseDeliveryStreamRedshiftConfigurationS3BackupConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamRedshiftConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamRedshiftConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamRedshiftConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamRedshiftConfigurationSecretsManagerConfiguration { /** * Enables or disables the Secrets Manager configuration. */ enabled: boolean; /** * The ARN of the role the stream assumes. */ roleArn?: string; /** * The ARN of the Secrets Manager secret. This value is required if `enabled` is true. */ secretArn?: string; } interface FirehoseDeliveryStreamServerSideEncryption { /** * Whether to enable encryption at rest. Default is `false`. */ enabled?: boolean; /** * ARN of the encryption key. Required when `keyType` is `CUSTOMER_MANAGED_CMK`. */ keyArn?: string; /** * Type of encryption key. Default is `AWS_OWNED_CMK`. Valid values are `AWS_OWNED_CMK` and `CUSTOMER_MANAGED_CMK` */ keyType?: string; } interface FirehoseDeliveryStreamSnowflakeConfiguration { /** * The URL of the Snowflake account. Format: https://[accountIdentifier].snowflakecomputing.com. */ accountUrl: string; /** * Buffer incoming data for the specified period of time, in seconds between 0 to 900, before delivering it to the destination. The default value is 0s. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs between 1 to 128, before delivering it to the destination. The default value is 1MB. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationCloudwatchLoggingOptions; /** * The name of the content column. */ contentColumnName?: string; /** * The data loading option. */ dataLoadingOption?: string; /** * The Snowflake database name. */ database: string; /** * The passphrase for the private key. */ keyPassphrase?: string; /** * The name of the metadata column. */ metadataColumnName?: string; /** * The private key for authentication. This value is required if `secretsManagerConfiguration` is not provided. */ privateKey?: string; /** * The processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationProcessingConfiguration; /** * After an initial failure to deliver to Snowflake, the total amount of time, in seconds between 0 to 7200, during which Firehose re-attempts delivery (including the first attempt). After this time has elapsed, the failed documents are written to Amazon S3. The default value is 60s. There will be no retry if the value is 0. */ retryDuration?: number; /** * The ARN of the IAM role. */ roleArn: string; /** * The S3 backup mode. */ s3BackupMode?: string; /** * The S3 configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationS3Configuration; /** * The Snowflake schema name. */ schema: string; /** * The Secrets Manager configuration. See `secretsManagerConfiguration` block below for details. This value is required if `user` and `privateKey` are not provided. */ secretsManagerConfiguration: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationSecretsManagerConfiguration; /** * The configuration for Snowflake role. */ snowflakeRoleConfiguration?: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationSnowflakeRoleConfiguration; /** * The VPC configuration for Snowflake. */ snowflakeVpcConfiguration?: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationSnowflakeVpcConfiguration; /** * The Snowflake table name. */ table: string; /** * The user for authentication. This value is required if `secretsManagerConfiguration` is not provided. */ user?: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamSnowflakeConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamSnowflakeConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationSecretsManagerConfiguration { /** * Enables or disables the Secrets Manager configuration. */ enabled: boolean; /** * The ARN of the role the stream assumes. */ roleArn?: string; /** * The ARN of the Secrets Manager secret. This value is required if `enabled` is true. */ secretArn?: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationSnowflakeRoleConfiguration { /** * Whether the Snowflake role is enabled. */ enabled?: boolean; /** * The Snowflake role. */ snowflakeRole?: string; } interface FirehoseDeliveryStreamSnowflakeConfigurationSnowflakeVpcConfiguration { /** * The VPCE ID for Firehose to privately connect with Snowflake. */ privateLinkVpceId: string; } interface FirehoseDeliveryStreamSplunkConfiguration { /** * Buffer incoming data for the specified period of time, in seconds between 0 to 60, before delivering it to the destination. The default value is 60s. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs between 1 to 5, before delivering it to the destination. The default value is 5MB. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationCloudwatchLoggingOptions; /** * The amount of time, in seconds between 180 and 600, that Kinesis Firehose waits to receive an acknowledgment from Splunk after it sends it data. */ hecAcknowledgmentTimeout?: number; /** * The HTTP Event Collector (HEC) endpoint to which Kinesis Firehose sends your data. */ hecEndpoint: string; /** * The HEC endpoint type. Valid values are `Raw` or `Event`. The default value is `Raw`. */ hecEndpointType?: string; /** * The GUID that you obtain from your Splunk cluster when you create a new HEC endpoint. This value is required if `secretsManagerConfiguration` is not provided. */ hecToken?: string; /** * The data processing configuration. See `processingConfiguration` block below for details. */ processingConfiguration?: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationProcessingConfiguration; /** * After an initial failure to deliver to Splunk, the total amount of time, in seconds between 0 to 7200, during which Firehose re-attempts delivery (including the first attempt). After this time has elapsed, the failed documents are written to Amazon S3. The default value is 300s. There will be no retry if the value is 0. */ retryDuration?: number; /** * Defines how documents should be delivered to Amazon S3. Valid values are `FailedEventsOnly` and `AllEvents`. Default value is `FailedEventsOnly`. * `secretsManagerConfiguration` - (Optional) The Secrets Manager configuration. See `secretsManagerConfiguration` block below for details. This value is required if `hecToken` is not provided. */ s3BackupMode?: string; /** * The S3 Configuration. See `s3Configuration` block below for details. */ s3Configuration: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationS3Configuration; secretsManagerConfiguration: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationSecretsManagerConfiguration; } interface FirehoseDeliveryStreamSplunkConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamSplunkConfigurationProcessingConfiguration { /** * Enables or disables data processing. */ enabled?: boolean; /** * Specifies the data processors as multiple blocks. See `processors` block below for details. */ processors?: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationProcessingConfigurationProcessor[]; } interface FirehoseDeliveryStreamSplunkConfigurationProcessingConfigurationProcessor { /** * Specifies the processor parameters as multiple blocks. See `parameters` block below for details. */ parameters?: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationProcessingConfigurationProcessorParameter[]; /** * The type of processor. Valid Values: `RecordDeAggregation`, `Lambda`, `MetadataExtraction`, `AppendDelimiterToRecord`, `Decompression`, `CloudWatchLogProcessing`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorType); so values not explicitly listed may also work. */ type: string; } interface FirehoseDeliveryStreamSplunkConfigurationProcessingConfigurationProcessorParameter { /** * Parameter name. Valid Values: `LambdaArn`, `NumberOfRetries`, `MetadataExtractionQuery`, `JsonParsingEngine`, `RoleArn`, `BufferSizeInMBs`, `BufferIntervalInSeconds`, `SubRecordType`, `Delimiter`, `CompressionFormat`, `DataMessageExtraction`. Validation is done against [AWS SDK constants](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/service/firehose/types#ProcessorParameterName); so values not explicitly listed may also work. */ parameterName: string; /** * Parameter value. Must be between 1 and 512 length (inclusive). When providing a Lambda ARN, you should specify the resource version as well. * * > **NOTE:** Parameters with default values, including `NumberOfRetries`(default: 3), `RoleArn`(default: firehose role ARN), `BufferSizeInMBs`(default: 1), and `BufferIntervalInSeconds`(default: 60), are not stored in Pulumi state. To prevent perpetual differences, it is therefore recommended to only include parameters with non-default values. */ parameterValue: string; } interface FirehoseDeliveryStreamSplunkConfigurationS3Configuration { /** * The ARN of the S3 bucket */ bucketArn: string; /** * Buffer incoming data for the specified period of time, in seconds, before delivering it to the destination. The default value is 300. */ bufferingInterval?: number; /** * Buffer incoming data to the specified size, in MBs, before delivering it to the destination. The default value is 5. * We recommend setting SizeInMBs to a value greater than the amount of data you typically ingest into the delivery stream in 10 seconds. For example, if you typically ingest data at 1 MB/sec set SizeInMBs to be 10 MB or higher. */ bufferingSize?: number; /** * The CloudWatch Logging Options for the delivery stream. See `cloudwatchLoggingOptions` block below for details. */ cloudwatchLoggingOptions: outputs.kinesis.FirehoseDeliveryStreamSplunkConfigurationS3ConfigurationCloudwatchLoggingOptions; /** * The compression format. If no value is specified, the default is `UNCOMPRESSED`. Other supported values are `GZIP`, `ZIP`, `Snappy`, & `HADOOP_SNAPPY`. */ compressionFormat?: string; /** * Prefix added to failed records before writing them to S3. Not currently supported for `redshift` destination. This prefix appears immediately following the bucket name. For information about how to specify this prefix, see [Custom Prefixes for Amazon S3 Objects](https://docs.aws.amazon.com/firehose/latest/dev/s3-prefixes.html). */ errorOutputPrefix?: string; /** * Specifies the KMS key ARN the stream will use to encrypt data. If not set, no encryption will * be used. */ kmsKeyArn?: string; /** * The "YYYY/MM/DD/HH" time format prefix is automatically used for delivered S3 files. You can specify an extra prefix to be added in front of the time format prefix. Note that if the prefix ends with a slash, it appears as a folder in the S3 bucket */ prefix?: string; /** * The ARN of the AWS credentials. */ roleArn: string; } interface FirehoseDeliveryStreamSplunkConfigurationS3ConfigurationCloudwatchLoggingOptions { /** * Enables or disables the logging. Defaults to `false`. */ enabled?: boolean; /** * The CloudWatch group name for logging. This value is required if `enabled` is true. */ logGroupName?: string; /** * The CloudWatch log stream name for logging. This value is required if `enabled` is true. */ logStreamName?: string; } interface FirehoseDeliveryStreamSplunkConfigurationSecretsManagerConfiguration { /** * Enables or disables the Secrets Manager configuration. */ enabled: boolean; /** * The ARN of the role the stream assumes. */ roleArn?: string; /** * The ARN of the Secrets Manager secret. This value is required if `enabled` is true. */ secretArn?: string; } interface GetStreamStreamModeDetail { /** * Capacity mode of the stream. Either `ON_DEMAND` or `PROVISIONED`. */ streamMode: string; } interface GetStreamWarmThroughput { /** * Current warm throughput value on the stream. */ currentMibPs: number; /** * Target warm throughput value on the stream. */ targetMibPs: number; } interface StreamStreamModeDetails { /** * Specifies the capacity mode of the stream. Must be either `PROVISIONED` or `ON_DEMAND`. */ streamMode: string; } } export declare namespace kinesisanalyticsv2 { interface ApplicationApplicationConfiguration { /** * The code location and type parameters for the application. */ applicationCodeConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationApplicationCodeConfiguration; /** * The encryption configuration for the application. This can be used to encrypt data at rest in the application. */ applicationEncryptionConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationApplicationEncryptionConfiguration; /** * Describes whether snapshots are enabled for a Flink-based application. */ applicationSnapshotConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationApplicationSnapshotConfiguration; /** * Describes execution properties for a Flink-based application. */ environmentProperties?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationEnvironmentProperties; /** * The configuration of a Flink-based application. */ flinkApplicationConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationFlinkApplicationConfiguration; /** * Describes the starting properties for a Flink-based application. */ runConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationRunConfiguration; /** * The configuration of a SQL-based application. */ sqlApplicationConfiguration?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfiguration; /** * The VPC configuration of a Flink-based application. */ vpcConfiguration?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationVpcConfiguration; } interface ApplicationApplicationConfigurationApplicationCodeConfiguration { /** * The location and type of the application code. */ codeContent?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationApplicationCodeConfigurationCodeContent; /** * Specifies whether the code content is in text or zip format. Valid values: `PLAINTEXT`, `ZIPFILE`. */ codeContentType: string; } interface ApplicationApplicationConfigurationApplicationCodeConfigurationCodeContent { /** * Information about the Amazon S3 bucket containing the application code. */ s3ContentLocation?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationApplicationCodeConfigurationCodeContentS3ContentLocation; /** * The text-format code for the application. */ textContent?: string; } interface ApplicationApplicationConfigurationApplicationCodeConfigurationCodeContentS3ContentLocation { /** * The ARN for the S3 bucket containing the application code. */ bucketArn: string; /** * The file key for the object containing the application code. */ fileKey: string; /** * The version of the object containing the application code. */ objectVersion?: string; } interface ApplicationApplicationConfigurationApplicationEncryptionConfiguration { /** * The ARN of the KMS key to use for encryption. Required when `keyType` is set to `CUSTOMER_MANAGED_KEY`. The KMS key must be in the same region as the application. */ keyId?: string; /** * The type of encryption key to use. Valid values: `CUSTOMER_MANAGED_KEY`, `AWS_OWNED_KEY`. */ keyType: string; } interface ApplicationApplicationConfigurationApplicationSnapshotConfiguration { /** * Describes whether snapshots are enabled for a Flink-based Kinesis Data Analytics application. */ snapshotsEnabled: boolean; } interface ApplicationApplicationConfigurationEnvironmentProperties { /** * Describes the execution property groups. */ propertyGroups: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationEnvironmentPropertiesPropertyGroup[]; } interface ApplicationApplicationConfigurationEnvironmentPropertiesPropertyGroup { /** * The key of the application execution property key-value map. */ propertyGroupId: string; /** * Application execution property key-value map. */ propertyMap: { [key: string]: string; }; } interface ApplicationApplicationConfigurationFlinkApplicationConfiguration { /** * Describes an application's checkpointing configuration. */ checkpointConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationFlinkApplicationConfigurationCheckpointConfiguration; /** * Describes configuration parameters for CloudWatch logging for an application. */ monitoringConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationFlinkApplicationConfigurationMonitoringConfiguration; /** * Describes parameters for how an application executes multiple tasks simultaneously. */ parallelismConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationFlinkApplicationConfigurationParallelismConfiguration; } interface ApplicationApplicationConfigurationFlinkApplicationConfigurationCheckpointConfiguration { /** * Describes the interval in milliseconds between checkpoint operations. */ checkpointInterval: number; /** * Describes whether checkpointing is enabled for a Flink-based Kinesis Data Analytics application. */ checkpointingEnabled: boolean; /** * Describes whether the application uses Kinesis Data Analytics' default checkpointing behavior. Valid values: `CUSTOM`, `DEFAULT`. Set this attribute to `CUSTOM` in order for any specified `checkpointingEnabled`, `checkpointInterval`, or `minPauseBetweenCheckpoints` attribute values to be effective. If this attribute is set to `DEFAULT`, the application will always use the following values: * * `checkpointingEnabled = true` * * `checkpointInterval = 60000` * * `minPauseBetweenCheckpoints = 5000` */ configurationType: string; /** * Describes the minimum time in milliseconds after a checkpoint operation completes that a new checkpoint operation can start. */ minPauseBetweenCheckpoints: number; } interface ApplicationApplicationConfigurationFlinkApplicationConfigurationMonitoringConfiguration { /** * Describes whether to use the default CloudWatch logging configuration for an application. Valid values: `CUSTOM`, `DEFAULT`. Set this attribute to `CUSTOM` in order for any specified `logLevel` or `metricsLevel` attribute values to be effective. */ configurationType: string; /** * Describes the verbosity of the CloudWatch Logs for an application. Valid values: `DEBUG`, `ERROR`, `INFO`, `WARN`. */ logLevel: string; /** * Describes the granularity of the CloudWatch Logs for an application. Valid values: `APPLICATION`, `OPERATOR`, `PARALLELISM`, `TASK`. */ metricsLevel: string; } interface ApplicationApplicationConfigurationFlinkApplicationConfigurationParallelismConfiguration { /** * Describes whether the Kinesis Data Analytics service can increase the parallelism of the application in response to increased throughput. */ autoScalingEnabled: boolean; /** * Describes whether the application uses the default parallelism for the Kinesis Data Analytics service. Valid values: `CUSTOM`, `DEFAULT`. Set this attribute to `CUSTOM` in order for any specified `autoScalingEnabled`, `parallelism`, or `parallelismPerKpu` attribute values to be effective. */ configurationType: string; /** * Describes the initial number of parallel tasks that a Flink-based Kinesis Data Analytics application can perform. */ parallelism: number; /** * Describes the number of parallel tasks that a Flink-based Kinesis Data Analytics application can perform per Kinesis Processing Unit (KPU) used by the application. */ parallelismPerKpu: number; } interface ApplicationApplicationConfigurationRunConfiguration { /** * The restore behavior of a restarting application. */ applicationRestoreConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationRunConfigurationApplicationRestoreConfiguration; /** * The starting parameters for a Flink-based Kinesis Data Analytics application. */ flinkRunConfiguration: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationRunConfigurationFlinkRunConfiguration; } interface ApplicationApplicationConfigurationRunConfigurationApplicationRestoreConfiguration { /** * Specifies how the application should be restored. Valid values: `RESTORE_FROM_CUSTOM_SNAPSHOT`, `RESTORE_FROM_LATEST_SNAPSHOT`, `SKIP_RESTORE_FROM_SNAPSHOT`. */ applicationRestoreType: string; /** * The identifier of an existing snapshot of application state to use to restart an application. The application uses this value if `RESTORE_FROM_CUSTOM_SNAPSHOT` is specified for `applicationRestoreType`. */ snapshotName?: string; } interface ApplicationApplicationConfigurationRunConfigurationFlinkRunConfiguration { /** * When restoring from a snapshot, specifies whether the runtime is allowed to skip a state that cannot be mapped to the new program. Default is `false`. */ allowNonRestoredState: boolean; } interface ApplicationApplicationConfigurationSqlApplicationConfiguration { /** * The input stream used by the application. */ input?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInput; /** * The destination streams used by the application. */ outputs?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationOutput[]; /** * The reference data source used by the application. */ referenceDataSource?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSource; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInput { inAppStreamNames: string[]; inputId: string; /** * Describes the number of in-application streams to create. */ inputParallelism: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputParallelism; /** * The input processing configuration for the input. * An input processor transforms records as they are received from the stream, before the application's SQL code executes. */ inputProcessingConfiguration?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputProcessingConfiguration; /** * Describes the format of the data in the streaming source, and how each data element maps to corresponding columns in the in-application stream that is being created. */ inputSchema: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchema; /** * The point at which the application starts processing records from the streaming source. */ inputStartingPositionConfigurations: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputStartingPositionConfiguration[]; /** * If the streaming source is a Kinesis Data Firehose delivery stream, identifies the delivery stream's ARN. */ kinesisFirehoseInput?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputKinesisFirehoseInput; /** * If the streaming source is a Kinesis data stream, identifies the stream's ARN. */ kinesisStreamsInput?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputKinesisStreamsInput; /** * The name prefix to use when creating an in-application stream. */ namePrefix: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputParallelism { /** * The number of in-application streams to create. */ count: number; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputProcessingConfiguration { /** * Describes the Lambda function that is used to preprocess the records in the stream before being processed by your application code. */ inputLambdaProcessor: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputProcessingConfigurationInputLambdaProcessor; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputProcessingConfigurationInputLambdaProcessor { /** * The ARN of the Lambda function that operates on records in the stream. */ resourceArn: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchema { /** * Describes the mapping of each data element in the streaming source to the corresponding column in the in-application stream. */ recordColumns: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordColumn[]; /** * Specifies the encoding of the records in the streaming source. For example, `UTF-8`. */ recordEncoding?: string; /** * Specifies the format of the records on the streaming source. */ recordFormat: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormat; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordColumn { /** * A reference to the data element in the streaming input or the reference data source. */ mapping?: string; /** * The name of the column that is created in the in-application input stream or reference table. */ name: string; /** * The type of column created in the in-application input stream or reference table. */ sqlType: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormat { /** * Provides additional mapping information specific to the record format (such as JSON, CSV, or record fields delimited by some delimiter) on the streaming source. */ mappingParameters: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormatMappingParameters; /** * The type of record format. Valid values: `CSV`, `JSON`. */ recordFormatType: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormatMappingParameters { /** * Provides additional mapping information when the record format uses delimiters (for example, CSV). */ csvMappingParameters?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormatMappingParametersCsvMappingParameters; /** * Provides additional mapping information when JSON is the record format on the streaming source. */ jsonMappingParameters?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormatMappingParametersJsonMappingParameters; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormatMappingParametersCsvMappingParameters { /** * The column delimiter. For example, in a CSV format, a comma (`,`) is the typical column delimiter. */ recordColumnDelimiter: string; /** * The row delimiter. For example, in a CSV format, `\n` is the typical row delimiter. */ recordRowDelimiter: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputSchemaRecordFormatMappingParametersJsonMappingParameters { /** * The path to the top-level parent that contains the records. */ recordRowPath: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputInputStartingPositionConfiguration { /** * The starting position on the stream. Valid values: `LAST_STOPPED_POINT`, `NOW`, `TRIM_HORIZON`. */ inputStartingPosition: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputKinesisFirehoseInput { /** * The ARN of the delivery stream. */ resourceArn: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationInputKinesisStreamsInput { /** * The ARN of the input Kinesis data stream to read. */ resourceArn: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationOutput { /** * Describes the data format when records are written to the destination. */ destinationSchema: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationOutputDestinationSchema; /** * Identifies a Kinesis Data Firehose delivery stream as the destination. */ kinesisFirehoseOutput?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationOutputKinesisFirehoseOutput; /** * Identifies a Kinesis data stream as the destination. */ kinesisStreamsOutput?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationOutputKinesisStreamsOutput; /** * Identifies a Lambda function as the destination. */ lambdaOutput?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationOutputLambdaOutput; /** * The name of the in-application stream. */ name: string; outputId: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationOutputDestinationSchema { /** * Specifies the format of the records on the output stream. Valid values: `CSV`, `JSON`. */ recordFormatType: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationOutputKinesisFirehoseOutput { /** * The ARN of the destination delivery stream to write to. */ resourceArn: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationOutputKinesisStreamsOutput { /** * The ARN of the destination Kinesis data stream to write to. */ resourceArn: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationOutputLambdaOutput { /** * The ARN of the destination Lambda function to write to. */ resourceArn: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSource { referenceId: string; /** * Describes the format of the data in the streaming source, and how each data element maps to corresponding columns created in the in-application stream. */ referenceSchema: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchema; /** * Identifies the S3 bucket and object that contains the reference data. */ s3ReferenceDataSource: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceS3ReferenceDataSource; /** * The name of the in-application table to create. */ tableName: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchema { /** * Describes the mapping of each data element in the streaming source to the corresponding column in the in-application stream. */ recordColumns: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordColumn[]; /** * Specifies the encoding of the records in the streaming source. For example, `UTF-8`. */ recordEncoding?: string; /** * Specifies the format of the records on the streaming source. */ recordFormat: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormat; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordColumn { /** * A reference to the data element in the streaming input or the reference data source. */ mapping?: string; /** * The name of the column that is created in the in-application input stream or reference table. */ name: string; /** * The type of column created in the in-application input stream or reference table. */ sqlType: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormat { /** * Provides additional mapping information specific to the record format (such as JSON, CSV, or record fields delimited by some delimiter) on the streaming source. */ mappingParameters: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormatMappingParameters; /** * The type of record format. Valid values: `CSV`, `JSON`. */ recordFormatType: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormatMappingParameters { /** * Provides additional mapping information when the record format uses delimiters (for example, CSV). */ csvMappingParameters?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormatMappingParametersCsvMappingParameters; /** * Provides additional mapping information when JSON is the record format on the streaming source. */ jsonMappingParameters?: outputs.kinesisanalyticsv2.ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormatMappingParametersJsonMappingParameters; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormatMappingParametersCsvMappingParameters { /** * The column delimiter. For example, in a CSV format, a comma (`,`) is the typical column delimiter. */ recordColumnDelimiter: string; /** * The row delimiter. For example, in a CSV format, `\n` is the typical row delimiter. */ recordRowDelimiter: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceReferenceSchemaRecordFormatMappingParametersJsonMappingParameters { /** * The path to the top-level parent that contains the records. */ recordRowPath: string; } interface ApplicationApplicationConfigurationSqlApplicationConfigurationReferenceDataSourceS3ReferenceDataSource { /** * The ARN of the S3 bucket. */ bucketArn: string; /** * The object key name containing the reference data. */ fileKey: string; } interface ApplicationApplicationConfigurationVpcConfiguration { /** * The Security Group IDs used by the VPC configuration. */ securityGroupIds: string[]; /** * The Subnet IDs used by the VPC configuration. */ subnetIds: string[]; vpcConfigurationId: string; vpcId: string; } interface ApplicationCloudwatchLoggingOptions { cloudwatchLoggingOptionId: string; /** * The ARN of the CloudWatch log stream to receive application messages. */ logStreamArn: string; } } export declare namespace kms { interface CustomKeyStoreXksProxyAuthenticationCredential { /** * A unique identifier for the raw secret access key. */ accessKeyId: string; /** * A secret string of 43-64 characters. */ rawSecretAccessKey: string; } interface GetKeyMultiRegionConfiguration { /** * Indicates whether the KMS key is a `PRIMARY` or `REPLICA` key. */ multiRegionKeyType: string; /** * The key ARN and Region of the primary key. This is the current KMS key if it is the primary key. */ primaryKeys: outputs.kms.GetKeyMultiRegionConfigurationPrimaryKey[]; /** * The key ARNs and Regions of all replica keys. Includes the current KMS key if it is a replica key. */ replicaKeys: outputs.kms.GetKeyMultiRegionConfigurationReplicaKey[]; } interface GetKeyMultiRegionConfigurationPrimaryKey { /** * The key ARN of a primary or replica key of a multi-Region key. */ arn: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface GetKeyMultiRegionConfigurationReplicaKey { /** * The key ARN of a primary or replica key of a multi-Region key. */ arn: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface GetKeyXksKeyConfiguration { /** * The globally unique identifier for the key */ id: string; } interface GetSecretSecret { context?: { [key: string]: string; }; grantTokens?: string[]; name: string; payload: string; } interface GetSecretsSecret { /** * An optional mapping that makes up the Encryption Context for the secret. */ context?: { [key: string]: string; }; /** * The encryption algorithm that will be used to decrypt the ciphertext. This parameter is required only when the ciphertext was encrypted under an asymmetric KMS key. Valid Values: SYMMETRIC_DEFAULT | RSAES_OAEP_SHA_1 | RSAES_OAEP_SHA_256 | SM2PKE */ encryptionAlgorithm?: string; /** * An optional list of Grant Tokens for the secret. */ grantTokens?: string[]; /** * Specifies the KMS key that AWS KMS uses to decrypt the ciphertext. This parameter is required only when the ciphertext was encrypted under an asymmetric KMS key. * * For more information on `context` and `grantTokens` see the [KMS * Concepts](https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html) */ keyId?: string; /** * Name to export this secret under in the attributes. */ name: string; /** * Base64 encoded payload, as returned from a KMS encrypt operation. */ payload: string; } interface GrantConstraint { /** * A list of key-value pairs that must match the encryption context in subsequent cryptographic operation requests. The grant allows the operation only when the encryption context in the request is the same as the encryption context specified in this constraint. Conflicts with `encryptionContextSubset`. */ encryptionContextEquals?: { [key: string]: string; }; /** * A list of key-value pairs that must be included in the encryption context of subsequent cryptographic operation requests. The grant allows the cryptographic operation only when the encryption context in the request includes the key-value pairs specified in this constraint, although it can include additional key-value pairs. Conflicts with `encryptionContextEquals`. */ encryptionContextSubset?: { [key: string]: string; }; } } export declare namespace lakeformation { interface DataCellsFilterTableData { /** * A list of column names and/or nested column attributes. */ columnNames: string[]; /** * A wildcard with exclusions. See Column Wildcard below for details. */ columnWildcard?: outputs.lakeformation.DataCellsFilterTableDataColumnWildcard; /** * The name of the database. */ databaseName: string; /** * The name of the data cells filter. */ name: string; /** * A PartiQL predicate. See Row Filter below for details. */ rowFilter: outputs.lakeformation.DataCellsFilterTableDataRowFilter; /** * The ID of the Data Catalog. */ tableCatalogId: string; /** * The name of the table. */ tableName: string; /** * ID of the data cells filter version. */ versionId: string; } interface DataCellsFilterTableDataColumnWildcard { /** * (Optional) Excludes column names. Any column with this name will be excluded. */ excludedColumnNames?: string[]; } interface DataCellsFilterTableDataRowFilter { /** * (Optional) A wildcard that matches all rows. Required when applying column-level filtering without row-level filtering. Use an empty block: `allRowsWildcard {}`. */ allRowsWildcard?: outputs.lakeformation.DataCellsFilterTableDataRowFilterAllRowsWildcard; /** * (Optional) A PartiQL predicate expression for row-level filtering. */ filterExpression: string; } interface DataCellsFilterTableDataRowFilterAllRowsWildcard { } interface DataCellsFilterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface DataLakeSettingsCreateDatabaseDefaultPermission { /** * List of permissions that are granted to the principal. Valid values may include `ALL`, `SELECT`, `ALTER`, `DROP`, `DELETE`, `INSERT`, `DESCRIBE`, and `CREATE_TABLE`. For more details, see [Lake Formation Permissions Reference](https://docs.aws.amazon.com/lake-formation/latest/dg/lf-permissions-reference.html). */ permissions: string[]; /** * Principal who is granted permissions. To enforce metadata and underlying data access control only by IAM on new databases and tables set `principal` to `IAM_ALLOWED_PRINCIPALS` and `permissions` to `["ALL"]`. */ principal: string; } interface DataLakeSettingsCreateTableDefaultPermission { /** * List of permissions that are granted to the principal. Valid values may include `ALL`, `SELECT`, `ALTER`, `DROP`, `DELETE`, `INSERT`, and `DESCRIBE`. For more details, see [Lake Formation Permissions Reference](https://docs.aws.amazon.com/lake-formation/latest/dg/lf-permissions-reference.html). */ permissions: string[]; /** * Principal who is granted permissions. To enforce metadata and underlying data access control only by IAM on new databases and tables set `principal` to `IAM_ALLOWED_PRINCIPALS` and `permissions` to `["ALL"]`. */ principal: string; } interface GetDataLakeSettingsCreateDatabaseDefaultPermission { /** * List of permissions granted to the principal. */ permissions: string[]; /** * Principal who is granted permissions. */ principal: string; } interface GetDataLakeSettingsCreateTableDefaultPermission { /** * List of permissions granted to the principal. */ permissions: string[]; /** * Principal who is granted permissions. */ principal: string; } interface GetPermissionsDataCellsFilter { /** * The name of the database. */ databaseName: string; /** * The name of the data cells filter. */ name: string; /** * The ID of the Data Catalog. */ tableCatalogId: string; /** * The name of the table. */ tableName: string; } interface GetPermissionsDataLocation { /** * ARN that uniquely identifies the data location resource. * * The following argument is optional: */ arn: string; /** * Identifier for the Data Catalog where the location is registered with Lake Formation. By default, it is the account ID of the caller. */ catalogId: string; } interface GetPermissionsDatabase { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Name of the database resource. Unique to the Data Catalog. * * The following argument is optional: */ name: string; } interface GetPermissionsLfTag { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Key-name for the tag. */ key: string; /** * List of possible values an attribute can take. * * The following argument is optional: */ values: string[]; } interface GetPermissionsLfTagPolicy { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * List of tag conditions that apply to the resource's tag policy. Configuration block for tag conditions that apply to the policy. See `expression` below. * * The following argument is optional: */ expressions: outputs.lakeformation.GetPermissionsLfTagPolicyExpression[]; /** * Resource type for which the tag policy applies. Valid values are `DATABASE` and `TABLE`. */ resourceType: string; } interface GetPermissionsLfTagPolicyExpression { /** * Key-name of an LF-Tag. */ key: string; /** * List of possible values of an LF-Tag. */ values: string[]; } interface GetPermissionsTable { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Name of the database for the table. Unique to a Data Catalog. * * The following arguments are optional: */ databaseName: string; /** * Name of the table. At least one of `name` or `wildcard` is required. */ name: string; /** * Whether to use a wildcard representing every table under a database. At least one of `name` or `wildcard` is required. Defaults to `false`. */ wildcard?: boolean; } interface GetPermissionsTableWithColumns { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Set of column names for the table. At least one of `columnNames` or `excludedColumnNames` is required. */ columnNames?: string[]; /** * Name of the database for the table with columns resource. Unique to the Data Catalog. */ databaseName: string; /** * Set of column names for the table to exclude. At least one of `columnNames` or `excludedColumnNames` is required. */ excludedColumnNames?: string[]; /** * Name of the table resource. * * The following arguments are optional: */ name: string; /** * Whether to use a wildcard representing every table under a database. At least one of `name` or `wildcard` is required. Defaults to `false`. */ wildcard?: boolean; } interface LfTagExpressionExpression { /** * The key-name for the LF-Tag. */ tagKey: string; /** * A list of possible values for the LF-Tag */ tagValues: string[]; } interface OptInCondition { /** * Expression written based on the Cedar Policy Language used to match the principal attributes. */ expression: string; } interface OptInPrincipal { /** * Identifier for the Lake Formation principal. */ dataLakePrincipalIdentifier: string; } interface OptInResourceData { /** * Identifier for the Data Catalog. By default, the account ID. The Data Catalog is the persistent metadata store. It contains database definitions, table definitions, and other control information to manage your Lake Formation environment. See `catalog` Block for more details. */ catalogs?: outputs.lakeformation.OptInResourceDataCatalog[]; /** * Data cell filter. See `dataCellsFilter` Block for more details. */ dataCellsFilters?: outputs.lakeformation.OptInResourceDataDataCellsFilter[]; /** * Location of an Amazon S3 path where permissions are granted or revoked. See `dataLocation` Block for more details. */ dataLocations?: outputs.lakeformation.OptInResourceDataDataLocation[]; /** * Database for the resource. Unique to the Data Catalog. A database is a set of associated table definitions organized into a logical group. You can Grant and Revoke database permissions to a principal. See `database` Block for more details. */ database?: outputs.lakeformation.OptInResourceDataDatabase; /** * LF-tag key and values attached to a resource. */ lfTag?: outputs.lakeformation.OptInResourceDataLfTag; /** * Logical expression composed of one or more LF-Tag key:value pairs. See `lfTagExpression` Block for more details. */ lfTagExpressions?: outputs.lakeformation.OptInResourceDataLfTagExpression[]; /** * List of LF-Tag conditions or saved LF-Tag expressions that define a resource's LF-Tag policy. See `lfTagPolicy` Block for more details. */ lfTagPolicies?: outputs.lakeformation.OptInResourceDataLfTagPolicy[]; /** * Table for the resource. A table is a metadata definition that represents your data. You can Grant and Revoke table privileges to a principal. See `table` Block for more details. */ table?: outputs.lakeformation.OptInResourceDataTable; /** * Table with columns for the resource. A principal with permissions to this resource can select metadata from the columns of a table in the Data Catalog and the underlying data in Amazon S3. See `tableWithColumns` Block for more details. */ tableWithColumns?: outputs.lakeformation.OptInResourceDataTableWithColumns; } interface OptInResourceDataCatalog { /** * Identifier for the catalog resource. */ id?: string; } interface OptInResourceDataDataCellsFilter { /** * Database in the Glue Data Catalog. */ databaseName?: string; /** * Name of the data cells filter. */ name?: string; /** * ID of the catalog to which the table belongs. */ tableCatalogId?: string; /** * Name of the table. */ tableName?: string; } interface OptInResourceDataDataLocation { /** * Identifier for the Data Catalog where the location is registered with Lake Formation. By default, it is the account ID of the caller. */ catalogId: string; /** * ARN that uniquely identifies the data location resource. */ resourceArn: string; } interface OptInResourceDataDatabase { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * Name of the database resource. Unique to the Data Catalog. */ name: string; } interface OptInResourceDataLfTag { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Key name for the LF-Tag. */ key: string; /** * Set of tag values for the LF-Tag key. At least one value is required. Each value can be 1-255 characters. */ values: string[]; } interface OptInResourceDataLfTagExpression { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * Name of the LF-Tag expression to grant permissions on. */ name: string; } interface OptInResourceDataLfTagPolicy { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. The Data Catalog is the persistent metadata store. It contains database definitions, table definitions, and other control information to manage your Lake Formation environment. */ catalogId: string; /** * Name of the saved expression to match. If provided, permissions are granted to the Data Catalog resources whose assigned LF-Tags match the expression body of the saved expression under the provided expression name. */ expressionName?: string; /** * List of LF-tag conditions or a saved expression that apply to the resource's LF-Tag policy. */ expressions?: string[]; /** * Resource type for which the LF-tag policy applies. */ resourceType: string; } interface OptInResourceDataTable { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * Name of the database for the table. Unique to a Data Catalog. A database is a set of associated table definitions organized into a logical group. You can Grant and Revoke database privileges to a principal. */ databaseName: string; /** * Name of the table. */ name?: string; /** * Boolean value that indicates whether to use a wildcard representing every table under the specified database. When set to true, this represents all tables within the specified database. At least one of TableResource$Name or TableResource$Wildcard is required. */ wildcard?: boolean; } interface OptInResourceDataTableWithColumns { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * List of column names for the table. At least one of ColumnNames or ColumnWildcard is required. */ columnNames?: string[]; /** * Wildcard specified by a ColumnWildcard object. At least one of ColumnNames or ColumnWildcard is required. See `columnWildcard` Block for more details. */ columnWildcard?: outputs.lakeformation.OptInResourceDataTableWithColumnsColumnWildcard; /** * Name of the database for the table. Unique to a Data Catalog. A database is a set of associated table definitions organized into a logical group. You can Grant and Revoke database privileges to a principal. */ databaseName: string; /** * Name of the table. */ name: string; } interface OptInResourceDataTableWithColumnsColumnWildcard { /** * Excludes column names. Any column with this name will be excluded. */ excludedColumnNames?: string[]; } interface PermissionsDataCellsFilter { /** * The name of the database. */ databaseName: string; /** * The name of the data cells filter. */ name: string; /** * The ID of the Data Catalog. */ tableCatalogId: string; /** * The name of the table. */ tableName: string; } interface PermissionsDataLocation { /** * ARN that uniquely identifies the data location resource. * * The following argument is optional: */ arn: string; /** * Identifier for the Data Catalog where the location is registered with Lake Formation. By default, it is the account ID of the caller. */ catalogId: string; } interface PermissionsDatabase { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Name of the database resource. Unique to the Data Catalog. * * The following argument is optional: */ name: string; } interface PermissionsLfTag { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * The key-name for the tag. */ key: string; /** * A list of possible values an attribute can take. * * The following argument is optional: */ values: string[]; } interface PermissionsLfTagPolicy { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * A list of tag conditions that apply to the resource's tag policy. Configuration block for tag conditions that apply to the policy. See `expression` below. * * The following argument is optional: */ expressions: outputs.lakeformation.PermissionsLfTagPolicyExpression[]; /** * The resource type for which the tag policy applies. Valid values are `DATABASE` and `TABLE`. */ resourceType: string; } interface PermissionsLfTagPolicyExpression { /** * The key-name of an LF-Tag. */ key: string; /** * A list of possible values of an LF-Tag. */ values: string[]; } interface PermissionsTable { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Name of the database for the table. Unique to a Data Catalog. */ databaseName: string; /** * Name of the table. */ name: string; /** * Whether to use a wildcard representing every table under a database. Defaults to `false`. * * The following arguments are optional: */ wildcard?: boolean; } interface PermissionsTableWithColumns { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Set of column names for the table. */ columnNames?: string[]; /** * Name of the database for the table with columns resource. Unique to the Data Catalog. */ databaseName: string; /** * Set of column names for the table to exclude. If `excludedColumnNames` is included, `wildcard` must be set to `true` to avoid the provider reporting a difference. */ excludedColumnNames?: string[]; /** * Name of the table resource. */ name: string; /** * Whether to use a column wildcard. If `excludedColumnNames` is included, `wildcard` must be set to `true` to avoid the provider reporting a difference. * * The following arguments are optional: */ wildcard?: boolean; } interface ResourceLfTagDatabase { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * Name of the database resource. Unique to the Data Catalog. * * The following argument is optional: */ name: string; } interface ResourceLfTagLfTag { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Key name for an existing LF-tag. */ key: string; /** * Value from the possible values for the LF-tag. * * The following argument is optional: */ value: string; } interface ResourceLfTagTable { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * Name of the database for the table. Unique to a Data Catalog. */ databaseName: string; /** * Name of the table. */ name?: string; /** * Whether to use a wildcard representing every table under a database. Defaults to `false`. * * The following arguments are optional: */ wildcard?: boolean; } interface ResourceLfTagTableWithColumns { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId?: string; /** * Set of column names for the table. */ columnNames?: string[]; /** * Option to add column wildcard. See Column Wildcard for more details. */ columnWildcard?: outputs.lakeformation.ResourceLfTagTableWithColumnsColumnWildcard; /** * Name of the database for the table with columns resource. Unique to the Data Catalog. */ databaseName: string; /** * Name of the table resource. * * The following arguments are optional: */ name: string; } interface ResourceLfTagTableWithColumnsColumnWildcard { /** * Set of column names for the table to exclude. If `excludedColumnNames` is included, `wildcard` must be set to `true` to avoid Terraform reporting a difference. */ excludedColumnNames?: string[]; } interface ResourceLfTagTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface ResourceLfTagsDatabase { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Name of the database resource. Unique to the Data Catalog. * * The following argument is optional: */ name: string; } interface ResourceLfTagsLfTag { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Key name for an existing LF-tag. */ key: string; /** * Value from the possible values for the LF-tag. * * The following argument is optional: */ value: string; } interface ResourceLfTagsTable { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Name of the database for the table. Unique to a Data Catalog. */ databaseName: string; /** * Name of the table. */ name: string; /** * Whether to use a wildcard representing every table under a database. Defaults to `false`. * * The following arguments are optional: */ wildcard?: boolean; } interface ResourceLfTagsTableWithColumns { /** * Identifier for the Data Catalog. By default, it is the account ID of the caller. */ catalogId: string; /** * Set of column names for the table. */ columnNames?: string[]; /** * Name of the database for the table with columns resource. Unique to the Data Catalog. */ databaseName: string; /** * Set of column names for the table to exclude. If `excludedColumnNames` is included, `wildcard` must be set to `true` to avoid the provider reporting a difference. */ excludedColumnNames?: string[]; /** * Name of the table resource. */ name: string; /** * Whether to use a column wildcard. If `excludedColumnNames` is included, `wildcard` must be set to `true` to avoid the provider reporting a difference. * * The following arguments are optional: */ wildcard?: boolean; } } export declare namespace lambda { interface AliasRoutingConfig { /** * Map that defines the proportion of events that should be sent to different versions of a Lambda function. */ additionalVersionWeights?: { [key: string]: number; }; } interface CapacityProviderCapacityProviderScalingConfig { /** * Maximum number of VCPUs for the Capacity Provider. */ maxVcpuCount: number; /** * Scaling mode for the Capacity Provider. Valid values are `"Auto"` and `"Manual"`. Defaults to `"Auto"`. */ scalingMode: string; /** * List of scaling policies. Only required if `scalingMode` is set to `"Manual"`. See Scaling Policies below. */ scalingPolicies: outputs.lambda.CapacityProviderCapacityProviderScalingConfigScalingPolicy[]; } interface CapacityProviderCapacityProviderScalingConfigScalingPolicy { /** * Predefined metric type for the scaling policy. Valid values are `"LambdaCapacityProviderAverageCPUUtilization"`. */ predefinedMetricType: string; /** * Target value for the scaling policy. */ targetValue: number; } interface CapacityProviderInstanceRequirement { /** * List of allowed instance types (e.g., `["m5.xlarge"]`). */ allowedInstanceTypes: string[]; /** * List of CPU architectures. Valid values are `["x8664"]` and `["arm64"]`. */ architectures: string[]; /** * List of excluded instance types. You can specify only one of `allowedInstanceTypes` or `excludedInstanceTypes`. */ excludedInstanceTypes: string[]; } interface CapacityProviderPermissionsConfig { /** * ARN of the IAM role that allows Lambda to manage the Capacity Provider. */ capacityProviderOperatorRoleArn: string; } interface CapacityProviderTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface CapacityProviderVpcConfig { /** * List of security group IDs for the VPC. */ securityGroupIds: string[]; /** * List of subnet IDs for the VPC. */ subnetIds: string[]; } interface CodeSigningConfigAllowedPublishers { /** * Set of ARNs for each of the signing profiles. A signing profile defines a trusted user who can sign a code package. Maximum of 20 signing profiles. */ signingProfileVersionArns: string[]; } interface CodeSigningConfigPolicies { /** * Code signing configuration policy for deployment validation failure. If you set the policy to `Enforce`, Lambda blocks the deployment request if code-signing validation checks fail. If you set the policy to `Warn`, Lambda allows the deployment and creates a CloudWatch log. Valid values: `Warn`, `Enforce`. Default value: `Warn`. */ untrustedArtifactOnDeployment: string; } interface CoreNetworkConnectorConfiguration { /** * Configuration for routing egress traffic through a VPC. See `vpcEgressConfiguration` Block below. */ vpcEgressConfiguration?: outputs.lambda.CoreNetworkConnectorConfigurationVpcEgressConfiguration; } interface CoreNetworkConnectorConfigurationVpcEgressConfiguration { /** * Compute resource types that may use this connector. Valid values: `MicroVm`. */ associatedComputeResourceTypes: string[]; /** * Network protocol. Valid values: `IPv4`, `DualStack`. */ networkProtocol: string; /** * Set of security group IDs applied to the connector's ENIs. */ securityGroupIds: string[]; /** * Set of subnet IDs where the connector provisions its ENIs. */ subnetIds: string[]; } interface CoreNetworkConnectorTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface EventSourceMappingAmazonManagedKafkaEventSourceConfig { /** * Kafka consumer group ID between 1 and 200 characters for use when creating this event source mapping. If one is not specified, this value will be automatically generated. See [AmazonManagedKafkaEventSourceConfig Syntax](https://docs.aws.amazon.com/lambda/latest/dg/API_AmazonManagedKafkaEventSourceConfig.html). */ consumerGroupId: string; /** * Block for a Kafka schema registry setting. See below. */ schemaRegistryConfig?: outputs.lambda.EventSourceMappingAmazonManagedKafkaEventSourceConfigSchemaRegistryConfig; } interface EventSourceMappingAmazonManagedKafkaEventSourceConfigSchemaRegistryConfig { /** * Configuration block for authentication Lambda uses to access the schema registry. See below. */ accessConfigs?: outputs.lambda.EventSourceMappingAmazonManagedKafkaEventSourceConfigSchemaRegistryConfigAccessConfig[]; /** * Record format that Lambda delivers to the function after schema validation. Valid values: `JSON`, `SOURCE`. */ eventRecordFormat?: string; /** * URI of the schema registry. For AWS Glue schema registries, use the ARN of the registry. For Confluent schema registries, use the registry URL. */ schemaRegistryUri?: string; /** * Repeatable block that defines schema validation settings. These specify the message attributes that Lambda should validate and filter using the schema registry. See below. */ schemaValidationConfigs?: outputs.lambda.EventSourceMappingAmazonManagedKafkaEventSourceConfigSchemaRegistryConfigSchemaValidationConfig[]; } interface EventSourceMappingAmazonManagedKafkaEventSourceConfigSchemaRegistryConfigAccessConfig { type?: string; uri?: string; } interface EventSourceMappingAmazonManagedKafkaEventSourceConfigSchemaRegistryConfigSchemaValidationConfig { /** * Message attribute to validate. Valid values: `KEY`, `VALUE`. */ attribute?: string; } interface EventSourceMappingDestinationConfig { /** * Destination configuration for failed invocations. See below. */ onFailure?: outputs.lambda.EventSourceMappingDestinationConfigOnFailure; } interface EventSourceMappingDestinationConfigOnFailure { /** * ARN of the destination resource, or `kafka://your-topic-name` for Amazon MSK and self-managed Apache Kafka destinations. */ destinationArn: string; } interface EventSourceMappingDocumentDbEventSourceConfig { /** * Name of the collection to consume within the database. If you do not specify a collection, Lambda consumes all collections. */ collectionName?: string; /** * Name of the database to consume within the DocumentDB cluster. */ databaseName: string; /** * DocumentDB behavior during document update operations. If set to `UpdateLookup`, DocumentDB sends a delta describing the changes, along with a copy of the entire document. Otherwise, DocumentDB sends only a partial document that contains the changes. Valid values: `UpdateLookup`, `Default`. */ fullDocument?: string; } interface EventSourceMappingFilterCriteria { /** * Set of up to 5 filter. If an event satisfies at least one, Lambda sends the event to the function or adds it to the next batch. See below. */ filters?: outputs.lambda.EventSourceMappingFilterCriteriaFilter[]; } interface EventSourceMappingFilterCriteriaFilter { /** * Filter pattern up to 4096 characters. See [Filter Rule Syntax](https://docs.aws.amazon.com/lambda/latest/dg/invocation-eventfiltering.html#filtering-syntax). */ pattern?: string; } interface EventSourceMappingMetricsConfig { /** * List containing the metrics to be produced by the event source mapping. Valid values: `EventCount`, `ErrorCount`, `KafkaMetrics`. */ metrics: string[]; } interface EventSourceMappingProvisionedPollerConfig { /** * Maximum number of event pollers this event source can scale up to. The range is between 1 and 2000. */ maximumPollers: number; /** * Minimum number of event pollers this event source can scale down to. The range is between 1 and 200. */ minimumPollers: number; /** * Name of the provisioned poller group used to group multiple ESMs within the event source's VPC to share Event Poller Unit (EPU) capacity. You can use this option to optimize Provisioned mode costs for your ESMs. You can group up to 100 ESMs per poller group and aggregate maximum pollers across all ESMs in a group cannot exceed 2000. */ pollerGroupName: string; } interface EventSourceMappingScalingConfig { /** * Limits the number of concurrent instances that the Amazon SQS event source can invoke. Must be greater than or equal to 2. See [Configuring maximum concurrency for Amazon SQS event sources](https://docs.aws.amazon.com/lambda/latest/dg/with-sqs.html#events-sqs-max-concurrency). You need to raise a [Service Quota Ticket](https://docs.aws.amazon.com/general/latest/gr/aws_service_limits.html) to increase the concurrency beyond 1000. */ maximumConcurrency?: number; } interface EventSourceMappingSelfManagedEventSource { /** * Map of endpoints for the self managed source. For Kafka self-managed sources, the key should be `KAFKA_BOOTSTRAP_SERVERS` and the value should be a string with a comma separated list of broker endpoints. */ endpoints: { [key: string]: string; }; } interface EventSourceMappingSelfManagedKafkaEventSourceConfig { /** * Kafka consumer group ID between 1 and 200 characters for use when creating this event source mapping. If one is not specified, this value will be automatically generated. See [SelfManagedKafkaEventSourceConfig Syntax](https://docs.aws.amazon.com/lambda/latest/dg/API_SelfManagedKafkaEventSourceConfig.html). */ consumerGroupId: string; /** * Block for a Kafka schema registry setting. See below. */ schemaRegistryConfig?: outputs.lambda.EventSourceMappingSelfManagedKafkaEventSourceConfigSchemaRegistryConfig; } interface EventSourceMappingSelfManagedKafkaEventSourceConfigSchemaRegistryConfig { /** * Configuration block for authentication Lambda uses to access the schema registry. See below. */ accessConfigs?: outputs.lambda.EventSourceMappingSelfManagedKafkaEventSourceConfigSchemaRegistryConfigAccessConfig[]; /** * Record format that Lambda delivers to the function after schema validation. Valid values: `JSON`, `SOURCE`. */ eventRecordFormat?: string; /** * URI of the schema registry. For AWS Glue schema registries, use the ARN of the registry. For Confluent schema registries, use the registry URL. */ schemaRegistryUri?: string; /** * Repeatable block that defines schema validation settings. These specify the message attributes that Lambda should validate and filter using the schema registry. See below. */ schemaValidationConfigs?: outputs.lambda.EventSourceMappingSelfManagedKafkaEventSourceConfigSchemaRegistryConfigSchemaValidationConfig[]; } interface EventSourceMappingSelfManagedKafkaEventSourceConfigSchemaRegistryConfigAccessConfig { type?: string; uri?: string; } interface EventSourceMappingSelfManagedKafkaEventSourceConfigSchemaRegistryConfigSchemaValidationConfig { /** * Message attribute to validate. Valid values: `KEY`, `VALUE`. */ attribute?: string; } interface EventSourceMappingSourceAccessConfiguration { /** * Type of authentication protocol, VPC components, or virtual host for your event source. For valid values, refer to the [AWS documentation](https://docs.aws.amazon.com/lambda/latest/api/API_SourceAccessConfiguration.html). */ type: string; /** * URI for this configuration. For type `VPC_SUBNET` the value should be `subnet:subnet_id` where `subnetId` is the value you would find in an aws.ec2.Subnet resource's id attribute. For type `VPC_SECURITY_GROUP` the value should be `security_group:security_group_id` where `securityGroupId` is the value you would find in an aws.ec2.SecurityGroup resource's id attribute. */ uri: string; } interface FunctionCapacityProviderConfig { /** * Configuration block for Lambda Managed Instances Capacity Provider. See below. */ lambdaManagedInstancesCapacityProviderConfig: outputs.lambda.FunctionCapacityProviderConfigLambdaManagedInstancesCapacityProviderConfig; } interface FunctionCapacityProviderConfigLambdaManagedInstancesCapacityProviderConfig { /** * ARN of the Capacity Provider. */ capacityProviderArn: string; /** * Memory GiB per vCPU for the execution environment. */ executionEnvironmentMemoryGibPerVcpu: number; /** * Maximum concurrency per execution environment. */ perExecutionEnvironmentMaxConcurrency: number; } interface FunctionDeadLetterConfig { /** * ARN of an SNS topic or SQS queue to notify when an invocation fails. */ targetArn: string; } interface FunctionDurableConfig { /** * Maximum execution time in seconds for the durable function. Valid value between 1 and 31622400 (366 days). */ executionTimeout: number; /** * Number of days to retain the function's execution state. Valid value between 1 and 90. If not specified, the function's execution state is not retained. Defaults to 14. */ retentionPeriod?: number; } interface FunctionEnvironment { /** * Map of environment variables available to your Lambda function during execution. */ variables?: { [key: string]: string; }; } interface FunctionEphemeralStorage { /** * Amount of ephemeral storage (`/tmp`) in MB. Valid between 512 MB and 10,240 MB (10 GB). */ size: number; } interface FunctionEventInvokeConfigDestinationConfig { /** * Configuration block with destination configuration for failed asynchronous invocations. See below. */ onFailure?: outputs.lambda.FunctionEventInvokeConfigDestinationConfigOnFailure; /** * Configuration block with destination configuration for successful asynchronous invocations. See below. */ onSuccess?: outputs.lambda.FunctionEventInvokeConfigDestinationConfigOnSuccess; } interface FunctionEventInvokeConfigDestinationConfigOnFailure { /** * ARN of the destination resource. See the [Lambda Developer Guide](https://docs.aws.amazon.com/lambda/latest/dg/invocation-async.html#invocation-async-destinations) for acceptable resource types and associated IAM permissions. */ destination: string; } interface FunctionEventInvokeConfigDestinationConfigOnSuccess { /** * ARN of the destination resource. See the [Lambda Developer Guide](https://docs.aws.amazon.com/lambda/latest/dg/invocation-async.html#invocation-async-destinations) for acceptable resource types and associated IAM permissions. */ destination: string; } interface FunctionFileSystemConfig { /** * ARN of the Amazon EFS Access Point, or the Amazon S3 Files access point. */ arn: string; /** * Path where the function can access the file system. Must start with `/mnt/`. */ localMountPath: string; } interface FunctionImageConfig { /** * Parameters to pass to the container image. */ commands?: string[]; /** * Entry point to your application. */ entryPoints?: string[]; /** * Working directory for the container image. */ workingDirectory?: string; } interface FunctionLoggingConfig { /** * Detail level of application logs. Valid values: `TRACE`, `DEBUG`, `INFO`, `WARN`, `ERROR`, `FATAL`. */ applicationLogLevel?: string; /** * Log format. Valid values: `Text`, `JSON`. */ logFormat: string; /** * CloudWatch log group where logs are sent. */ logGroup: string; /** * Detail level of Lambda platform logs. Valid values: `DEBUG`, `INFO`, `WARN`. */ systemLogLevel?: string; } interface FunctionScalingConfigFunctionScalingConfig { /** * Maximum number of execution environments that can be provisioned for the function. */ maxExecutionEnvironments: number; /** * Minimum number of execution environments to maintain for the function. */ minExecutionEnvironments: number; } interface FunctionScalingConfigTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface FunctionSnapStart { /** * When to apply snap start optimization. Valid value: `PublishedVersions`. */ applyOn: string; /** * Optimization status of the snap start configuration. Valid values are `On` and `Off`. */ optimizationStatus: string; } interface FunctionTenancyConfig { /** * Tenant Isolation Mode. Valid values: `PER_TENANT`. */ tenantIsolationMode: string; } interface FunctionTracingConfig { /** * X-Ray tracing mode. Valid values: `Active`, `PassThrough`. */ mode: string; } interface FunctionUrlCors { /** * Whether to allow cookies or other credentials in requests to the function URL. */ allowCredentials?: boolean; /** * HTTP headers that origins can include in requests to the function URL. */ allowHeaders?: string[]; /** * HTTP methods that are allowed when calling the function URL. */ allowMethods?: string[]; /** * Origins that can access the function URL. */ allowOrigins?: string[]; /** * HTTP headers in your function response that you want to expose to origins that call the function URL. */ exposeHeaders?: string[]; /** * Maximum amount of time, in seconds, that web browsers can cache results of a preflight request. Maximum value is `86400`. */ maxAge?: number; } interface FunctionVpcConfig { /** * Whether to allow outbound IPv6 traffic on VPC functions connected to dual-stack subnets. Default: `false`. */ ipv6AllowedForDualStack?: boolean; /** * List of security group IDs associated with the Lambda function. */ securityGroupIds: string[]; /** * List of subnet IDs associated with the Lambda function. */ subnetIds: string[]; /** * ID of the VPC. */ vpcId: string; } interface GetCodeSigningConfigAllowedPublisher { /** * Set of ARNs for each of the signing profiles. A signing profile defines a trusted user who can sign a code package. */ signingProfileVersionArns: string[]; } interface GetCodeSigningConfigPolicy { /** * Code signing configuration policy for deployment validation failure. Valid values: `Warn`, `Enforce`. */ untrustedArtifactOnDeployment: string; } interface GetFunctionCapacityProviderConfig { /** * Configuration block for Lambda Managed Instances Capacity Provider. See `lambdaManagedInstancesCapacityProviderConfig` below. */ lambdaManagedInstancesCapacityProviderConfigs: outputs.lambda.GetFunctionCapacityProviderConfigLambdaManagedInstancesCapacityProviderConfig[]; } interface GetFunctionCapacityProviderConfigLambdaManagedInstancesCapacityProviderConfig { /** * ARN of the Capacity Provider. */ capacityProviderArn: string; /** * Memory GiB per vCPU for the execution environment. */ executionEnvironmentMemoryGibPerVcpu: number; /** * Maximum concurrency per execution environment. */ perExecutionEnvironmentMaxConcurrency: number; } interface GetFunctionDeadLetterConfig { /** * ARN of an SNS topic or SQS queue to notify when an invocation fails. */ targetArn: string; } interface GetFunctionDurableConfig { /** * Maximum execution time in seconds for the durable function. */ executionTimeout: number; /** * Number of days to retain the function's execution state. */ retentionPeriod: number; } interface GetFunctionEnvironment { /** * Map of environment variables that are accessible from the function code during execution. */ variables: { [key: string]: string; }; } interface GetFunctionEphemeralStorage { /** * Size of the Lambda function ephemeral storage (`/tmp`) in MB. */ size: number; } interface GetFunctionFileSystemConfig { /** * ARN of the Amazon EFS Access Point that provides access to the file system. */ arn: string; /** * Path where the function can access the file system, starting with `/mnt/`. */ localMountPath: string; } interface GetFunctionLoggingConfig { /** * Detail level of the logs your application sends to CloudWatch when using supported logging libraries. */ applicationLogLevel: string; /** * Format for your function's logs. Valid values: `Text`, `JSON`. */ logFormat: string; /** * CloudWatch log group your function sends logs to. */ logGroup: string; /** * Detail level of the Lambda platform event logs sent to CloudWatch. */ systemLogLevel: string; } interface GetFunctionTenancyConfig { /** * Tenant Isolation Mode. Valid values: `PER_TENANT`. */ tenantIsolationMode: string; } interface GetFunctionTracingConfig { /** * Tracing mode. Valid values: `Active`, `PassThrough`. */ mode: string; } interface GetFunctionUrlCor { /** * Whether credentials are included in the CORS request. */ allowCredentials: boolean; /** * List of headers that are specified in the Access-Control-Request-Headers header. */ allowHeaders: string[]; /** * List of HTTP methods that are allowed when calling the function URL. */ allowMethods: string[]; /** * List of origins that are allowed to make requests to the function URL. */ allowOrigins: string[]; /** * List of headers in the response that you want to expose to the origin that called the function URL. */ exposeHeaders: string[]; /** * Maximum amount of time, in seconds, that web browsers can cache results of a preflight request. */ maxAge: number; } interface GetFunctionVpcConfig { /** * Whether IPv6 is allowed for dual-stack VPC. */ ipv6AllowedForDualStack: boolean; /** * List of security group IDs associated with the Lambda function. */ securityGroupIds: string[]; /** * List of subnet IDs associated with the Lambda function. */ subnetIds: string[]; /** * ID of the VPC. */ vpcId: string; } interface MicrovmsImageCodeArtifact { /** * S3 URI of the zip archive containing the application code and Dockerfile (e.g., `s3://bucket/code.zip`). */ uri: string; } interface MicrovmsImageCpuConfiguration { /** * CPU architecture for the MicroVM. Valid values are `x8664` and `arm64`. */ architecture: string; } interface MicrovmsImageTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace lambdamicrovms { interface ImageCodeArtifact { /** * S3 URI of the zip archive containing the application code and Dockerfile (e.g., `s3://bucket/code.zip`). */ uri: string; } interface ImageCpuConfiguration { /** * CPU architecture for the MicroVM. Valid values are `x8664` and `arm64`. */ architecture: string; } interface ImageTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface MicrovmIdlePolicy { /** * Whether to automatically resume the MicroVM when it receives a request while suspended. */ autoResumeEnabled: boolean; /** * Number of seconds without traffic after which the MicroVM is suspended. */ maxIdleDurationSeconds: number; /** * Number of seconds a MicroVM remains suspended before it is automatically terminated. */ suspendedDurationSeconds: number; } interface MicrovmLogging { /** * Send logs to Amazon CloudWatch Logs. See below. */ cloudwatch?: outputs.lambdamicrovms.MicrovmLoggingCloudwatch; /** * Disable logging for the MicroVM. Specify an empty block: `disabled {}`. */ disabled?: outputs.lambdamicrovms.MicrovmLoggingDisabled; } interface MicrovmLoggingCloudwatch { /** * Name of the CloudWatch Logs log group to send logs to. */ logGroup?: string; /** * Name of the CloudWatch Logs log stream within the log group. */ logStream?: string; } interface MicrovmLoggingDisabled { } interface MicrovmTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace lb { interface GetListenerDefaultAction { authenticateCognitos: outputs.lb.GetListenerDefaultActionAuthenticateCognito[]; authenticateOidcs: outputs.lb.GetListenerDefaultActionAuthenticateOidc[]; fixedResponses: outputs.lb.GetListenerDefaultActionFixedResponse[]; forwards: outputs.lb.GetListenerDefaultActionForward[]; jwtValidations: outputs.lb.GetListenerDefaultActionJwtValidation[]; order: number; redirects: outputs.lb.GetListenerDefaultActionRedirect[]; targetGroupArn: string; type: string; } interface GetListenerDefaultActionAuthenticateCognito { authenticationRequestExtraParams: { [key: string]: string; }; onUnauthenticatedRequest: string; scope: string; sessionCookieName: string; sessionTimeout: number; userPoolArn: string; userPoolClientId: string; userPoolDomain: string; } interface GetListenerDefaultActionAuthenticateOidc { authenticationRequestExtraParams: { [key: string]: string; }; authorizationEndpoint: string; clientId: string; clientSecret: string; issuer: string; onUnauthenticatedRequest: string; scope: string; sessionCookieName: string; sessionTimeout: number; tokenEndpoint: string; userInfoEndpoint: string; } interface GetListenerDefaultActionFixedResponse { contentType: string; messageBody: string; statusCode: string; } interface GetListenerDefaultActionForward { stickinesses: outputs.lb.GetListenerDefaultActionForwardStickiness[]; targetGroups: outputs.lb.GetListenerDefaultActionForwardTargetGroup[]; } interface GetListenerDefaultActionForwardStickiness { duration: number; enabled: boolean; } interface GetListenerDefaultActionForwardTargetGroup { /** * ARN of the listener. Required if `loadBalancerArn` and `port` is not set. */ arn: string; weight: number; } interface GetListenerDefaultActionJwtValidation { additionalClaims: outputs.lb.GetListenerDefaultActionJwtValidationAdditionalClaim[]; issuer: string; jwksEndpoint: string; } interface GetListenerDefaultActionJwtValidationAdditionalClaim { format: string; name: string; values: string[]; } interface GetListenerDefaultActionRedirect { host: string; path: string; /** * Port of the listener. Required if `arn` is not set. */ port: string; protocol: string; query: string; statusCode: string; } interface GetListenerMutualAuthentication { advertiseTrustStoreCaNames: string; ignoreClientCertificateExpiry: boolean; mode: string; trustStoreArn: string; } interface GetListenerRuleAction { /** * An action to authenticate using Amazon Cognito. * Detailed below. */ authenticateCognitos?: outputs.lb.GetListenerRuleActionAuthenticateCognito[]; /** * An action to authenticate using OIDC. * Detailed below. */ authenticateOidcs?: outputs.lb.GetListenerRuleActionAuthenticateOidc[]; /** * An action to return a fixed response. * Detailed below. */ fixedResponses?: outputs.lb.GetListenerRuleActionFixedResponse[]; /** * An action to forward the request. * Detailed below. */ forwards?: outputs.lb.GetListenerRuleActionForward[]; /** * An action to validate using JWT. * Detailed below. */ jwtValidations?: outputs.lb.GetListenerRuleActionJwtValidation[]; /** * The evaluation order of the action. */ order: number; /** * An action to redirect the request. * Detailed below. */ redirects?: outputs.lb.GetListenerRuleActionRedirect[]; /** * Type of transform. */ type: string; } interface GetListenerRuleActionAuthenticateCognito { /** * Set of additional parameters for the request. * Detailed below. */ authenticationRequestExtraParams: { [key: string]: string; }; /** * Behavior when the client is not authenticated. */ onUnauthenticatedRequest: string; /** * Set of user claims requested. */ scope: string; /** * Name of the cookie used to maintain session information. */ sessionCookieName: string; /** * Maximum duration of the authentication session in seconds. */ sessionTimeout: number; /** * ARN of the Cognito user pool. */ userPoolArn: string; /** * ID of the Cognito user pool client. */ userPoolClientId: string; /** * Domain prefix or fully-qualified domain name of the Cognito user pool. */ userPoolDomain: string; } interface GetListenerRuleActionAuthenticateOidc { /** * Set of additional parameters for the request. * Detailed below. */ authenticationRequestExtraParams: { [key: string]: string; }; /** * The authorization endpoint of the IdP. */ authorizationEndpoint: string; /** * OAuth 2.0 client identifier. */ clientId: string; /** * Issuer of the JWT. */ issuer: string; /** * Behavior when the client is not authenticated. */ onUnauthenticatedRequest: string; /** * Set of user claims requested. */ scope: string; /** * Name of the cookie used to maintain session information. */ sessionCookieName: string; /** * Maximum duration of the authentication session in seconds. */ sessionTimeout: number; /** * The token endpoint of the IdP. */ tokenEndpoint: string; /** * The user info endpoint of the IdP. */ userInfoEndpoint: string; } interface GetListenerRuleActionFixedResponse { /** * Content type of the response. */ contentType: string; /** * Message body of the response. */ messageBody: string; /** * The HTTP redirect code. */ statusCode: string; } interface GetListenerRuleActionForward { /** * Target group stickiness for the rule. * Detailed below. */ stickinesses?: outputs.lb.GetListenerRuleActionForwardStickiness[]; /** * Set of target groups for the action. * Detailed below. */ targetGroups?: outputs.lb.GetListenerRuleActionForwardTargetGroup[]; } interface GetListenerRuleActionForwardStickiness { /** * The time period, in seconds, during which requests from a client should be routed to the same target group. */ duration: number; /** * Indicates whether target group stickiness is enabled. */ enabled: boolean; } interface GetListenerRuleActionForwardTargetGroup { /** * ARN of the Listener Rule. * Either `arn` or `listenerArn` must be set. */ arn: string; /** * Weight of the target group. */ weight: number; } interface GetListenerRuleActionJwtValidation { /** * Additional claims to validate. */ additionalClaims?: outputs.lb.GetListenerRuleActionJwtValidationAdditionalClaim[]; /** * Issuer of the JWT. */ issuer: string; /** * JSON Web Key Set (JWKS) endpoint. */ jwksEndpoint: string; } interface GetListenerRuleActionJwtValidationAdditionalClaim { /** * Format of the claim value. */ format: string; /** * Name of the claim to validate. */ name: string; /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values: string[]; } interface GetListenerRuleActionRedirect { /** * The hostname. */ host: string; /** * The absolute path, starting with `/`. */ path: string; /** * The port. */ port: string; /** * The protocol. */ protocol: string; /** * The query parameters. */ query: string; /** * The HTTP redirect code. */ statusCode: string; } interface GetListenerRuleCondition { /** * Host header patterns to match. * Detailed below. */ hostHeaders?: outputs.lb.GetListenerRuleConditionHostHeader[]; /** * HTTP header and values to match. * Detailed below. */ httpHeaders?: outputs.lb.GetListenerRuleConditionHttpHeader[]; /** * Contains a single attribute `values`, which contains a set of HTTP request methods. */ httpRequestMethods?: outputs.lb.GetListenerRuleConditionHttpRequestMethod[]; /** * Path patterns to compare against the request URL. * Detailed below. */ pathPatterns?: outputs.lb.GetListenerRuleConditionPathPattern[]; /** * Query string parameters to match. * Detailed below. */ queryStrings?: outputs.lb.GetListenerRuleConditionQueryString[]; /** * Source IP address to match. * Detailed below. */ sourceIps?: outputs.lb.GetListenerRuleConditionSourceIp[]; } interface GetListenerRuleConditionHostHeader { /** * Set of regular expressions to compare against the request URL. */ regexValues: string[]; /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values: string[]; } interface GetListenerRuleConditionHttpHeader { /** * Name of the HTTP header to match. */ httpHeaderName: string; /** * Set of regular expressions to compare against the request URL. */ regexValues: string[]; /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values: string[]; } interface GetListenerRuleConditionHttpRequestMethod { /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values: string[]; } interface GetListenerRuleConditionPathPattern { /** * Set of regular expressions to compare against the request URL. */ regexValues: string[]; /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values: string[]; } interface GetListenerRuleConditionQueryString { /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values?: outputs.lb.GetListenerRuleConditionQueryStringValue[]; } interface GetListenerRuleConditionQueryStringValue { /** * Key of query parameter */ key: string; /** * Value of query parameter */ value: string; } interface GetListenerRuleConditionSourceIp { /** * IP address type for Network Load Balancers. */ ipAddressType: string; /** * Set of source IP addresses in CIDR format for Application Load Balancers */ values: string[]; } interface GetListenerRuleTransform { /** * Block for host header rewrite. Detailed below. */ hostHeaderRewriteConfigs?: outputs.lb.GetListenerRuleTransformHostHeaderRewriteConfig[]; /** * Type of transform. */ type: string; /** * Block for URL rewrite. Detailed below. */ urlRewriteConfigs?: outputs.lb.GetListenerRuleTransformUrlRewriteConfig[]; } interface GetListenerRuleTransformHostHeaderRewriteConfig { /** * Block for URL rewrite configuration. Detailed below. */ rewrites?: outputs.lb.GetListenerRuleTransformHostHeaderRewriteConfigRewrite[]; } interface GetListenerRuleTransformHostHeaderRewriteConfigRewrite { /** * Regular expression to match in the input string. */ regex: string; /** * Replacement string to use when rewriting the matched input. */ replace: string; } interface GetListenerRuleTransformUrlRewriteConfig { /** * Block for URL rewrite configuration. Detailed below. */ rewrites?: outputs.lb.GetListenerRuleTransformUrlRewriteConfigRewrite[]; } interface GetListenerRuleTransformUrlRewriteConfigRewrite { /** * Regular expression to match in the input string. */ regex: string; /** * Replacement string to use when rewriting the matched input. */ replace: string; } interface GetLoadBalancerAccessLogs { bucket: string; enabled: boolean; prefix: string; } interface GetLoadBalancerConnectionLog { bucket: string; enabled: boolean; prefix: string; } interface GetLoadBalancerHealthCheckLog { bucket: string; enabled: boolean; prefix: string; } interface GetLoadBalancerIpamPool { ipv4IpamPoolId: string; } interface GetLoadBalancerSubnetMapping { allocationId: string; ipv6Address: string; outpostId: string; privateIpv4Address: string; subnetId: string; } interface GetTargetGroupHealthCheck { enabled: boolean; healthyThreshold: number; interval: number; matcher: string; path: string; port: string; protocol: string; timeout: number; unhealthyThreshold: number; } interface GetTargetGroupStickiness { cookieDuration: number; cookieName: string; enabled: boolean; type: string; } interface ListenerDefaultAction { /** * Configuration block for using Amazon Cognito to authenticate users. Specify only when `type` is `authenticate-cognito`. See below. */ authenticateCognito?: outputs.lb.ListenerDefaultActionAuthenticateCognito; /** * Configuration block for an identity provider that is compliant with OpenID Connect (OIDC). Specify only when `type` is `authenticate-oidc`. See below. */ authenticateOidc?: outputs.lb.ListenerDefaultActionAuthenticateOidc; /** * Information for creating an action that returns a custom HTTP response. Required if `type` is `fixed-response`. */ fixedResponse?: outputs.lb.ListenerDefaultActionFixedResponse; /** * Configuration block for creating an action that distributes requests among one or more target groups. Specify only if `type` is `forward`. See below. */ forward?: outputs.lb.ListenerDefaultActionForward; /** * Configuration block for creating a JWT validation action. Required if `type` is `jwt-validation`. */ jwtValidation?: outputs.lb.ListenerDefaultActionJwtValidation; /** * Order for the action. The action with the lowest value for order is performed first. Valid values are between `1` and `50000`. Defaults to the position in the list of actions. */ order: number; /** * Configuration block for creating a redirect action. Required if `type` is `redirect`. See below. */ redirect?: outputs.lb.ListenerDefaultActionRedirect; /** * ARN of the Target Group to which to route traffic. Specify only if `type` is `forward` and you want to route to a single target group. To route to one or more target groups, use a `forward` block instead. Can be specified with `forward` but ARNs must match. */ targetGroupArn?: string; /** * Type of routing action. Valid values are `forward`, `redirect`, `fixed-response`, `authenticate-cognito`, `authenticate-oidc` and `jwt-validation`. * * The following arguments are optional: */ type: string; } interface ListenerDefaultActionAuthenticateCognito { /** * Query parameters to include in the redirect request to the authorization endpoint. Max: 10. See below. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * Behavior if the user is not authenticated. Valid values are `deny`, `allow` and `authenticate`. */ onUnauthenticatedRequest: string; /** * Set of user claims to be requested from the IdP. */ scope: string; /** * Name of the cookie used to maintain session information. */ sessionCookieName: string; /** * Maximum duration of the authentication session, in seconds. */ sessionTimeout: number; /** * ARN of the Cognito user pool. */ userPoolArn: string; /** * ID of the Cognito user pool client. */ userPoolClientId: string; /** * Domain prefix or fully-qualified domain name of the Cognito user pool. * * The following arguments are optional: */ userPoolDomain: string; } interface ListenerDefaultActionAuthenticateOidc { /** * Query parameters to include in the redirect request to the authorization endpoint. Max: 10. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * Authorization endpoint of the IdP. */ authorizationEndpoint: string; /** * OAuth 2.0 client identifier. */ clientId: string; /** * OAuth 2.0 client secret. */ clientSecret: string; /** * OIDC issuer identifier of the IdP. */ issuer: string; /** * Behavior if the user is not authenticated. Valid values: `deny`, `allow` and `authenticate` */ onUnauthenticatedRequest: string; /** * Set of user claims to be requested from the IdP. */ scope: string; /** * Name of the cookie used to maintain session information. */ sessionCookieName: string; /** * Maximum duration of the authentication session, in seconds. */ sessionTimeout: number; /** * Token endpoint of the IdP. */ tokenEndpoint: string; /** * User info endpoint of the IdP. * * The following arguments are optional: */ userInfoEndpoint: string; } interface ListenerDefaultActionFixedResponse { /** * Content type. Valid values are `text/plain`, `text/css`, `text/html`, `application/javascript` and `application/json`. * * The following arguments are optional: */ contentType: string; /** * Message body. */ messageBody?: string; /** * HTTP response code. Valid values are `2XX`, `4XX`, or `5XX`. */ statusCode: string; } interface ListenerDefaultActionForward { /** * Configuration block for target group stickiness for the rule. See below. */ stickiness?: outputs.lb.ListenerDefaultActionForwardStickiness; /** * Set of 1-5 target group blocks. See below. * * The following arguments are optional: */ targetGroups: outputs.lb.ListenerDefaultActionForwardTargetGroup[]; } interface ListenerDefaultActionForwardStickiness { /** * Time period, in seconds, during which requests from a client should be routed to the same target group. The range is 1-604800 seconds (7 days). * * The following arguments are optional: */ duration: number; /** * Whether target group stickiness is enabled. Default is `false`. */ enabled?: boolean; } interface ListenerDefaultActionForwardTargetGroup { /** * ARN of the target group. * * The following arguments are optional: */ arn: string; /** * Weight. The range is 0 to 999. */ weight?: number; } interface ListenerDefaultActionJwtValidation { /** * Repeatable configuration block for additional claims to validate. */ additionalClaims?: outputs.lb.ListenerDefaultActionJwtValidationAdditionalClaim[]; /** * Issuer of the JWT. */ issuer: string; /** * JSON Web Key Set (JWKS) endpoint. This endpoint contains JSON Web Keys (JWK) that are used to validate signatures from the provider. This must be a full URL, including the HTTPS protocol, the domain, and the path. * * The following arguments are optional: */ jwksEndpoint: string; } interface ListenerDefaultActionJwtValidationAdditionalClaim { /** * Format of the claim value. Valid values are `single-string`, `string-array` and `space-separated-values`. */ format: string; /** * Name of the claim to validate. `exp`, `iss`, `nbf`, or `iat` cannot be specified because they are validated by default. */ name: string; /** * List of expected values of the claim. */ values: string[]; } interface ListenerDefaultActionRedirect { /** * Hostname. This component is not percent-encoded. The hostname can contain `#{host}`. Defaults to `#{host}`. */ host?: string; /** * Absolute path, starting with the leading "/". This component is not percent-encoded. The path can contain #{host}, #{path}, and #{port}. Defaults to `/#{path}`. */ path?: string; /** * Port. Specify a value from `1` to `65535` or `#{port}`. Defaults to `#{port}`. */ port?: string; /** * Protocol. Valid values are `HTTP`, `HTTPS`, or `#{protocol}`. Defaults to `#{protocol}`. */ protocol?: string; /** * Query parameters, URL-encoded when necessary, but not percent-encoded. Do not include the leading "?". Defaults to `#{query}`. */ query?: string; /** * HTTP redirect code. The redirect is either permanent (`HTTP_301`) or temporary (`HTTP_302`). * * The following arguments are optional: */ statusCode: string; } interface ListenerMutualAuthentication { /** * Valid values are `off` and `on`. */ advertiseTrustStoreCaNames: string; /** * Whether client certificate expiry is ignored. * Default is `false`. */ ignoreClientCertificateExpiry?: boolean; /** * Valid values are `off`, `passthrough`, and `verify`. */ mode: string; /** * ARN of the elbv2 Trust Store. */ trustStoreArn?: string; } interface ListenerRuleAction { /** * Information for creating an authenticate action using Cognito. Required if `type` is `authenticate-cognito`. */ authenticateCognito?: outputs.lb.ListenerRuleActionAuthenticateCognito; /** * Information for creating an authenticate action using OIDC. Required if `type` is `authenticate-oidc`. */ authenticateOidc?: outputs.lb.ListenerRuleActionAuthenticateOidc; /** * Information for creating an action that returns a custom HTTP response. Required if `type` is `fixed-response`. */ fixedResponse?: outputs.lb.ListenerRuleActionFixedResponse; /** * Configuration block for creating an action that distributes requests among one or more target groups. * Specify only if `type` is `forward`. * Cannot be specified with `targetGroupArn`. */ forward?: outputs.lb.ListenerRuleActionForward; /** * Information for creating a JWT validation action. Required if `type` is `jwt-validation`. */ jwtValidation?: outputs.lb.ListenerRuleActionJwtValidation; /** * Order for the action. * The action with the lowest value for order is performed first. * Valid values are between `1` and `50000`. * Defaults to the position in the list of actions. */ order: number; /** * Information for creating a redirect action. Required if `type` is `redirect`. */ redirect?: outputs.lb.ListenerRuleActionRedirect; /** * ARN of the Target Group to which to route traffic. * Specify only if `type` is `forward` and you want to route to a single target group. * To route to one or more target groups, use a `forward` block instead. * Cannot be specified with `forward`. */ targetGroupArn?: string; /** * The type of routing action. Valid values are `forward`, `redirect`, `fixed-response`, `authenticate-cognito`, `authenticate-oidc` and `jwt-validation`. */ type: string; } interface ListenerRuleActionAuthenticateCognito { /** * The query parameters to include in the redirect request to the authorization endpoint. Max: 10. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * The behavior if the user is not authenticated. Valid values: `deny`, `allow` and `authenticate` */ onUnauthenticatedRequest: string; /** * The set of user claims to be requested from the IdP. */ scope?: string; /** * The name of the cookie used to maintain session information. */ sessionCookieName?: string; /** * The maximum duration of the authentication session, in seconds. */ sessionTimeout?: number; /** * The ARN of the Cognito user pool. */ userPoolArn: string; /** * The ID of the Cognito user pool client. */ userPoolClientId: string; /** * The domain prefix or fully-qualified domain name of the Cognito user pool. */ userPoolDomain: string; } interface ListenerRuleActionAuthenticateOidc { /** * The query parameters to include in the redirect request to the authorization endpoint. Max: 10. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * The authorization endpoint of the IdP. */ authorizationEndpoint: string; /** * The OAuth 2.0 client identifier. */ clientId: string; /** * The OAuth 2.0 client secret. */ clientSecret: string; /** * The OIDC issuer identifier of the IdP. */ issuer: string; /** * The behavior if the user is not authenticated. Valid values: `deny`, `allow` and `authenticate` */ onUnauthenticatedRequest: string; /** * The set of user claims to be requested from the IdP. */ scope?: string; /** * The name of the cookie used to maintain session information. */ sessionCookieName?: string; /** * The maximum duration of the authentication session, in seconds. */ sessionTimeout?: number; /** * The token endpoint of the IdP. */ tokenEndpoint: string; /** * The user info endpoint of the IdP. */ userInfoEndpoint: string; } interface ListenerRuleActionFixedResponse { /** * The content type. Valid values are `text/plain`, `text/css`, `text/html`, `application/javascript` and `application/json`. */ contentType: string; /** * The message body. */ messageBody?: string; /** * The HTTP response code. Valid values are `2XX`, `4XX`, or `5XX`. */ statusCode: string; } interface ListenerRuleActionForward { /** * The target group stickiness for the rule. */ stickiness?: outputs.lb.ListenerRuleActionForwardStickiness; /** * One or more target group blocks. */ targetGroups: outputs.lb.ListenerRuleActionForwardTargetGroup[]; } interface ListenerRuleActionForwardStickiness { /** * The time period, in seconds, during which requests from a client should be routed to the same target group. The range is 1-604800 seconds (7 days). */ duration: number; /** * Indicates whether target group stickiness is enabled. */ enabled?: boolean; } interface ListenerRuleActionForwardTargetGroup { /** * ARN of the target group. */ arn: string; /** * The weight. The range is 0 to 999. */ weight?: number; } interface ListenerRuleActionJwtValidation { /** * Repeatable configuration block for additional claims to validate. */ additionalClaims?: outputs.lb.ListenerRuleActionJwtValidationAdditionalClaim[]; /** * Issuer of the JWT. */ issuer: string; /** * JSON Web Key Set (JWKS) endpoint. This endpoint contains JSON Web Keys (JWK) that are used to validate signatures from the provider. This must be a full URL, including the HTTPS protocol, the domain, and the path. */ jwksEndpoint: string; } interface ListenerRuleActionJwtValidationAdditionalClaim { /** * Format of the claim value. Valid values are `single-string`, `string-array` and `space-separated-values`. */ format: string; /** * Name of the claim to validate. `exp`, `iss`, `nbf`, or `iat` cannot be specified because they are validated by default. */ name: string; /** * List of expected values of the claim. */ values: string[]; } interface ListenerRuleActionRedirect { /** * The hostname. This component is not percent-encoded. The hostname can contain `#{host}`. Defaults to `#{host}`. */ host?: string; /** * The absolute path, starting with the leading "/". This component is not percent-encoded. The path can contain #{host}, #{path}, and #{port}. Defaults to `/#{path}`. */ path?: string; /** * The port. Specify a value from `1` to `65535` or `#{port}`. Defaults to `#{port}`. */ port?: string; /** * The protocol. Valid values are `HTTP`, `HTTPS`, or `#{protocol}`. Defaults to `#{protocol}`. */ protocol?: string; /** * The query parameters, URL-encoded when necessary, but not percent-encoded. Do not include the leading "?". Defaults to `#{query}`. */ query?: string; /** * The HTTP redirect code. The redirect is either permanent (`HTTP_301`) or temporary (`HTTP_302`). */ statusCode: string; } interface ListenerRuleCondition { /** * Host header patterns to match. Host Header block fields documented below. */ hostHeader?: outputs.lb.ListenerRuleConditionHostHeader; /** * HTTP headers to match. HTTP Header block fields documented below. */ httpHeader?: outputs.lb.ListenerRuleConditionHttpHeader; /** * Contains a single `values` item which is a list of HTTP request methods or verbs to match. Maximum size is 40 characters. Only allowed characters are A-Z, hyphen (-) and underscore (\_). Comparison is case sensitive. Wildcards are not supported. Only one needs to match for the condition to be satisfied. AWS recommends that GET and HEAD requests are routed in the same way because the response to a HEAD request may be cached. */ httpRequestMethod?: outputs.lb.ListenerRuleConditionHttpRequestMethod; /** * Path patterns to match against the request URL. Path Pattern block fields documented below. */ pathPattern?: outputs.lb.ListenerRuleConditionPathPattern; /** * Query strings to match. Query String block fields documented below. */ queryStrings?: outputs.lb.ListenerRuleConditionQueryString[]; /** * Source IP address to match. For ALB, use `values` to specify CIDR ranges. For NLB, use `ipAddressType` to match the IP address type (`ipv4` or `ipv6`). Source IP block fields documented below. * * > **NOTE::** Exactly one of `hostHeader`, `httpHeader`, `httpRequestMethod`, `pathPattern`, `queryString` or `sourceIp` must be set per condition. */ sourceIp?: outputs.lb.ListenerRuleConditionSourceIp; } interface ListenerRuleConditionHostHeader { /** * List of regular expressions to compare against the host header. The maximum length of each string is 128 characters. Conflicts with `values`. */ regexValues?: string[]; /** * List of host header value patterns to match. Maximum size of each pattern is 128 characters. Comparison is case-insensitive. Wildcard characters supported: * (matches 0 or more characters) and ? (matches exactly 1 character). Only one pattern needs to match for the condition to be satisfied. To match host headers containing a non-standard port (for example, `example.com:8443`), use `regexValues`. Conflicts with `regexValues`. */ values?: string[]; } interface ListenerRuleConditionHttpHeader { /** * Name of HTTP header to search. The maximum size is 40 characters. Comparison is case-insensitive. Only RFC7240 characters are supported. Wildcards are not supported. You cannot use HTTP header condition to specify the host header, use a `host-header` condition instead. */ httpHeaderName: string; /** * List of regular expression to compare against the HTTP header. The maximum length of each string is 128 characters. Conflicts with `values`. */ regexValues?: string[]; /** * List of header value patterns to match. Maximum size of each pattern is 128 characters. Comparison is case-insensitive. Wildcard characters supported: * (matches 0 or more characters) and ? (matches exactly 1 character). If the same header appears multiple times in the request they will be searched in order until a match is found. Only one pattern needs to match for the condition to be satisfied. To require that all of the strings are a match, create one condition block per string. Conflicts with `regexValues`. */ values?: string[]; } interface ListenerRuleConditionHttpRequestMethod { values: string[]; } interface ListenerRuleConditionPathPattern { /** * List of regular expressions to compare against the request URL. The maximum length of each string is 128 characters. Conflicts with `values`. */ regexValues?: string[]; /** * List of path patterns to compare against the request URL. Maximum size of each pattern is 128 characters. Comparison is case-sensitive. Wildcard characters supported: * (matches 0 or more characters) and ? (matches exactly 1 character). Only one pattern needs to match for the condition to be satisfied. Path pattern is compared only to the path of the URL, not to its query string. To compare against the query string, use a `queryString` condition. Conflicts with `regexValues`. */ values?: string[]; } interface ListenerRuleConditionQueryString { /** * Query string key pattern to match. */ key?: string; /** * Query string value pattern to match. */ value: string; } interface ListenerRuleConditionSourceIp { /** * IP address type for Network Load Balancers. Valid values are `ipv4` and `ipv6`. */ ipAddressType?: string; /** * List of source IP addresses in CIDR format for Application Load Balancers. Both IPv4 and IPv6 addresses can be used. Wildcards are not supported. Condition is satisfied if the source IP address of the request matches one of the CIDR blocks. Condition is not satisfied by the addresses in the `X-Forwarded-For` header, use `httpHeader` condition instead. */ values?: string[]; } interface ListenerRuleTransform { /** * Configuration block for host header rewrite. Required if `type` is `host-header-rewrite`. See Host Header Rewrite Config Blocks below. */ hostHeaderRewriteConfig?: outputs.lb.ListenerRuleTransformHostHeaderRewriteConfig; /** * Type of transform. Valid values are `host-header-rewrite` and `url-rewrite`. */ type: string; /** * Configuration block for URL rewrite. Required if `type` is `url-rewrite`. See URL Rewrite Config Blocks below. */ urlRewriteConfig?: outputs.lb.ListenerRuleTransformUrlRewriteConfig; } interface ListenerRuleTransformHostHeaderRewriteConfig { /** * Block for host header rewrite configuration. Only one block is accepted. See Rewrite Blocks below. */ rewrite?: outputs.lb.ListenerRuleTransformHostHeaderRewriteConfigRewrite; } interface ListenerRuleTransformHostHeaderRewriteConfigRewrite { /** * Regular expression to match in the input string. Length constraints: Between 1 and 1024 characters. */ regex: string; /** * Replacement string to use when rewriting the matched input. Capture groups in the regular expression (for example, `$1` and `$2`) can be specified. Length constraints: Between 0 and 1024 characters. */ replace: string; } interface ListenerRuleTransformUrlRewriteConfig { /** * Block for URL rewrite configuration. Only one block is accepted. See Rewrite Blocks below. */ rewrite?: outputs.lb.ListenerRuleTransformUrlRewriteConfigRewrite; } interface ListenerRuleTransformUrlRewriteConfigRewrite { /** * Regular expression to match in the input string. Length constraints: Between 1 and 1024 characters. */ regex: string; /** * Replacement string to use when rewriting the matched input. Capture groups in the regular expression (for example, `$1` and `$2`) can be specified. Length constraints: Between 0 and 1024 characters. */ replace: string; } interface LoadBalancerAccessLogs { /** * S3 bucket name to store the logs in. */ bucket: string; /** * Boolean to enable / disable `accessLogs`. Defaults to `false`, even when `bucket` is specified. */ enabled?: boolean; /** * S3 bucket prefix. Logs are stored in the root if not configured. */ prefix?: string; } interface LoadBalancerConnectionLogs { /** * S3 bucket name to store the logs in. */ bucket: string; /** * Boolean to enable / disable `connectionLogs`. Defaults to `false`, even when `bucket` is specified. */ enabled?: boolean; /** * S3 bucket prefix. Logs are stored in the root if not configured. */ prefix?: string; } interface LoadBalancerHealthCheckLogs { /** * S3 bucket name to store the logs in. */ bucket: string; /** * Boolean to enable / disable `healthCheckLogs`. Defaults to `false`, even when `bucket` is specified. */ enabled?: boolean; /** * S3 bucket prefix. Logs are stored in the root if not configured. */ prefix?: string; } interface LoadBalancerIpamPools { /** * The ID of the IPv4 IPAM pool. */ ipv4IpamPoolId: string; } interface LoadBalancerMinimumLoadBalancerCapacity { /** * The number of capacity units. */ capacityUnits: number; } interface LoadBalancerSubnetMapping { /** * Allocation ID of the Elastic IP address for an internet-facing load balancer. */ allocationId?: string; /** * IPv6 address. You associate IPv6 CIDR blocks with your VPC and choose the subnets where you launch both internet-facing and internal Application Load Balancers or Network Load Balancers. */ ipv6Address?: string; outpostId: string; /** * Private IPv4 address for an internal load balancer. */ privateIpv4Address?: string; /** * ID of the subnet of which to attach to the load balancer. You can specify only one subnet per Availability Zone. */ subnetId: string; } interface TargetGroupHealthCheck { /** * Whether health checks are enabled. Defaults to `true`. */ enabled?: boolean; /** * Number of consecutive health check successes required before considering a target healthy. The range is 2-10. Defaults to 3. */ healthyThreshold?: number; /** * Approximate amount of time, in seconds, between health checks of an individual target. The range is 5-300. For `lambda` target groups, it needs to be greater than the timeout of the underlying `lambda`. Defaults to 30. */ interval?: number; /** * The HTTP or gRPC codes to use when checking for a successful response from a target. * The `health_check.protocol` must be one of `HTTP` or `HTTPS` or the `targetType` must be `lambda`. * Values can be comma-separated individual values (e.g., "200,202") or a range of values (e.g., "200-299"). * Once the value has been set, removing it has no effect. To unset it, set it to an empty string `""`. * * For gRPC-based target groups (i.e., the `protocol` is one of `HTTP` or `HTTPS` and the `protocolVersion` is `GRPC`), values can be between `0` and `99`. The default is `12`. * * When used with an Application Load Balancer (i.e., the `protocol` is one of `HTTP` or `HTTPS` and the `protocolVersion` is not `GRPC`), values can be between `200` and `499`. The default is `200`. * * When used with a Network Load Balancer (i.e., the `protocol` is one of `TCP`, `TCP_UDP`, `UDP`, or `TLS`), values can be between `200` and `599`. The default is `200-399`. * * When the `targetType` is `lambda`, values can be between `200` and `499`. The default is `200`. */ matcher: string; /** * Destination for the health check request. Required for HTTP/HTTPS ALB and HTTP NLB. Only applies to HTTP/HTTPS. * Once the value has been set, removing it has no effect. To unset it, set it to an empty string `""`. * * For HTTP and HTTPS health checks, the default is `/`. * * For gRPC health checks, the default is `/AWS.ALB/healthcheck`. */ path: string; /** * The port the load balancer uses when performing health checks on targets. * Valid values are either `traffic-port`, to use the same port as the target group, or a valid port number between `1` and `65536`. * Default is `traffic-port`. */ port?: string; /** * Protocol the load balancer uses when performing health checks on targets. * Must be one of `TCP`, `HTTP`, or `HTTPS`. * The `TCP` protocol is not supported for health checks if the protocol of the target group is `HTTP` or `HTTPS`. * Default is `HTTP`. * Cannot be specified when the `targetType` is `lambda`. */ protocol?: string; /** * Amount of time, in seconds, during which no response from a target means a failed health check. The range is 2–120 seconds. For target groups with a protocol of HTTP, the default is 6 seconds. For target groups with a protocol of TCP, TLS or HTTPS, the default is 10 seconds. For target groups with a protocol of GENEVE, the default is 5 seconds. If the target type is lambda, the default is 30 seconds. */ timeout: number; /** * Number of consecutive health check failures required before considering a target unhealthy. The range is 2-10. Defaults to 3. */ unhealthyThreshold?: number; } interface TargetGroupStickiness { /** * Only used when the type is `lbCookie`. The time period, in seconds, during which requests from a client should be routed to the same target. After this time period expires, the load balancer-generated cookie is considered stale. The range is 1 second to 1 week (604800 seconds). The default value is 1 day (86400 seconds). */ cookieDuration?: number; /** * Name of the application based cookie. AWSALB, AWSALBAPP, and AWSALBTG prefixes are reserved and cannot be used. Only needed when type is `appCookie`. */ cookieName?: string; /** * Boolean to enable / disable `stickiness`. Default is `true`. */ enabled?: boolean; /** * The type of sticky sessions. The only current possible values are `lbCookie`, `appCookie` for ALBs, `sourceIp` for NLBs, and `sourceIpDestIp`, `sourceIpDestIpProto` for GWLBs. */ type: string; } interface TargetGroupTargetFailover { /** * Indicates how the GWLB handles existing flows when a target is deregistered. Possible values are `rebalance` and `noRebalance`. Must match the attribute value set for `onUnhealthy`. Default: `noRebalance`. */ onDeregistration: string; /** * Indicates how the GWLB handles existing flows when a target is unhealthy. Possible values are `rebalance` and `noRebalance`. Must match the attribute value set for `onDeregistration`. Default: `noRebalance`. */ onUnhealthy: string; } interface TargetGroupTargetGroupHealth { /** * Block to configure DNS Failover requirements. See DNS Failover below for details on attributes. */ dnsFailover?: outputs.lb.TargetGroupTargetGroupHealthDnsFailover; /** * Block to configure Unhealthy State Routing requirements. See Unhealthy State Routing below for details on attributes. */ unhealthyStateRouting?: outputs.lb.TargetGroupTargetGroupHealthUnhealthyStateRouting; } interface TargetGroupTargetGroupHealthDnsFailover { /** * The minimum number of targets that must be healthy. If the number of healthy targets is below this value, mark the zone as unhealthy in DNS, so that traffic is routed only to healthy zones. The possible values are `off` or an integer from `1` to the maximum number of targets. The default is `off`. */ minimumHealthyTargetsCount?: string; /** * The minimum percentage of targets that must be healthy. If the percentage of healthy targets is below this value, mark the zone as unhealthy in DNS, so that traffic is routed only to healthy zones. The possible values are `off` or an integer from `1` to `100`. The default is `off`. */ minimumHealthyTargetsPercentage?: string; } interface TargetGroupTargetGroupHealthUnhealthyStateRouting { /** * The minimum number of targets that must be healthy. If the number of healthy targets is below this value, send traffic to all targets, including unhealthy targets. The possible values are `1` to the maximum number of targets. The default is `1`. */ minimumHealthyTargetsCount?: number; /** * The minimum percentage of targets that must be healthy. If the percentage of healthy targets is below this value, send traffic to all targets, including unhealthy targets. The possible values are `off` or an integer from `1` to `100`. The default is `off`. */ minimumHealthyTargetsPercentage?: string; } interface TargetGroupTargetHealthState { /** * Indicates whether the load balancer terminates connections to unhealthy targets. Possible values are `true` or `false`. Default: `true`. */ enableUnhealthyConnectionTermination: boolean; /** * Indicates the time to wait for in-flight requests to complete when a target becomes unhealthy. The range is `0-360000`. This value has to be set only if `enableUnhealthyConnectionTermination` is set to false. Default: `0`. */ unhealthyDrainingInterval?: number; } } export declare namespace lex { interface BotAbortStatement { messages: outputs.lex.BotAbortStatementMessage[]; responseCard?: string; } interface BotAbortStatementMessage { /** * The text of the message. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. */ groupNumber?: number; } interface BotAliasConversationLogs { /** * ARN of the IAM role used to write your logs to CloudWatch Logs or an S3 bucket. Must be between 20 and 2048 characters in length. */ iamRoleArn: string; /** * The settings for your conversation logs. You can log text, audio, or both. Attributes are documented under log_settings. */ logSettings?: outputs.lex.BotAliasConversationLogsLogSetting[]; } interface BotAliasConversationLogsLogSetting { /** * The destination where logs are delivered. Options are `CLOUDWATCH_LOGS` or `S3`. */ destination: string; /** * ARN of the key used to encrypt audio logs in an S3 bucket. This can only be specified when `destination` is set to `S3`. Must be between 20 and 2048 characters in length. */ kmsKeyArn?: string; /** * The type of logging that is enabled. Options are `AUDIO` or `TEXT`. */ logType: string; /** * ARN of the CloudWatch Logs log group or S3 bucket where the logs are delivered. Must be less than or equal to 2048 characters in length. */ resourceArn: string; /** * The prefix of the S3 object key for `AUDIO` logs or the log stream name for `TEXT` logs. */ resourcePrefix: string; } interface BotClarificationPrompt { /** * The number of times to prompt the user for information. */ maxAttempts: number; messages: outputs.lex.BotClarificationPromptMessage[]; responseCard?: string; } interface BotClarificationPromptMessage { /** * The text of the message. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. */ groupNumber?: number; } interface BotIntent { /** * The name of the intent. Must be less than or equal to 100 characters in length. */ intentName: string; /** * The version of the intent. Must be less than or equal to 64 characters in length. */ intentVersion: string; } interface GetSlotTypeEnumerationValue { synonyms: string[]; value: string; } interface IntentConclusionStatement { messages: outputs.lex.IntentConclusionStatementMessage[]; responseCard?: string; } interface IntentConclusionStatementMessage { /** * The text of the message. Must be less than or equal to 1000 characters in length. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. Must be a number between 1 and 5 (inclusive). */ groupNumber?: number; } interface IntentConfirmationPrompt { /** * The number of times to prompt the user for information. Must be a number between 1 and 5 (inclusive). */ maxAttempts: number; messages: outputs.lex.IntentConfirmationPromptMessage[]; responseCard?: string; } interface IntentConfirmationPromptMessage { /** * The text of the message. Must be less than or equal to 1000 characters in length. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. Must be a number between 1 and 5 (inclusive). */ groupNumber?: number; } interface IntentDialogCodeHook { /** * The version of the request-response that you want Amazon Lex to use * to invoke your Lambda function. For more information, see * [Using Lambda Functions](https://docs.aws.amazon.com/lex/latest/dg/using-lambda.html). Must be less than or equal to 5 characters in length. */ messageVersion: string; /** * ARN of the Lambda function. */ uri: string; } interface IntentFollowUpPrompt { /** * Prompts for information from the user. Attributes are documented under prompt. */ prompt: outputs.lex.IntentFollowUpPromptPrompt; /** * If the user answers "no" to the question defined in the prompt field, * Amazon Lex responds with this statement to acknowledge that the intent was canceled. Attributes are * documented below under statement. */ rejectionStatement: outputs.lex.IntentFollowUpPromptRejectionStatement; } interface IntentFollowUpPromptPrompt { /** * The number of times to prompt the user for information. Must be a number between 1 and 5 (inclusive). */ maxAttempts: number; /** * A set of messages, each of which provides a message string and its type. * You can specify the message string in plain text or in Speech Synthesis Markup Language (SSML). * Attributes are documented under message. Must contain between 1 and 15 messages. */ messages: outputs.lex.IntentFollowUpPromptPromptMessage[]; /** * The response card. Amazon Lex will substitute session attributes and * slot values into the response card. For more information, see * [Example: Using a Response Card](https://docs.aws.amazon.com/lex/latest/dg/ex-resp-card.html). Must be less than or equal to 50000 characters in length. */ responseCard?: string; } interface IntentFollowUpPromptPromptMessage { /** * The text of the message. Must be less than or equal to 1000 characters in length. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. Must be a number between 1 and 5 (inclusive). */ groupNumber?: number; } interface IntentFollowUpPromptRejectionStatement { messages: outputs.lex.IntentFollowUpPromptRejectionStatementMessage[]; responseCard?: string; } interface IntentFollowUpPromptRejectionStatementMessage { /** * The text of the message. Must be less than or equal to 1000 characters in length. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. Must be a number between 1 and 5 (inclusive). */ groupNumber?: number; } interface IntentFulfillmentActivity { /** * A description of the Lambda function that is run to fulfill the intent. * Required if type is CodeHook. Attributes are documented under code_hook. */ codeHook?: outputs.lex.IntentFulfillmentActivityCodeHook; /** * How the intent should be fulfilled, either by running a Lambda function or by * returning the slot data to the client application. Type can be either `ReturnIntent` or `CodeHook`, as documented [here](https://docs.aws.amazon.com/lex/latest/dg/API_FulfillmentActivity.html). */ type: string; } interface IntentFulfillmentActivityCodeHook { /** * The version of the request-response that you want Amazon Lex to use * to invoke your Lambda function. For more information, see * [Using Lambda Functions](https://docs.aws.amazon.com/lex/latest/dg/using-lambda.html). Must be less than or equal to 5 characters in length. */ messageVersion: string; /** * ARN of the Lambda function. */ uri: string; } interface IntentRejectionStatement { messages: outputs.lex.IntentRejectionStatementMessage[]; responseCard?: string; } interface IntentRejectionStatementMessage { /** * The text of the message. Must be less than or equal to 1000 characters in length. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. Must be a number between 1 and 5 (inclusive). */ groupNumber?: number; } interface IntentSlot { /** * A description of the bot. Must be less than or equal to 200 characters in length. */ description?: string; /** * The name of the intent slot that you want to create. The name is case sensitive. Must be less than or equal to 100 characters in length. */ name: string; /** * Directs Lex the order in which to elicit this slot value from the user. * For example, if the intent has two slots with priorities 1 and 2, AWS Lex first elicits a value for * the slot with priority 1. If multiple slots share the same priority, the order in which Lex elicits * values is arbitrary. Must be between 1 and 100. */ priority?: number; /** * The response card. Amazon Lex will substitute session attributes and * slot values into the response card. For more information, see * [Example: Using a Response Card](https://docs.aws.amazon.com/lex/latest/dg/ex-resp-card.html). Must be less than or equal to 50000 characters in length. */ responseCard?: string; /** * If you know a specific pattern with which users might respond to * an Amazon Lex request for a slot value, you can provide those utterances to improve accuracy. This * is optional. In most cases, Amazon Lex is capable of understanding user utterances. Must have between 1 and 10 items in the list, and each item must be less than or equal to 200 characters in length. */ sampleUtterances?: string[]; /** * Specifies whether the slot is required or optional. */ slotConstraint: string; /** * The type of the slot, either a custom slot type that you defined or one of * the built-in slot types. Must be less than or equal to 100 characters in length. */ slotType: string; /** * The version of the slot type. Must be less than or equal to 64 characters in length. */ slotTypeVersion?: string; /** * The prompt that Amazon Lex uses to elicit the slot value * from the user. Attributes are documented under prompt. */ valueElicitationPrompt?: outputs.lex.IntentSlotValueElicitationPrompt; } interface IntentSlotValueElicitationPrompt { /** * The number of times to prompt the user for information. Must be a number between 1 and 5 (inclusive). */ maxAttempts: number; messages: outputs.lex.IntentSlotValueElicitationPromptMessage[]; responseCard?: string; } interface IntentSlotValueElicitationPromptMessage { /** * The text of the message. Must be less than or equal to 1000 characters in length. */ content: string; /** * The content type of the message string. */ contentType: string; /** * Identifies the message group that the message belongs to. When a group * is assigned to a message, Amazon Lex returns one message from each group in the response. Must be a number between 1 and 5 (inclusive). */ groupNumber?: number; } interface SlotTypeEnumerationValue { /** * Additional values related to the slot type value. Each item must be less than or equal to 140 characters in length. */ synonyms?: string[]; /** * The value of the slot type. Must be less than or equal to 140 characters in length. */ value: string; } interface V2modelsBotDataPrivacy { /** * (Required) - For each Amazon Lex bot created with the Amazon Lex Model Building Service, you must specify whether your use of Amazon Lex is related to a website, program, or other application that is directed or targeted, in whole or in part, to children under age 13 and subject to the Children's Online Privacy Protection Act (COPPA) by specifying true or false in the childDirected field. */ childDirected: boolean; } interface V2modelsBotLocaleTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface V2modelsBotLocaleVoiceSettings { /** * Indicates the type of Amazon Polly voice that Amazon Lex should use for voice interaction with the user. Valid values are `standard` and `neural`. If not specified, the default is `standard`. */ engine: string; /** * Identifier of the Amazon Polly voice to use. */ voiceId: string; } interface V2modelsBotMember { /** * (Required) - Alias ID of a bot that is a member of this network of bots. */ aliasId: string; /** * (Required) - Alias name of a bot that is a member of this network of bots. */ aliasName: string; /** * (Required) - Unique ID of a bot that is a member of this network of bots. */ id: string; /** * Name of the bot. The bot name must be unique in the account that creates the bot. Type String. Length Constraints: Minimum length of 1. Maximum length of 100. */ name: string; /** * (Required) - Version of a bot that is a member of this network of bots. */ version: string; } interface V2modelsBotTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface V2modelsBotVersionLocaleSpecification { sourceBotVersion: string; } interface V2modelsBotVersionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface V2modelsIntentClosingSetting { /** * Whether an intent's closing response is used. When this field is false, the closing response isn't sent to the user. If the active field isn't specified, the default is true. */ active?: boolean; /** * Configuration block for response that Amazon Lex sends to the user when the intent is complete. See `closingResponse`. */ closingResponse?: outputs.lex.V2modelsIntentClosingSettingClosingResponse; /** * Configuration block for list of conditional branches associated with the intent's closing response. These branches are executed when the `nextStep` attribute is set to `EvalutateConditional`. See `conditional`. */ conditional?: outputs.lex.V2modelsIntentClosingSettingConditional; /** * Next step that the bot executes after playing the intent's closing response. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentClosingSettingNextStep; } interface V2modelsIntentClosingSettingClosingResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroup[]; } interface V2modelsIntentClosingSettingClosingResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupVariation[]; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentClosingSettingClosingResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentClosingSettingClosingResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentClosingSettingConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranch; } interface V2modelsIntentClosingSettingConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponse; } interface V2modelsIntentClosingSettingConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentClosingSettingConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentClosingSettingConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentClosingSettingConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentClosingSettingConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponse; } interface V2modelsIntentClosingSettingConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentClosingSettingConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentClosingSettingConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentClosingSettingConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentClosingSettingConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentClosingSettingNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentClosingSettingNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentClosingSettingNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentClosingSettingNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentClosingSettingNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentClosingSettingNextStepIntentSlot[]; } interface V2modelsIntentClosingSettingNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentClosingSettingNextStepIntentSlotValue; } interface V2modelsIntentClosingSettingNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSetting { /** * Whether the intent's confirmation is sent to the user. When this field is false, confirmation and declination responses aren't sent. If the active field isn't specified, the default is true. */ active?: boolean; /** * Configuration block for the intent's confirmation step. The dialog code hook is triggered based on these invocation settings when the confirmation next step or declination next step or failure next step is `invokeDialogCodeHook`. See `codeHook`. */ codeHook?: outputs.lex.V2modelsIntentConfirmationSettingCodeHook; /** * Configuration block for conditional branches to evaluate after the intent is closed. See `confirmationConditional`. */ confirmationConditional?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditional; /** * Configuration block for the next step that the bot executes when the customer confirms the intent. See `confirmationNextStep`. */ confirmationNextStep?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `confirmationResponse`. */ confirmationResponse?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponse; /** * Configuration block for conditional branches to evaluate after the intent is declined. See `declinationConditional`. */ declinationConditional?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditional; /** * Configuration block for the next step that the bot executes when the customer declines the intent. See `declinationNextStep`. */ declinationNextStep?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationNextStep; /** * Configuration block for when the user answers "no" to the question defined in `promptSpecification`, Amazon Lex responds with this response to acknowledge that the intent was canceled. See `declinationResponse`. */ declinationResponse?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponse; /** * Configuration block for when the code hook is invoked during confirmation prompt retries. See `elicitationCodeHook`. */ elicitationCodeHook?: outputs.lex.V2modelsIntentConfirmationSettingElicitationCodeHook; /** * Configuration block for conditional branches. Branches are evaluated in the order that they are entered in the list. The first branch with a condition that evaluates to true is executed. The last branch in the list is the default branch. The default branch should not have any condition expression. The default branch is executed if no other branch has a matching condition. See `failureConditional`. */ failureConditional?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditional; /** * Configuration block for the next step to take in the conversation if the confirmation step fails. See `failureNextStep`. */ failureNextStep?: outputs.lex.V2modelsIntentConfirmationSettingFailureNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `failureResponse`. */ failureResponse?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponse; /** * Configuration block for prompting the user to confirm the intent. This question should have a yes or no answer. Amazon Lex uses this prompt to ensure that the user acknowledges that the intent is ready for fulfillment. See `promptSpecification`. */ promptSpecification?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecification; } interface V2modelsIntentConfirmationSettingCodeHook { /** * Whether a dialog code hook is used when the intent is activated. */ active: boolean; /** * Whether a Lambda function should be invoked for the dialog. */ enableCodeHookInvocation: boolean; /** * Label that indicates the dialog step from which the dialog code hook is happening. */ invocationLabel?: string; /** * Configuration block that contains the responses and actions that Amazon Lex takes after the Lambda function is complete. See `postCodeHookSpecification`. */ postCodeHookSpecification?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecification; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecification { /** * Configuration block for conditional branches to evaluate after the dialog code hook throws an exception or returns with the State field of the Intent object set to Failed. */ failureConditional?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditional; /** * Configuration block for the next step the bot runs after the dialog code hook throws an exception or returns with the State field of the Intent object set to Failed . See `failureNextStep`. */ failureNextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `failureResponse`. */ failureResponse?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponse; /** * Configuration block for conditional branches to evaluate after the dialog code hook finishes successfully. See `successConditional`. */ successConditional?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditional; /** * Configuration block for the next step the bot runs after the dialog code hook finishes successfully. See `successNextStep`. */ successNextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `successResponse`. */ successResponse?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponse; /** * Configuration block for conditional branches to evaluate if the code hook times out. See `timeoutConditional`. */ timeoutConditional?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditional; /** * Configuration block for the next step that the bot runs when the code hook times out. See `timeoutNextStep`. */ timeoutNextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond the user input. See `timeoutResponse`. */ timeoutResponse?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranch; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranch; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranch; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponse; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranch; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponse; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponse; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingConfirmationNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingConfirmationNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingConfirmationNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingConfirmationNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingConfirmationResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingConfirmationResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranch; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponse; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponse; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingDeclinationNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingDeclinationNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingDeclinationNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingDeclinationNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingDeclinationResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingDeclinationResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingElicitationCodeHook { /** * Whether a Lambda function should be invoked for the dialog. */ enableCodeHookInvocation?: boolean; /** * Label that indicates the dialog step from which the dialog code hook is happening. */ invocationLabel?: string; } interface V2modelsIntentConfirmationSettingFailureConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranch; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponse; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponse; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingFailureNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentConfirmationSettingFailureNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentConfirmationSettingFailureNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentConfirmationSettingFailureNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentConfirmationSettingFailureNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentConfirmationSettingFailureNextStepIntentSlot[]; } interface V2modelsIntentConfirmationSettingFailureNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentConfirmationSettingFailureNextStepIntentSlotValue; } interface V2modelsIntentConfirmationSettingFailureNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentConfirmationSettingFailureResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroup[]; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingFailureResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecification { /** * Whether the user can interrupt a speech prompt from the bot. */ allowInterrupt?: boolean; /** * Maximum number of times the bot tries to elicit a response from the user using this prompt. */ maxRetries: number; /** * Configuration block for messages that Amazon Lex can send to the user. Amazon Lex chooses the actual message to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroup[]; /** * How a message is selected from a message group among retries. Valid values are `Random` and `Ordered`. */ messageSelectionStrategy?: string; /** * Configuration block for advanced settings on each attempt of the prompt. See `promptAttemptsSpecification`. */ promptAttemptsSpecifications?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecification[]; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariation[]; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageSsmlMessage; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationSsmlMessage; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecification { /** * Whether the user can interrupt a speech prompt attempt from the bot. */ allowInterrupt?: boolean; /** * Configuration block for the allowed input types of the prompt attempt. See `allowedInputTypes`. */ allowedInputTypes?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAllowedInputTypes; /** * Configuration block for settings on audio and DTMF input. See `audioAndDtmfInputSpecification`. */ audioAndDtmfInputSpecification?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecification; /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * Configuration block for the settings on text input. See `textInputSpecification`. */ textInputSpecification?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationTextInputSpecification; } interface V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAllowedInputTypes { /** * Whether audio input is allowed. */ allowAudioInput: boolean; /** * Whether DTMF input is allowed. */ allowDtmfInput: boolean; } interface V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecification { /** * Configuration block for the settings on audio input. See `audioSpecification`. */ audioSpecification?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationAudioSpecification; /** * Configuration block for the settings on DTMF input. See `dtmfSpecification`. */ dtmfSpecification?: outputs.lex.V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationDtmfSpecification; /** * Time for which a bot waits before assuming that the customer isn't going to speak or press a key. This timeout is shared between Audio and DTMF inputs. */ startTimeoutMs: number; } interface V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationAudioSpecification { /** * Time for which a bot waits after the customer stops speaking to assume the utterance is finished. */ endTimeoutMs: number; /** * Time for how long Amazon Lex waits before speech input is truncated and the speech is returned to application. */ maxLengthMs: number; } interface V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationDtmfSpecification { /** * DTMF character that clears the accumulated DTMF digits and immediately ends the input. */ deletionCharacter: string; /** * DTMF character that immediately ends input. If the user does not press this character, the input ends after the end timeout. */ endCharacter: string; /** * How long the bot should wait after the last DTMF character input before assuming that the input has concluded. */ endTimeoutMs: number; /** * Maximum number of DTMF digits allowed in an utterance. */ maxLength: number; } interface V2modelsIntentConfirmationSettingPromptSpecificationPromptAttemptsSpecificationTextInputSpecification { /** * Time for which a bot waits before re-prompting a customer for text input. */ startTimeoutMs: number; } interface V2modelsIntentDialogCodeHook { /** * Enables the dialog code hook so that it processes user requests. */ enabled: boolean; } interface V2modelsIntentFulfillmentCodeHook { /** * Whether the fulfillment code hook is used. When active is false, the code hook doesn't run. */ active?: boolean; /** * Whether a Lambda function should be invoked to fulfill a specific intent. */ enabled: boolean; /** * Configuration block for settings for update messages sent to the user for long-running Lambda fulfillment functions. Fulfillment updates can be used only with streaming conversations. See `fulfillmentUpdatesSpecification`. */ fulfillmentUpdatesSpecification?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecification; /** * Configuration block for settings for messages sent to the user for after the Lambda fulfillment function completes. Post-fulfillment messages can be sent for both streaming and non-streaming conversations. See `postFulfillmentStatusSpecification`. */ postFulfillmentStatusSpecification?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecification; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecification { /** * Whether fulfillment updates are sent to the user. When this field is true, updates are sent. If the active field is set to true, the `startResponse`, `updateResponse`, and `timeoutInSeconds` fields are required. */ active: boolean; /** * Configuration block for the message sent to users when the fulfillment Lambda functions starts running. */ startResponse?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponse; /** * Length of time that the fulfillment Lambda function should run before it times out. */ timeoutInSeconds?: number; /** * Configuration block for messages sent periodically to the user while the fulfillment Lambda function is running. */ updateResponse?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponse; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponse { /** * Whether the user can interrupt the start message while it is playing. */ allowInterrupt?: boolean; /** * Delay between when the Lambda fulfillment function starts running and the start message is played. If the Lambda function returns before the delay is over, the start message isn't played. */ delayInSeconds?: number; /** * Between 1-5 configuration block message groups that contain start messages. Amazon Lex chooses one of the messages to play to the user. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationStartResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponse { /** * Whether the user can interrupt the start message while it is playing. */ allowInterrupt?: boolean; /** * Frequency that a message is sent to the user. When the period ends, Amazon Lex chooses a message from the message groups and plays it to the user. If the fulfillment Lambda returns before the first period ends, an update message is not played to the user. */ frequencyInSeconds: number; /** * Between 1-5 configuration block message groups that contain start messages. Amazon Lex chooses one of the messages to play to the user. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookFulfillmentUpdatesSpecificationUpdateResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecification { /** * Configuration block for conditional branches to evaluate after the dialog code hook throws an exception or returns with the State field of the Intent object set to Failed. See `failureConditional`. */ failureConditional?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditional; /** * Configuration block for the next step the bot runs after the dialog code hook throws an exception or returns with the State field of the Intent object set to Failed. See `failureNextStep`. */ failureNextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `failureResponse`. */ failureResponse?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponse; /** * Configuration block for conditional branches to evaluate after the dialog code hook finishes successfully. See `successConditional`. */ successConditional?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditional; /** * Configuration block for the next step the bot runs after the dialog code hook finishes successfully. See `successNextStep`. */ successNextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `successResponse`. */ successResponse?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponse; /** * Configuration block for conditional branches to evaluate if the code hook times out. See `timeoutConditional`. */ timeoutConditional?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditional; /** * Configuration block for the next step that the bot runs when the code hook times out. See `timeoutNextStep`. */ timeoutNextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond the user input. See `timeoutResponse`. */ timeoutResponse?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranch; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationFailureResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranch; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationSuccessResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranch; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponse; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepIntentSlot[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepIntentSlotValue; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroup[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariation[]; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentFulfillmentCodeHookPostFulfillmentStatusSpecificationTimeoutResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSetting { /** * Configuration block for the dialog code hook that is called by Amazon Lex at a step of the conversation. See `codeHook`. */ codeHook?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHook; /** * Configuration block for conditional branches. Branches are evaluated in the order that they are entered in the list. The first branch with a condition that evaluates to true is executed. The last branch in the list is the default branch. The default branch should not have any condition expression. The default branch is executed if no other branch has a matching condition. See `conditional`. */ conditional?: outputs.lex.V2modelsIntentInitialResponseSettingConditional; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `initialResponse`. */ initialResponse?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponse; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingNextStep; } interface V2modelsIntentInitialResponseSettingCodeHook { /** * Whether a dialog code hook is used when the intent is activated. */ active: boolean; /** * Whether a Lambda function should be invoked for the dialog. */ enableCodeHookInvocation: boolean; /** * Label that indicates the dialog step from which the dialog code hook is happening. */ invocationLabel?: string; /** * Configuration block that contains the responses and actions that Amazon Lex takes after the Lambda function is complete. See `postCodeHookSpecification`. */ postCodeHookSpecification?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecification; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecification { /** * Configuration block for conditional branches to evaluate after the dialog code hook throws an exception or returns with the State field of the Intent object set to Failed. */ failureConditional?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditional; /** * Configuration block for the next step the bot runs after the dialog code hook throws an exception or returns with the State field of the Intent object set to Failed . See `failureNextStep`. */ failureNextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `failureResponse`. */ failureResponse?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponse; /** * Configuration block for conditional branches to evaluate after the dialog code hook finishes successfully. See `successConditional`. */ successConditional?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditional; /** * Configuration block for the next step the bot runs after the dialog code hook finishes successfully. See `successNextStep`. */ successNextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStep; /** * Configuration block for message groups that Amazon Lex uses to respond the user input. See `successResponse`. */ successResponse?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponse; /** * Configuration block for conditional branches to evaluate if the code hook times out. See `timeoutConditional`. */ timeoutConditional?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditional; /** * Configuration block for the next step that the bot runs when the code hook times out. See `timeoutNextStep`. */ timeoutNextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond the user input. See `timeoutResponse`. */ timeoutResponse?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranch; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationFailureResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranch; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationSuccessResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranch; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponse; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingCodeHookPostCodeHookSpecificationTimeoutResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingConditional { /** * Whether a conditional branch is active. When active is false, the conditions are not evaluated. */ active: boolean; /** * Configuration blocks for conditional branches. A conditional branch is made up of a condition, a response and a next step. The response and next step are executed when the condition is true. See `conditionalBranch`. */ conditionalBranches?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranch[]; /** * Configuration block for the conditional branch that should be followed when the conditions for other branches are not satisfied. A branch is made up of a condition, a response and a next step. See `defaultBranch`. */ defaultBranch?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranch; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranch { /** * Configuration block for the expression to evaluate. If the condition is true, the branch's actions are taken. See `condition`. */ condition?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchCondition; /** * Name of the branch. */ name: string; /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponse; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchCondition { /** * Expression string that is evaluated. */ expressionString: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalConditionalBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranch { /** * Configuration block for the next step in the conversation. See `nextStep`. */ nextStep?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStep; /** * Configuration block for a list of message groups that Amazon Lex uses to respond to the user input. See `response`. */ response?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponse; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingConditionalDefaultBranchResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. Amazon Lex chooses the actual response to send at runtime. See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroup[]; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. See `message`. */ message?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. See `variation`. */ variations?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariation[]; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessage { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessagePlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageSsmlMessage; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessagePlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupMessageSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariation { /** * Configuration block for a message in a custom format defined by the client application. See `customPayload`. */ customPayload?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationCustomPayload; /** * Configuration block for a message that defines a response card that the client application can show to the user. See `imageResponseCard`. */ imageResponseCard?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationImageResponseCard; /** * Configuration block for a message in plain text format. See `plainTextMessage`. */ plainTextMessage?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationPlainTextMessage; /** * Configuration block for a message in Speech Synthesis Markup Language (SSML). See `ssmlMessage`. */ ssmlMessage?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationSsmlMessage; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationCustomPayload { /** * String that is sent to your application. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationImageResponseCard { /** * Configuration blocks for buttons that should be displayed on the response card. The arrangement of the buttons is determined by the platform that displays the button. See `button`. */ buttons?: outputs.lex.V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationImageResponseCardButton[]; /** * URL of an image to display on the response card. The image URL must be publicly available so that the platform displaying the response card has access to the image. */ imageUrl?: string; /** * Subtitle to display on the response card. The format of the subtitle is determined by the platform displaying the response card. */ subtitle?: string; /** * Title to display on the response card. The format of the title is determined by the platform displaying the response card. */ title: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationImageResponseCardButton { /** * Text that appears on the button. Use this to tell the user what value is returned when they choose this button. */ text: string; /** * Value returned to Amazon Lex when the user chooses this button. This must be one of the slot values configured for the slot. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationPlainTextMessage { /** * Message to send to the user. */ value: string; } interface V2modelsIntentInitialResponseSettingInitialResponseMessageGroupVariationSsmlMessage { /** * SSML text that defines the prompt. */ value: string; } interface V2modelsIntentInitialResponseSettingNextStep { /** * Configuration block for action that the bot executes at runtime when the conversation reaches this step. See `dialogAction`. */ dialogAction?: outputs.lex.V2modelsIntentInitialResponseSettingNextStepDialogAction; /** * Configuration block for override settings to configure the intent state. See `intent`. */ intent?: outputs.lex.V2modelsIntentInitialResponseSettingNextStepIntent; /** * Map of key/value pairs representing session-specific context information. It contains application information passed between Amazon Lex and a client application. */ sessionAttributes?: { [key: string]: string; }; } interface V2modelsIntentInitialResponseSettingNextStepDialogAction { /** * If the dialog action is `ElicitSlot`, defines the slot to elicit from the user. */ slotToElicit?: string; /** * Whether the next message for the intent is _not_ used. */ suppressNextMessage?: boolean; /** * Action that the bot should execute. Valid values are `ElicitIntent`, `StartIntent`, `ElicitSlot`, `EvaluateConditional`, `InvokeDialogCodeHook`, `ConfirmIntent`, `FulfillIntent`, `CloseIntent`, `EndConversation`. */ type: string; } interface V2modelsIntentInitialResponseSettingNextStepIntent { /** * Name of the intent. */ name?: string; /** * Configuration block for all of the slot value overrides for the intent. The name of the slot maps to the value of the slot. Slots that are not included in the map aren't overridden. See `slot`. */ slots?: outputs.lex.V2modelsIntentInitialResponseSettingNextStepIntentSlot[]; } interface V2modelsIntentInitialResponseSettingNextStepIntentSlot { /** * Which attempt to configure. Valid values are `Initial`, `Retry1`, `Retry2`, `Retry3`, `Retry4`, `Retry5`. */ mapBlockKey: string; /** * When the shape value is `List`, `values` contains a list of slot values. When the value is `Scalar`, `value` contains a single value. */ shape?: string; /** * Configuration block for the current value of the slot. See `value`. */ value?: outputs.lex.V2modelsIntentInitialResponseSettingNextStepIntentSlotValue; } interface V2modelsIntentInitialResponseSettingNextStepIntentSlotValue { /** * Value that Amazon Lex determines for the slot. The actual value depends on the setting of the value selection strategy for the bot. You can choose to use the value entered by the user, or you can have Amazon Lex choose the first value in the resolvedValues list. */ interpretedValue?: string; } interface V2modelsIntentInputContext { /** * Name of the context. */ name: string; } interface V2modelsIntentKendraConfiguration { /** * ARN of the Kendra index. */ kendraIndex: string; /** * Query filter string for Kendra. */ queryFilterString?: string; /** * Whether the query filter string is enabled. */ queryFilterStringEnabled?: boolean; } interface V2modelsIntentOutputContext { /** * Name of the output context. */ name: string; /** * Amount of time, in seconds, that the output context should remain active. The time is figured from the first time the context is sent to the user. */ timeToLiveInSeconds: number; /** * Number of conversation turns that the output context should remain active. The number of turns is counted from the first time that the context is sent to the user. */ turnsToLive: number; } interface V2modelsIntentQnaIntentConfiguration { /** * Configuration block for the Amazon Bedrock model to use for generating responses. See `bedrockModelConfiguration`. */ bedrockModelConfiguration?: outputs.lex.V2modelsIntentQnaIntentConfigurationBedrockModelConfiguration; /** * Configuration block for the data sources to use for the QnA intent. Only one data source (Bedrock Knowledge Base, Kendra, or OpenSearch) can be specified. See `dataSourceConfiguration`. */ dataSourceConfiguration?: outputs.lex.V2modelsIntentQnaIntentConfigurationDataSourceConfiguration; } interface V2modelsIntentQnaIntentConfigurationBedrockModelConfiguration { /** * Custom prompt to use for the Bedrock model. */ customPrompt?: string; /** * Configuration block for the guardrail to use with the Bedrock model. See `guardrail`. */ guardrail?: outputs.lex.V2modelsIntentQnaIntentConfigurationBedrockModelConfigurationGuardrail; /** * ARN of the Bedrock model to use. */ modelArn: string; /** * Whether to enable tracing for the Bedrock model. Valid values are `ENABLED` and `DISABLED`. */ traceStatus?: string; } interface V2modelsIntentQnaIntentConfigurationBedrockModelConfigurationGuardrail { /** * Identifier of the guardrail. */ identifier: string; /** * Version of the guardrail. */ version: string; } interface V2modelsIntentQnaIntentConfigurationDataSourceConfiguration { /** * Configuration block for Amazon Bedrock Knowledge Base as a data source. See `bedrockKnowledgeStoreConfiguration`. */ bedrockKnowledgeStoreConfiguration?: outputs.lex.V2modelsIntentQnaIntentConfigurationDataSourceConfigurationBedrockKnowledgeStoreConfiguration; /** * Configuration block for Amazon Kendra as a data source. See `kendraConfiguration`. */ kendraConfiguration?: outputs.lex.V2modelsIntentQnaIntentConfigurationDataSourceConfigurationKendraConfiguration; /** * Configuration block for OpenSearch as a data source. See `opensearchConfiguration`. */ opensearchConfiguration?: outputs.lex.V2modelsIntentQnaIntentConfigurationDataSourceConfigurationOpensearchConfiguration; } interface V2modelsIntentQnaIntentConfigurationDataSourceConfigurationBedrockKnowledgeStoreConfiguration { /** * ARN of the Bedrock Knowledge Base. */ bedrockKnowledgeBaseArn: string; /** * Whether to return exact responses from the knowledge base. Defaults to `false`. */ exactResponse: boolean; /** * Configuration block for exact response fields. See `exactResponseFields`. */ exactResponseFields?: outputs.lex.V2modelsIntentQnaIntentConfigurationDataSourceConfigurationBedrockKnowledgeStoreConfigurationExactResponseFields; } interface V2modelsIntentQnaIntentConfigurationDataSourceConfigurationBedrockKnowledgeStoreConfigurationExactResponseFields { /** * Field name for the answer. */ answerField?: string; } interface V2modelsIntentQnaIntentConfigurationDataSourceConfigurationKendraConfiguration { /** * Whether to return exact responses from Kendra. Defaults to `false`. */ exactResponse: boolean; /** * ARN of the Kendra index. */ kendraIndex: string; /** * Query filter string for Kendra. */ queryFilterString?: string; /** * Whether the query filter string is enabled. */ queryFilterStringEnabled?: boolean; } interface V2modelsIntentQnaIntentConfigurationDataSourceConfigurationOpensearchConfiguration { /** * Endpoint of the OpenSearch domain. */ domainEndpoint: string; /** * Whether to return exact responses from OpenSearch. Defaults to `false`. */ exactResponse: boolean; /** * Configuration block for exact response fields. See `exactResponseFields`. */ exactResponseFields?: outputs.lex.V2modelsIntentQnaIntentConfigurationDataSourceConfigurationOpensearchConfigurationExactResponseFields; /** * List of fields to include in the response. */ includeFields?: string[]; /** * Name of the OpenSearch index. */ indexName: string; } interface V2modelsIntentQnaIntentConfigurationDataSourceConfigurationOpensearchConfigurationExactResponseFields { /** * Field name for the answer. */ answerField: string; /** * Field name for the question. */ questionField: string; } interface V2modelsIntentSampleUtterance { /** * Sample utterance that Amazon Lex uses to build its machine-learning model to recognize intents. */ utterance: string; } interface V2modelsIntentSlotPriority { /** * Priority that Amazon Lex should apply to the slot. */ priority: number; /** * Unique identifier of the slot. */ slotId: string; } interface V2modelsIntentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface V2modelsSlotMultipleValuesSetting { /** * Whether a slot can return multiple values. When `true`, the slot may return more than one value in a response. When `false`, the slot returns only a single value. Multi-value slots are only available in the `en-US` locale. */ allowMultipleValues?: boolean; } interface V2modelsSlotObfuscationSetting { /** * Whether Amazon Lex obscures slot values in conversation logs. Valid values are `DefaultObfuscation` and `None`. */ obfuscationSettingType: string; } interface V2modelsSlotSubSlotSetting { /** * Expression text for defining the constituent sub slots in the composite slot using logical `AND` and `OR` operators. */ expression?: string; /** * Specifications for the constituent sub slots of a composite slot. * See the `slotSpecification` argument reference below. */ slotSpecifications?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecification[]; } interface V2modelsSlotSubSlotSettingSlotSpecification { mapBlockKey: string; /** * Unique identifier assigned to the slot type. */ slotTypeId: string; /** * Elicitation setting details for constituent sub slots of a composite slot. * See the `valueElicitationSetting` argument reference below. */ valueElicitationSettings?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSetting[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSetting { /** * List of default values for a slot. * See the `defaultValueSpecification` argument reference below. */ defaultValueSpecifications?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingDefaultValueSpecification[]; /** * Prompt that Amazon Lex uses to elicit the slot value from the user. * See the `aws.lex.V2modelsIntent` resource for details on the `promptSpecification` argument reference - they are identical. */ promptSpecification?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecification; sampleUtterances?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingSampleUtterance[]; /** * Specifies the prompts that Amazon Lex uses while a bot is waiting for customer input. * See the `waitAndContinueSpecification` argument reference below. */ waitAndContinueSpecifications?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecification[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingDefaultValueSpecification { /** * List of default values. * Amazon Lex chooses the default value to use in the order that they are presented in the list. * See the `defaultValueList` argument reference below. */ defaultValueLists: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingDefaultValueSpecificationDefaultValueList[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingDefaultValueSpecificationDefaultValueList { /** * Default value to use when a user doesn't provide a value for a slot. */ defaultValue: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecification { allowInterrupt?: boolean; maxRetries: number; messageGroups?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroup[]; messageSelectionStrategy?: string; promptAttemptsSpecifications?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecification[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariation[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecification { allowInterrupt?: boolean; allowedInputTypes?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAllowedInputTypes; audioAndDtmfInputSpecification?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecification; mapBlockKey: string; textInputSpecification?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationTextInputSpecification; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAllowedInputTypes { allowAudioInput: boolean; allowDtmfInput: boolean; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecification { audioSpecification?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationAudioSpecification; dtmfSpecification?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationDtmfSpecification; startTimeoutMs: number; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationAudioSpecification { endTimeoutMs: number; maxLengthMs: number; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationDtmfSpecification { deletionCharacter: string; endCharacter: string; endTimeoutMs: number; maxLength: number; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationTextInputSpecification { startTimeoutMs: number; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingSampleUtterance { /** * The sample utterance that Amazon Lex uses to build its machine-learning model to recognize intents. */ utterance: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecification { /** * Specifies whether the bot will wait for a user to respond. * When this field is `false`, wait and continue responses for a slot aren't used. * If the active field isn't specified, the default is `true`. */ active?: boolean; /** * Response that Amazon Lex sends to indicate that the bot is ready to continue the conversation. * See the `continueResponse` argument reference below. */ continueResponses?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponse[]; /** * Response that Amazon Lex sends periodically to the user to indicate that the bot is still waiting for input from the user. * See the `stillWaitingResponse` argument reference below. */ stillWaitingResponses?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponse[]; /** * Response that Amazon Lex sends to indicate that the bot is waiting for the conversation to continue. * See the `waitingResponse` argument reference below. */ waitingResponses?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponse[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. * Amazon Lex chooses the actual response to send at runtime. * See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroup[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariation[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * How often a message should be sent to the user. */ frequencyInSeconds: number; messageGroups?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroup[]; /** * If Amazon Lex waits longer than this length of time for a response, it will stop sending messages. */ timeoutInSeconds: number; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariation[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. * Amazon Lex chooses the actual response to send at runtime. * See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroup[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariation[]; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationSsmlMessage; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotSubSlotSettingSlotSpecificationValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface V2modelsSlotTypeCompositeSlotTypeSetting { /** * Sub slots in the composite slot. * See `subSlots` argument reference below. */ subSlots?: outputs.lex.V2modelsSlotTypeCompositeSlotTypeSettingSubSlot[]; } interface V2modelsSlotTypeCompositeSlotTypeSettingSubSlot { /** * Name of a constituent sub slot inside a composite slot. */ name: string; /** * Unique identifier assigned to a slot type. * This refers to either a built-in slot type or the unique `slotTypeId` of a custom slot type. */ slotTypeId: string; } interface V2modelsSlotTypeExternalSourceSetting { /** * Settings required for a slot type based on a grammar that you provide. * See `grammarSlotTypeSetting` argument reference below. */ grammarSlotTypeSettings?: outputs.lex.V2modelsSlotTypeExternalSourceSettingGrammarSlotTypeSetting[]; } interface V2modelsSlotTypeExternalSourceSettingGrammarSlotTypeSetting { /** * Source of the grammar used to create the slot type. * See `source` argument reference below. */ sources?: outputs.lex.V2modelsSlotTypeExternalSourceSettingGrammarSlotTypeSettingSource[]; } interface V2modelsSlotTypeExternalSourceSettingGrammarSlotTypeSettingSource { /** * KMS key required to decrypt the contents of the grammar, if any. */ kmsKeyArn: string; /** * Name of the Amazon S3 bucket that contains the grammar source. */ s3BucketName: string; /** * Path to the grammar in the Amazon S3 bucket. */ s3ObjectKey: string; } interface V2modelsSlotTypeSlotTypeValue { /** * Value of the slot type entry. * See `sampleValue` argument reference below. */ sampleValues?: outputs.lex.V2modelsSlotTypeSlotTypeValueSampleValue[]; /** * A list of additional values related to the slot type entry. * See `synonyms` argument reference below. */ synonyms?: outputs.lex.V2modelsSlotTypeSlotTypeValueSynonym[]; } interface V2modelsSlotTypeSlotTypeValueSampleValue { /** * Value that can be used for a slot type. */ value: string; } interface V2modelsSlotTypeSlotTypeValueSynonym { /** * Value that can be used for a slot type. */ value: string; } interface V2modelsSlotTypeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface V2modelsSlotTypeValueSelectionSetting { /** * Provides settings that enable advanced recognition settings for slot values. * You can use this to enable using slot values as a custom vocabulary for recognizing user utterances. * See `advancedRecognitionSetting` argument reference below. */ advancedRecognitionSettings?: outputs.lex.V2modelsSlotTypeValueSelectionSettingAdvancedRecognitionSetting[]; /** * Used to validate the value of the slot. * See `regexFilter` argument reference below. */ regexFilters?: outputs.lex.V2modelsSlotTypeValueSelectionSettingRegexFilter[]; /** * Determines the slot resolution strategy that Amazon Lex uses to return slot type values. * Valid values are `OriginalValue`, `TopResolution`, and `Concatenation`. */ resolutionStrategy: string; } interface V2modelsSlotTypeValueSelectionSettingAdvancedRecognitionSetting { /** * Enables using the slot values as a custom vocabulary for recognizing user utterances. * Valid value is `UseSlotValuesAsCustomVocabulary`. */ audioRecognitionStrategy?: string; } interface V2modelsSlotTypeValueSelectionSettingRegexFilter { /** * A regular expression used to validate the value of a slot. */ pattern: string; } interface V2modelsSlotValueElicitationSetting { /** * List of default values for a slot. * See the `defaultValueSpecification` argument reference below. */ defaultValueSpecifications?: outputs.lex.V2modelsSlotValueElicitationSettingDefaultValueSpecification[]; /** * Prompt that Amazon Lex uses to elicit the slot value from the user. * See the `aws.lex.V2modelsIntent` resource for details on the `promptSpecification` argument reference - they are identical. */ promptSpecification?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecification; sampleUtterances?: outputs.lex.V2modelsSlotValueElicitationSettingSampleUtterance[]; /** * Whether the slot is required or optional. Valid values are `Required` or `Optional`. */ slotConstraint: string; /** * Information about whether assisted slot resolution is turned on for the slot or not. * See the `slotResolutionSetting` argument reference below. */ slotResolutionSettings?: outputs.lex.V2modelsSlotValueElicitationSettingSlotResolutionSetting[]; /** * Specifies the prompts that Amazon Lex uses while a bot is waiting for customer input. * See the `waitAndContinueSpecification` argument reference below. */ waitAndContinueSpecifications?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecification[]; } interface V2modelsSlotValueElicitationSettingDefaultValueSpecification { /** * List of default values. * Amazon Lex chooses the default value to use in the order that they are presented in the list. * See the `defaultValueList` argument reference below. */ defaultValueLists: outputs.lex.V2modelsSlotValueElicitationSettingDefaultValueSpecificationDefaultValueList[]; } interface V2modelsSlotValueElicitationSettingDefaultValueSpecificationDefaultValueList { /** * Default value to use when a user doesn't provide a value for a slot. */ defaultValue: string; } interface V2modelsSlotValueElicitationSettingPromptSpecification { allowInterrupt?: boolean; maxRetries: number; messageGroups?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroup[]; messageSelectionStrategy?: string; promptAttemptsSpecifications?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecification[]; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariation[]; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageSsmlMessage; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationSsmlMessage; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecification { allowInterrupt?: boolean; allowedInputTypes?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAllowedInputTypes; audioAndDtmfInputSpecification?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecification; mapBlockKey: string; textInputSpecification?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationTextInputSpecification; } interface V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAllowedInputTypes { allowAudioInput: boolean; allowDtmfInput: boolean; } interface V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecification { audioSpecification?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationAudioSpecification; dtmfSpecification?: outputs.lex.V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationDtmfSpecification; startTimeoutMs: number; } interface V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationAudioSpecification { endTimeoutMs: number; maxLengthMs: number; } interface V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationAudioAndDtmfInputSpecificationDtmfSpecification { deletionCharacter: string; endCharacter: string; endTimeoutMs: number; maxLength: number; } interface V2modelsSlotValueElicitationSettingPromptSpecificationPromptAttemptsSpecificationTextInputSpecification { startTimeoutMs: number; } interface V2modelsSlotValueElicitationSettingSampleUtterance { /** * The sample utterance that Amazon Lex uses to build its machine-learning model to recognize intents. */ utterance: string; } interface V2modelsSlotValueElicitationSettingSlotResolutionSetting { /** * Specifies whether assisted slot resolution is turned on for the slot or not. * Valid values are `EnhancedFallback` or `Default`. * If the value is `EnhancedFallback`, assisted slot resolution is activated when Amazon Lex defaults to the `AMAZON.FallbackIntent`. * If the value is `Default`, assisted slot resolution is turned off. */ slotResolutionStrategy: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecification { /** * Specifies whether the bot will wait for a user to respond. * When this field is `false`, wait and continue responses for a slot aren't used. * If the active field isn't specified, the default is `true`. */ active?: boolean; /** * Response that Amazon Lex sends to indicate that the bot is ready to continue the conversation. * See the `continueResponse` argument reference below. */ continueResponses?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponse[]; /** * Response that Amazon Lex sends periodically to the user to indicate that the bot is still waiting for input from the user. * See the `stillWaitingResponse` argument reference below. */ stillWaitingResponses?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponse[]; /** * Response that Amazon Lex sends to indicate that the bot is waiting for the conversation to continue. * See the `waitingResponse` argument reference below. */ waitingResponses?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponse[]; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. * Amazon Lex chooses the actual response to send at runtime. * See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroup[]; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariation[]; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageSsmlMessage; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationSsmlMessage; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationContinueResponseMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * How often a message should be sent to the user. */ frequencyInSeconds: number; messageGroups?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroup[]; /** * If Amazon Lex waits longer than this length of time for a response, it will stop sending messages. */ timeoutInSeconds: number; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariation[]; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageSsmlMessage; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationSsmlMessage; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationStillWaitingResponseMessageGroupVariationSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponse { /** * Whether the user can interrupt a speech response from Amazon Lex. */ allowInterrupt?: boolean; /** * Configuration blocks for responses that Amazon Lex can send to the user. * Amazon Lex chooses the actual response to send at runtime. * See `messageGroup`. */ messageGroups?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroup[]; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroup { /** * Configuration block for the primary message that Amazon Lex should send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `message` argument reference - they are identical. */ message?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessage; /** * Configuration blocks for message variations to send to the user. * When variations are defined, Amazon Lex chooses the primary message or one of the variations to send to the user. * See the `aws.lex.V2modelsIntent` resource for details on the `variation` argument reference - they are identical. */ variations?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariation[]; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessage { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessagePlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageSsmlMessage; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessagePlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupMessageSsmlMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariation { customPayload?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationCustomPayload; imageResponseCard?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCard; plainTextMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationPlainTextMessage; ssmlMessage?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationSsmlMessage; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationCustomPayload { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCard { buttons?: outputs.lex.V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCardButton[]; imageUrl?: string; subtitle?: string; title: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationImageResponseCardButton { text: string; value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationPlainTextMessage { value: string; } interface V2modelsSlotValueElicitationSettingWaitAndContinueSpecificationWaitingResponseMessageGroupVariationSsmlMessage { value: string; } } export declare namespace licensemanager { interface GetLicenseGrantsFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/license-manager/latest/APIReference/API_ListReceivedGrants.html#API_ListReceivedGrants_RequestSyntax). * For example, if filtering using `ProductSKU`, use: * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const selected = aws.licensemanager.getLicenseGrants({ * filters: [{ * name: "ProductSKU", * values: [""], * }], * }); * ``` */ name: string; /** * Set of values that are accepted for the given field. */ values: string[]; } interface GetReceivedLicenseConsumptionConfiguration { /** * Details about a borrow configuration. Detailed below */ borrowConfigurations: outputs.licensemanager.GetReceivedLicenseConsumptionConfigurationBorrowConfiguration[]; /** * Details about a provisional configuration. Detailed below */ provisionalConfigurations: outputs.licensemanager.GetReceivedLicenseConsumptionConfigurationProvisionalConfiguration[]; renewType: string; } interface GetReceivedLicenseConsumptionConfigurationBorrowConfiguration { /** * Indicates whether early check-ins are allowed. */ allowEarlyCheckIn: boolean; /** * Maximum time for the provisional configuration, in minutes. */ maxTimeToLiveInMinutes: number; } interface GetReceivedLicenseConsumptionConfigurationProvisionalConfiguration { /** * Maximum time for the provisional configuration, in minutes. */ maxTimeToLiveInMinutes: number; } interface GetReceivedLicenseEntitlement { /** * Indicates whether check-ins are allowed. */ allowCheckIn: boolean; /** * Maximum entitlement count. Use if the unit is not None. */ maxCount: number; /** * The key name. */ name: string; /** * Indicates whether overages are allowed. */ overage: boolean; /** * Entitlement unit. */ unit: string; /** * The value. */ value: string; } interface GetReceivedLicenseIssuer { /** * Issuer key fingerprint. */ keyFingerprint: string; /** * The key name. */ name: string; /** * Asymmetric KMS key from KMS. The KMS key must have a key usage of sign and verify, and support the RSASSA-PSS SHA-256 signing algorithm. */ signKey: string; } interface GetReceivedLicenseLicenseMetadata { /** * The key name. */ name: string; /** * The value. */ value: string; } interface GetReceivedLicenseReceivedMetadata { /** * A list of allowed operations. */ allowedOperations: string[]; /** * Received status. */ receivedStatus: string; /** * Received status reason. */ receivedStatusReason: string; } interface GetReceivedLicenseValidity { /** * Start of the validity time range. */ begin: string; /** * End of the validity time range. */ end: string; } interface GetReceivedLicensesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/license-manager/latest/APIReference/API_ListReceivedLicenses.html#API_ListReceivedLicenses_RequestSyntax). * For example, if filtering using `ProductSKU`, use: * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const selected = aws.licensemanager.getReceivedLicenses({ * filters: [{ * name: "ProductSKU", * values: [""], * }], * }); * ``` */ name: string; /** * Set of values that are accepted for the given field. */ values: string[]; } } export declare namespace lightsail { interface CertificateDomainValidationOption { /** * Domain name for which the certificate should be issued. */ domainName: string; /** * Name of the DNS record to create to validate the certificate. */ resourceRecordName: string; /** * Type of DNS record to create to validate the certificate. */ resourceRecordType: string; /** * Value of the DNS record to create to validate the certificate. */ resourceRecordValue: string; } interface ContainerServiceDeploymentVersionContainer { /** * Launch command for the container. A list of strings. */ commands?: string[]; /** * Name of the container. */ containerName: string; /** * Key-value map of the environment variables of the container. */ environment?: { [key: string]: string; }; /** * Name of the image used for the container. Container images sourced from your Lightsail container service, that are registered and stored on your service, start with a colon (`:`). For example, `:container-service-1.mystaticwebsite.1`. Container images sourced from a public registry like Docker Hub don't start with a colon. For example, `nginx:latest` or `nginx`. */ image: string; /** * Key-value map of the open firewall ports of the container. Valid values: `HTTP`, `HTTPS`, `TCP`, `UDP`. */ ports?: { [key: string]: string; }; } interface ContainerServiceDeploymentVersionPublicEndpoint { /** * Name of the container for the endpoint. */ containerName: string; /** * Port of the container to which traffic is forwarded to. */ containerPort: number; /** * Configuration block that describes the health check configuration of the container. See below. */ healthCheck: outputs.lightsail.ContainerServiceDeploymentVersionPublicEndpointHealthCheck; } interface ContainerServiceDeploymentVersionPublicEndpointHealthCheck { /** * Number of consecutive health check successes required before moving the container to the Healthy state. Defaults to 2. */ healthyThreshold?: number; /** * Approximate interval, in seconds, between health checks of an individual container. You can specify between 5 and 300 seconds. Defaults to 5. */ intervalSeconds?: number; /** * Path on the container on which to perform the health check. Defaults to "/". */ path?: string; /** * HTTP codes to use when checking for a successful response from a container. You can specify values between 200 and 499. Defaults to "200-499". */ successCodes?: string; /** * Amount of time, in seconds, during which no response means a failed health check. You can specify between 2 and 60 seconds. Defaults to 2. */ timeoutSeconds?: number; /** * Number of consecutive health check failures required before moving the container to the Unhealthy state. Defaults to 2. */ unhealthyThreshold?: number; } interface ContainerServicePrivateRegistryAccess { /** * Configuration to access private container image repositories, such as Amazon Elastic Container Registry (Amazon ECR) private repositories. See below. */ ecrImagePullerRole: outputs.lightsail.ContainerServicePrivateRegistryAccessEcrImagePullerRole; } interface ContainerServicePrivateRegistryAccessEcrImagePullerRole { /** * Whether to activate the role. Defaults to `false`. */ isActive?: boolean; /** * Principal ARN of the container service. The principal ARN can be used to create a trust relationship between your standard AWS account and your Lightsail container service. */ principalArn: string; } interface ContainerServicePublicDomainNames { /** * Set of certificate configurations for the public domain names. Each element contains the following attributes: */ certificates: outputs.lightsail.ContainerServicePublicDomainNamesCertificate[]; } interface ContainerServicePublicDomainNamesCertificate { /** * Name of the certificate. */ certificateName: string; /** * List of domain names for the certificate. */ domainNames: string[]; } interface DistributionCacheBehavior { /** * Cache behavior for the specified path. Valid values: `cache`, `dont-cache`. */ behavior: string; /** * Path to a directory or file to cache, or not cache. Use an asterisk symbol to specify wildcard directories (`path/to/assets/*`), and file types (`*.html`, `*.jpg`, `*.js`). Directories and file paths are case-sensitive. */ path: string; } interface DistributionCacheBehaviorSettings { /** * HTTP methods that are processed and forwarded to the distribution's origin. */ allowedHttpMethods?: string; /** * HTTP method responses that are cached by your distribution. */ cachedHttpMethods?: string; /** * Default amount of time that objects stay in the distribution's cache before the distribution forwards another request to the origin to determine whether the content has been updated. */ defaultTtl?: number; /** * Cookies that are forwarded to the origin. Your content is cached based on the cookies that are forwarded. See below. */ forwardedCookies?: outputs.lightsail.DistributionCacheBehaviorSettingsForwardedCookies; /** * Headers that are forwarded to the origin. Your content is cached based on the headers that are forwarded. See below. */ forwardedHeaders?: outputs.lightsail.DistributionCacheBehaviorSettingsForwardedHeaders; /** * Query strings that are forwarded to the origin. Your content is cached based on the query strings that are forwarded. See below. */ forwardedQueryStrings?: outputs.lightsail.DistributionCacheBehaviorSettingsForwardedQueryStrings; /** * Maximum amount of time that objects stay in the distribution's cache before the distribution forwards another request to the origin to determine whether the object has been updated. */ maximumTtl?: number; /** * Minimum amount of time that objects stay in the distribution's cache before the distribution forwards another request to the origin to determine whether the object has been updated. */ minimumTtl?: number; } interface DistributionCacheBehaviorSettingsForwardedCookies { /** * Specific cookies to forward to your distribution's origin. */ cookiesAllowLists?: string[]; /** * Which cookies to forward to the distribution's origin for a cache behavior. Valid values: `all`, `none`, `allow-list`. */ option?: string; } interface DistributionCacheBehaviorSettingsForwardedHeaders { /** * Specific headers to forward to your distribution's origin. */ headersAllowLists?: string[]; /** * Headers that you want your distribution to forward to your origin and base caching on. Valid values: `default`, `allow-list`, `all`. */ option?: string; } interface DistributionCacheBehaviorSettingsForwardedQueryStrings { /** * Whether the distribution forwards and caches based on query strings. */ option?: boolean; /** * Specific query strings that the distribution forwards to the origin. */ queryStringsAllowedLists?: string[]; } interface DistributionDefaultCacheBehavior { /** * Cache behavior of the distribution. Valid values: `cache`, `dont-cache`. */ behavior: string; } interface DistributionLocation { /** * Availability Zone. Follows the format us-east-2a (case-sensitive). */ availabilityZone: string; /** * AWS Region name. */ regionName: string; } interface DistributionOrigin { /** * Name of the origin resource. Your origin can be an instance with an attached static IP, a bucket, or a load balancer that has at least one instance attached to it. */ name: string; /** * Protocol that your Amazon Lightsail distribution uses when establishing a connection with your origin to pull content. */ protocolPolicy?: string; /** * AWS Region name of the origin resource. */ regionName: string; /** * Lightsail resource type (e.g., Distribution). */ resourceType: string; } interface InstanceAddOn { /** * Daily time when an automatic snapshot will be created. Must be in HH:00 format, and in an hourly increment and specified in Coordinated Universal Time (UTC). The snapshot will be automatically created between the time specified and up to 45 minutes after. */ snapshotTime: string; /** * Status of the add-on. Valid values: `Enabled`, `Disabled`. */ status: string; /** * Add-on type. There is currently only one valid type `AutoSnapshot`. */ type: string; } interface InstancePublicPortsPortInfo { /** * Set of CIDR aliases that define access for a preconfigured range of IP addresses. */ cidrListAliases: string[]; /** * Set of IPv4 addresses or ranges of IPv4 addresses (in CIDR notation) that are allowed to connect to an instance through the ports, and the protocol. */ cidrs: string[]; /** * First port in a range of open ports on an instance. See [PortInfo](https://docs.aws.amazon.com/lightsail/2016-11-28/api-reference/API_PortInfo.html) for details. */ fromPort: number; /** * Set of IPv6 addresses or ranges of IPv6 addresses (in CIDR notation) that are allowed to connect to an instance through the ports, and the protocol. */ ipv6Cidrs: string[]; /** * IP protocol name. Valid values: `tcp`, `all`, `udp`, `icmp`, `icmpv6`. See [PortInfo](https://docs.aws.amazon.com/lightsail/2016-11-28/api-reference/API_PortInfo.html) for details. */ protocol: string; /** * Last port in a range of open ports on an instance. See [PortInfo](https://docs.aws.amazon.com/lightsail/2016-11-28/api-reference/API_PortInfo.html) for details. */ toPort: number; } interface LbCertificateDomainValidationRecord { /** * Domain name (e.g., example.com) for your SSL/TLS certificate. */ domainName: string; /** * Name of the DNS record to create to validate the certificate. */ resourceRecordName: string; /** * Type of DNS record to create to validate the certificate. */ resourceRecordType: string; /** * Value of the DNS record to create to validate the certificate. */ resourceRecordValue: string; } } export declare namespace location { interface GetMapConfiguration { /** * The map style selected from an available data provider. */ style: string; } interface GetPlaceIndexDataSourceConfiguration { intendedUse: string; } interface MapConfiguration { /** * Specifies the map style selected from an available data provider. Valid values can be found in the [Location Service CreateMap API Reference](https://docs.aws.amazon.com/location/latest/APIReference/API_CreateMap.html). */ style: string; } interface PlaceIndexDataSourceConfiguration { /** * How the results of an operation will be stored by the caller. Valid values: `SingleUse`, `Storage`. Default: `SingleUse`. */ intendedUse?: string; } } export declare namespace m2 { interface ApplicationDefinition { /** * JSON application definition. Either this or `s3Location` must be specified. */ content?: string; /** * Location of the application definition in S3. Either this or `content` must be specified. */ s3Location?: string; } interface ApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DeploymentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface EnvironmentHighAvailabilityConfig { /** * Desired number of instances for the Environment. */ desiredCapacity: number; } interface EnvironmentStorageConfiguration { efs?: outputs.m2.EnvironmentStorageConfigurationEfs; fsx?: outputs.m2.EnvironmentStorageConfigurationFsx; } interface EnvironmentStorageConfigurationEfs { /** * Id of the EFS filesystem to mount. */ fileSystemId: string; /** * Path to mount the filesystem on, must start with `/m2/mount/`. */ mountPoint: string; } interface EnvironmentStorageConfigurationFsx { /** * Id of the FSX filesystem to mount. */ fileSystemId: string; /** * Path to mount the filesystem on, must start with `/m2/mount/`. */ mountPoint: string; } interface EnvironmentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace macie { interface FindingsFilterFindingCriteria { /** * A condition that specifies the property, operator, and one or more values to use to filter the results. (documented below) */ criterions?: outputs.macie.FindingsFilterFindingCriteriaCriterion[]; } interface FindingsFilterFindingCriteriaCriterion { /** * The value for the property exclusively matches (equals an exact match for) all the specified values. If you specify multiple values, Amazon Macie uses AND logic to join the values. */ eqExactMatches?: string[]; /** * The value for the property matches (equals) the specified value. If you specify multiple values, Amazon Macie uses OR logic to join the values. */ eqs?: string[]; /** * The name of the field to be evaluated. */ field: string; /** * The value for the property is greater than the specified value. */ gt?: string; /** * The value for the property is greater than or equal to the specified value. */ gte?: string; /** * The value for the property is less than the specified value. */ lt?: string; /** * The value for the property is less than or equal to the specified value. */ lte?: string; /** * The value for the property doesn't match (doesn't equal) the specified value. If you specify multiple values, Amazon Macie uses OR logic to join the values. */ neqs?: string[]; } } export declare namespace macie2 { interface ClassificationExportConfigurationS3Destination { /** * The Amazon S3 bucket name in which Amazon Macie exports the data classification results. */ bucketName: string; /** * The object key for the bucket in which Amazon Macie exports the data classification results. */ keyPrefix?: string; /** * ARN of the KMS key to be used to encrypt the data. * * Additional information can be found in the [Storing and retaining sensitive data discovery results with Amazon Macie for AWS Macie documentation](https://docs.aws.amazon.com/macie/latest/user/discovery-results-repository-s3.html). */ kmsKeyArn: string; } interface ClassificationJobS3JobDefinition { /** * The property- and tag-based conditions that determine which S3 buckets to include or exclude from the analysis. Conflicts with `bucketDefinitions`. (documented below) */ bucketCriteria: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteria; /** * An array of objects, one for each AWS account that owns buckets to analyze. Each object specifies the account ID for an account and one or more buckets to analyze for the account. Conflicts with `bucketCriteria`. (documented below) */ bucketDefinitions?: outputs.macie2.ClassificationJobS3JobDefinitionBucketDefinition[]; /** * The property- and tag-based conditions that determine which objects to include or exclude from the analysis. (documented below) */ scoping: outputs.macie2.ClassificationJobS3JobDefinitionScoping; } interface ClassificationJobS3JobDefinitionBucketCriteria { /** * The property- or tag-based conditions that determine which S3 buckets to exclude from the analysis. (documented below) */ excludes: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaExcludes; /** * The property- or tag-based conditions that determine which S3 buckets to include in the analysis. (documented below) */ includes: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaIncludes; } interface ClassificationJobS3JobDefinitionBucketCriteriaExcludes { /** * An array of conditions, one for each condition that determines which objects to include or exclude from the job. (documented below) */ ands: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaExcludesAnd[]; } interface ClassificationJobS3JobDefinitionBucketCriteriaExcludesAnd { /** * A property-based condition that defines a property, operator, and one or more values for including or excluding an S3 buckets from the job. (documented below) */ simpleCriterion: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaExcludesAndSimpleCriterion; /** * A tag-based condition that defines the operator and tag keys or tag key and value pairs for including or excluding an S3 buckets from the job. (documented below) */ tagCriterion: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaExcludesAndTagCriterion; } interface ClassificationJobS3JobDefinitionBucketCriteriaExcludesAndSimpleCriterion { /** * The operator to use in a condition. Valid combination of values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-jobcomparator) */ comparator: string; /** * The object property to use in the condition. Valid combination of values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-simplecriterionkeyforjob) */ key: string; /** * An array that lists the values to use in the condition. Valid combination of values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-simplecriterionforjob) */ values: string[]; } interface ClassificationJobS3JobDefinitionBucketCriteriaExcludesAndTagCriterion { /** * The operator to use in the condition. Valid combination and values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-jobcomparator) */ comparator: string; /** * The tag key and value pairs to use in the condition. One or more blocks are allowed. (documented below) */ tagValues?: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaExcludesAndTagCriterionTagValue[]; } interface ClassificationJobS3JobDefinitionBucketCriteriaExcludesAndTagCriterionTagValue { /** * The tag key. */ key: string; /** * The tag value. */ value: string; } interface ClassificationJobS3JobDefinitionBucketCriteriaIncludes { /** * An array of conditions, one for each condition that determines which objects to include or exclude from the job. (documented below) */ ands: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaIncludesAnd[]; } interface ClassificationJobS3JobDefinitionBucketCriteriaIncludesAnd { /** * A property-based condition that defines a property, operator, and one or more values for including or excluding an S3 buckets from the job. (documented below) */ simpleCriterion: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaIncludesAndSimpleCriterion; /** * A tag-based condition that defines the operator and tag keys or tag key and value pairs for including or excluding an S3 buckets from the job. (documented below) */ tagCriterion: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaIncludesAndTagCriterion; } interface ClassificationJobS3JobDefinitionBucketCriteriaIncludesAndSimpleCriterion { /** * The operator to use in a condition. Valid combination of values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-jobcomparator) */ comparator: string; /** * The object property to use in the condition. Valid combination of values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-simplecriterionkeyforjob) */ key: string; /** * An array that lists the values to use in the condition. Valid combination of values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-simplecriterionforjob) */ values: string[]; } interface ClassificationJobS3JobDefinitionBucketCriteriaIncludesAndTagCriterion { /** * The operator to use in the condition. Valid combination and values are available in the [AWS Documentation](https://docs.aws.amazon.com/macie/latest/APIReference/jobs.html#jobs-model-jobcomparator) */ comparator: string; /** * The tag key and value pairs to use in the condition. One or more blocks are allowed. (documented below) */ tagValues?: outputs.macie2.ClassificationJobS3JobDefinitionBucketCriteriaIncludesAndTagCriterionTagValue[]; } interface ClassificationJobS3JobDefinitionBucketCriteriaIncludesAndTagCriterionTagValue { /** * The tag key. */ key: string; /** * The tag value. */ value: string; } interface ClassificationJobS3JobDefinitionBucketDefinition { /** * The unique identifier for the AWS account that owns the buckets. */ accountId: string; /** * An array that lists the names of the buckets. */ buckets: string[]; } interface ClassificationJobS3JobDefinitionScoping { /** * The property- or tag-based conditions that determine which objects to exclude from the analysis. (documented below) */ excludes: outputs.macie2.ClassificationJobS3JobDefinitionScopingExcludes; /** * The property- or tag-based conditions that determine which objects to include in the analysis. (documented below) */ includes: outputs.macie2.ClassificationJobS3JobDefinitionScopingIncludes; } interface ClassificationJobS3JobDefinitionScopingExcludes { /** * An array of conditions, one for each condition that determines which objects to include or exclude from the job. (documented below) */ ands: outputs.macie2.ClassificationJobS3JobDefinitionScopingExcludesAnd[]; } interface ClassificationJobS3JobDefinitionScopingExcludesAnd { /** * A property-based condition that defines a property, operator, and one or more values for including or excluding an object from the job. (documented below) */ simpleScopeTerm: outputs.macie2.ClassificationJobS3JobDefinitionScopingExcludesAndSimpleScopeTerm; /** * A tag-based condition that defines the operator and tag keys or tag key and value pairs for including or excluding an object from the job. (documented below) */ tagScopeTerm: outputs.macie2.ClassificationJobS3JobDefinitionScopingExcludesAndTagScopeTerm; } interface ClassificationJobS3JobDefinitionScopingExcludesAndSimpleScopeTerm { /** * The operator to use in a condition. Valid values are: `EQ`, `GT`, `GTE`, `LT`, `LTE`, `NE`, `CONTAINS`, `STARTS_WITH` */ comparator: string; /** * The object property to use in the condition. */ key: string; /** * An array that lists the values to use in the condition. */ values: string[]; } interface ClassificationJobS3JobDefinitionScopingExcludesAndTagScopeTerm { /** * The operator to use in the condition. */ comparator: string; /** * The tag key to use in the condition. The only valid value is `TAG`. */ key: string; /** * The tag keys or tag key and value pairs to use in the condition. */ tagValues: outputs.macie2.ClassificationJobS3JobDefinitionScopingExcludesAndTagScopeTermTagValue[]; /** * The type of object to apply the condition to. The only valid value is `S3_OBJECT`. */ target: string; } interface ClassificationJobS3JobDefinitionScopingExcludesAndTagScopeTermTagValue { /** * The tag key. */ key: string; /** * The tag value. */ value: string; } interface ClassificationJobS3JobDefinitionScopingIncludes { /** * An array of conditions, one for each condition that determines which objects to include or exclude from the job. (documented below) */ ands: outputs.macie2.ClassificationJobS3JobDefinitionScopingIncludesAnd[]; } interface ClassificationJobS3JobDefinitionScopingIncludesAnd { /** * A property-based condition that defines a property, operator, and one or more values for including or excluding an object from the job. (documented below) */ simpleScopeTerm: outputs.macie2.ClassificationJobS3JobDefinitionScopingIncludesAndSimpleScopeTerm; /** * A tag-based condition that defines the operator and tag keys or tag key and value pairs for including or excluding an object from the job. (documented below) */ tagScopeTerm: outputs.macie2.ClassificationJobS3JobDefinitionScopingIncludesAndTagScopeTerm; } interface ClassificationJobS3JobDefinitionScopingIncludesAndSimpleScopeTerm { /** * The operator to use in a condition. Valid values are: `EQ`, `GT`, `GTE`, `LT`, `LTE`, `NE`, `CONTAINS`, `STARTS_WITH` */ comparator: string; /** * The object property to use in the condition. */ key: string; /** * An array that lists the values to use in the condition. */ values: string[]; } interface ClassificationJobS3JobDefinitionScopingIncludesAndTagScopeTerm { /** * The operator to use in the condition. */ comparator: string; /** * The tag key to use in the condition. The only valid value is `TAG`. */ key: string; /** * The tag keys or tag key and value pairs to use in the condition. */ tagValues?: outputs.macie2.ClassificationJobS3JobDefinitionScopingIncludesAndTagScopeTermTagValue[]; /** * The type of object to apply the condition to. The only valid value is `S3_OBJECT`. */ target: string; } interface ClassificationJobS3JobDefinitionScopingIncludesAndTagScopeTermTagValue { /** * The tag key. */ key: string; /** * The tag value. */ value: string; } interface ClassificationJobScheduleFrequency { /** * Specifies a daily recurrence pattern for running the job. */ dailySchedule?: boolean; /** * Specifies a monthly recurrence pattern for running the job. */ monthlySchedule: number; /** * Specifies a weekly recurrence pattern for running the job. */ weeklySchedule: string; } interface ClassificationJobUserPausedDetail { jobExpiresAt: string; jobImminentExpirationHealthEventArn: string; jobPausedAt: string; } } export declare namespace mailmanager { interface ArchiveRetention { /** * Retention period for the archive. Valid values: `THREE_MONTHS`, `SIX_MONTHS`, `NINE_MONTHS`, `ONE_YEAR`, `EIGHTEEN_MONTHS`, `TWO_YEARS`, `THIRTY_MONTHS`, `THREE_YEARS`, `FOUR_YEARS`, `FIVE_YEARS`, `SIX_YEARS`, `SEVEN_YEARS`, `EIGHT_YEARS`, `NINE_YEARS`, `TEN_YEARS`, `PERMANENT`. */ retentionPeriod: string; } interface ArchiveRetentionActual { /** * Retention period for the archive. Possible values: `THREE_MONTHS`, `SIX_MONTHS`, `NINE_MONTHS`, `ONE_YEAR`, `EIGHTEEN_MONTHS`, `TWO_YEARS`, `THIRTY_MONTHS`, `THREE_YEARS`, `FOUR_YEARS`, `FIVE_YEARS`, `SIX_YEARS`, `SEVEN_YEARS`, `EIGHT_YEARS`, `NINE_YEARS`, `TEN_YEARS`, `PERMANENT`. */ retentionPeriod: string; } interface IngressPointIngressPointConfiguration { /** * ARN of the secret in AWS Secrets Manager that holds the SMTP password, used for `AUTH` ingress points. */ secretArn?: string; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. * SMTP password used for `AUTH` ingress points. This argument is not stored in state. If set, requires `smtpPasswordWoVersion` to be set. */ smtpPasswordWo?: string; /** * Required when `smtpPasswordWo` is set. Changing this value triggers an update to `smtpPasswordWo`. */ smtpPasswordWoVersion?: number; /** * Configuration used to authenticate with `MTLS` ingress points. See `tlsAuthConfiguration` Block for details. */ tlsAuthConfiguration?: outputs.mailmanager.IngressPointIngressPointConfigurationTlsAuthConfiguration; } interface IngressPointIngressPointConfigurationTlsAuthConfiguration { /** * Trust store used to validate client certificates. See `trustStore` Block for details. */ trustStore?: outputs.mailmanager.IngressPointIngressPointConfigurationTlsAuthConfigurationTrustStore; } interface IngressPointIngressPointConfigurationTlsAuthConfigurationTrustStore { /** * PEM-encoded certificate authority (CA) content used to validate client certificates. */ caContent: string; /** * PEM-encoded certificate revocation list (CRL) content used to check whether client certificates have been revoked. */ crlContent?: string; /** * ARN of the AWS KMS key used to decrypt the CRL content. */ kmsKeyArn?: string; } interface IngressPointNetworkConfiguration { /** * Configuration for a private ingress point that uses a VPC endpoint. See `privateNetworkConfiguration` Block for details. */ privateNetworkConfiguration?: outputs.mailmanager.IngressPointNetworkConfigurationPrivateNetworkConfiguration; /** * Configuration for a public ingress point. See `publicNetworkConfiguration` Block for details. */ publicNetworkConfiguration?: outputs.mailmanager.IngressPointNetworkConfigurationPublicNetworkConfiguration; } interface IngressPointNetworkConfigurationPrivateNetworkConfiguration { /** * Identifier of the VPC endpoint to associate with the ingress point. */ vpcEndpointId: string; } interface IngressPointNetworkConfigurationPublicNetworkConfiguration { /** * IP address type for the public ingress point. Valid values are `IPV4` and `DUAL_STACK`. */ ipType: string; } interface IngressPointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface RelayAuthentication { /** * No authentication is required to connect to the SMTP server. */ noAuthentication?: outputs.mailmanager.RelayAuthenticationNoAuthentication; /** * ARN of the Secrets Manager secret containing the SMTP credentials. */ secretArn?: string; } interface RelayAuthenticationNoAuthentication { } interface RuleSetRule { /** * One or more actions to execute when all conditions match. Between 1 and 10 actions are supported. Each action must contain exactly one action configuration. See `action` Block. */ actions?: outputs.mailmanager.RuleSetRuleAction[]; /** * One or more conditions that must all evaluate to true for the rule to match. Up to 10 conditions are supported. See `condition` Block. */ conditions?: outputs.mailmanager.RuleSetRuleCondition[]; /** * Name of the rule. */ name?: string; /** * One or more conditions that prevent the rule from matching when any evaluates to true. Up to 10 conditions are supported. See `condition` Block. */ unlesses?: outputs.mailmanager.RuleSetRuleUnless[]; } interface RuleSetRuleAction { /** * Adds a header to the email. See `addHeader` Block. */ addHeader?: outputs.mailmanager.RuleSetRuleActionAddHeader; /** * Archives the email. See `archive` Block. */ archive?: outputs.mailmanager.RuleSetRuleActionArchive; /** * Sends a bounce response. See `bounce` Block. */ bounce?: outputs.mailmanager.RuleSetRuleActionBounce; /** * Delivers the email to a WorkMail mailbox. See `deliverToMailbox` Block. */ deliverToMailbox?: outputs.mailmanager.RuleSetRuleActionDeliverToMailbox; /** * Delivers the email to an Amazon Q Business application. See `deliverToQBusiness` Block. */ deliverToQBusiness?: outputs.mailmanager.RuleSetRuleActionDeliverToQBusiness; /** * Stops rule evaluation and drops the email. */ drop?: outputs.mailmanager.RuleSetRuleActionDrop; /** * Invokes a Lambda function. See `invokeLambda` Block. */ invokeLambda?: outputs.mailmanager.RuleSetRuleActionInvokeLambda; /** * Publishes the email to an SNS topic. See `publishToSns` Block. */ publishToSns?: outputs.mailmanager.RuleSetRuleActionPublishToSns; /** * Relays the email to an SMTP server. See `relay` Block. */ relay?: outputs.mailmanager.RuleSetRuleActionRelay; /** * Replaces envelope recipients. See `replaceRecipient` Block. */ replaceRecipient?: outputs.mailmanager.RuleSetRuleActionReplaceRecipient; /** * Sends the email to the internet. See `send` Block. */ send?: outputs.mailmanager.RuleSetRuleActionSend; /** * Writes the email MIME content to an S3 bucket. See `writeToS3` Block. */ writeToS3?: outputs.mailmanager.RuleSetRuleActionWriteToS3; } interface RuleSetRuleActionAddHeader { /** * Header name. Must begin with `X-`. */ headerName: string; /** * Header value. */ headerValue: string; } interface RuleSetRuleActionArchive { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * Identifier of the archive. */ targetArchive: string; } interface RuleSetRuleActionBounce { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * Diagnostic message included in the bounce. */ diagnosticMessage: string; /** * Human-readable bounce message. */ message?: string; /** * ARN of the IAM role used to send the bounce. */ roleArn: string; /** * Sender address of the bounce. */ sender: string; /** * SMTP reply code. */ smtpReplyCode: string; /** * Enhanced status code. */ statusCode: string; } interface RuleSetRuleActionDeliverToMailbox { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * ARN of the WorkMail organization. */ mailboxArn: string; /** * ARN of the IAM role used to deliver the email. */ roleArn: string; } interface RuleSetRuleActionDeliverToQBusiness { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * Q Business application identifier. */ applicationId: string; /** * Q Business index identifier. */ indexId: string; /** * ARN of the IAM role used to deliver the email. */ roleArn: string; } interface RuleSetRuleActionDrop { } interface RuleSetRuleActionInvokeLambda { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * ARN of the Lambda function. */ functionArn: string; /** * Lambda invocation type. */ invocationType: string; /** * Maximum retry time in minutes. */ retryTimeMinutes?: number; /** * ARN of the IAM role used to invoke the function. */ roleArn: string; } interface RuleSetRuleActionPublishToSns { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * Email encoding in the notification. */ encoding?: string; /** * Notification payload type. */ payloadType?: string; /** * ARN of the IAM role used to publish the email. */ roleArn: string; /** * ARN of the SNS topic. */ topicArn: string; } interface RuleSetRuleActionRelay { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * Whether to preserve or replace the original MAIL FROM address. */ mailFrom?: string; /** * Identifier of the relay resource. */ relay: string; } interface RuleSetRuleActionReplaceRecipient { /** * Replacement envelope recipient addresses. */ replaceWiths?: string[]; } interface RuleSetRuleActionSend { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * ARN of the IAM role used to send the email. */ roleArn: string; } interface RuleSetRuleActionWriteToS3 { /** * Policy applied when the action fails. */ actionFailurePolicy?: string; /** * ARN of the IAM role used to write to S3. */ roleArn: string; /** * Name of the S3 bucket. */ s3Bucket: string; /** * S3 object key prefix. */ s3Prefix?: string; /** * KMS key identifier used to encrypt the email. */ s3SseKmsKeyId?: string; } interface RuleSetRuleCondition { /** * Boolean expression evaluated against an email attribute or Add On result. See `booleanExpression` Block. */ booleanExpression?: outputs.mailmanager.RuleSetRuleConditionBooleanExpression; /** * DMARC policy expression evaluated against the email's DMARC result. See `dmarcExpression` Block. */ dmarcExpression?: outputs.mailmanager.RuleSetRuleConditionDmarcExpression; /** * IP CIDR expression evaluated against the sender IP address. See `ipExpression` Block. */ ipExpression?: outputs.mailmanager.RuleSetRuleConditionIpExpression; /** * Numeric expression evaluated against an email attribute such as message size. See `numberExpression` Block. */ numberExpression?: outputs.mailmanager.RuleSetRuleConditionNumberExpression; /** * String expression evaluated against an email attribute, MIME header, client certificate field, or Add On result. See `stringExpression` Block. */ stringExpression?: outputs.mailmanager.RuleSetRuleConditionStringExpression; /** * Verdict expression evaluated against email authentication results such as SPF or DKIM. See `verdictExpression` Block. */ verdictExpression?: outputs.mailmanager.RuleSetRuleConditionVerdictExpression; } interface RuleSetRuleConditionBooleanExpression { /** * Operand evaluated by the expression. Exactly one of `analysis`, `attribute`, or `isInAddressList` must be configured. */ evaluate?: outputs.mailmanager.RuleSetRuleConditionBooleanExpressionEvaluate; /** * Boolean matching operator. Valid values are `IS_TRUE` and `IS_FALSE`. */ operator: string; } interface RuleSetRuleConditionBooleanExpressionEvaluate { /** * Add On result to evaluate. See `analysis` Block. */ analysis?: outputs.mailmanager.RuleSetRuleConditionBooleanExpressionEvaluateAnalysis; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute?: string; /** * Address-list membership expression. */ isInAddressList?: outputs.mailmanager.RuleSetRuleConditionBooleanExpressionEvaluateIsInAddressList; } interface RuleSetRuleConditionBooleanExpressionEvaluateAnalysis { /** * ARN of the Mail Manager Add On. */ analyzer: string; /** * Result field returned by the Add On. Must contain between 1 and 256 characters. */ resultField: string; } interface RuleSetRuleConditionBooleanExpressionEvaluateIsInAddressList { /** * List containing exactly one address list ARN or identifier. */ addressLists: string[]; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute: string; } interface RuleSetRuleConditionDmarcExpression { /** * DMARC policy matching operator. Valid values are `EQUALS` and `NOT_EQUALS`. */ operator: string; /** * List of DMARC policy values. Valid values are `NONE`, `QUARANTINE`, and `REJECT`. */ values: string[]; } interface RuleSetRuleConditionIpExpression { /** * Left-hand operand of the expression. */ evaluate?: outputs.mailmanager.RuleSetRuleConditionIpExpressionEvaluate; /** * CIDR matching operator. Valid values are `CIDR_MATCHES` and `NOT_CIDR_MATCHES`. */ operator: string; /** * List of IP CIDR ranges against which the sender IP address is evaluated. Between 1 and 10 values are supported. */ values: string[]; } interface RuleSetRuleConditionIpExpressionEvaluate { /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute: string; } interface RuleSetRuleConditionNumberExpression { /** * Left-hand operand of the expression. */ evaluate?: outputs.mailmanager.RuleSetRuleConditionNumberExpressionEvaluate; /** * Numeric comparison operator. Valid values are `EQUALS`, `NOT_EQUALS`, `LESS_THAN`, `GREATER_THAN`, `LESS_THAN_OR_EQUAL`, and `GREATER_THAN_OR_EQUAL`. */ operator: string; /** * Numeric value to compare against. */ value: number; } interface RuleSetRuleConditionNumberExpressionEvaluate { /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute: string; } interface RuleSetRuleConditionStringExpression { /** * Left-hand operand of the expression. Exactly one of `analysis`, `attribute`, `clientCertificateAttribute`, or `mimeHeaderAttribute` must be configured. */ evaluate?: outputs.mailmanager.RuleSetRuleConditionStringExpressionEvaluate; /** * String matching operator. Valid values are `EQUALS`, `NOT_EQUALS`, `STARTS_WITH`, `ENDS_WITH`, and `CONTAINS`. */ operator: string; /** * List of strings against which the selected operand is evaluated. Between 1 and 10 values are supported, each up to 4096 characters. */ values: string[]; } interface RuleSetRuleConditionStringExpressionEvaluate { /** * Add On result to evaluate. See `analysis` Block. */ analysis?: outputs.mailmanager.RuleSetRuleConditionStringExpressionEvaluateAnalysis; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute?: string; /** * Client certificate field to evaluate. Valid values are `CN`, `SAN_RFC822_NAME`, `SAN_DNS_NAME`, `SAN_DIRECTORY_NAME`, `SAN_UNIFORM_RESOURCE_IDENTIFIER`, `SAN_IP_ADDRESS`, `SAN_REGISTERED_ID`, and `SERIAL_NUMBER`. */ clientCertificateAttribute?: string; /** * MIME header name to evaluate. Must contain between 1 and 256 characters and begin with `X-` or `x-`. */ mimeHeaderAttribute?: string; } interface RuleSetRuleConditionStringExpressionEvaluateAnalysis { /** * ARN of the Mail Manager Add On. */ analyzer: string; /** * Result field returned by the Add On. Must contain between 1 and 256 characters. */ resultField: string; } interface RuleSetRuleConditionVerdictExpression { /** * Left-hand operand of the expression. Exactly one of `analysis` or `attribute` must be configured. */ evaluate?: outputs.mailmanager.RuleSetRuleConditionVerdictExpressionEvaluate; /** * Verdict matching operator. Valid values are `EQUALS` and `NOT_EQUALS`. */ operator: string; /** * List of verdict values. Valid values are `PASS`, `FAIL`, `GRAY`, and `PROCESSING_FAILED`. Between 1 and 10 values are supported. */ values: string[]; } interface RuleSetRuleConditionVerdictExpressionEvaluate { /** * Add On result to evaluate. See `analysis` Block. */ analysis?: outputs.mailmanager.RuleSetRuleConditionVerdictExpressionEvaluateAnalysis; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute?: string; } interface RuleSetRuleConditionVerdictExpressionEvaluateAnalysis { /** * ARN of the Mail Manager Add On. */ analyzer: string; /** * Result field returned by the Add On. Must contain between 1 and 256 characters. */ resultField: string; } interface RuleSetRuleUnless { /** * Boolean expression evaluated against an email attribute or Add On result. See `booleanExpression` Block. */ booleanExpression?: outputs.mailmanager.RuleSetRuleUnlessBooleanExpression; /** * DMARC policy expression evaluated against the email's DMARC result. See `dmarcExpression` Block. */ dmarcExpression?: outputs.mailmanager.RuleSetRuleUnlessDmarcExpression; /** * IP CIDR expression evaluated against the sender IP address. See `ipExpression` Block. */ ipExpression?: outputs.mailmanager.RuleSetRuleUnlessIpExpression; /** * Numeric expression evaluated against an email attribute such as message size. See `numberExpression` Block. */ numberExpression?: outputs.mailmanager.RuleSetRuleUnlessNumberExpression; /** * String expression evaluated against an email attribute, MIME header, client certificate field, or Add On result. See `stringExpression` Block. */ stringExpression?: outputs.mailmanager.RuleSetRuleUnlessStringExpression; /** * Verdict expression evaluated against email authentication results such as SPF or DKIM. See `verdictExpression` Block. */ verdictExpression?: outputs.mailmanager.RuleSetRuleUnlessVerdictExpression; } interface RuleSetRuleUnlessBooleanExpression { /** * Operand evaluated by the expression. Exactly one of `analysis`, `attribute`, or `isInAddressList` must be configured. */ evaluate?: outputs.mailmanager.RuleSetRuleUnlessBooleanExpressionEvaluate; /** * Boolean matching operator. Valid values are `IS_TRUE` and `IS_FALSE`. */ operator: string; } interface RuleSetRuleUnlessBooleanExpressionEvaluate { /** * Add On result to evaluate. See `analysis` Block. */ analysis?: outputs.mailmanager.RuleSetRuleUnlessBooleanExpressionEvaluateAnalysis; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute?: string; /** * Address-list membership expression. */ isInAddressList?: outputs.mailmanager.RuleSetRuleUnlessBooleanExpressionEvaluateIsInAddressList; } interface RuleSetRuleUnlessBooleanExpressionEvaluateAnalysis { /** * ARN of the Mail Manager Add On. */ analyzer: string; /** * Result field returned by the Add On. Must contain between 1 and 256 characters. */ resultField: string; } interface RuleSetRuleUnlessBooleanExpressionEvaluateIsInAddressList { /** * List containing exactly one address list ARN or identifier. */ addressLists: string[]; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute: string; } interface RuleSetRuleUnlessDmarcExpression { /** * DMARC policy matching operator. Valid values are `EQUALS` and `NOT_EQUALS`. */ operator: string; /** * List of DMARC policy values. Valid values are `NONE`, `QUARANTINE`, and `REJECT`. */ values: string[]; } interface RuleSetRuleUnlessIpExpression { /** * Left-hand operand of the expression. */ evaluate?: outputs.mailmanager.RuleSetRuleUnlessIpExpressionEvaluate; /** * CIDR matching operator. Valid values are `CIDR_MATCHES` and `NOT_CIDR_MATCHES`. */ operator: string; /** * List of IP CIDR ranges against which the sender IP address is evaluated. Between 1 and 10 values are supported. */ values: string[]; } interface RuleSetRuleUnlessIpExpressionEvaluate { /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute: string; } interface RuleSetRuleUnlessNumberExpression { /** * Left-hand operand of the expression. */ evaluate?: outputs.mailmanager.RuleSetRuleUnlessNumberExpressionEvaluate; /** * Numeric comparison operator. Valid values are `EQUALS`, `NOT_EQUALS`, `LESS_THAN`, `GREATER_THAN`, `LESS_THAN_OR_EQUAL`, and `GREATER_THAN_OR_EQUAL`. */ operator: string; /** * Numeric value to compare against. */ value: number; } interface RuleSetRuleUnlessNumberExpressionEvaluate { /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute: string; } interface RuleSetRuleUnlessStringExpression { /** * Left-hand operand of the expression. Exactly one of `analysis`, `attribute`, `clientCertificateAttribute`, or `mimeHeaderAttribute` must be configured. */ evaluate?: outputs.mailmanager.RuleSetRuleUnlessStringExpressionEvaluate; /** * String matching operator. Valid values are `EQUALS`, `NOT_EQUALS`, `STARTS_WITH`, `ENDS_WITH`, and `CONTAINS`. */ operator: string; /** * List of strings against which the selected operand is evaluated. Between 1 and 10 values are supported, each up to 4096 characters. */ values: string[]; } interface RuleSetRuleUnlessStringExpressionEvaluate { /** * Add On result to evaluate. See `analysis` Block. */ analysis?: outputs.mailmanager.RuleSetRuleUnlessStringExpressionEvaluateAnalysis; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute?: string; /** * Client certificate field to evaluate. Valid values are `CN`, `SAN_RFC822_NAME`, `SAN_DNS_NAME`, `SAN_DIRECTORY_NAME`, `SAN_UNIFORM_RESOURCE_IDENTIFIER`, `SAN_IP_ADDRESS`, `SAN_REGISTERED_ID`, and `SERIAL_NUMBER`. */ clientCertificateAttribute?: string; /** * MIME header name to evaluate. Must contain between 1 and 256 characters and begin with `X-` or `x-`. */ mimeHeaderAttribute?: string; } interface RuleSetRuleUnlessStringExpressionEvaluateAnalysis { /** * ARN of the Mail Manager Add On. */ analyzer: string; /** * Result field returned by the Add On. Must contain between 1 and 256 characters. */ resultField: string; } interface RuleSetRuleUnlessVerdictExpression { /** * Left-hand operand of the expression. Exactly one of `analysis` or `attribute` must be configured. */ evaluate?: outputs.mailmanager.RuleSetRuleUnlessVerdictExpressionEvaluate; /** * Verdict matching operator. Valid values are `EQUALS` and `NOT_EQUALS`. */ operator: string; /** * List of verdict values. Valid values are `PASS`, `FAIL`, `GRAY`, and `PROCESSING_FAILED`. Between 1 and 10 values are supported. */ values: string[]; } interface RuleSetRuleUnlessVerdictExpressionEvaluate { /** * Add On result to evaluate. See `analysis` Block. */ analysis?: outputs.mailmanager.RuleSetRuleUnlessVerdictExpressionEvaluateAnalysis; /** * Email authentication attribute to evaluate. Valid values are `SPF` and `DKIM`. */ attribute?: string; } interface RuleSetRuleUnlessVerdictExpressionEvaluateAnalysis { /** * ARN of the Mail Manager Add On. */ analyzer: string; /** * Result field returned by the Add On. Must contain between 1 and 256 characters. */ resultField: string; } interface TrafficPolicyPolicyStatement { /** * Action applied when all conditions match. Valid values are `ALLOW` and `DENY`. */ action: string; /** * Conditions evaluated by the statement. See `condition` Block below. */ conditions?: outputs.mailmanager.TrafficPolicyPolicyStatementCondition[]; } interface TrafficPolicyPolicyStatementCondition { /** * Boolean comparison. See `booleanExpression` Block below. */ booleanExpression?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionBooleanExpression; /** * IPv4 address comparison. See `ipExpression` Block below. */ ipExpression?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionIpExpression; /** * IPv6 address comparison. See `ipv6Expression` Block below. */ ipv6Expression?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionIpv6Expression; /** * String comparison. See `stringExpression` Block below. */ stringExpression?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionStringExpression; /** * TLS policy comparison. See `tlsExpression` Block below. */ tlsExpression?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionTlsExpression; } interface TrafficPolicyPolicyStatementConditionBooleanExpression { /** * Operand evaluated by the expression. See `policy_statement.condition.boolean_expression.evaluate` Block below. */ evaluate?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionBooleanExpressionEvaluate; /** * Boolean operator used for the comparison. */ operator: string; } interface TrafficPolicyPolicyStatementConditionBooleanExpressionEvaluate { /** * Analysis result to evaluate. See `policy_statement.condition.string_expression.evaluate.analysis` Block below. */ analysis?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionBooleanExpressionEvaluateAnalysis; /** * Address list membership check. See `isInAddressList` Block below. */ isInAddressList?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionBooleanExpressionEvaluateIsInAddressList; } interface TrafficPolicyPolicyStatementConditionBooleanExpressionEvaluateAnalysis { /** * ARN of the analyzer performing the analysis. */ analyzer: string; /** * Result field returned in the analysis. */ resultField: string; } interface TrafficPolicyPolicyStatementConditionBooleanExpressionEvaluateIsInAddressList { /** * List containing exactly one address list ARN to check membership against. */ addressLists: string[]; /** * Email attribute to check against the address list. */ attribute: string; } interface TrafficPolicyPolicyStatementConditionIpExpression { /** * Operand evaluated by the expression. See `policy_statement.condition.ip_expression.evaluate` Block below. */ evaluate?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionIpExpressionEvaluate; /** * IP address operator used for the comparison. */ operator: string; /** * IPv4 CIDR ranges used for the comparison. */ values: string[]; } interface TrafficPolicyPolicyStatementConditionIpExpressionEvaluate { attribute: string; } interface TrafficPolicyPolicyStatementConditionIpv6Expression { /** * Operand evaluated by the expression. See `policy_statement.condition.ipv6_expression.evaluate` Block below. */ evaluate?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionIpv6ExpressionEvaluate; /** * IPv6 address operator used for the comparison. */ operator: string; /** * IPv6 CIDR ranges used for the comparison. */ values: string[]; } interface TrafficPolicyPolicyStatementConditionIpv6ExpressionEvaluate { attribute: string; } interface TrafficPolicyPolicyStatementConditionStringExpression { /** * Operand evaluated by the expression. See `policy_statement.condition.string_expression.evaluate` Block below. */ evaluate?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionStringExpressionEvaluate; /** * String operator used for the comparison. */ operator: string; /** * Strings used for the comparison. */ values: string[]; } interface TrafficPolicyPolicyStatementConditionStringExpressionEvaluate { /** * Analysis result to evaluate. See `policy_statement.condition.string_expression.evaluate.analysis` Block below. */ analysis?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionStringExpressionEvaluateAnalysis; attribute?: string; } interface TrafficPolicyPolicyStatementConditionStringExpressionEvaluateAnalysis { /** * ARN of the analyzer performing the analysis. */ analyzer: string; /** * Result field returned in the analysis. */ resultField: string; } interface TrafficPolicyPolicyStatementConditionTlsExpression { /** * Operand evaluated by the expression. See `policy_statement.condition.tls_expression.evaluate` Block below. */ evaluate?: outputs.mailmanager.TrafficPolicyPolicyStatementConditionTlsExpressionEvaluate; /** * TLS policy operator used for the comparison. */ operator: string; /** * TLS policy used for the comparison. */ value: string; } interface TrafficPolicyPolicyStatementConditionTlsExpressionEvaluate { attribute: string; } } export declare namespace mediaconvert { interface QueueReservationPlanSettings { /** * The length of the term of your reserved queue pricing plan commitment. Valid value is `ONE_YEAR`. */ commitment: string; /** * Specifies whether the term of your reserved queue pricing plan. Valid values are `AUTO_RENEW` or `EXPIRE`. */ renewalType: string; /** * Specifies the number of reserved transcode slots (RTS) for queue. */ reservedSlots: number; } } export declare namespace medialive { interface ChannelCdiInputSpecification { /** * Maximum CDI input resolution. */ resolution: string; } interface ChannelDestination { /** * User-specified id. Ths is used in an output group or an output. */ id: string; /** * Destination settings for a MediaPackage output; one destination for both encoders. See Media Package Settings for more details. */ mediaPackageSettings?: outputs.medialive.ChannelDestinationMediaPackageSetting[]; /** * Destination settings for a Multiplex output; one destination for both encoders. See Multiplex Settings for more details. */ multiplexSettings?: outputs.medialive.ChannelDestinationMultiplexSettings; /** * Destination settings for a standard output; one destination for each redundant encoder. See Settings for more details. */ settings?: outputs.medialive.ChannelDestinationSetting[]; } interface ChannelDestinationMediaPackageSetting { /** * ID of the channel in MediaPackage that is the destination for this output group. */ channelId: string; } interface ChannelDestinationMultiplexSettings { /** * The ID of the Multiplex that the encoder is providing output to. */ multiplexId: string; /** * The program name of the Multiplex program that the encoder is providing output to. */ programName: string; } interface ChannelDestinationSetting { /** * Key used to extract the password from EC2 Parameter store. */ passwordParam?: string; /** * Stream name RTMP destinations (URLs of type rtmp://) */ streamName?: string; /** * A URL specifying a destination. */ url?: string; /** * Username for destination. */ username?: string; } interface ChannelEncoderSettings { /** * Audio descriptions for the channel. See Audio Descriptions for more details. */ audioDescriptions?: outputs.medialive.ChannelEncoderSettingsAudioDescription[]; /** * Settings for ad avail blanking. See Avail Blanking for more details. */ availBlanking: outputs.medialive.ChannelEncoderSettingsAvailBlanking; /** * Caption Descriptions. See Caption Descriptions for more details. */ captionDescriptions: outputs.medialive.ChannelEncoderSettingsCaptionDescription[]; /** * Configuration settings that apply to the event as a whole. See Global Configuration for more details. */ globalConfiguration?: outputs.medialive.ChannelEncoderSettingsGlobalConfiguration; /** * Settings for motion graphics. See Motion Graphics Configuration for more details. */ motionGraphicsConfiguration?: outputs.medialive.ChannelEncoderSettingsMotionGraphicsConfiguration; /** * Nielsen configuration settings. See Nielsen Configuration for more details. */ nielsenConfiguration?: outputs.medialive.ChannelEncoderSettingsNielsenConfiguration; /** * Output groups for the channel. See Output Groups for more details. */ outputGroups: outputs.medialive.ChannelEncoderSettingsOutputGroup[]; /** * Contains settings used to acquire and adjust timecode information from inputs. See Timecode Config for more details. */ timecodeConfig: outputs.medialive.ChannelEncoderSettingsTimecodeConfig; /** * Video Descriptions. See Video Descriptions for more details. */ videoDescriptions: outputs.medialive.ChannelEncoderSettingsVideoDescription[]; } interface ChannelEncoderSettingsAudioDescription { /** * Advanced audio normalization settings. See Audio Normalization Settings for more details. */ audioNormalizationSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionAudioNormalizationSettings; /** * The name of the audio selector used as the source for this AudioDescription. */ audioSelectorName: string; /** * Applies only if audioTypeControl is useConfigured. The values for audioType are defined in ISO-IEC 13818-1. */ audioType: string; /** * Determined how audio type is determined. */ audioTypeControl: string; /** * Settings to configure one or more solutions that insert audio watermarks in the audio encode. See Audio Watermark Settings for more details. */ audioWatermarkSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettings; /** * Audio codec settings. See Audio Codec Settings for more details. */ codecSettings: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettings; languageCode: string; languageCodeControl: string; /** * The name of this audio description. */ name: string; remixSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionRemixSettings; /** * Stream name RTMP destinations (URLs of type rtmp://) */ streamName: string; } interface ChannelEncoderSettingsAudioDescriptionAudioNormalizationSettings { /** * Audio normalization algorithm to use. itu17701 conforms to the CALM Act specification, itu17702 to the EBU R-128 specification. */ algorithm: string; /** * Algorithm control for the audio description. */ algorithmControl: string; /** * Target LKFS (loudness) to adjust volume to. */ targetLkfs: number; } interface ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettings { nielsenWatermarksSettings: outputs.medialive.ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettingsNielsenWatermarksSettings; } interface ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettingsNielsenWatermarksSettings { /** * Used to insert watermarks of type Nielsen CBET. See Nielsen CBET Settings for more details. */ nielsenCbetSettings: outputs.medialive.ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettingsNielsenWatermarksSettingsNielsenCbetSettings; /** * Distribution types to assign to the watermarks. Options are `PROGRAM_CONTENT` and `FINAL_DISTRIBUTOR`. */ nielsenDistributionType: string; /** * Used to insert watermarks of type Nielsen NAES, II (N2) and Nielsen NAES VI (NW). See Nielsen NAES II NW Settings for more details. */ nielsenNaesIiNwSettings: outputs.medialive.ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettingsNielsenWatermarksSettingsNielsenNaesIiNwSetting[]; } interface ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettingsNielsenWatermarksSettingsNielsenCbetSettings { cbetCheckDigitString: string; /** * Determines the method of CBET insertion mode when prior encoding is detected on the same layer. */ cbetStepaside: string; /** * CBET source ID to use in the watermark. */ csid: string; } interface ChannelEncoderSettingsAudioDescriptionAudioWatermarkSettingsNielsenWatermarksSettingsNielsenNaesIiNwSetting { checkDigitString: string; /** * The Nielsen Source ID to include in the watermark. */ sid: number; } interface ChannelEncoderSettingsAudioDescriptionCodecSettings { /** * Aac Settings. See AAC Settings for more details. */ aacSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsAacSettings; /** * Ac3 Settings. See AC3 Settings for more details. */ ac3Settings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsAc3Settings; /** * Eac3 Atmos Settings. See EAC3 Atmos Settings */ eac3AtmosSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsEac3AtmosSettings; /** * Eac3 Settings. See EAC3 Settings */ eac3Settings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsEac3Settings; mp2Settings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsMp2Settings; passThroughSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsPassThroughSettings; wavSettings?: outputs.medialive.ChannelEncoderSettingsAudioDescriptionCodecSettingsWavSettings; } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsAacSettings { /** * Average bitrate in bits/second. */ bitrate: number; /** * Mono, Stereo, or 5.1 channel layout. */ codingMode: string; /** * Set to "broadcasterMixedAd" when input contains pre-mixed main audio + AD (narration) as a stereo pair. */ inputType: string; /** * AAC profile. */ profile: string; /** * The rate control mode. */ rateControlMode: string; /** * Sets LATM/LOAS AAC output for raw containers. */ rawFormat: string; /** * Sample rate in Hz. */ sampleRate: number; /** * Use MPEG-2 AAC audio instead of MPEG-4 AAC audio for raw or MPEG-2 Transport Stream containers. */ spec: string; /** * VBR Quality Level - Only used if rateControlMode is VBR. */ vbrQuality: string; } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsAc3Settings { /** * Average bitrate in bits/second. */ bitrate: number; /** * Specifies the bitstream mode (bsmod) for the emitted AC-3 stream. */ bitstreamMode: string; /** * Dolby Digital coding mode. */ codingMode: string; /** * Sets the dialnorm of the output. */ dialnorm: number; /** * If set to filmStandard, adds dynamic range compression signaling to the output bitstream as defined in the Dolby Digital specification. */ drcProfile: string; /** * When set to enabled, applies a 120Hz lowpass filter to the LFE channel prior to encoding. */ lfeFilter: string; /** * Metadata control. */ metadataControl: string; } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsEac3AtmosSettings { /** * Average bitrate in bits/second. */ bitrate: number; /** * Dolby Digital Plus with Dolby Atmos coding mode. */ codingMode: string; /** * Sets the dialnorm for the output. */ dialnorm: number; /** * Sets the Dolby dynamic range compression profile. */ drcLine: string; /** * Sets the profile for heavy Dolby dynamic range compression. */ drcRf: string; /** * Height dimensional trim. */ heightTrim: number; /** * Surround dimensional trim. */ surroundTrim: number; } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsEac3Settings { /** * Sets the attenuation control. */ attenuationControl: string; /** * Average bitrate in bits/second. */ bitrate: number; /** * Specifies the bitstream mode (bsmod) for the emitted AC-3 stream. */ bitstreamMode: string; /** * Dolby Digital Plus coding mode. */ codingMode: string; dcFilter: string; dialnorm: number; /** * Sets the Dolby dynamic range compression profile. */ drcLine: string; /** * Sets the profile for heavy Dolby dynamic range compression. */ drcRf: string; lfeControl: string; /** * When set to enabled, applies a 120Hz lowpass filter to the LFE channel prior to encoding. */ lfeFilter: string; loRoCenterMixLevel: number; loRoSurroundMixLevel: number; ltRtCenterMixLevel: number; ltRtSurroundMixLevel: number; /** * Metadata control. */ metadataControl: string; passthroughControl: string; phaseControl: string; stereoDownmix: string; surroundExMode: string; surroundMode: string; } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsMp2Settings { bitrate: number; codingMode: string; /** * Sample rate in Hz. */ sampleRate: number; } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsPassThroughSettings { } interface ChannelEncoderSettingsAudioDescriptionCodecSettingsWavSettings { bitDepth: number; codingMode: string; /** * Sample rate in Hz. */ sampleRate: number; } interface ChannelEncoderSettingsAudioDescriptionRemixSettings { channelMappings: outputs.medialive.ChannelEncoderSettingsAudioDescriptionRemixSettingsChannelMapping[]; channelsIn: number; channelsOut: number; } interface ChannelEncoderSettingsAudioDescriptionRemixSettingsChannelMapping { inputChannelLevels: outputs.medialive.ChannelEncoderSettingsAudioDescriptionRemixSettingsChannelMappingInputChannelLevel[]; outputChannel: number; } interface ChannelEncoderSettingsAudioDescriptionRemixSettingsChannelMappingInputChannelLevel { gain: number; inputChannel: number; } interface ChannelEncoderSettingsAvailBlanking { /** * Blanking image to be used. See Avail Blanking Image for more details. */ availBlankingImage?: outputs.medialive.ChannelEncoderSettingsAvailBlankingAvailBlankingImage; /** * When set to enabled, causes video, audio and captions to be blanked when insertion metadata is added. */ state: string; } interface ChannelEncoderSettingsAvailBlankingAvailBlankingImage { /** * Key used to extract the password from EC2 Parameter store. */ passwordParam: string; /** * Path to a file accessible to the live stream. */ uri: string; /** * . Username to be used. */ username: string; } interface ChannelEncoderSettingsCaptionDescription { /** * Indicates whether the caption track implements accessibility features such as written descriptions of spoken dialog, music, and sounds. */ accessibility?: string; /** * Specifies which input caption selector to use as a caption source when generating output captions. This field should match a captionSelector name. */ captionSelectorName: string; /** * Additional settings for captions destination that depend on the destination type. See Destination Settings for more details. */ destinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettings; /** * ISO 639-2 three-digit code. */ languageCode?: string; /** * Human readable information to indicate captions available for players (eg. English, or Spanish). */ languageDescription?: string; /** * Name of the caption description. Used to associate a caption description with an output. Names must be unique within an event. */ name: string; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettings { /** * ARIB Destination Settings. */ aribDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsAribDestinationSettings; /** * Burn In Destination Settings. See Burn In Destination Settings for more details. */ burnInDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsBurnInDestinationSettings; /** * DVB Sub Destination Settings. See DVB Sub Destination Settings for more details. */ dvbSubDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsDvbSubDestinationSettings; /** * EBU TT D Destination Settings. See EBU TT D Destination Settings for more details. */ ebuTtDDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsEbuTtDDestinationSettings; /** * Embedded Destination Settings. */ embeddedDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsEmbeddedDestinationSettings; /** * Embedded Plus SCTE20 Destination Settings. */ embeddedPlusScte20DestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsEmbeddedPlusScte20DestinationSettings; /** * RTMP Caption Info Destination Settings. */ rtmpCaptionInfoDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsRtmpCaptionInfoDestinationSettings; /** * SCTE20 Plus Embedded Destination Settings. */ scte20PlusEmbeddedDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsScte20PlusEmbeddedDestinationSettings; /** * SCTE27 Destination Settings. */ scte27DestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsScte27DestinationSettings; /** * SMPTE TT Destination Settings. */ smpteTtDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsSmpteTtDestinationSettings; /** * Teletext Destination Settings. */ teletextDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsTeletextDestinationSettings; /** * TTML Destination Settings. See TTML Destination Settings for more details. */ ttmlDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsTtmlDestinationSettings; /** * WebVTT Destination Settings. See WebVTT Destination Settings for more details. */ webvttDestinationSettings?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsWebvttDestinationSettings; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsAribDestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsBurnInDestinationSettings { /** * If no explicit xPosition or yPosition is provided, setting alignment to centered will place the captions at the bottom center of the output. Similarly, setting a left alignment will align captions to the bottom left of the output. If x and y positions are given in conjunction with the alignment parameter, the font will be justified (either left or centered) relative to those coordinates. Selecting “smart” justification will left-justify live subtitles and center-justify pre-recorded subtitles. All burn-in and DVB-Sub font settings must match. */ alignment?: string; /** * Specifies the color of the rectangle behind the captions. All burn-in and DVB-Sub font settings must match. */ backgroundColor?: string; /** * Specifies the opacity of the background rectangle. 255 is opaque; 0 is transparent. Leaving this parameter out is equivalent to setting it to 0 (transparent). All burn-in and DVB-Sub font settings must match. */ backgroundOpacity?: number; /** * External font file used for caption burn-in. File extension must be ‘ttf’ or ‘tte’. Although the user can select output fonts for many different types of input captions, embedded, STL and teletext sources use a strict grid system. Using external fonts with these caption sources could cause unexpected display of proportional fonts. All burn-in and DVB-Sub font settings must match. See Font for more details. */ font?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsBurnInDestinationSettingsFont; /** * Specifies the color of the burned-in captions. This option is not valid for source captions that are STL, 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ fontColor?: string; /** * Specifies the opacity of the burned-in captions. 255 is opaque; 0 is transparent. All burn-in and DVB-Sub font settings must match. */ fontOpacity?: number; /** * Font resolution in DPI (dots per inch); default is 96 dpi. All burn-in and DVB-Sub font settings must match. */ fontResolution?: number; /** * When set to ‘auto’ fontSize will scale depending on the size of the output. Giving a positive integer will specify the exact font size in points. All burn-in and DVB-Sub font settings must match. */ fontSize?: string; /** * Specifies font outline color. This option is not valid for source captions that are either 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ outlineColor: string; /** * Specifies font outline size in pixels. This option is not valid for source captions that are either 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ outlineSize?: number; /** * Specifies the color of the shadow cast by the captions. All burn-in and DVB-Sub font settings must match. */ shadowColor?: string; /** * Specifies the opacity of the shadow. 255 is opaque; 0 is transparent. Leaving this parameter out is equivalent to setting it to 0 (transparent). All burn-in and DVB-Sub font settings must match. */ shadowOpacity?: number; /** * Specifies the horizontal offset of the shadow relative to the captions in pixels. A value of -2 would result in a shadow offset 2 pixels to the left. All burn-in and DVB-Sub font settings must match. */ shadowXOffset?: number; /** * Specifies the vertical offset of the shadow relative to the captions in pixels. A value of -2 would result in a shadow offset 2 pixels above the text. All burn-in and DVB-Sub font settings must match. */ shadowYOffset?: number; /** * Controls whether a fixed grid size will be used to generate the output subtitles bitmap. Only applicable for Teletext inputs and DVB-Sub/Burn-in outputs. */ teletextGridControl: string; /** * Specifies the horizontal position of the caption relative to the left side of the output in pixels. A value of 10 would result in the captions starting 10 pixels from the left of the output. If no explicit xPosition is provided, the horizontal caption position will be determined by the alignment parameter. All burn-in and DVB-Sub font settings must match. */ xPosition?: number; /** * Specifies the vertical position of the caption relative to the top of the output in pixels. A value of 10 would result in the captions starting 10 pixels from the top of the output. If no explicit yPosition is provided, the caption will be positioned towards the bottom of the output. All burn-in and DVB-Sub font settings must match. */ yPosition?: number; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsBurnInDestinationSettingsFont { /** * Key used to extract the password from EC2 Parameter store. */ passwordParam: string; /** * Path to a file accessible to the live stream. */ uri: string; /** * Username to be used. */ username: string; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsDvbSubDestinationSettings { /** * If no explicit xPosition or yPosition is provided, setting alignment to centered will place the captions at the bottom center of the output. Similarly, setting a left alignment will align captions to the bottom left of the output. If x and y positions are given in conjunction with the alignment parameter, the font will be justified (either left or centered) relative to those coordinates. Selecting “smart” justification will left-justify live subtitles and center-justify pre-recorded subtitles. This option is not valid for source captions that are STL or 608/embedded. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ alignment?: string; /** * Specifies the color of the rectangle behind the captions. All burn-in and DVB-Sub font settings must match. */ backgroundColor?: string; /** * Specifies the opacity of the background rectangle. 255 is opaque; 0 is transparent. Leaving this parameter blank is equivalent to setting it to 0 (transparent). All burn-in and DVB-Sub font settings must match. */ backgroundOpacity?: number; /** * External font file used for caption burn-in. File extension must be ‘ttf’ or ‘tte’. Although the user can select output fonts for many different types of input captions, embedded, STL and teletext sources use a strict grid system. Using external fonts with these caption sources could cause unexpected display of proportional fonts. All burn-in and DVB-Sub font settings must match. See Font for more details. */ font?: outputs.medialive.ChannelEncoderSettingsCaptionDescriptionDestinationSettingsDvbSubDestinationSettingsFont; /** * Specifies the color of the burned-in captions. This option is not valid for source captions that are STL, 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ fontColor?: string; /** * Specifies the opacity of the burned-in captions. 255 is opaque; 0 is transparent. All burn-in and DVB-Sub font settings must match. */ fontOpacity?: number; /** * Font resolution in DPI (dots per inch); default is 96 dpi. All burn-in and DVB-Sub font settings must match. */ fontResolution?: number; /** * When set to auto fontSize will scale depending on the size of the output. Giving a positive integer will specify the exact font size in points. All burn-in and DVB-Sub font settings must match. */ fontSize: string; /** * Specifies font outline color. This option is not valid for source captions that are either 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ outlineColor?: string; /** * Specifies font outline size in pixels. This option is not valid for source captions that are either 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ outlineSize?: number; /** * Specifies the color of the shadow cast by the captions. All burn-in and DVB-Sub font settings must match. */ shadowColor?: string; /** * Specifies the opacity of the shadow. 255 is opaque; 0 is transparent. Leaving this parameter blank is equivalent to setting it to 0 (transparent). All burn-in and DVB-Sub font settings must match. */ shadowOpacity?: number; /** * Specifies the horizontal offset of the shadow relative to the captions in pixels. A value of -2 would result in a shadow offset 2 pixels to the left. All burn-in and DVB-Sub font settings must match. */ shadowXOffset?: number; /** * Specifies the vertical offset of the shadow relative to the captions in pixels. A value of -2 would result in a shadow offset 2 pixels above the text. All burn-in and DVB-Sub font settings must match. */ shadowYOffset?: number; /** * Controls whether a fixed grid size will be used to generate the output subtitles bitmap. Only applicable for Teletext inputs and DVB-Sub/Burn-in outputs. */ teletextGridControl?: string; /** * Specifies the horizontal position of the caption relative to the left side of the output in pixels. A value of 10 would result in the captions starting 10 pixels from the left of the output. If no explicit xPosition is provided, the horizontal caption position will be determined by the alignment parameter. This option is not valid for source captions that are STL, 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ xPosition?: number; /** * Specifies the vertical position of the caption relative to the top of the output in pixels. A value of 10 would result in the captions starting 10 pixels from the top of the output. If no explicit yPosition is provided, the caption will be positioned towards the bottom of the output. This option is not valid for source captions that are STL, 608/embedded or teletext. These source settings are already pre-defined by the caption stream. All burn-in and DVB-Sub font settings must match. */ yPosition?: number; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsDvbSubDestinationSettingsFont { /** * Key used to extract the password from EC2 Parameter store. */ passwordParam: string; /** * Path to a file accessible to the live stream. */ uri: string; /** * Username to be used. */ username: string; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsEbuTtDDestinationSettings { /** * Complete this field if you want to include the name of the copyright holder in the copyright tag in the captions metadata. */ copyrightHolder?: string; /** * Specifies how to handle the gap between the lines (in multi-line captions). - enabled: Fill with the captions background color (as specified in the input captions). - disabled: Leave the gap unfilled. */ fillLineGap?: string; /** * Specifies the font family to include in the font data attached to the EBU-TT captions. Valid only if styleControl is set to include. If you leave this field empty, the font family is set to “monospaced”. (If styleControl is set to exclude, the font family is always set to “monospaced”.) You specify only the font family. All other style information (color, bold, position and so on) is copied from the input captions. The size is always set to 100% to allow the downstream player to choose the size. - Enter a list of font families, as a comma-separated list of font names, in order of preference. The name can be a font family (such as “Arial”), or a generic font family (such as “serif”), or “default” (to let the downstream player choose the font). - Leave blank to set the family to “monospace”. */ fontFamily?: string; /** * Specifies the style information (font color, font position, and so on) to include in the font data that is attached to the EBU-TT captions. - include: Take the style information (font color, font position, and so on) from the source captions and include that information in the font data attached to the EBU-TT captions. This option is valid only if the source captions are Embedded or Teletext. - exclude: In the font data attached to the EBU-TT captions, set the font family to “monospaced”. Do not include any other style information. */ styleControl: string; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsEmbeddedDestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsEmbeddedPlusScte20DestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsRtmpCaptionInfoDestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsScte20PlusEmbeddedDestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsScte27DestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsSmpteTtDestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsTeletextDestinationSettings { } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsTtmlDestinationSettings { /** * This field is not currently supported and will not affect the output styling. Leave the default value. */ styleControl: string; } interface ChannelEncoderSettingsCaptionDescriptionDestinationSettingsWebvttDestinationSettings { /** * Controls whether the color and position of the source captions is passed through to the WebVTT output captions. PASSTHROUGH - Valid only if the source captions are EMBEDDED or TELETEXT. NO\_STYLE\_DATA - Don’t pass through the style. The output captions will not contain any font styling information. */ styleControl: string; } interface ChannelEncoderSettingsGlobalConfiguration { /** * Value to set the initial audio gain for the Live Event. */ initialAudioGain?: number; /** * Indicates the action to take when the current input completes (e.g. end-of-file). When switchAndLoopInputs is configured the encoder will restart at the beginning of the first input. When “none” is configured the encoder will transcode either black, a solid color, or a user specified slate images per the “Input Loss Behavior” configuration until the next input switch occurs (which is controlled through the Channel Schedule API). */ inputEndAction?: string; /** * Settings for system actions when input is lost. See Input Loss Behavior for more details. */ inputLossBehavior?: outputs.medialive.ChannelEncoderSettingsGlobalConfigurationInputLossBehavior; /** * Indicates how MediaLive pipelines are synchronized. PIPELINE\_LOCKING - MediaLive will attempt to synchronize the output of each pipeline to the other. EPOCH\_LOCKING - MediaLive will attempt to synchronize the output of each pipeline to the Unix epoch. */ outputLockingMode?: string; /** * Indicates whether the rate of frames emitted by the Live encoder should be paced by its system clock (which optionally may be locked to another source via NTP) or should be locked to the clock of the source that is providing the input stream. */ outputTimingSource?: string; /** * Adjusts video input buffer for streams with very low video framerates. This is commonly set to enabled for music channels with less than one video frame per second. */ supportLowFramerateInputs?: string; } interface ChannelEncoderSettingsGlobalConfigurationInputLossBehavior { blackFrameMsec?: number; inputLossImageColor?: string; inputLossImageSlate?: outputs.medialive.ChannelEncoderSettingsGlobalConfigurationInputLossBehaviorInputLossImageSlate; inputLossImageType?: string; repeatFrameMsec?: number; } interface ChannelEncoderSettingsGlobalConfigurationInputLossBehaviorInputLossImageSlate { passwordParam: string; uri: string; username: string; } interface ChannelEncoderSettingsMotionGraphicsConfiguration { /** * Motion Graphics Insertion. */ motionGraphicsInsertion?: string; /** * Motion Graphics Settings. See Motion Graphics Settings for more details. */ motionGraphicsSettings: outputs.medialive.ChannelEncoderSettingsMotionGraphicsConfigurationMotionGraphicsSettings; } interface ChannelEncoderSettingsMotionGraphicsConfigurationMotionGraphicsSettings { /** * Html Motion Graphics Settings. */ htmlMotionGraphicsSettings?: outputs.medialive.ChannelEncoderSettingsMotionGraphicsConfigurationMotionGraphicsSettingsHtmlMotionGraphicsSettings; } interface ChannelEncoderSettingsMotionGraphicsConfigurationMotionGraphicsSettingsHtmlMotionGraphicsSettings { } interface ChannelEncoderSettingsNielsenConfiguration { /** * Enter the Distributor ID assigned to your organization by Nielsen. */ distributorId?: string; /** * Enables Nielsen PCM to ID3 tagging. */ nielsenPcmToId3Tagging?: string; } interface ChannelEncoderSettingsOutputGroup { /** * Custom output group name defined by the user. */ name?: string; /** * Settings associated with the output group. See Output Group Settings for more details. */ outputGroupSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettings; /** * List of outputs. See Outputs for more details. */ outputs: outputs.medialive.ChannelEncoderSettingsOutputGroupOutput[]; } interface ChannelEncoderSettingsOutputGroupOutput { /** * The names of the audio descriptions used as audio sources for the output. */ audioDescriptionNames?: string[]; /** * The names of the caption descriptions used as caption sources for the output. */ captionDescriptionNames: string[]; /** * The name used to identify an output. */ outputName?: string; /** * Settings for output. See Output Settings for more details. */ outputSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettings; /** * The name of the video description used as video source for the output. */ videoDescriptionName?: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettings { /** * Archive group settings. See Archive Group Settings for more details. */ archiveGroupSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSetting[]; frameCaptureGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettings; hlsGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettings; /** * Media package group settings. See Media Package Group Settings for more details. */ mediaPackageGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsMediaPackageGroupSettings; msSmoothGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsMsSmoothGroupSettings; multiplexGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsMultiplexGroupSettings; /** * RTMP group settings. See RTMP Group Settings for more details. */ rtmpGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsRtmpGroupSettings; udpGroupSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsUdpGroupSettings; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSetting { /** * Parameters that control the interactions with the CDN. See Archive CDN Settings for more details. */ archiveCdnSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSettingArchiveCdnSettings; /** * A director and base filename where archive files should be written. See Destination for more details. */ destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSettingDestination; /** * Number of seconds to write to archive file before closing and starting a new one. */ rolloverInterval?: number; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSettingArchiveCdnSettings { /** * Archive S3 Settings. See Archive S3 Settings for more details. */ archiveS3Settings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSettingArchiveCdnSettingsArchiveS3Settings; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSettingArchiveCdnSettingsArchiveS3Settings { /** * Specify the canned ACL to apply to each S3 request. */ cannedAcl?: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsArchiveGroupSettingDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettings { destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettingsDestination; frameCaptureCdnSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettingsFrameCaptureCdnSettings; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettingsFrameCaptureCdnSettings { frameCaptureS3Settings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettingsFrameCaptureCdnSettingsFrameCaptureS3Settings; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsFrameCaptureGroupSettingsFrameCaptureCdnSettingsFrameCaptureS3Settings { /** * Specify the canned ACL to apply to each S3 request. */ cannedAcl?: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettings { /** * The ad marker type for this output group. */ adMarkers: string[]; baseUrlContent: string; baseUrlContent1: string; baseUrlManifest: string; baseUrlManifest1: string; captionLanguageMappings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsCaptionLanguageMapping[]; captionLanguageSetting: string; clientCache: string; codecSpecification: string; constantIv: string; destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsDestination; directoryStructure: string; discontinuityTags: string; encryptionType: string; hlsCdnSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSetting[]; hlsId3SegmentTagging: string; iframeOnlyPlaylists: string; incompleteSegmentBehavior: string; indexNSegments: number; inputLossAction: string; ivInManifest: string; ivSource: string; keepSegments: number; keyFormat: string; keyFormatVersions: string; keyProviderSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsKeyProviderSettings; manifestCompression: string; manifestDurationFormat: string; minSegmentLength: number; mode: string; outputSelection: string; programDateTime: string; programDateTimeClock: string; programDateTimePeriod: number; redundantManifest: string; segmentLength: number; segmentsPerSubdirectory: number; streamInfResolution: string; /** * Indicates ID3 frame that has the timecode. */ timedMetadataId3Frame: string; timedMetadataId3Period: number; timestampDeltaMilliseconds: number; tsFileMode: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsCaptionLanguageMapping { captionChannel: number; languageCode: string; /** * Human readable information to indicate captions available for players (eg. English, or Spanish). */ languageDescription: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSetting { hlsAkamaiSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsAkamaiSettings; hlsBasicPutSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsBasicPutSettings; hlsMediaStoreSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsMediaStoreSettings; hlsS3Settings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsS3Settings; hlsWebdavSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsWebdavSettings; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsAkamaiSettings { /** * Number of seconds to wait before retrying connection to the flash media server if the connection is lost. */ connectionRetryInterval?: number; filecacheDuration?: number; httpTransferMode: string; /** * Number of retry attempts. */ numRetries?: number; /** * Number of seconds to wait until a restart is initiated. */ restartDelay?: number; salt: string; token: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsBasicPutSettings { /** * Number of seconds to wait before retrying connection to the flash media server if the connection is lost. */ connectionRetryInterval?: number; filecacheDuration?: number; /** * Number of retry attempts. */ numRetries?: number; /** * Number of seconds to wait until a restart is initiated. */ restartDelay?: number; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsMediaStoreSettings { /** * Number of seconds to wait before retrying connection to the flash media server if the connection is lost. */ connectionRetryInterval?: number; filecacheDuration?: number; mediaStoreStorageClass: string; /** * Number of retry attempts. */ numRetries?: number; /** * Number of seconds to wait until a restart is initiated. */ restartDelay?: number; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsS3Settings { /** * Specify the canned ACL to apply to each S3 request. */ cannedAcl?: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsHlsCdnSettingHlsWebdavSettings { /** * Number of seconds to wait before retrying connection to the flash media server if the connection is lost. */ connectionRetryInterval?: number; filecacheDuration?: number; httpTransferMode: string; /** * Number of retry attempts. */ numRetries?: number; /** * Number of seconds to wait until a restart is initiated. */ restartDelay?: number; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsKeyProviderSettings { staticKeySettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsKeyProviderSettingsStaticKeySetting[]; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsKeyProviderSettingsStaticKeySetting { keyProviderServer?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsKeyProviderSettingsStaticKeySettingKeyProviderServer; staticKeyValue: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsHlsGroupSettingsKeyProviderSettingsStaticKeySettingKeyProviderServer { passwordParam: string; uri: string; username: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsMediaPackageGroupSettings { /** * A director and base filename where archive files should be written. See Destination for more details. */ destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsMediaPackageGroupSettingsDestination; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsMediaPackageGroupSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsMsSmoothGroupSettings { acquisitionPointId: string; audioOnlyTimecodeControl: string; /** * Setting to allow self signed or verified RTMP certificates. */ certificateMode: string; /** * Number of seconds to wait before retrying connection to the flash media server if the connection is lost. */ connectionRetryInterval: number; destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputGroupSettingsMsSmoothGroupSettingsDestination; eventId: string; eventIdMode: string; eventStopBehavior: string; filecacheDuration?: number; fragmentLength: number; inputLossAction: string; /** * Number of retry attempts. */ numRetries?: number; /** * Number of seconds to wait until a restart is initiated. */ restartDelay?: number; segmentationMode: string; sendDelayMs: number; sparseTrackType: string; streamManifestBehavior: string; timestampOffset: string; timestampOffsetMode: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsMsSmoothGroupSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsMultiplexGroupSettings { } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsRtmpGroupSettings { /** * The ad marker type for this output group. */ adMarkers?: string[]; /** * Authentication scheme to use when connecting with CDN. */ authenticationScheme: string; /** * Controls behavior when content cache fills up. */ cacheFullBehavior: string; /** * Cache length in seconds, is used to calculate buffer size. */ cacheLength: number; /** * Controls the types of data that passes to onCaptionInfo outputs. */ captionData: string; /** * Controls the behavior of the RTMP group if input becomes unavailable. */ inputLossAction: string; /** * Number of seconds to wait until a restart is initiated. */ restartDelay?: number; } interface ChannelEncoderSettingsOutputGroupOutputGroupSettingsUdpGroupSettings { /** * Specifies behavior of last resort when input video os lost. */ inputLossAction: string; /** * Indicates ID3 frame that has the timecode. */ timedMetadataId3Frame: string; timedMetadataId3Period: number; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettings { /** * Archive output settings. See Archive Output Settings for more details. */ archiveOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettings; frameCaptureOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsFrameCaptureOutputSettings; hlsOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettings; /** * Media package output settings. This can be set as an empty block. */ mediaPackageOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsMediaPackageOutputSettings; msSmoothOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsMsSmoothOutputSettings; /** * Multiplex output settings. See Multiplex Output Settings for more details. */ multiplexOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsMultiplexOutputSettings; /** * RTMP output settings. See RTMP Output Settings for more details. */ rtmpOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsRtmpOutputSettings; /** * UDP output settings. See UDP Output Settings for more details. */ udpOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettings; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettings { /** * Settings specific to the container type of the file. See Container Settings for more details. */ containerSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettings; /** * Output file extension. */ extension?: string; /** * String concatenated to the end of the destination filename. Required for multiple outputs of the same type. */ nameModifier?: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettings { /** * M2TS Settings. See [M2TS Settings](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-medialive-channel-m2tssettings.html) for more details. */ m2tsSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettings; /** * Raw Settings. This can be set as an empty block. */ rawSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsRawSettings; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettings { absentInputAudioBehavior: string; arib?: string; aribCaptionsPid: string; aribCaptionsPidControl?: string; audioBufferModel?: string; audioFramesPerPes?: number; audioPids: string; audioStreamType?: string; bitrate?: number; bufferModel?: string; ccDescriptor?: string; dvbNitSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettingsDvbNitSettings; dvbSdtSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettingsDvbSdtSettings; dvbSubPids: string; dvbTdtSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettingsDvbTdtSettings; dvbTeletextPid: string; ebif?: string; ebpAudioInterval?: string; ebpLookaheadMs?: number; ebpPlacement?: string; ecmPid?: string; esRateInPes?: string; etvPlatformPid: string; etvSignalPid: string; fragmentTime?: number; klv?: string; klvDataPids: string; nielsenId3Behavior?: string; nullPacketBitrate?: number; patInterval?: number; pcrControl?: string; pcrPeriod?: number; pcrPid?: string; pmtInterval?: number; pmtPid: string; programNum?: number; rateMode?: string; scte27Pids: string; scte35Control?: string; /** * PID from which to read SCTE-35 messages. */ scte35Pid: string; segmentationMarkers?: string; segmentationStyle?: string; segmentationTime?: number; timedMetadataBehavior?: string; timedMetadataPid: string; transportStreamId?: number; videoPid: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettingsDvbNitSettings { networkId: number; networkName: string; repInterval?: number; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettingsDvbSdtSettings { outputSdt?: string; repInterval?: number; serviceName?: string; serviceProviderName?: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsM2tsSettingsDvbTdtSettings { repInterval?: number; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsArchiveOutputSettingsContainerSettingsRawSettings { } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsFrameCaptureOutputSettings { /** * String concatenated to the end of the destination filename. Required for multiple outputs of the same type. */ nameModifier: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettings { h265PackagingType: string; hlsSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettings; /** * String concatenated to the end of the destination filename. Required for multiple outputs of the same type. */ nameModifier: string; segmentModifier: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettings { audioOnlyHlsSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsAudioOnlyHlsSettings; fmp4HlsSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsFmp4HlsSettings; frameCaptureHlsSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsFrameCaptureHlsSettings; standardHlsSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsStandardHlsSettings; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsAudioOnlyHlsSettings { audioGroupId: string; audioOnlyImage?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsAudioOnlyHlsSettingsAudioOnlyImage; audioTrackType: string; segmentType: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsAudioOnlyHlsSettingsAudioOnlyImage { passwordParam: string; uri: string; username: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsFmp4HlsSettings { audioRenditionSets: string; nielsenId3Behavior: string; timedMetadataBehavior: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsFrameCaptureHlsSettings { } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsStandardHlsSettings { audioRenditionSets: string; m3u8Settings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsStandardHlsSettingsM3u8Settings; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsHlsOutputSettingsHlsSettingsStandardHlsSettingsM3u8Settings { audioFramesPerPes: number; audioPids: string; ecmPid: string; nielsenId3Behavior: string; patInterval: number; pcrControl: string; pcrPeriod: number; pcrPid: string; pmtInterval: number; pmtPid: string; programNum: number; scte35Behavior: string; /** * PID from which to read SCTE-35 messages. */ scte35Pid: string; timedMetadataBehavior: string; timedMetadataPid: string; transportStreamId: number; videoPid: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsMediaPackageOutputSettings { } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsMsSmoothOutputSettings { h265PackagingType: string; /** * String concatenated to the end of the destination filename. Required for multiple outputs of the same type. */ nameModifier: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsMultiplexOutputSettings { /** * Destination is a multiplex. See Destination for more details. */ destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsMultiplexOutputSettingsDestination; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsMultiplexOutputSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsRtmpOutputSettings { /** * Setting to allow self signed or verified RTMP certificates. */ certificateMode: string; /** * Number of seconds to wait before retrying connection to the flash media server if the connection is lost. */ connectionRetryInterval: number; /** * The RTMP endpoint excluding the stream name. See Destination for more details. */ destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsRtmpOutputSettingsDestination; /** * Number of retry attempts. */ numRetries: number; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsRtmpOutputSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettings { /** * UDP output buffering in milliseconds. */ bufferMsec: number; /** * UDP container settings. See Container Settings for more details. */ containerSettings: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettings; /** * Destination address and port number for RTP or UDP packets. See Destination for more details. */ destination: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsDestination; fecOutputSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsFecOutputSettings; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettings { /** * M2TS Settings. See [M2TS Settings](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-medialive-channel-m2tssettings.html) for more details. */ m2tsSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettings; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettings { absentInputAudioBehavior: string; arib?: string; aribCaptionsPid: string; aribCaptionsPidControl?: string; audioBufferModel?: string; audioFramesPerPes?: number; audioPids: string; audioStreamType?: string; bitrate?: number; bufferModel?: string; ccDescriptor?: string; dvbNitSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettingsDvbNitSettings; dvbSdtSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettingsDvbSdtSettings; dvbSubPids: string; dvbTdtSettings?: outputs.medialive.ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettingsDvbTdtSettings; dvbTeletextPid: string; ebif?: string; ebpAudioInterval?: string; ebpLookaheadMs?: number; ebpPlacement?: string; ecmPid?: string; esRateInPes?: string; etvPlatformPid: string; etvSignalPid: string; fragmentTime?: number; klv?: string; klvDataPids: string; nielsenId3Behavior?: string; nullPacketBitrate?: number; patInterval?: number; pcrControl?: string; pcrPeriod?: number; pcrPid?: string; pmtInterval?: number; pmtPid: string; programNum?: number; rateMode?: string; scte27Pids: string; scte35Control?: string; /** * PID from which to read SCTE-35 messages. */ scte35Pid: string; segmentationMarkers?: string; segmentationStyle?: string; segmentationTime?: number; timedMetadataBehavior?: string; timedMetadataPid: string; transportStreamId?: number; videoPid: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettingsDvbNitSettings { networkId: number; networkName: string; repInterval?: number; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettingsDvbSdtSettings { outputSdt?: string; repInterval?: number; serviceName?: string; serviceProviderName?: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsContainerSettingsM2tsSettingsDvbTdtSettings { repInterval?: number; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsDestination { /** * Reference ID for the destination. */ destinationRefId: string; } interface ChannelEncoderSettingsOutputGroupOutputOutputSettingsUdpOutputSettingsFecOutputSettings { /** * The height of the FEC protection matrix. */ columnDepth: number; /** * Enables column only or column and row based FEC. */ includeFec: string; /** * The width of the FEC protection matrix. */ rowLength: number; } interface ChannelEncoderSettingsTimecodeConfig { /** * The source for the timecode that will be associated with the events outputs. */ source: string; /** * Threshold in frames beyond which output timecode is resynchronized to the input timecode. */ syncThreshold: number; } interface ChannelEncoderSettingsVideoDescription { /** * The video codec settings. See Video Codec Settings for more details. */ codecSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettings; /** * Output video height in pixels. */ height: number; /** * The name of the video description. */ name: string; /** * Indicate how to respond to the AFD values that might be in the input video. */ respondToAfd: string; /** * Behavior on how to scale. */ scalingBehavior: string; /** * Changes the strength of the anti-alias filter used for scaling. */ sharpness: number; /** * Output video width in pixels. */ width: number; } interface ChannelEncoderSettingsVideoDescriptionCodecSettings { /** * Frame capture settings. See Frame Capture Settings for more details. */ frameCaptureSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsFrameCaptureSettings; /** * H264 settings. See H264 Settings for more details. */ h264Settings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH264Settings; h265Settings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265Settings; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsFrameCaptureSettings { /** * The frequency at which to capture frames for inclusion in the output. */ captureInterval: number; /** * Unit for the frame capture interval. */ captureIntervalUnits: string; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH264Settings { /** * Enables or disables adaptive quantization. */ adaptiveQuantization: string; /** * Indicates that AFD values will be written into the output stream. */ afdSignaling: string; /** * Average bitrate in bits/second. */ bitrate: number; bufFillPct: number; /** * Size of buffer in bits. */ bufSize: number; /** * Includes color space metadata in the output. */ colorMetadata: string; /** * Entropy encoding mode. */ entropyEncoding: string; /** * Filters to apply to an encode. See H264 Filter Settings for more details. */ filterSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH264SettingsFilterSettings; /** * Four bit AFD value to write on all frames of video in the output stream. */ fixedAfd: string; flickerAq: string; /** * Controls whether coding is performed on a field basis or on a frame basis. */ forceFieldPictures: string; /** * Indicates how the output video frame rate is specified. */ framerateControl: string; /** * Framerate denominator. */ framerateDenominator: number; /** * Framerate numerator. */ framerateNumerator: number; /** * GOP-B reference. */ gopBReference: string; /** * Frequency of closed GOPs. */ gopClosedCadence: number; /** * Number of B-frames between reference frames. */ gopNumBFrames: number; /** * GOP size in units of either frames of seconds per `gopSizeUnits`. */ gopSize: number; /** * Indicates if the `gopSize` is specified in frames or seconds. */ gopSizeUnits: string; /** * H264 level. */ level: string; /** * Amount of lookahead. */ lookAheadRateControl: string; /** * Set the maximum bitrate in order to accommodate expected spikes in the complexity of the video. */ maxBitrate: number; /** * Min interval. */ minIInterval: number; /** * Number of reference frames to use. */ numRefFrames: number; /** * Indicates how the output pixel aspect ratio is specified. */ parControl: string; /** * Pixel Aspect Ratio denominator. */ parDenominator: number; /** * Pixel Aspect Ratio numerator. */ parNumerator: number; /** * H264 profile. */ profile: string; /** * Quality level. */ qualityLevel: string; /** * Controls the target quality for the video encode. */ qvbrQualityLevel: number; /** * Rate control mode. */ rateControlMode: string; /** * Sets the scan type of the output. */ scanType: string; /** * Scene change detection. */ sceneChangeDetect: string; /** * Number of slices per picture. */ slices: number; /** * Softness. */ softness: number; /** * Makes adjustments within each frame based on spatial variation of content complexity. */ spatialAq: string; /** * Subgop length. */ subgopLength: string; /** * Produces a bitstream compliant with SMPTE RP-2027. */ syntax: string; /** * Makes adjustments within each frame based on temporal variation of content complexity. */ temporalAq: string; /** * Determines how timecodes should be inserted into the video elementary stream. */ timecodeInsertion: string; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH264SettingsFilterSettings { temporalFilterSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH264SettingsFilterSettingsTemporalFilterSettings; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH264SettingsFilterSettingsTemporalFilterSettings { /** * Post filter sharpening. */ postFilterSharpening?: string; /** * Filter strength. */ strength?: string; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265Settings { /** * Enables or disables adaptive quantization. */ adaptiveQuantization: string; /** * Indicates that AFD values will be written into the output stream. */ afdSignaling: string; /** * Whether or not EML should insert an Alternative Transfer Function SEI message. */ alternativeTransferFunction: string; /** * Average bitrate in bits/second. */ bitrate: number; /** * Size of buffer in bits. */ bufSize?: number; /** * Includes color space metadata in the output. */ colorMetadata: string; /** * Define the color metadata for the output. H265 Color Space Settings for more details. */ colorSpaceSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettings; /** * Filters to apply to an encode. See H265 Filter Settings for more details. */ filterSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsFilterSettings; /** * Four bit AFD value to write on all frames of video in the output stream. */ fixedAfd: string; flickerAq: string; /** * Framerate denominator. */ framerateDenominator: number; /** * Framerate numerator. */ framerateNumerator: number; /** * Frequency of closed GOPs. */ gopClosedCadence?: number; /** * GOP size in units of either frames of seconds per `gopSizeUnits`. */ gopSize?: number; /** * Indicates if the `gopSize` is specified in frames or seconds. */ gopSizeUnits: string; /** * H265 level. */ level: string; /** * Amount of lookahead. */ lookAheadRateControl: string; /** * Set the maximum bitrate in order to accommodate expected spikes in the complexity of the video. */ maxBitrate?: number; /** * Min interval. */ minIInterval?: number; /** * Set the minimum QP. */ minQp?: number; /** * Enables or disables motion vector over picture boundaries. */ mvOverPictureBoundaries: string; /** * Enables or disables the motion vector temporal predictor. */ mvTemporalPredictor: string; /** * Pixel Aspect Ratio denominator. */ parDenominator?: number; /** * Pixel Aspect Ratio numerator. */ parNumerator?: number; /** * H265 profile. */ profile: string; /** * Controls the target quality for the video encode. */ qvbrQualityLevel?: number; /** * Rate control mode. */ rateControlMode: string; /** * Sets the scan type of the output. */ scanType: string; /** * Scene change detection. */ sceneChangeDetect: string; /** * Number of slices per picture. */ slices?: number; /** * Set the H265 tier in the output. */ tier: string; /** * Sets the height of tiles. */ tileHeight?: number; /** * Enables or disables padding of tiles. */ tilePadding: string; /** * Sets the width of tiles. */ tileWidth?: number; /** * Apply a burned in timecode. See H265 Timecode Burnin Settings for more details. */ timecodeBurninSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsTimecodeBurninSettings; /** * Determines how timecodes should be inserted into the video elementary stream. */ timecodeInsertion: string; /** * Sets the size of the treeblock. */ treeblockSize: string; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettings { /** * Sets the colorspace metadata to be passed through. */ colorSpacePassthroughSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsColorSpacePassthroughSettings; /** * Set the colorspace to Dolby Vision81. */ dolbyVision81Settings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsDolbyVision81Settings; /** * Set the colorspace to be HDR10. See H265 HDR10 Settings for more details. */ hdr10Settings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsHdr10Settings; /** * Set the colorspace to Rec. 601. */ rec601Settings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsRec601Settings; /** * Set the colorspace to Rec. 709. */ rec709Settings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsRec709Settings; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsColorSpacePassthroughSettings { } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsDolbyVision81Settings { } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsHdr10Settings { /** * Sets the MaxCLL value for HDR10. */ maxCll?: number; /** * Sets the MaxFALL value for HDR10. */ maxFall?: number; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsRec601Settings { } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsColorSpaceSettingsRec709Settings { } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsFilterSettings { temporalFilterSettings?: outputs.medialive.ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsFilterSettingsTemporalFilterSettings; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsFilterSettingsTemporalFilterSettings { /** * Post filter sharpening. */ postFilterSharpening?: string; /** * Filter strength. */ strength?: string; } interface ChannelEncoderSettingsVideoDescriptionCodecSettingsH265SettingsTimecodeBurninSettings { /** * Set a prefix on the burned in timecode. */ prefix: string; /** * Sets the size of the burned in timecode. */ timecodeBurninFontSize: string; /** * Sets the position of the burned in timecode. */ timecodeBurninPosition: string; } interface ChannelInputAttachment { /** * User-specified settings for defining what the conditions are for declaring the input unhealthy and failing over to a different input. See Automatic Input Failover Settings for more details. */ automaticInputFailoverSettings?: outputs.medialive.ChannelInputAttachmentAutomaticInputFailoverSettings; /** * User-specified name for the attachment. */ inputAttachmentName: string; /** * The ID of the input. */ inputId: string; /** * Settings of an input. See Input Settings for more details. */ inputSettings: outputs.medialive.ChannelInputAttachmentInputSettings; } interface ChannelInputAttachmentAutomaticInputFailoverSettings { /** * This clear time defines the requirement a recovered input must meet to be considered healthy. The input must have no failover conditions for this length of time. Enter a time in milliseconds. This value is particularly important if the input\_preference for the failover pair is set to PRIMARY\_INPUT\_PREFERRED, because after this time, MediaLive will switch back to the primary input. */ errorClearTimeMsec?: number; /** * A list of failover conditions. If any of these conditions occur, MediaLive will perform a failover to the other input. See Failover Condition Block for more details. */ failoverConditions?: outputs.medialive.ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverCondition[]; /** * Input preference when deciding which input to make active when a previously failed input has recovered. */ inputPreference?: string; /** * The input ID of the secondary input in the automatic input failover pair. */ secondaryInputId: string; } interface ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverCondition { /** * Failover condition type-specific settings. See Failover Condition Settings for more details. */ failoverConditionSettings?: outputs.medialive.ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettings; } interface ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettings { /** * MediaLive will perform a failover if the specified audio selector is silent for the specified period. See Audio Silence Failover Settings for more details. */ audioSilenceSettings?: outputs.medialive.ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettingsAudioSilenceSettings; /** * MediaLive will perform a failover if content is not detected in this input for the specified period. See Input Loss Failover Settings for more details. */ inputLossSettings?: outputs.medialive.ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettingsInputLossSettings; /** * MediaLive will perform a failover if content is considered black for the specified period. See Video Black Failover Settings for more details. */ videoBlackSettings?: outputs.medialive.ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettingsVideoBlackSettings; } interface ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettingsAudioSilenceSettings { audioSelectorName: string; /** * The amount of time (in milliseconds) that the active input must be silent before automatic input failover occurs. Silence is defined as audio loss or audio quieter than -50 dBFS. */ audioSilenceThresholdMsec?: number; } interface ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettingsInputLossSettings { /** * The amount of time (in milliseconds) that no input is detected. After that time, an input failover will occur. */ inputLossThresholdMsec?: number; } interface ChannelInputAttachmentAutomaticInputFailoverSettingsFailoverConditionFailoverConditionSettingsVideoBlackSettings { /** * A value used in calculating the threshold below which MediaLive considers a pixel to be 'black'. For the input to be considered black, every pixel in a frame must be below this threshold. The threshold is calculated as a percentage (expressed as a decimal) of white. Therefore .1 means 10% white (or 90% black). Note how the formula works for any color depth. For example, if you set this field to 0.1 in 10-bit color depth: (10230.1=102.3), which means a pixel value of 102 or less is 'black'. If you set this field to .1 in an 8-bit color depth: (2550.1=25.5), which means a pixel value of 25 or less is 'black'. The range is 0.0 to 1.0, with any number of decimal places. */ blackDetectThreshold?: number; /** * The amount of time (in milliseconds) that the active input must be black before automatic input failover occurs. */ videoBlackThresholdMsec?: number; } interface ChannelInputAttachmentInputSettings { /** * Used to select the audio stream to decode for inputs that have multiple. See Audio Selectors for more details. */ audioSelectors?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelector[]; /** * Used to select the caption input to use for inputs that have multiple available. See Caption Selectors for more details. */ captionSelectors?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelector[]; /** * Enable or disable the deblock filter when filtering. */ deblockFilter?: string; /** * Enable or disable the denoise filter when filtering. */ denoiseFilter?: string; /** * Adjusts the magnitude of filtering from 1 (minimal) to 5 (strongest). */ filterStrength?: number; /** * Turns on the filter for the input. */ inputFilter: string; /** * Input settings. See Network Input Settings for more details. */ networkInputSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsNetworkInputSettings; /** * PID from which to read SCTE-35 messages. */ scte35Pid?: number; /** * Specifies whether to extract applicable ancillary data from a SMPTE-2038 source in the input. */ smpte2038DataPreference?: string; /** * Loop input if it is a file. */ sourceEndBehavior?: string; videoSelector?: outputs.medialive.ChannelInputAttachmentInputSettingsVideoSelector; } interface ChannelInputAttachmentInputSettingsAudioSelector { /** * Name of the Channel. * * The following arguments are optional: */ name: string; selectorSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettings; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettings { /** * Audio HLS Rendition Selection. See Audio HLS Rendition Selection for more details. */ audioHlsRenditionSelection?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioHlsRenditionSelection; /** * Audio Language Selection. See Audio Language Selection for more details. */ audioLanguageSelection?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioLanguageSelection; /** * Audio Pid Selection. See Audio PID Selection for more details. */ audioPidSelection?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioPidSelection; /** * Audio Track Selection. See Audio Track Selection for more details. */ audioTrackSelection?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioTrackSelection; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioHlsRenditionSelection { /** * Specifies the GROUP-ID in the #EXT-X-MEDIA tag of the target HLS audio rendition. */ groupId: string; /** * Specifies the NAME in the #EXT-X-MEDIA tag of the target HLS audio rendition. */ name: string; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioLanguageSelection { /** * Selects a specific three-letter language code from within an audio source. */ languageCode: string; /** * When set to “strict”, the transport stream demux strictly identifies audio streams by their language descriptor. If a PMT update occurs such that an audio stream matching the initially selected language is no longer present then mute will be encoded until the language returns. If “loose”, then on a PMT update the demux will choose another audio stream in the program with the same stream type if it can’t find one with the same language. */ languageSelectionPolicy?: string; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioPidSelection { /** * Selects a specific PID from within a source. */ pid: number; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioTrackSelection { /** * Configure decoding options for Dolby E streams - these should be Dolby E frames carried in PCM streams tagged with SMPTE-337. See Dolby E Decode for more details. */ dolbyEDecode?: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioTrackSelectionDolbyEDecode; /** * Selects one or more unique audio tracks from within a source. See Audio Tracks for more details. */ tracks: outputs.medialive.ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioTrackSelectionTrack[]; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioTrackSelectionDolbyEDecode { /** * Applies only to Dolby E. Enter the program ID (according to the metadata in the audio) of the Dolby E program to extract from the specified track. One program extracted per audio selector. To select multiple programs, create multiple selectors with the same Track and different Program numbers. “All channels” means to ignore the program IDs and include all the channels in this selector; useful if metadata is known to be incorrect. */ programSelection: string; } interface ChannelInputAttachmentInputSettingsAudioSelectorSelectorSettingsAudioTrackSelectionTrack { /** * 1-based integer value that maps to a specific audio track. */ track: number; } interface ChannelInputAttachmentInputSettingsCaptionSelector { languageCode?: string; /** * Name of the Channel. * * The following arguments are optional: */ name: string; selectorSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettings; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettings { /** * Ancillary Source Settings. See Ancillary Source Settings for more details. */ ancillarySourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsAncillarySourceSettings; /** * ARIB Source Settings. */ aribSourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsAribSourceSettings; /** * DVB Sub Source Settings. See DVB Sub Source Settings for more details. */ dvbSubSourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsDvbSubSourceSettings; /** * Embedded Source Settings. See Embedded Source Settings for more details. */ embeddedSourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsEmbeddedSourceSettings; /** * SCTE20 Source Settings. See SCTE 20 Source Settings for more details. */ scte20SourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsScte20SourceSettings; /** * SCTE27 Source Settings. See SCTE 27 Source Settings for more details. */ scte27SourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsScte27SourceSettings; /** * Teletext Source Settings. See Teletext Source Settings for more details. */ teletextSourceSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsTeletextSourceSettings; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsAncillarySourceSettings { /** * Specifies the number (1 to 4) of the captions channel you want to extract from the ancillary captions. If you plan to convert the ancillary captions to another format, complete this field. If you plan to choose Embedded as the captions destination in the output (to pass through all the channels in the ancillary captions), leave this field blank because MediaLive ignores the field. */ sourceAncillaryChannelNumber?: number; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsAribSourceSettings { } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsDvbSubSourceSettings { /** * If you will configure a WebVTT caption description that references this caption selector, use this field to provide the language to consider when translating the image-based source to text. */ ocrLanguage?: string; /** * When using DVB-Sub with Burn-In or SMPTE-TT, use this PID for the source content. Unused for DVB-Sub passthrough. All DVB-Sub content is passed through, regardless of selectors. */ pid?: number; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsEmbeddedSourceSettings { /** * If upconvert, 608 data is both passed through via the “608 compatibility bytes” fields of the 708 wrapper as well as translated into 708. 708 data present in the source content will be discarded. */ convert608To708?: string; /** * Set to “auto” to handle streams with intermittent and/or non-aligned SCTE-20 and Embedded captions. */ scte20Detection?: string; /** * Specifies the 608/708 channel number within the video track from which to extract captions. Unused for passthrough. */ source608ChannelNumber?: number; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsScte20SourceSettings { convert608To708?: string; source608ChannelNumber?: number; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsScte27SourceSettings { ocrLanguage?: string; pid?: number; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsTeletextSourceSettings { /** * Optionally defines a region where TTML style captions will be displayed. See Caption Rectangle for more details. */ outputRectangle?: outputs.medialive.ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsTeletextSourceSettingsOutputRectangle; /** * Specifies the teletext page number within the data stream from which to extract captions. Range of 0x100 (256) to 0x8FF (2303). Unused for passthrough. Should be specified as a hexadecimal string with no “0x” prefix. */ pageNumber?: string; } interface ChannelInputAttachmentInputSettingsCaptionSelectorSelectorSettingsTeletextSourceSettingsOutputRectangle { height: number; /** * Applies only if you plan to convert these source captions to EBU-TT-D or TTML in an output. (Make sure to leave the default if you don’t have either of these formats in the output.) You can define a display rectangle for the captions that is smaller than the underlying video frame. You define the rectangle by specifying the position of the left edge, top edge, bottom edge, and right edge of the rectangle, all within the underlying video frame. The units for the measurements are percentages. If you specify a value for one of these fields, you must specify a value for all of them. For leftOffset, specify the position of the left edge of the rectangle, as a percentage of the underlying frame width, and relative to the left edge of the frame. For example, "10" means the measurement is 10% of the underlying frame width. The rectangle left edge starts at that position from the left edge of the frame. This field corresponds to tts:origin - X in the TTML standard. */ leftOffset: number; /** * See the description in left\_offset. For top\_offset, specify the position of the top edge of the rectangle, as a percentage of the underlying frame height, and relative to the top edge of the frame. For example, "10" means the measurement is 10% of the underlying frame height. The rectangle top edge starts at that position from the top edge of the frame. This field corresponds to tts:origin - Y in the TTML standard. */ topOffset: number; width: number; } interface ChannelInputAttachmentInputSettingsNetworkInputSettings { /** * Specifies HLS input settings when the uri is for a HLS manifest. See HLS Input Settings for more details. */ hlsInputSettings?: outputs.medialive.ChannelInputAttachmentInputSettingsNetworkInputSettingsHlsInputSettings; /** * Check HTTPS server certificates. */ serverValidation?: string; } interface ChannelInputAttachmentInputSettingsNetworkInputSettingsHlsInputSettings { /** * The bitrate is specified in bits per second, as in an HLS manifest. */ bandwidth?: number; /** * Buffer segments. */ bufferSegments?: number; /** * The number of consecutive times that attempts to read a manifest or segment must fail before the input is considered unavailable. */ retries?: number; /** * The number of seconds between retries when an attempt to read a manifest or segment fails. */ retryInterval?: number; scte35Source?: string; } interface ChannelInputAttachmentInputSettingsVideoSelector { colorSpace?: string; colorSpaceUsage?: string; } interface ChannelInputSpecification { codec: string; inputResolution: string; maximumBitrate: string; } interface ChannelMaintenance { /** * The day of the week to use for maintenance. */ maintenanceDay: string; /** * The hour maintenance will start. */ maintenanceStartTime: string; } interface ChannelVpc { availabilityZones: string[]; networkInterfaceIds: string[]; /** * List of public address allocation ids to associate with ENIs that will be created in Output VPC. Must specify one for SINGLE_PIPELINE, two for STANDARD channels. */ publicAddressAllocationIds: string[]; /** * A list of up to 5 EC2 VPC security group IDs to attach to the Output VPC network interfaces. If none are specified then the VPC default security group will be used. */ securityGroupIds: string[]; /** * A list of VPC subnet IDs from the same VPC. If STANDARD channel, subnet IDs must be mapped to two unique availability zones (AZ). */ subnetIds: string[]; } interface GetInputDestination { ip: string; port: string; url: string; vpcs: outputs.medialive.GetInputDestinationVpc[]; } interface GetInputDestinationVpc { availabilityZone: string; networkInterfaceId: string; } interface GetInputInputDevice { /** * The ID of the Input. */ id: string; } interface GetInputMediaConnectFlow { flowArn: string; } interface GetInputSource { passwordParam: string; url: string; username: string; } interface InputDestination { /** * A unique name for the location the RTMP stream is being pushed to. */ streamName: string; } interface InputInputDevice { /** * The unique ID for the device. */ id: string; } interface InputMediaConnectFlow { /** * The ARN of the MediaConnect Flow */ flowArn: string; } interface InputSecurityGroupWhitelistRule { /** * The IPv4 CIDR that's whitelisted. */ cidr: string; } interface InputSource { /** * The key used to extract the password from EC2 Parameter store. */ passwordParam: string; /** * The URL where the stream is pulled from. */ url: string; /** * The username for the input source. */ username: string; } interface InputVpc { /** * A list of up to 5 EC2 VPC security group IDs to attach to the Input. */ securityGroupIds?: string[]; /** * A list of 2 VPC subnet IDs from the same VPC. */ subnetIds: string[]; } interface MultiplexMultiplexSettings { /** * Maximum video buffer delay. */ maximumVideoBufferDelayMilliseconds: number; /** * Transport stream bit rate. */ transportStreamBitrate: number; /** * Unique ID for each multiplex. */ transportStreamId: number; /** * Transport stream reserved bit rate. */ transportStreamReservedBitrate: number; } interface MultiplexProgramMultiplexProgramSettings { /** * Enum for preferred channel pipeline. Options are `CURRENTLY_ACTIVE`, `PIPELINE_0`, or `PIPELINE_1`. */ preferredChannelPipeline: string; /** * Unique program number. */ programNumber: number; /** * Service Descriptor. See Service Descriptor for more details. */ serviceDescriptor?: outputs.medialive.MultiplexProgramMultiplexProgramSettingsServiceDescriptor; /** * Video settings. See Video Settings for more details. */ videoSettings?: outputs.medialive.MultiplexProgramMultiplexProgramSettingsVideoSettings; } interface MultiplexProgramMultiplexProgramSettingsServiceDescriptor { /** * Unique provider name. */ providerName: string; /** * Unique service name. */ serviceName: string; } interface MultiplexProgramMultiplexProgramSettingsVideoSettings { /** * Constant bitrate value. */ constantBitrate: number; /** * Statmux settings. See Statmux Settings for more details. */ statmuxSettings?: outputs.medialive.MultiplexProgramMultiplexProgramSettingsVideoSettingsStatmuxSettings; } interface MultiplexProgramMultiplexProgramSettingsVideoSettingsStatmuxSettings { /** * Maximum bitrate. */ maximumBitrate: number; /** * Minimum bitrate. */ minimumBitrate: number; /** * Priority value. */ priority: number; } interface MultiplexProgramTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } } export declare namespace mediapackage { interface ChannelHlsIngest { /** * A list of the ingest endpoints */ ingestEndpoints: outputs.mediapackage.ChannelHlsIngestIngestEndpoint[]; } interface ChannelHlsIngestIngestEndpoint { /** * The password */ password: string; /** * The URL */ url: string; /** * The username */ username: string; } } export declare namespace memorydb { interface ClusterClusterEndpoint { /** * DNS hostname of the node. */ address: string; /** * The port number on which each of the nodes accepts connections. Defaults to `6379`. */ port: number; } interface ClusterShard { /** * Name of the cluster. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name: string; /** * Set of nodes in this shard. */ nodes: outputs.memorydb.ClusterShardNode[]; /** * Number of individual nodes in this shard. */ numNodes: number; /** * Keyspace for this shard. Example: `0-16383`. */ slots: string; } interface ClusterShardNode { /** * The Availability Zone in which the node resides. */ availabilityZone: string; /** * The date and time when the node was created. Example: `2022-01-01T21:00:00Z`. */ createTime: string; endpoints: outputs.memorydb.ClusterShardNodeEndpoint[]; /** * Name of the cluster. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name: string; } interface ClusterShardNodeEndpoint { /** * DNS hostname of the node. */ address: string; /** * The port number on which each of the nodes accepts connections. Defaults to `6379`. */ port: number; } interface GetClusterClusterEndpoint { /** * DNS hostname of the node. */ address: string; /** * Port number that this node is listening on. */ port: number; } interface GetClusterShard { /** * Name of the cluster. */ name: string; /** * Set of nodes in this shard. */ nodes: outputs.memorydb.GetClusterShardNode[]; /** * Number of individual nodes in this shard. */ numNodes: number; /** * Keyspace for this shard. Example: `0-16383`. */ slots: string; } interface GetClusterShardNode { /** * The Availability Zone in which the node resides. */ availabilityZone: string; /** * The date and time when the node was created. Example: `2022-01-01T21:00:00Z`. */ createTime: string; endpoints: outputs.memorydb.GetClusterShardNodeEndpoint[]; /** * Name of the cluster. */ name: string; } interface GetClusterShardNodeEndpoint { /** * DNS hostname of the node. */ address: string; /** * Port number that this node is listening on. */ port: number; } interface GetParameterGroupParameter { /** * Name of the parameter group. */ name: string; /** * Value of the parameter. */ value: string; } interface GetSnapshotClusterConfiguration { /** * Description for the cluster. */ description: string; /** * The engine that will run on cluster nodes. */ engine: string; /** * Version number of the engine used by the cluster. */ engineVersion: string; /** * The weekly time range during which maintenance on the cluster is performed. */ maintenanceWindow: string; /** * Name of the snapshot. */ name: string; /** * Compute and memory capacity of the nodes in the cluster. */ nodeType: string; /** * Number of shards in the cluster. */ numShards: number; /** * Name of the parameter group associated with the cluster. */ parameterGroupName: string; /** * Port number on which the cluster accepts connections. */ port: number; /** * Number of days for which MemoryDB retains automatic snapshots before deleting them. */ snapshotRetentionLimit: number; /** * The daily time range (in UTC) during which MemoryDB begins taking a daily snapshot of the shard. */ snapshotWindow: string; /** * Name of the subnet group used by the cluster. */ subnetGroupName: string; /** * ARN of the SNS topic to which cluster notifications are sent. */ topicArn: string; /** * The VPC in which the cluster exists. */ vpcId: string; } interface GetUserAuthenticationMode { /** * Number of passwords belonging to the user if `type` is set to `password`. */ passwordCount: number; /** * Type of authentication configured. */ type: string; } interface MultiRegionClusterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ParameterGroupParameter { /** * The name of the parameter. */ name: string; /** * The value of the parameter. */ value: string; } interface SnapshotClusterConfiguration { /** * Description for the cluster. */ description: string; /** * The engine that will run on cluster nodes. */ engine: string; /** * Version number of the engine used by the cluster. */ engineVersion: string; /** * The weekly time range during which maintenance on the cluster is performed. */ maintenanceWindow: string; /** * Name of the snapshot. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name: string; /** * Compute and memory capacity of the nodes in the cluster. */ nodeType: string; /** * Number of shards in the cluster. */ numShards: number; /** * Name of the parameter group associated with the cluster. */ parameterGroupName: string; /** * Port number on which the cluster accepts connections. */ port: number; /** * Number of days for which MemoryDB retains automatic snapshots before deleting them. */ snapshotRetentionLimit: number; /** * The daily time range (in UTC) during which MemoryDB begins taking a daily snapshot of the shard. */ snapshotWindow: string; /** * Name of the subnet group used by the cluster. */ subnetGroupName: string; /** * ARN of the SNS topic to which cluster notifications are sent. */ topicArn: string; /** * The VPC in which the cluster exists. */ vpcId: string; } interface UserAuthenticationMode { /** * Number of passwords belonging to the user if `type` is set to `password`. */ passwordCount: number; /** * Set of passwords used for authentication if `type` is set to `password`. You can create up to two passwords for each user. */ passwords?: string[]; /** * Specifies the authentication type. Valid values are: `password` or `iam`. */ type: string; } } export declare namespace mq { interface BrokerConfiguration { /** * Configuration ID. */ id: string; /** * Revision of the Configuration. */ revision: number; } interface BrokerEncryptionOptions { /** * ARN of KMS CMK to use for encryption at rest. Requires setting `useAwsOwnedKey` to `false`. To perform drift detection when AWS-managed CMKs or customer-managed CMKs are in use, this value must be configured. */ kmsKeyId: string; /** * Whether to enable an AWS-owned KMS CMK not in your account. Defaults to `true`. Setting to `false` without configuring `kmsKeyId` creates an AWS-managed CMK aliased to `aws/mq` in your account. */ useAwsOwnedKey?: boolean; } interface BrokerInstance { /** * URL of the [ActiveMQ Web Console](http://activemq.apache.org/web-console.html) or the [RabbitMQ Management UI](https://www.rabbitmq.com/management.html#external-monitoring) depending on `engineType`. */ consoleUrl: string; /** * `amqps://broker-id.mq.us-west-2.amazonaws.com:5671` */ endpoints: string[]; /** * IP Address of the broker. */ ipAddress: string; } interface BrokerLdapServerMetadata { /** * List of fully qualified domain names of the LDAP server and optional failover server. */ hosts?: string[]; /** * Fully qualified name of the directory to search for a user's groups. */ roleBase?: string; /** * LDAP attribute that identifies the group name attribute in the object returned from the group membership query. */ roleName?: string; /** * Search criteria for groups. */ roleSearchMatching?: string; /** * Whether the directory search scope is the entire sub-tree. */ roleSearchSubtree?: boolean; /** * Service account password. */ serviceAccountPassword?: string; /** * Service account username. */ serviceAccountUsername?: string; /** * Fully qualified name of the directory where you want to search for users. */ userBase?: string; /** * Name of the LDAP attribute for the user group membership. */ userRoleName?: string; /** * Search criteria for users. */ userSearchMatching?: string; /** * Whether the directory search scope is the entire sub-tree. */ userSearchSubtree?: boolean; } interface BrokerLogs { /** * Whether to enable audit logging. Only possible for `engineType` of `ActiveMQ`. Logs user management actions via JMX or ActiveMQ Web Console. Defaults to `false`. */ audit?: boolean; /** * Whether to enable general logging via CloudWatch. Defaults to `false`. */ general?: boolean; } interface BrokerMaintenanceWindowStartTime { /** * Day of the week, e.g., `MONDAY`, `TUESDAY`, or `WEDNESDAY`. */ dayOfWeek: string; /** * Time, in 24-hour format, e.g., `02:00`. */ timeOfDay: string; /** * Time zone in either the Country/City format or the UTC offset format, e.g., `CET`. */ timeZone: string; } interface BrokerSharedResource { /** * DNS names through which the broker reaches the shared resource. */ dnsNames: string[]; /** * ARN of the shared resource. */ resourceArn: string; /** * Status of the shared resource. */ status: string; /** * Type of the shared resource, either `RESOURCE_SHARE` or `RESOURCE`. */ type: string; } interface BrokerUser { /** * Whether to enable access to the [ActiveMQ Web Console](http://activemq.apache.org/web-console.html) for the user. Applies to `engineType` of `ActiveMQ` only. */ consoleAccess?: boolean; /** * List of groups (20 maximum) to which the ActiveMQ user belongs. Applies to `engineType` of `ActiveMQ` only. */ groups?: string[]; /** * Password of the user. Must be 12 to 250 characters long, contain at least 4 unique characters, and must not contain commas. */ password: string; /** * Whether to set replication user. Defaults to `false`. */ replicationUser?: boolean; /** * Username of the user. * * The following arguments are optional: */ username: string; } interface GetBrokerConfiguration { /** * Configuration ID. */ id: string; /** * Revision of the Configuration. */ revision: number; } interface GetBrokerEncryptionOption { /** * ARN of KMS Customer Master Key (CMK) to use for encryption at rest. */ kmsKeyId: string; /** * Whether to enable an AWS-owned KMS CMK that is not in your account. */ useAwsOwnedKey: boolean; } interface GetBrokerEngineTypesBrokerEngineType { /** * MQ engine type to return version details for. */ engineType: string; /** * List of engine versions. See `engineVersions` Block. */ engineVersions: outputs.mq.GetBrokerEngineTypesBrokerEngineTypeEngineVersion[]; } interface GetBrokerEngineTypesBrokerEngineTypeEngineVersion { /** * Name of the engine version. */ name: string; } interface GetBrokerInstance { /** * URL of the ActiveMQ Web Console or the RabbitMQ Management UI depending on `engineType`. */ consoleUrl: string; /** * Broker's wire-level protocol endpoints. */ endpoints: string[]; /** * IP Address of the broker. */ ipAddress: string; } interface GetBrokerLdapServerMetadata { /** * List of a fully qualified domain name of the LDAP server and an optional failover server. */ hosts: string[]; /** * Fully qualified name of the directory to search for a user's groups. */ roleBase: string; /** * LDAP attribute that identifies the group name attribute in the object returned from the group membership query. */ roleName: string; /** * Search criteria for groups. */ roleSearchMatching: string; /** * Whether the directory search scope is the entire sub-tree. */ roleSearchSubtree: boolean; /** * Service account password. */ serviceAccountPassword: string; /** * Service account username. */ serviceAccountUsername: string; /** * Fully qualified name of the directory where you want to search for users. */ userBase: string; /** * Name of the LDAP attribute for the user group membership. */ userRoleName: string; /** * Search criteria for users. */ userSearchMatching: string; /** * Whether the directory search scope is the entire sub-tree. */ userSearchSubtree: boolean; } interface GetBrokerLogs { /** * Whether audit logging is enabled. */ audit: boolean; /** * Whether general logging is enabled. */ general: boolean; } interface GetBrokerMaintenanceWindowStartTime { /** * Day of the week. */ dayOfWeek: string; /** * Time, in 24-hour format. */ timeOfDay: string; /** * Time zone in either the Country/City format or the UTC offset format. */ timeZone: string; } interface GetBrokerSharedResource { /** * DNS names through which the broker reaches the shared resource. */ dnsNames: string[]; /** * ARN of the shared resource. */ resourceArn: string; /** * Status of the shared resource. */ status: string; /** * Type of the shared resource, either `RESOURCE_SHARE` or `RESOURCE`. */ type: string; } interface GetBrokerUser { /** * Whether to enable access to the ActiveMQ Web Console for the user. */ consoleAccess: boolean; /** * List of groups to which the ActiveMQ user belongs. */ groups: string[]; /** * Whether to set replication user. */ replicationUser: boolean; /** * Username of the user. */ username: string; } interface GetInstanceTypeOfferingsBrokerInstanceOption { /** * List of available Availability Zones. See `availabilityZones` Block below. */ availabilityZones: outputs.mq.GetInstanceTypeOfferingsBrokerInstanceOptionAvailabilityZone[]; /** * Filter response by engine type. */ engineType: string; /** * Filter response by host instance type. */ hostInstanceType: string; /** * Filter response by storage type. */ storageType: string; /** * List of supported deployment modes. */ supportedDeploymentModes: string[]; /** * List of supported engine versions. */ supportedEngineVersions: string[]; } interface GetInstanceTypeOfferingsBrokerInstanceOptionAvailabilityZone { /** * Name of the Availability Zone. */ name: string; } } export declare namespace msk { interface ChannelEncryptionConfiguration { /** * ARN of the AWS KMS key used to encrypt the data. */ kmsKeyArn: string; } interface ChannelIcebergDestination { /** * Whether the destination is append-only. Must be `true`; updates and deletes are not supported. */ appendOnly: boolean; /** * AWS Glue Data Catalog and S3 Tables warehouse used by the destination. See `catalog` Block below. */ catalog?: outputs.msk.ChannelIcebergDestinationCatalog; /** * Compression codec for Iceberg table data files. Defaults to `ZSTD`. */ compressionType: string; /** * Maximum time, in seconds, that records buffer in MSK before being flushed to the destination. Valid values are between `300` and `900`. Defaults to `600`. Can be updated in place without recreating the channel. */ dataFreshnessInSeconds: number; /** * Amazon S3 bucket and prefix where MSK writes records that fail to deliver. See `deadLetterQueueS3` Block below. */ deadLetterQueueS3: outputs.msk.ChannelIcebergDestinationDeadLetterQueueS3; /** * Destination Iceberg table. See `destinationTable` Block below. */ destinationTable: outputs.msk.ChannelIcebergDestinationDestinationTable; /** * Configuration controlling whether the destination table's schema is evolved to match incoming records. See `schemaEvolution` Block below. */ schemaEvolution: outputs.msk.ChannelIcebergDestinationSchemaEvolution; /** * ARN of the IAM role that MSK assumes to access the destination table, the AWS Glue Data Catalog, and the dead-letter Amazon S3 bucket. */ serviceExecutionRoleArn: string; /** * Configuration controlling whether MSK creates the destination table if it does not already exist. See `tableCreation` Block below. * * The following arguments are optional: */ tableCreation: outputs.msk.ChannelIcebergDestinationTableCreation; } interface ChannelIcebergDestinationCatalog { /** * ARN of the federated AWS Glue Data Catalog that projects the S3 Tables bucket. */ catalogArn?: string; /** * ARN of the S3 Tables bucket that backs the Apache Iceberg warehouse. */ warehouseLocation?: string; } interface ChannelIcebergDestinationDeadLetterQueueS3 { /** * ARN of the dead-letter Amazon S3 bucket. * * The following arguments are optional: */ bucketArn: string; /** * Prefix prepended to every dead-letter Amazon S3 object key. */ errorOutputPrefix?: string; /** * 12-digit AWS account ID expected to own the dead-letter Amazon S3 bucket. */ expectedBucketOwner?: string; } interface ChannelIcebergDestinationDestinationTable { /** * Name of the destination namespace (database) in the AWS Glue Data Catalog. */ destinationDatabaseName?: string; /** * Name of the destination Apache Iceberg table. */ destinationTableName?: string; /** * Partition specification for the destination table. See `partitionSpec` Block below. */ partitionSpec?: outputs.msk.ChannelIcebergDestinationDestinationTablePartitionSpec; } interface ChannelIcebergDestinationDestinationTablePartitionSpec { /** * Partitioning strategy applied to records written to the table. `TIME_HOUR` partitions by hour using a timestamp source column. */ partitionStrategy: string; /** * Source column used by the partitioning strategy. For `TIME_HOUR`, exactly one source must be specified and its column must be a timestamp. See `source` Block below. */ sources?: outputs.msk.ChannelIcebergDestinationDestinationTablePartitionSpecSource[]; } interface ChannelIcebergDestinationDestinationTablePartitionSpecSource { /** * Name of the source column. For `TIME_HOUR` partitioning this must be a timestamp column defined in the Glue Schema Registry schema. */ sourceName?: string; } interface ChannelIcebergDestinationSchemaEvolution { /** * Whether to allow MSK to evolve the destination table's schema. */ enableSchemaEvolution?: boolean; } interface ChannelIcebergDestinationTableCreation { /** * Whether MSK creates the destination table on the customer's behalf. */ enableTableCreation?: boolean; } interface ChannelLoggingInfo { /** * CloudWatch Logs destination for channel logs. See `cloudwatchLogs` Block below. */ cloudwatchLogs?: outputs.msk.ChannelLoggingInfoCloudwatchLogs; /** * Kinesis Data Firehose delivery stream destination for channel logs. See `firehose` Block below. */ firehose?: outputs.msk.ChannelLoggingInfoFirehose; /** * Amazon S3 destination for channel logs. See `s3` Block below. */ s3?: outputs.msk.ChannelLoggingInfoS3; } interface ChannelLoggingInfoCloudwatchLogs { /** * Whether the CloudWatch Logs destination is enabled. * * The following arguments are optional: */ enabled: boolean; /** * Name of the CloudWatch log group that receives the logs. */ logGroup?: string; } interface ChannelLoggingInfoFirehose { /** * Name of the Kinesis Data Firehose delivery stream that receives the logs. */ deliveryStream?: string; /** * Whether the Firehose destination is enabled. * * The following arguments are optional: */ enabled: boolean; } interface ChannelLoggingInfoS3 { /** * Name of the Amazon S3 bucket that receives the logs. */ bucket?: string; /** * Whether the Amazon S3 destination is enabled. * * The following arguments are optional: */ enabled: boolean; /** * Prefix applied to the Amazon S3 log object keys. */ prefix?: string; } interface ChannelS3Destination { /** * Maximum time, in seconds, that records buffer in MSK before being flushed to the destination. Valid values are between `300` and `900`. Defaults to `600`. Can be updated in place without recreating the channel. */ dataFreshnessInSeconds: number; /** * Amazon S3 bucket and prefix where MSK writes records that fail to deliver. See `deadLetterQueueS3` Block below. */ deadLetterQueueS3: outputs.msk.ChannelS3DestinationDeadLetterQueueS3; /** * ARN of the IAM role that MSK assumes to write to the destination Amazon S3 bucket and the dead-letter bucket. */ serviceExecutionRoleArn: string; /** * Amazon S3 bucket, prefix, and storage class for delivered records. See `storage` Block below. * * The following arguments are optional: */ storage: outputs.msk.ChannelS3DestinationStorage; } interface ChannelS3DestinationDeadLetterQueueS3 { /** * ARN of the dead-letter Amazon S3 bucket. * * The following arguments are optional: */ bucketArn: string; /** * Prefix prepended to every dead-letter Amazon S3 object key. */ errorOutputPrefix?: string; /** * 12-digit AWS account ID expected to own the dead-letter Amazon S3 bucket. */ expectedBucketOwner?: string; } interface ChannelS3DestinationStorage { /** * ARN of the destination Amazon S3 bucket. */ bucketArn: string; /** * Compression codec applied to delivered Amazon S3 objects. */ compressionType: string; /** * 12-digit AWS account ID expected to own the Amazon S3 bucket. */ expectedBucketOwner?: string; /** * Template that controls the Amazon S3 object key for each delivered record. */ outputKeyTemplate?: string; /** * Prefix prepended to every Amazon S3 object key written by the channel. */ outputPrefix?: string; /** * Amazon S3 storage class for delivered objects. * * The following arguments are optional: */ storageClass: string; } interface ChannelTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ChannelTopicConfiguration { /** * Configuration that controls how Apache Kafka record values are deserialized for the destination. See `recordConverter` Block below. */ recordConverter: outputs.msk.ChannelTopicConfigurationRecordConverter; /** * Schema used to validate records when the value converter requires one. See `recordSchema` Block below. */ recordSchema?: outputs.msk.ChannelTopicConfigurationRecordSchema; /** * ARN that uniquely identifies the topic. * * The following arguments are optional: */ topicArn: string; } interface ChannelTopicConfigurationRecordConverter { /** * Deserialization format applied to Apache Kafka record values. Valid values are `BYTE_ARRAY`, `STRING`, `JSON`, and `JSON_SCHEMA_GSR`. The `icebergDestination` accepts only `JSON` or `JSON_SCHEMA_GSR`; the `s3Destination` accepts `BYTE_ARRAY`, `STRING`, or `JSON`. */ valueConverter: string; } interface ChannelTopicConfigurationRecordSchema { /** * ARN of the AWS Glue Schema Registry schema used to validate records for the destination Apache Iceberg table. */ gsrArn: string; } interface ClusterBrokerNodeGroupInfo { /** * The distribution of broker nodes across availability zones ([documentation](https://docs.aws.amazon.com/msk/1.0/apireference/clusters.html#clusters-model-brokerazdistribution)). Currently, the only valid value is `DEFAULT`. */ azDistribution?: string; /** * A list of subnets to connect to in client VPC ([documentation](https://docs.aws.amazon.com/msk/1.0/apireference/clusters.html#clusters-prop-brokernodegroupinfo-clientsubnets)). */ clientSubnets: string[]; /** * Information about the cluster access configuration. See brokerNodeGroupInfo connectivity_info Argument Reference below. For security reasons, you can't turn on public access while creating an MSK cluster. However, you can update an existing cluster to make it publicly accessible. You can also create a new cluster and then update it to make it publicly accessible ([documentation](https://docs.aws.amazon.com/msk/latest/developerguide/public-access.html)). */ connectivityInfo: outputs.msk.ClusterBrokerNodeGroupInfoConnectivityInfo; /** * Specify the instance type to use for the kafka brokersE.g., kafka.m5.large. ([Pricing info](https://aws.amazon.com/msk/pricing/)) */ instanceType: string; /** * A list of the security groups to associate with the elastic network interfaces to control who can communicate with the cluster. */ securityGroups: string[]; /** * A block that contains information about storage volumes attached to MSK broker nodes. See brokerNodeGroupInfo storage_info Argument Reference below. This block must not be specified when an Express instance type is specified for `instanceType`. */ storageInfo: outputs.msk.ClusterBrokerNodeGroupInfoStorageInfo; } interface ClusterBrokerNodeGroupInfoConnectivityInfo { /** * Network type of the cluster. Valid values are: `IPV4` or `DUAL`. Default value: `IPV4`. Only updating from `IPV4` to `DUAL` is allowed. */ networkType: string; /** * Access control settings for brokers. See connectivityInfo public_access Argument Reference below. */ publicAccess: outputs.msk.ClusterBrokerNodeGroupInfoConnectivityInfoPublicAccess; /** * VPC connectivity access control for brokers. See connectivityInfo vpc_connectivity Argument Reference below. */ vpcConnectivity: outputs.msk.ClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivity; } interface ClusterBrokerNodeGroupInfoConnectivityInfoPublicAccess { /** * Public access type. Valid values: `DISABLED`, `SERVICE_PROVIDED_EIPS`. */ type: string; } interface ClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivity { /** * Configuration block for specifying a client authentication. See clientAuthentication Argument Reference below. */ clientAuthentication: outputs.msk.ClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthentication; } interface ClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthentication { /** * Configuration block for specifying SASL client authentication. See clientAuthentication sasl Argument Reference below. */ sasl: outputs.msk.ClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthenticationSasl; /** * Configuration block for specifying TLS client authentication. See clientAuthentication tls Argument Reference below. */ tls: boolean; } interface ClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthenticationSasl { iam: boolean; scram: boolean; } interface ClusterBrokerNodeGroupInfoStorageInfo { /** * A block that contains EBS volume information. See storageInfo ebs_storage_info Argument Reference below. */ ebsStorageInfo?: outputs.msk.ClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfo; } interface ClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfo { /** * A block that contains EBS volume provisioned throughput information. To provision storage throughput, you must choose broker type kafka.m5.4xlarge or larger. See ebsStorageInfo provisioned_throughput Argument Reference below. */ provisionedThroughput?: outputs.msk.ClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfoProvisionedThroughput; /** * The size in GiB of the EBS volume for the data drive on each broker node. Minimum value of `1` and maximum value of `16384`. */ volumeSize?: number; } interface ClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfoProvisionedThroughput { enabled?: boolean; /** * Throughput value of the EBS volumes for the data drive on each kafka broker node in MiB per second. The minimum value is `250`. The maximum value varies between broker type. You can refer to the valid values for the maximum volume throughput at the following [documentation on throughput bottlenecks](https://docs.aws.amazon.com/msk/latest/developerguide/msk-provision-throughput.html#throughput-bottlenecks) */ volumeThroughput?: number; } interface ClusterClientAuthentication { /** * Configuration block for specifying SASL client authentication. See clientAuthentication sasl Argument Reference below. */ sasl?: outputs.msk.ClusterClientAuthenticationSasl; /** * Configuration block for specifying TLS client authentication. See clientAuthentication tls Argument Reference below. */ tls?: outputs.msk.ClusterClientAuthenticationTls; /** * Enables unauthenticated access. */ unauthenticated?: boolean; } interface ClusterClientAuthenticationSasl { iam?: boolean; scram?: boolean; } interface ClusterClientAuthenticationTls { /** * List of ACM Certificate Authority ARNs. */ certificateAuthorityArns?: string[]; } interface ClusterConfigurationInfo { /** * ARN of the MSK Configuration to use in the cluster. */ arn: string; /** * Revision of the MSK Configuration to use in the cluster. */ revision: number; } interface ClusterEncryptionInfo { /** * You may specify a KMS key short ID or ARN (it will always output an ARN) to use for encrypting your data at rest. If no key is specified, an AWS managed KMS ('aws/msk' managed service) key will be used for encrypting the data at rest. */ encryptionAtRestKmsKeyArn: string; /** * Configuration block to specify encryption in transit. See encryptionInfo encryption_in_transit Argument Reference below. */ encryptionInTransit?: outputs.msk.ClusterEncryptionInfoEncryptionInTransit; } interface ClusterEncryptionInfoEncryptionInTransit { /** * Encryption setting for data in transit between clients and brokers. Valid values: `TLS`, `TLS_PLAINTEXT`, and `PLAINTEXT`. Default value is `TLS`. */ clientBroker?: string; /** * Whether data communication among broker nodes is encrypted. Default value: `true`. */ inCluster?: boolean; } interface ClusterLoggingInfo { /** * Configuration block for Broker Logs settings for logging info. See loggingInfo broker_logs Argument Reference below. */ brokerLogs: outputs.msk.ClusterLoggingInfoBrokerLogs; } interface ClusterLoggingInfoBrokerLogs { /** * Configuration block for Cloudwatch Logs settings. See loggingInfo broker_logs cloudwatchLogs Argument Reference below. */ cloudwatchLogs?: outputs.msk.ClusterLoggingInfoBrokerLogsCloudwatchLogs; /** * Configuration block for Kinesis Data Firehose settings. See loggingInfo broker_logs firehose Argument Reference below. */ firehose?: outputs.msk.ClusterLoggingInfoBrokerLogsFirehose; /** * Configuration block for S3 settings. See loggingInfo broker_logs s3 Argument Reference below. */ s3?: outputs.msk.ClusterLoggingInfoBrokerLogsS3; } interface ClusterLoggingInfoBrokerLogsCloudwatchLogs { enabled: boolean; /** * Name of the Cloudwatch Log Group to deliver logs to. */ logGroup?: string; } interface ClusterLoggingInfoBrokerLogsFirehose { /** * Name of the Kinesis Data Firehose delivery stream to deliver logs to. */ deliveryStream?: string; enabled: boolean; } interface ClusterLoggingInfoBrokerLogsS3 { /** * Name of the S3 bucket to deliver logs to. */ bucket?: string; enabled: boolean; /** * Prefix to append to the folder name. */ prefix?: string; } interface ClusterOpenMonitoring { /** * Configuration block for Prometheus settings for open monitoring. See openMonitoring prometheus Argument Reference below. */ prometheus: outputs.msk.ClusterOpenMonitoringPrometheus; } interface ClusterOpenMonitoringPrometheus { /** * Configuration block for JMX Exporter. See openMonitoring prometheus jmxExporter Argument Reference below. */ jmxExporter?: outputs.msk.ClusterOpenMonitoringPrometheusJmxExporter; /** * Configuration block for Node Exporter. See openMonitoring prometheus nodeExporter Argument Reference below. */ nodeExporter?: outputs.msk.ClusterOpenMonitoringPrometheusNodeExporter; } interface ClusterOpenMonitoringPrometheusJmxExporter { /** * Indicates whether you want to enable or disable the Node Exporter. */ enabledInBroker: boolean; } interface ClusterOpenMonitoringPrometheusNodeExporter { /** * Indicates whether you want to enable or disable the Node Exporter. */ enabledInBroker: boolean; } interface ClusterRebalancing { /** * The status of intelligent rebalancing. Valid values: `ACTIVE`, `PAUSED`. Default is `ACTIVE` for new Express-based clusters. * * > **NOTE:** Intelligent rebalancing is only available for MSK Provisioned clusters with Express brokers. When enabled, you cannot use third-party rebalancing tools such as Cruise Control. See [AWS MSK Intelligent Rebalancing](https://docs.aws.amazon.com/msk/latest/developerguide/intelligent-rebalancing.html) for more information. */ status: string; } interface GetBrokerNodesNodeInfoList { /** * Attached elastic network interface of the broker */ attachedEniId: string; /** * ID of the broker */ brokerId: number; /** * Client subnet to which this broker node belongs */ clientSubnet: string; /** * Client VPC IP address */ clientVpcIpAddress: string; /** * Set of endpoints for accessing the broker. This does not include ports */ endpoints: string[]; /** * ARN of the node */ nodeArn: string; } interface GetClusterBrokerNodeGroupInfo { azDistribution: string; clientSubnets: string[]; connectivityInfos: outputs.msk.GetClusterBrokerNodeGroupInfoConnectivityInfo[]; instanceType: string; securityGroups: string[]; storageInfos: outputs.msk.GetClusterBrokerNodeGroupInfoStorageInfo[]; } interface GetClusterBrokerNodeGroupInfoConnectivityInfo { networkType: string; publicAccesses: outputs.msk.GetClusterBrokerNodeGroupInfoConnectivityInfoPublicAccess[]; vpcConnectivities: outputs.msk.GetClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivity[]; } interface GetClusterBrokerNodeGroupInfoConnectivityInfoPublicAccess { type: string; } interface GetClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivity { clientAuthentications: outputs.msk.GetClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthentication[]; } interface GetClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthentication { sasls: outputs.msk.GetClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthenticationSasl[]; tls: boolean; } interface GetClusterBrokerNodeGroupInfoConnectivityInfoVpcConnectivityClientAuthenticationSasl { iam: boolean; scram: boolean; } interface GetClusterBrokerNodeGroupInfoStorageInfo { ebsStorageInfos: outputs.msk.GetClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfo[]; } interface GetClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfo { provisionedThroughputs: outputs.msk.GetClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfoProvisionedThroughput[]; volumeSize: number; } interface GetClusterBrokerNodeGroupInfoStorageInfoEbsStorageInfoProvisionedThroughput { enabled: boolean; volumeThroughput: number; } interface ReplicatorKafkaCluster { /** * Details of an Amazon MSK cluster. Exactly one of `amazonMskCluster` or `apacheKafkaCluster` must be specified. Detailed below. */ amazonMskCluster?: outputs.msk.ReplicatorKafkaClusterAmazonMskCluster; /** * Details of a self-managed or on-premises Apache Kafka cluster. Exactly one of `amazonMskCluster` or `apacheKafkaCluster` must be specified. Detailed below. */ apacheKafkaCluster?: outputs.msk.ReplicatorKafkaClusterApacheKafkaCluster; /** * Details of the client authentication used by the Kafka cluster. Only valid for an `apacheKafkaCluster`. Detailed below. */ clientAuthentication?: outputs.msk.ReplicatorKafkaClusterClientAuthentication; /** * Details of encryption in transit to the Kafka cluster. Only valid for an `apacheKafkaCluster`. TLS encryption in transit is always applied to an `apacheKafkaCluster`; this block is only required to supply a custom root CA chain (for a cluster using a private or self-signed certificate). Detailed below. */ encryptionInTransit?: outputs.msk.ReplicatorKafkaClusterEncryptionInTransit; /** * Details of an Amazon VPC which has network connectivity to the Kafka cluster. Provide this on the `amazonMskCluster` entry only; the replicator reaches the Apache Kafka cluster through that VPC. */ vpcConfig?: outputs.msk.ReplicatorKafkaClusterVpcConfig; } interface ReplicatorKafkaClusterAmazonMskCluster { /** * The ARN of an Amazon MSK cluster. */ mskClusterArn: string; } interface ReplicatorKafkaClusterApacheKafkaCluster { /** * The Kafka `cluster.id` of the self-managed or on-premises Apache Kafka cluster (as reported by the cluster itself, e.g. via the Kafka admin tooling), not an arbitrary name. MSK Replicator validates this value against the source cluster. See [Migrate third-party and self-managed Apache Kafka clusters to Amazon MSK](https://aws.amazon.com/blogs/big-data/migrate-third-party-and-self-managed-apache-kafka-clusters-to-amazon-msk-express-and-standard-brokers-with-amazon-msk-replicator/) for how to obtain the cluster ID and the other required inputs. */ apacheKafkaClusterId: string; /** * The bootstrap broker connection string used to connect to the Apache Kafka cluster. */ bootstrapBrokerString: string; } interface ReplicatorKafkaClusterClientAuthentication { /** * Details of the mTLS client authentication used by the Kafka cluster. Detailed below. */ mtls?: outputs.msk.ReplicatorKafkaClusterClientAuthenticationMtls; /** * Details of the SASL/SCRAM client authentication used by the Kafka cluster. Detailed below. */ saslScram?: outputs.msk.ReplicatorKafkaClusterClientAuthenticationSaslScram; } interface ReplicatorKafkaClusterClientAuthenticationMtls { /** * The ARN of the AWS Secrets Manager secret that stores the private key and certificate used for mTLS authentication. See [Set up prerequisites for MSK Replicator with self-managed Apache Kafka clusters](https://docs.aws.amazon.com/msk/latest/developerguide/msk-replicator-external-prereqs.html) for the required secret contents and format. */ secretArn: string; } interface ReplicatorKafkaClusterClientAuthenticationSaslScram { /** * The SASL/SCRAM mechanism used for authentication. Valid values are `SHA256` and `SHA512`. */ mechanism: string; /** * The ARN of the AWS Secrets Manager secret that stores the credentials used for SASL/SCRAM authentication. See [Set up prerequisites for MSK Replicator with self-managed Apache Kafka clusters](https://docs.aws.amazon.com/msk/latest/developerguide/msk-replicator-external-prereqs.html) for the required secret contents and format. */ secretArn: string; } interface ReplicatorKafkaClusterEncryptionInTransit { /** * The ARN of the AWS Secrets Manager secret that stores the custom root CA certificate chain used to trust the certificate authority of the Apache Kafka cluster. See [Set up prerequisites for MSK Replicator with self-managed Apache Kafka clusters](https://docs.aws.amazon.com/msk/latest/developerguide/msk-replicator-external-prereqs.html) for the required secret contents and format. */ rootCaCertificate: string; } interface ReplicatorKafkaClusterVpcConfig { /** * The AWS security groups to associate with the ENIs used by the replicator. If a security group is not specified, the default security group associated with the VPC is used. * * > **Note:** When an `apacheKafkaCluster` uses `clientAuthentication`, the replicator's network interfaces (created in these subnets, with private IPs only) must be able to reach AWS Secrets Manager and AWS KMS to retrieve and decrypt the credentials. Ensure the subnets have egress to those services via a NAT gateway or Secrets Manager and KMS interface VPC endpoints; otherwise the replicator times out connecting to the source cluster. */ securityGroupsIds?: string[]; /** * List of subnets to connect to in the VPC. AWS creates elastic network interfaces inside these subnets to allow communication between your Kafka Cluster and the replicator. */ subnetIds: string[]; } interface ReplicatorLogDelivery { /** * Configuration block for replicator log delivery. Detailed below. */ replicatorLogDelivery?: outputs.msk.ReplicatorLogDeliveryReplicatorLogDelivery; } interface ReplicatorLogDeliveryReplicatorLogDelivery { /** * Configuration block for replicator log delivery to Amazon CloudWatch Logs. Detailed below. */ cloudwatchLogs?: outputs.msk.ReplicatorLogDeliveryReplicatorLogDeliveryCloudwatchLogs; /** * Configuration block for replicator log delivery to Amazon Data Firehose. Detailed below. */ firehose?: outputs.msk.ReplicatorLogDeliveryReplicatorLogDeliveryFirehose; /** * Configuration block for replicator log delivery to Amazon S3. Detailed below. */ s3?: outputs.msk.ReplicatorLogDeliveryReplicatorLogDeliveryS3; } interface ReplicatorLogDeliveryReplicatorLogDeliveryCloudwatchLogs { /** * Boolean whether to enable log delivery to CloudWatch Logs. */ enabled: boolean; /** * Name of CloudWatch Logs log group. Required if `enabled` is `true`. If `enabled` is `false`, this value must not be set. */ logGroup?: string; } interface ReplicatorLogDeliveryReplicatorLogDeliveryFirehose { /** * Name of the Firehose delivery stream. Required if `enabled` is `true`. If `enabled` is `false`, this value must not be set. */ deliveryStream?: string; /** * Boolean whether to enable log delivery to Firehose. */ enabled: boolean; } interface ReplicatorLogDeliveryReplicatorLogDeliveryS3 { /** * Name of the S3 bucket. Required if `enabled` is `true`. If `enabled` is `false`, this value must not be set. */ bucket?: string; /** * Boolean whether to enable log delivery to S3. */ enabled: boolean; /** * Prefix to use when storing replicator logs in S3. If `enabled` is `false`, this value must not be set. */ prefix?: string; } interface ReplicatorReplicationInfoList { /** * Configuration relating to consumer group replication. */ consumerGroupReplications: outputs.msk.ReplicatorReplicationInfoListConsumerGroupReplication[]; sourceKafkaClusterAlias: string; /** * The ARN of the source Kafka cluster. Use for an Amazon MSK source. Exactly one of `sourceKafkaClusterArn` or `sourceKafkaClusterId` must be specified. */ sourceKafkaClusterArn?: string; /** * The identifier of the source Kafka cluster. Use for a self-managed / on-premises Apache Kafka source (matches `apacheKafkaClusterId`). Exactly one of `sourceKafkaClusterArn` or `sourceKafkaClusterId` must be specified. */ sourceKafkaClusterId?: string; /** * The type of compression to use writing records to target Kafka cluster. */ targetCompressionType: string; targetKafkaClusterAlias: string; /** * The ARN of the target Kafka cluster. Use for an Amazon MSK target. Exactly one of `targetKafkaClusterArn` or `targetKafkaClusterId` must be specified. */ targetKafkaClusterArn?: string; /** * The identifier of the target Kafka cluster. Use for a self-managed / on-premises Apache Kafka target (matches `apacheKafkaClusterId`). Exactly one of `targetKafkaClusterArn` or `targetKafkaClusterId` must be specified. */ targetKafkaClusterId?: string; /** * Configuration relating to topic replication. */ topicReplications: outputs.msk.ReplicatorReplicationInfoListTopicReplication[]; } interface ReplicatorReplicationInfoListConsumerGroupReplication { /** * Consumer group offset synchronization mode. Valid values are `LEGACY` and `ENHANCED`. With `LEGACY`, offsets are synchronized when producers write to the source cluster. With `ENHANCED`, consumer offsets are synchronized regardless of producer location. `ENHANCED` requires a corresponding replicator that replicates data from the target cluster to the source cluster and requires `topic_name_configuration.type` to be set to `IDENTICAL`. Defaults to `LEGACY`. Changing this value will force a new resource. */ consumerGroupOffsetSyncMode: string; /** * List of regular expression patterns indicating the consumer groups that should not be replicated. */ consumerGroupsToExcludes: string[]; /** * List of regular expression patterns indicating the consumer groups to copy. */ consumerGroupsToReplicates: string[]; /** * Whether to periodically check for new consumer groups. */ detectAndCopyNewConsumerGroups?: boolean; /** * Whether to periodically write the translated offsets to __consumer_offsets topic in target cluster. */ synchroniseConsumerGroupOffsets?: boolean; } interface ReplicatorReplicationInfoListTopicReplication { /** * Whether to periodically configure remote topic ACLs to match their corresponding upstream topics. */ copyAccessControlListsForTopics?: boolean; /** * Whether to periodically configure remote topics to match their corresponding upstream topics. */ copyTopicConfigurations?: boolean; /** * Whether to periodically check for new topics and partitions. */ detectAndCopyNewTopics?: boolean; /** * Configuration for specifying the position in the topics to start replicating from. */ startingPosition: outputs.msk.ReplicatorReplicationInfoListTopicReplicationStartingPosition; /** * Configuration for specifying replicated topic names should be the same as their corresponding upstream topics or prefixed with source cluster alias. */ topicNameConfiguration: outputs.msk.ReplicatorReplicationInfoListTopicReplicationTopicNameConfiguration; /** * List of regular expression patterns indicating the topics that should not be replica. */ topicsToExcludes: string[]; /** * List of regular expression patterns indicating the topics to copy. */ topicsToReplicates: string[]; } interface ReplicatorReplicationInfoListTopicReplicationStartingPosition { /** * The type of replication starting position. Supports `LATEST` and `EARLIEST`. */ type?: string; } interface ReplicatorReplicationInfoListTopicReplicationTopicNameConfiguration { /** * The type of topic configuration name. Supports `PREFIXED_WITH_SOURCE_CLUSTER_ALIAS` and `IDENTICAL`. */ type?: string; } interface ServerlessClusterClientAuthentication { /** * Details for client authentication using SASL. See below. */ sasl: outputs.msk.ServerlessClusterClientAuthenticationSasl; } interface ServerlessClusterClientAuthenticationSasl { /** * Details for client authentication using IAM. See below. */ iam: outputs.msk.ServerlessClusterClientAuthenticationSaslIam; } interface ServerlessClusterClientAuthenticationSaslIam { /** * Whether SASL/IAM authentication is enabled or not. */ enabled: boolean; } interface ServerlessClusterVpcConfig { /** * Specifies up to five security groups that control inbound and outbound traffic for the serverless cluster. */ securityGroupIds: string[]; /** * A list of subnets in at least two different Availability Zones that host your client applications. */ subnetIds: string[]; } interface TopicTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace mskconnect { interface ConnectorCapacity { /** * Information about the auto scaling parameters for the connector. See `autoscaling` Block for details. */ autoscaling?: outputs.mskconnect.ConnectorCapacityAutoscaling; /** * Details about a fixed capacity allocated to a connector. See `provisionedCapacity` Block for details. */ provisionedCapacity?: outputs.mskconnect.ConnectorCapacityProvisionedCapacity; } interface ConnectorCapacityAutoscaling { /** * The maximum number of workers allocated to the connector. */ maxWorkerCount: number; /** * The number of microcontroller units (MCUs) allocated to each connector worker. Valid values: `1`, `2`, `4`, `8`. The default value is `1`. */ mcuCount?: number; /** * The minimum number of workers allocated to the connector. */ minWorkerCount: number; /** * The scale-in policy for the connector. See `scaleInPolicy` Block for details. */ scaleInPolicy: outputs.mskconnect.ConnectorCapacityAutoscalingScaleInPolicy; /** * The scale-out policy for the connector. See `scaleOutPolicy` Block for details. */ scaleOutPolicy: outputs.mskconnect.ConnectorCapacityAutoscalingScaleOutPolicy; } interface ConnectorCapacityAutoscalingScaleInPolicy { /** * Specifies the CPU utilization percentage threshold at which you want connector scale in to be triggered. */ cpuUtilizationPercentage: number; } interface ConnectorCapacityAutoscalingScaleOutPolicy { /** * The CPU utilization percentage threshold at which you want connector scale out to be triggered. */ cpuUtilizationPercentage: number; } interface ConnectorCapacityProvisionedCapacity { /** * The number of microcontroller units (MCUs) allocated to each connector worker. Valid values: `1`, `2`, `4`, `8`. The default value is `1`. */ mcuCount?: number; /** * The number of workers that are allocated to the connector. */ workerCount: number; } interface ConnectorKafkaCluster { /** * The Apache Kafka cluster to which the connector is connected. See `apacheKafkaCluster` Block for details. */ apacheKafkaCluster: outputs.mskconnect.ConnectorKafkaClusterApacheKafkaCluster; } interface ConnectorKafkaClusterApacheKafkaCluster { /** * The bootstrap servers of the cluster. */ bootstrapServers: string; /** * Details of an Amazon VPC which has network connectivity to the Apache Kafka cluster. See `vpc` Block for details. */ vpc: outputs.mskconnect.ConnectorKafkaClusterApacheKafkaClusterVpc; } interface ConnectorKafkaClusterApacheKafkaClusterVpc { /** * The security groups for the connector. */ securityGroups: string[]; /** * The subnets for the connector. */ subnets: string[]; } interface ConnectorKafkaClusterClientAuthentication { /** * The type of client authentication used to connect to the Apache Kafka cluster. Valid values: `IAM`, `NONE`. A value of `NONE` means that no client authentication is used. The default value is `NONE`. */ authenticationType?: string; } interface ConnectorKafkaClusterEncryptionInTransit { /** * The type of encryption in transit to the Apache Kafka cluster. Valid values: `PLAINTEXT`, `TLS`. The default values is `PLAINTEXT`. */ encryptionType?: string; } interface ConnectorLogDelivery { /** * The workers can send worker logs to different destination types. This configuration specifies the details of these destinations. See `workerLogDelivery` Block for details. */ workerLogDelivery: outputs.mskconnect.ConnectorLogDeliveryWorkerLogDelivery; } interface ConnectorLogDeliveryWorkerLogDelivery { /** * Details about delivering logs to Amazon CloudWatch Logs. See `cloudwatchLogs` Block for details. */ cloudwatchLogs?: outputs.mskconnect.ConnectorLogDeliveryWorkerLogDeliveryCloudwatchLogs; /** * Details about delivering logs to Amazon Kinesis Data Firehose. See `firehose` Block for details. */ firehose?: outputs.mskconnect.ConnectorLogDeliveryWorkerLogDeliveryFirehose; /** * Details about delivering logs to Amazon S3. See `s3` Block for deetails. */ s3?: outputs.mskconnect.ConnectorLogDeliveryWorkerLogDeliveryS3; } interface ConnectorLogDeliveryWorkerLogDeliveryCloudwatchLogs { /** * Whether log delivery to Amazon CloudWatch Logs is enabled. */ enabled: boolean; /** * The name of the CloudWatch log group that is the destination for log delivery. */ logGroup?: string; } interface ConnectorLogDeliveryWorkerLogDeliveryFirehose { /** * The name of the Kinesis Data Firehose delivery stream that is the destination for log delivery. */ deliveryStream?: string; /** * Specifies whether connector logs get delivered to Amazon Kinesis Data Firehose. */ enabled: boolean; } interface ConnectorLogDeliveryWorkerLogDeliveryS3 { /** * The name of the S3 bucket that is the destination for log delivery. */ bucket?: string; /** * Specifies whether connector logs get sent to the specified Amazon S3 destination. */ enabled: boolean; /** * The S3 prefix that is the destination for log delivery. */ prefix?: string; } interface ConnectorPlugin { /** * Details about a custom plugin. See `customPlugin` Block for details. */ customPlugin: outputs.mskconnect.ConnectorPluginCustomPlugin; } interface ConnectorPluginCustomPlugin { /** * ARN of the custom plugin. */ arn: string; /** * The revision of the custom plugin. */ revision: number; } interface ConnectorWorkerConfiguration { /** * ARN of the worker configuration. */ arn: string; /** * The revision of the worker configuration. */ revision: number; } interface CustomPluginLocation { /** * Information of the plugin file stored in Amazon S3. See `s3` Block for details.. */ s3: outputs.mskconnect.CustomPluginLocationS3; } interface CustomPluginLocationS3 { /** * ARN of an S3 bucket. */ bucketArn: string; /** * The file key for an object in an S3 bucket. */ fileKey: string; /** * The version of an object in an S3 bucket. */ objectVersion?: string; } } export declare namespace mwaa { interface EnvironmentLastUpdated { /** * The Created At date of the MWAA Environment */ createdAt: string; errors: outputs.mwaa.EnvironmentLastUpdatedError[]; /** * The status of the Amazon MWAA Environment */ status: string; } interface EnvironmentLastUpdatedError { errorCode: string; errorMessage: string; } interface EnvironmentLoggingConfiguration { /** * (Optional) Log configuration options for processing DAGs. See Module logging configuration for more information. Disabled by default. */ dagProcessingLogs: outputs.mwaa.EnvironmentLoggingConfigurationDagProcessingLogs; /** * Log configuration options for the schedulers. See Module logging configuration for more information. Disabled by default. */ schedulerLogs: outputs.mwaa.EnvironmentLoggingConfigurationSchedulerLogs; /** * Log configuration options for DAG tasks. See Module logging configuration for more information. Enabled by default with `INFO` log level. */ taskLogs: outputs.mwaa.EnvironmentLoggingConfigurationTaskLogs; /** * Log configuration options for the webservers. See Module logging configuration for more information. Disabled by default. */ webserverLogs: outputs.mwaa.EnvironmentLoggingConfigurationWebserverLogs; /** * Log configuration options for the workers. See Module logging configuration for more information. Disabled by default. */ workerLogs: outputs.mwaa.EnvironmentLoggingConfigurationWorkerLogs; } interface EnvironmentLoggingConfigurationDagProcessingLogs { cloudWatchLogGroupArn: string; /** * Enabling or disabling the collection of logs */ enabled: boolean; /** * Logging level. Valid values: `CRITICAL`, `ERROR`, `WARNING`, `INFO`, `DEBUG`. Will be `INFO` by default. */ logLevel: string; } interface EnvironmentLoggingConfigurationSchedulerLogs { cloudWatchLogGroupArn: string; /** * Enabling or disabling the collection of logs */ enabled: boolean; /** * Logging level. Valid values: `CRITICAL`, `ERROR`, `WARNING`, `INFO`, `DEBUG`. Will be `INFO` by default. */ logLevel: string; } interface EnvironmentLoggingConfigurationTaskLogs { cloudWatchLogGroupArn: string; /** * Enabling or disabling the collection of logs */ enabled: boolean; /** * Logging level. Valid values: `CRITICAL`, `ERROR`, `WARNING`, `INFO`, `DEBUG`. Will be `INFO` by default. */ logLevel: string; } interface EnvironmentLoggingConfigurationWebserverLogs { cloudWatchLogGroupArn: string; /** * Enabling or disabling the collection of logs */ enabled: boolean; /** * Logging level. Valid values: `CRITICAL`, `ERROR`, `WARNING`, `INFO`, `DEBUG`. Will be `INFO` by default. */ logLevel: string; } interface EnvironmentLoggingConfigurationWorkerLogs { cloudWatchLogGroupArn: string; /** * Enabling or disabling the collection of logs */ enabled: boolean; /** * Logging level. Valid values: `CRITICAL`, `ERROR`, `WARNING`, `INFO`, `DEBUG`. Will be `INFO` by default. */ logLevel: string; } interface EnvironmentNetworkConfiguration { /** * Security groups IDs for the environment. At least one of the security group needs to allow MWAA resources to talk to each other, otherwise MWAA cannot be provisioned. */ securityGroupIds: string[]; /** * The private subnet IDs in which the environment should be created. MWAA requires two subnets. */ subnetIds: string[]; } } export declare namespace neptune { interface ClusterParameterGroupParameter { /** * Valid values are `immediate` and `pending-reboot`. Defaults to `pending-reboot`. */ applyMethod?: string; /** * The name of the neptune parameter. */ name: string; /** * The value of the neptune parameter. */ value: string; } interface ClusterServerlessV2ScalingConfiguration { /** * Maximum Neptune Capacity Units (NCUs) for this cluster. Must be lower or equal than **128**. See [AWS Documentation](https://docs.aws.amazon.com/neptune/latest/userguide/neptune-serverless-capacity-scaling.html) for more details. */ maxCapacity?: number; /** * Minimum Neptune Capacity Units (NCUs) for this cluster. Must be greater or equal than **1**. See [AWS Documentation](https://docs.aws.amazon.com/neptune/latest/userguide/neptune-serverless-capacity-scaling.html) for more details. */ minCapacity?: number; } interface GlobalClusterGlobalClusterMember { /** * ARN of member DB Cluster. */ dbClusterArn: string; /** * Whether the member is the primary DB Cluster. */ isWriter: boolean; } interface ParameterGroupParameter { /** * The apply method of the Neptune parameter. Valid values are `immediate` and `pending-reboot`. Defaults to `pending-reboot`. */ applyMethod?: string; /** * The name of the Neptune parameter. */ name: string; /** * The value of the Neptune parameter. */ value: string; } } export declare namespace neptunegraph { interface GraphTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GraphVectorSearchConfiguration { /** * Specifies the number of dimensions for vector embeddings. Value must be between 1 and 65,535. */ vectorSearchDimension?: number; } interface PrivateGraphEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace networkfirewall { interface ContainerAssociationContainerMonitoringConfiguration { /** * Key-value pairs that filter which containers within the cluster are monitored. For Amazon EKS, filter by namespace and Kubernetes labels. For Amazon ECS, filter by container instance attributes; attribute filters only match containers on the EC2 launch type, not Fargate. See `attributeFilter` Block below. */ attributeFilters?: outputs.networkfirewall.ContainerAssociationContainerMonitoringConfigurationAttributeFilter[]; /** * ARN of the Amazon ECS or Amazon EKS cluster to monitor. The cluster must be in the same Region and account as the container association. */ clusterArn: string; } interface ContainerAssociationContainerMonitoringConfigurationAttributeFilter { /** * Key of the container attribute to filter on. */ key: string; /** * Value of the container attribute to filter on. */ value: string; } interface ContainerAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface FirewallAvailabilityZoneMapping { /** * The ID of the Availability Zone where the firewall endpoint is located.. */ availabilityZoneId: string; } interface FirewallEncryptionConfiguration { /** * The ID of the customer managed key. You can use any of the [key identifiers](https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html#key-id) that KMS supports, unless you're using a key that's managed by another account. If you're using a key managed by another account, then specify the key ARN. */ keyId?: string; /** * The type of AWS KMS key to use for encryption of your Network Firewall resources. Valid values are `CUSTOMER_KMS` and `AWS_OWNED_KMS_KEY`. */ type: string; } interface FirewallFirewallStatus { /** * Set of subnets configured for use by the firewall. */ syncStates: outputs.networkfirewall.FirewallFirewallStatusSyncState[]; /** * Set of transit gateway configured for use by the firewall. */ transitGatewayAttachmentSyncStates: outputs.networkfirewall.FirewallFirewallStatusTransitGatewayAttachmentSyncState[]; } interface FirewallFirewallStatusSyncState { /** * Nested list describing the attachment status of the firewall's association with a single VPC subnet. */ attachments: outputs.networkfirewall.FirewallFirewallStatusSyncStateAttachment[]; /** * The Availability Zone where the subnet is configured. */ availabilityZone: string; } interface FirewallFirewallStatusSyncStateAttachment { /** * The identifier of the firewall endpoint that AWS Network Firewall has instantiated in the subnet. You use this to identify the firewall endpoint in the VPC route tables, when you redirect the VPC traffic through the endpoint. */ endpointId: string; /** * The unique identifier of the subnet that you've specified to be used for a firewall endpoint. */ subnetId: string; } interface FirewallFirewallStatusTransitGatewayAttachmentSyncState { /** * The unique identifier of the transit gateway attachment. */ attachmentId: string; } interface FirewallPolicyEncryptionConfiguration { /** * The ID of the customer managed key. You can use any of the [key identifiers](https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html#key-id) that KMS supports, unless you're using a key that's managed by another account. If you're using a key managed by another account, then specify the key ARN. */ keyId?: string; /** * The type of AWS KMS key to use for encryption of your Network Firewall resources. Valid values are `CUSTOMER_KMS` and `AWS_OWNED_KMS_KEY`. */ type: string; } interface FirewallPolicyFirewallPolicy { /** * Boolean indicating whether to prevent TCP and TLS packets from reaching destination servers until TLS Inspection has evaluated Server Name Indication (SNI) rules. If `true`, `tlsInspectionConfigurationArn` is required. Default value: `false`. */ enableTlsSessionHolding: boolean; /** * . Contains variables that you can use to override default Suricata settings in your firewall policy. See Rule Variables for details. */ policyVariables?: outputs.networkfirewall.FirewallPolicyFirewallPolicyPolicyVariables; /** * Set of actions to take on a packet if it does not match any stateful rules in the policy. This can only be specified if the policy has a `statefulEngineOptions` block with a `ruleOrder` value of `STRICT_ORDER`. Value values: `aws:drop_strict`, `aws:drop_established`, `aws:drop_established_app_layer`, `aws:alert_strict`, ` aws:alert_established, `aws:alert_established_app_layer`. For more information, see [Strict evaluation order](https://docs.aws.amazon.com/network-firewall/latest/developerguide/suricata-rule-evaluation-order.html#suricata-strict-rule-evaluation-order.html) in the AWS Network Firewall Developer Guide. */ statefulDefaultActions?: string[]; /** * A configuration block that defines options on how the policy handles stateful rules. See Stateful Engine Options below for details. */ statefulEngineOptions?: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatefulEngineOptions; /** * Set of configuration blocks containing references to the stateful rule groups that are used in the policy. See Stateful Rule Group Reference below for details. */ statefulRuleGroupReferences?: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatefulRuleGroupReference[]; /** * Set of configuration blocks describing the custom action definitions that are available for use in the firewall policy's `statelessDefaultActions`. See Stateless Custom Action below for details. */ statelessCustomActions?: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatelessCustomAction[]; /** * Set of actions to take on a packet if it does not match any of the stateless rules in the policy. You must specify one of the standard actions including: `aws:drop`, `aws:pass`, or `aws:forward_to_sfe`. * In addition, you can specify custom actions that are compatible with your standard action choice. If you want non-matching packets to be forwarded for stateful inspection, specify `aws:forward_to_sfe`. */ statelessDefaultActions: string[]; /** * Set of actions to take on a fragmented packet if it does not match any of the stateless rules in the policy. You must specify one of the standard actions including: `aws:drop`, `aws:pass`, or `aws:forward_to_sfe`. * In addition, you can specify custom actions that are compatible with your standard action choice. If you want non-matching packets to be forwarded for stateful inspection, specify `aws:forward_to_sfe`. */ statelessFragmentDefaultActions: string[]; /** * Set of configuration blocks containing references to the stateless rule groups that are used in the policy. See Stateless Rule Group Reference below for details. */ statelessRuleGroupReferences?: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatelessRuleGroupReference[]; /** * The (ARN) of the TLS Inspection policy to attach to the FW Policy. This must be added at creation of the resource per AWS documentation. "You can only add a TLS inspection configuration to a new policy, not to an existing policy." This cannot be removed from a FW Policy. */ tlsInspectionConfigurationArn?: string; } interface FirewallPolicyFirewallPolicyPolicyVariables { ruleVariables?: outputs.networkfirewall.FirewallPolicyFirewallPolicyPolicyVariablesRuleVariable[]; } interface FirewallPolicyFirewallPolicyPolicyVariablesRuleVariable { /** * A configuration block that defines a set of IP addresses. See IP Set below for details. */ ipSet: outputs.networkfirewall.FirewallPolicyFirewallPolicyPolicyVariablesRuleVariableIpSet; /** * An alphanumeric string to identify the `ipSet`. Valid values: `HOME_NET` */ key: string; } interface FirewallPolicyFirewallPolicyPolicyVariablesRuleVariableIpSet { /** * Set of IPv4 or IPv6 addresses in CIDR notation to use for the Suricata `HOME_NET` variable. */ definitions: string[]; } interface FirewallPolicyFirewallPolicyStatefulEngineOptions { /** * Amount of time that can pass without any traffic sent through the firewall before the firewall determines that the connection is idle. */ flowTimeouts?: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatefulEngineOptionsFlowTimeouts; /** * Indicates how to manage the order of stateful rule evaluation for the policy. Default value: `DEFAULT_ACTION_ORDER`. Valid values: `DEFAULT_ACTION_ORDER`, `STRICT_ORDER`. */ ruleOrder?: string; /** * Describes how to treat traffic which has broken midstream. Default value: `DROP`. Valid values: `DROP`, `CONTINUE`, `REJECT`. */ streamExceptionPolicy?: string; } interface FirewallPolicyFirewallPolicyStatefulEngineOptionsFlowTimeouts { /** * Number of seconds that can pass without any TCP traffic sent through the firewall before the firewall determines that the connection is idle. After the idle timeout passes, data packets are dropped, however, the next TCP SYN packet is considered a new flow and is processed by the firewall. Clients or targets can use TCP keepalive packets to reset the idle timeout. Default value: `350`. */ tcpIdleTimeoutSeconds?: number; } interface FirewallPolicyFirewallPolicyStatefulRuleGroupReference { /** * Whether to enable deep threat inspection, which allows AWS to analyze service logs of network traffic processed by these rule groups to identify threat indicators across customers. AWS will use these threat indicators to improve the active threat defense managed rule groups and protect the security of AWS customers and services. This only applies to active threat defense maanaged rule groups. * * For details, refer to [AWS active threat defense for AWS Network Firewall](https://docs.aws.amazon.com/network-firewall/latest/developerguide/aws-managed-rule-groups-atd.html) in the AWS Network Firewall Developer Guide. */ deepThreatInspection: string; /** * Configuration block for override values */ override?: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatefulRuleGroupReferenceOverride; /** * An integer setting that indicates the order in which to apply the stateful rule groups in a single policy. This argument must be specified if the policy has a `statefulEngineOptions` block with a `ruleOrder` value of `STRICT_ORDER`. AWS Network Firewall applies each stateful rule group to a packet starting with the group that has the lowest priority setting. */ priority?: number; /** * ARN of the stateful rule group. */ resourceArn: string; } interface FirewallPolicyFirewallPolicyStatefulRuleGroupReferenceOverride { /** * The action that changes the rule group from DROP to ALERT . This only applies to managed rule groups. */ action?: string; } interface FirewallPolicyFirewallPolicyStatelessCustomAction { /** * A configuration block describing the custom action associated with the `actionName`. See Action Definition below for details. */ actionDefinition: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatelessCustomActionActionDefinition; /** * A friendly name of the custom action. */ actionName: string; } interface FirewallPolicyFirewallPolicyStatelessCustomActionActionDefinition { /** * A configuration block describing the stateless inspection criteria that publishes the specified metrics to Amazon CloudWatch for the matching packet. You can pair this custom action with any of the standard stateless rule actions. See Publish Metric Action below for details. */ publishMetricAction: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricAction; } interface FirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricAction { /** * Set of configuration blocks describing dimension settings to use for Amazon CloudWatch custom metrics. See Dimension below for more details. */ dimensions: outputs.networkfirewall.FirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricActionDimension[]; } interface FirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricActionDimension { /** * The string value to use in the custom metric dimension. */ value: string; } interface FirewallPolicyFirewallPolicyStatelessRuleGroupReference { /** * An integer setting that indicates the order in which to run the stateless rule groups in a single policy. AWS Network Firewall applies each stateless rule group to a packet starting with the group that has the lowest priority setting. */ priority: number; /** * ARN of the stateless rule group. */ resourceArn: string; } interface FirewallSubnetMapping { /** * The subnet's IP address type. Valid values: `"DUALSTACK"`, `"IPV4"`. */ ipAddressType: string; /** * The unique identifier for the subnet. */ subnetId: string; } interface FirewallTransitGatewayAttachmentAccepterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface GetFirewallAvailabilityZoneMapping { /** * The ID of the Availability Zone where the firewall endpoint is located. */ availabilityZoneId: string; } interface GetFirewallEncryptionConfiguration { /** * The ID of the KMS customer managed key. */ keyId: string; /** * The type of the KMS key use by the firewall. */ type: string; } interface GetFirewallFirewallStatus { /** * Aggregated count of all resources used by reference sets in a firewall. */ capacityUsageSummaries: outputs.networkfirewall.GetFirewallFirewallStatusCapacityUsageSummary[]; /** * Summary of sync states for all availability zones in which the firewall is configured. */ configurationSyncStateSummary: string; /** * The current status of the firewall endpoint instantiation in the subnet. */ status: string; /** * Set of subnets configured for use by the firewall. */ syncStates: outputs.networkfirewall.GetFirewallFirewallStatusSyncState[]; /** * Set of transit gateway configured for use by the firewall. */ transitGatewayAttachmentSyncStates: outputs.networkfirewall.GetFirewallFirewallStatusTransitGatewayAttachmentSyncState[]; } interface GetFirewallFirewallStatusCapacityUsageSummary { /** * Capacity usage of CIDR blocks used by IP set references in a firewall. */ cidrs: outputs.networkfirewall.GetFirewallFirewallStatusCapacityUsageSummaryCidr[]; } interface GetFirewallFirewallStatusCapacityUsageSummaryCidr { /** * Available number of CIDR blocks available for use by the IP set references in a firewall. */ availableCidrCount: number; /** * The list of IP set references used by a firewall. */ ipSetReferences: outputs.networkfirewall.GetFirewallFirewallStatusCapacityUsageSummaryCidrIpSetReference[]; /** * Number of CIDR blocks used by the IP set references in a firewall. */ utilizedCidrCount: number; } interface GetFirewallFirewallStatusCapacityUsageSummaryCidrIpSetReference { /** * Total number of CIDR blocks used by the IP set references in a firewall. */ resolvedCidrCount: number; } interface GetFirewallFirewallStatusSyncState { /** * Nested list describing the attachment status of the firewall's association with a single VPC subnet. */ attachments: outputs.networkfirewall.GetFirewallFirewallStatusSyncStateAttachment[]; /** * The Availability Zone where the subnet is configured. */ availabilityZone: string; } interface GetFirewallFirewallStatusSyncStateAttachment { /** * The identifier of the firewall endpoint that AWS Network Firewall has instantiated in the subnet. You use this to identify the firewall endpoint in the VPC route tables, when you redirect the VPC traffic through the endpoint. */ endpointId: string; /** * The current status of the firewall endpoint instantiation in the subnet. */ status: string; /** * A message providing additional information about the current status. */ statusMessage: string; /** * The unique identifier for the subnet. */ subnetId: string; } interface GetFirewallFirewallStatusTransitGatewayAttachmentSyncState { /** * The unique identifier of the transit gateway attachment. */ attachmentId: string; /** * A message providing additional information about the current status. */ statusMessage: string; /** * The current status of the transit gateway attachment. */ transitGatewayAttachmentStatus: string; } interface GetFirewallPolicyFirewallPolicy { enableTlsSessionHolding: boolean; policyVariables: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyPolicyVariable[]; statefulDefaultActions: string[]; statefulEngineOptions: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatefulEngineOption[]; statefulRuleGroupReferences: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatefulRuleGroupReference[]; statelessCustomActions: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatelessCustomAction[]; statelessDefaultActions: string[]; statelessFragmentDefaultActions: string[]; statelessRuleGroupReferences: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatelessRuleGroupReference[]; tlsInspectionConfigurationArn: string; } interface GetFirewallPolicyFirewallPolicyPolicyVariable { ruleVariables: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyPolicyVariableRuleVariable[]; } interface GetFirewallPolicyFirewallPolicyPolicyVariableRuleVariable { ipSets: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyPolicyVariableRuleVariableIpSet[]; key: string; } interface GetFirewallPolicyFirewallPolicyPolicyVariableRuleVariableIpSet { definitions: string[]; } interface GetFirewallPolicyFirewallPolicyStatefulEngineOption { flowTimeouts: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatefulEngineOptionFlowTimeout[]; ruleOrder: string; streamExceptionPolicy: string; } interface GetFirewallPolicyFirewallPolicyStatefulEngineOptionFlowTimeout { tcpIdleTimeoutSeconds: number; } interface GetFirewallPolicyFirewallPolicyStatefulRuleGroupReference { deepThreatInspection: string; overrides: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatefulRuleGroupReferenceOverride[]; priority: number; resourceArn: string; } interface GetFirewallPolicyFirewallPolicyStatefulRuleGroupReferenceOverride { action: string; } interface GetFirewallPolicyFirewallPolicyStatelessCustomAction { actionDefinitions: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatelessCustomActionActionDefinition[]; actionName: string; } interface GetFirewallPolicyFirewallPolicyStatelessCustomActionActionDefinition { publishMetricActions: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricAction[]; } interface GetFirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricAction { dimensions: outputs.networkfirewall.GetFirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricActionDimension[]; } interface GetFirewallPolicyFirewallPolicyStatelessCustomActionActionDefinitionPublishMetricActionDimension { value: string; } interface GetFirewallPolicyFirewallPolicyStatelessRuleGroupReference { priority: number; resourceArn: string; } interface GetFirewallSubnetMapping { /** * The unique identifier for the subnet. */ subnetId: string; } interface LoggingConfigurationLoggingConfiguration { /** * Set of configuration blocks describing the logging details for a firewall. See Log Destination Config below for details. At most, only Three blocks can be specified; one for `FLOW` logs and one for `ALERT` logs and one for `TLS` logs. */ logDestinationConfigs: outputs.networkfirewall.LoggingConfigurationLoggingConfigurationLogDestinationConfig[]; } interface LoggingConfigurationLoggingConfigurationLogDestinationConfig { /** * A map describing the logging destination for the chosen `logDestinationType`. * * For an Amazon S3 bucket, specify the key `bucketName` with the name of the bucket and optionally specify the key `prefix` with a path (Do not add a leading / in the `prefix` as the configuration will have two // when applied). * * For a CloudWatch log group, specify the key `logGroup` with the name of the CloudWatch log group. * * For a Kinesis Data Firehose delivery stream, specify the key `deliveryStream` with the name of the delivery stream. */ logDestination: { [key: string]: string; }; /** * The location to send logs to. Valid values: `S3`, `CloudWatchLogs`, `KinesisDataFirehose`. */ logDestinationType: string; /** * The type of log to send. Valid values: `ALERT` or `FLOW` or `TLS`. Alert logs report traffic that matches a `StatefulRule` with an action setting that sends a log message. Flow logs are standard network traffic flow logs. */ logType: string; } interface RuleGroupEncryptionConfiguration { /** * The ID of the customer managed key. You can use any of the [key identifiers](https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html#key-id) that KMS supports, unless you're using a key that's managed by another account. If you're using a key managed by another account, then specify the key ARN. */ keyId?: string; /** * The type of AWS KMS key to use for encryption of your Network Firewall resources. Valid values are `CUSTOMER_KMS` and `AWS_OWNED_KMS_KEY`. */ type: string; } interface RuleGroupRuleGroup { /** * A configuration block that defines the IP Set References for the rule group. See Reference Sets below for details. Please notes that there can only be a maximum of 5 `referenceSets` in a `ruleGroup`. See the [AWS documentation](https://docs.aws.amazon.com/network-firewall/latest/developerguide/rule-groups-ip-set-references.html#rule-groups-ip-set-reference-limits) for details. */ referenceSets?: outputs.networkfirewall.RuleGroupRuleGroupReferenceSets; /** * A configuration block that defines additional settings available to use in the rules defined in the rule group. Can only be specified for **stateful** rule groups. See Rule Variables below for details. */ ruleVariables?: outputs.networkfirewall.RuleGroupRuleGroupRuleVariables; /** * A configuration block that defines the stateful or stateless rules for the rule group. See Rules Source below for details. */ rulesSource: outputs.networkfirewall.RuleGroupRuleGroupRulesSource; /** * A configuration block that defines stateful rule options for the rule group. See Stateful Rule Options below for details. */ statefulRuleOptions?: outputs.networkfirewall.RuleGroupRuleGroupStatefulRuleOptions; } interface RuleGroupRuleGroupReferenceSets { ipSetReferences?: outputs.networkfirewall.RuleGroupRuleGroupReferenceSetsIpSetReference[]; } interface RuleGroupRuleGroupReferenceSetsIpSetReference { /** * Set of configuration blocks that define the IP Reference information. See IP Set Reference below for details. */ ipSetReferences: outputs.networkfirewall.RuleGroupRuleGroupReferenceSetsIpSetReferenceIpSetReference[]; key: string; } interface RuleGroupRuleGroupReferenceSetsIpSetReferenceIpSetReference { /** * Set of Managed Prefix IP ARN(s) */ referenceArn: string; } interface RuleGroupRuleGroupRuleVariables { /** * Set of configuration blocks that define IP address information. See IP Sets below for details. */ ipSets?: outputs.networkfirewall.RuleGroupRuleGroupRuleVariablesIpSet[]; /** * Set of configuration blocks that define port range information. See Port Sets below for details. */ portSets?: outputs.networkfirewall.RuleGroupRuleGroupRuleVariablesPortSet[]; } interface RuleGroupRuleGroupRuleVariablesIpSet { /** * A configuration block that defines a set of IP addresses. See IP Set below for details. */ ipSet: outputs.networkfirewall.RuleGroupRuleGroupRuleVariablesIpSetIpSet; /** * A unique alphanumeric string to identify the `ipSet`. */ key: string; } interface RuleGroupRuleGroupRuleVariablesIpSetIpSet { /** * Set of IP addresses and address ranges, in CIDR notation. */ definitions: string[]; } interface RuleGroupRuleGroupRuleVariablesPortSet { /** * An unique alphanumeric string to identify the `portSet`. */ key: string; /** * A configuration block that defines a set of port ranges. See Port Set below for details. */ portSet: outputs.networkfirewall.RuleGroupRuleGroupRuleVariablesPortSetPortSet; } interface RuleGroupRuleGroupRuleVariablesPortSetPortSet { /** * Set of port ranges. */ definitions: string[]; } interface RuleGroupRuleGroupRulesSource { /** * A configuration block containing **stateful** inspection criteria for a domain list rule group. See Rules Source List below for details. */ rulesSourceList?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceRulesSourceList; /** * Stateful inspection criteria, provided in Suricata compatible rules. These rules contain the inspection criteria and the action to take for traffic that matches the criteria, so this type of rule group doesn’t have a separate action setting. */ rulesString?: string; /** * Set of configuration blocks containing **stateful** inspection criteria for 5-tuple rules to be used together in a rule group. See Stateful Rule below for details. */ statefulRules?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatefulRule[]; /** * A configuration block containing **stateless** inspection criteria for a stateless rule group. See Stateless Rules and Custom Actions below for details. */ statelessRulesAndCustomActions?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActions; } interface RuleGroupRuleGroupRulesSourceRulesSourceList { /** * String value to specify whether domains in the target list are allowed or denied access. Valid values: `ALLOWLIST`, `DENYLIST`. */ generatedRulesType: string; /** * Set of types of domain specifications that are provided in the `targets` argument. Valid values: `HTTP_HOST`, `TLS_SNI`. */ targetTypes: string[]; /** * Set of domains that you want to inspect for in your traffic flows. */ targets: string[]; } interface RuleGroupRuleGroupRulesSourceStatefulRule { /** * Action to take with packets in a traffic flow when the flow matches the stateful rule criteria. For all actions, AWS Network Firewall performs the specified action and discontinues stateful inspection of the traffic flow. Valid values: `ALERT`, `DROP`, `PASS`, or `REJECT`. */ action: string; /** * A configuration block containing the stateful 5-tuple inspection criteria for the rule, used to inspect traffic flows. See Header below for details. */ header: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatefulRuleHeader; /** * Set of configuration blocks containing additional settings for a stateful rule. See Rule Option below for details. */ ruleOptions: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatefulRuleRuleOption[]; } interface RuleGroupRuleGroupRulesSourceStatefulRuleHeader { /** * The destination IP address or address range to inspect for, in CIDR notation. To match with any address, specify `ANY`. */ destination: string; /** * The destination port to inspect for. To match with any address, specify `ANY`. */ destinationPort: string; /** * The direction of traffic flow to inspect. Valid values: `ANY` or `FORWARD`. */ direction: string; /** * The protocol to inspect. Valid values: `IP`, `TCP`, `UDP`, `ICMP`, `HTTP`, `FTP`, `TLS`, `SMB`, `DNS`, `DCERPC`, `SSH`, `SMTP`, `IMAP`, `MSN`, `KRB5`, `IKEV2`, `TFTP`, `NTP`, `DHCP`. */ protocol: string; /** * The source IP address or address range for, in CIDR notation. To match with any address, specify `ANY`. */ source: string; /** * The source port to inspect for. To match with any address, specify `ANY`. */ sourcePort: string; } interface RuleGroupRuleGroupRulesSourceStatefulRuleRuleOption { /** * Keyword defined by open source detection systems like Snort or Suricata for stateful rule inspection. * See [Snort General Rule Options](http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node31.html) or [Suricata Rule Options](https://suricata.readthedocs.io/en/suricata-5.0.1/rules/intro.html#rule-options) for more details. */ keyword: string; /** * Set of strings for additional settings to use in stateful rule inspection. */ settings?: string[]; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActions { /** * Set of configuration blocks containing custom action definitions that are available for use by the set of `stateless rule`. See Custom Action below for details. */ customActions?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomAction[]; /** * Set of configuration blocks containing the stateless rules for use in the stateless rule group. See Stateless Rule below for details. */ statelessRules: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRule[]; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomAction { /** * A configuration block describing the custom action associated with the `actionName`. See Action Definition below for details. */ actionDefinition: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomActionActionDefinition; /** * A friendly name of the custom action. */ actionName: string; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomActionActionDefinition { /** * A configuration block describing the stateless inspection criteria that publishes the specified metrics to Amazon CloudWatch for the matching packet. You can pair this custom action with any of the standard stateless rule actions. See Publish Metric Action below for details. */ publishMetricAction: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomActionActionDefinitionPublishMetricAction; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomActionActionDefinitionPublishMetricAction { /** * Set of configuration blocks containing the dimension settings to use for Amazon CloudWatch custom metrics. See Dimension below for details. */ dimensions: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomActionActionDefinitionPublishMetricActionDimension[]; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsCustomActionActionDefinitionPublishMetricActionDimension { /** * The value to use in the custom metric dimension. */ value: string; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRule { /** * A setting that indicates the order in which to run this rule relative to all of the rules that are defined for a stateless rule group. AWS Network Firewall evaluates the rules in a rule group starting with the lowest priority setting. */ priority: number; /** * A configuration block defining the stateless 5-tuple packet inspection criteria and the action to take on a packet that matches the criteria. See Rule Definition below for details. */ ruleDefinition: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinition; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinition { /** * Set of actions to take on a packet that matches one of the stateless rule definition's `matchAttributes`. For every rule you must specify 1 standard action, and you can add custom actions. Standard actions include: `aws:pass`, `aws:drop`, `aws:forward_to_sfe`. */ actions: string[]; /** * A configuration block containing criteria for AWS Network Firewall to use to inspect an individual packet in stateless rule inspection. See Match Attributes below for details. */ matchAttributes: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributes; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributes { /** * Set of configuration blocks describing the destination ports to inspect for. If not specified, this matches with any destination port. See Destination Port below for details. */ destinationPorts?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesDestinationPort[]; /** * Set of configuration blocks describing the destination IP address and address ranges to inspect for, in CIDR notation. If not specified, this matches with any destination address. See Destination below for details. */ destinations?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesDestination[]; /** * Set of protocols to inspect for, specified using the protocol's assigned IP number (IANA). If not specified, this matches with any protocol. */ protocols?: number[]; /** * Set of configuration blocks describing the source ports to inspect for. If not specified, this matches with any source port. See Source Port below for details. */ sourcePorts?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesSourcePort[]; /** * Set of configuration blocks describing the source IP address and address ranges to inspect for, in CIDR notation. If not specified, this matches with any source address. See Source below for details. */ sources?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesSource[]; /** * Set of configuration blocks containing the TCP flags and masks to inspect for. If not specified, this matches with any settings. */ tcpFlags?: outputs.networkfirewall.RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesTcpFlag[]; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesDestination { /** * An IP address or a block of IP addresses in CIDR notation. AWS Network Firewall supports all address ranges for IPv4 and IPv6. */ addressDefinition: string; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesDestinationPort { /** * The lower limit of the port range. This must be less than or equal to the `toPort`. */ fromPort: number; /** * The upper limit of the port range. This must be greater than or equal to the `fromPort`. */ toPort?: number; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesSource { /** * An IP address or a block of IP addresses in CIDR notation. AWS Network Firewall supports all address ranges for IPv4 and IPv6. */ addressDefinition: string; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesSourcePort { /** * The lower limit of the port range. This must be less than or equal to the `toPort`. */ fromPort: number; /** * The upper limit of the port range. This must be greater than or equal to the `fromPort`. */ toPort?: number; } interface RuleGroupRuleGroupRulesSourceStatelessRulesAndCustomActionsStatelessRuleRuleDefinitionMatchAttributesTcpFlag { /** * Set of flags to look for in a packet. This setting can only specify values that are also specified in `masks`. * Valid values: `FIN`, `SYN`, `RST`, `PSH`, `ACK`, `URG`, `ECE`, `CWR`. */ flags: string[]; /** * Set of flags to consider in the inspection. To inspect all flags, leave this empty. * Valid values: `FIN`, `SYN`, `RST`, `PSH`, `ACK`, `URG`, `ECE`, `CWR`. */ masks?: string[]; } interface RuleGroupRuleGroupStatefulRuleOptions { /** * Indicates how to manage the order of the rule evaluation for the rule group. Default value: `DEFAULT_ACTION_ORDER`. Valid values: `DEFAULT_ACTION_ORDER`, `STRICT_ORDER`. */ ruleOrder: string; } interface TlsInspectionConfigurationCertificate { /** * ARN of the certificate. */ certificateArn: string; /** * Serial number of the certificate. */ certificateSerial: string; /** * Status of the certificate. */ status: string; /** * Details about the certificate status, including information about certificate errors. */ statusMessage: string; } interface TlsInspectionConfigurationCertificateAuthority { /** * ARN of the certificate. */ certificateArn: string; /** * Serial number of the certificate. */ certificateSerial: string; /** * Status of the certificate. */ status: string; /** * Details about the certificate status, including information about certificate errors. */ statusMessage: string; } interface TlsInspectionConfigurationEncryptionConfiguration { /** * ARN of the Amazon Web Services KMS customer managed key. */ keyId: string; /** * Type of KMS key to use for encryption of your Network Firewall resources. Valid values: `AWS_OWNED_KMS_KEY`, `CUSTOMER_KMS`. */ type: string; } interface TlsInspectionConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface TlsInspectionConfigurationTlsInspectionConfiguration { /** * Server certificate configurations that are associated with the TLS configuration. Detailed below. */ serverCertificateConfiguration: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfiguration; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfiguration { /** * ARN of the imported certificate authority (CA) certificate within Certificate Manager (ACM) to use for outbound SSL/TLS inspection. See [Using SSL/TLS certificates with TLS inspection configurations](https://docs.aws.amazon.com/network-firewall/latest/developerguide/tls-inspection-certificate-requirements.html) for limitations on CA certificates. */ certificateAuthorityArn?: string; /** * Check Certificate Revocation Status block. Detailed below. */ checkCertificateRevocationStatus?: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationCheckCertificateRevocationStatus; /** * Scope block. Detailed below. */ scopes: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScope[]; /** * Server certificates to use for inbound SSL/TLS inspection. See [Using SSL/TLS certificates with TLS inspection configurations](https://docs.aws.amazon.com/network-firewall/latest/developerguide/tls-inspection-certificate-requirements.html). */ serverCertificates?: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationServerCertificate[]; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationCheckCertificateRevocationStatus { revokedStatusAction?: string; unknownStatusAction?: string; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScope { /** * Set of configuration blocks describing the destination ports to inspect for. If not specified, this matches with any destination port. See Destination Ports below for details. */ destinationPorts?: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeDestinationPort[]; /** * Set of configuration blocks describing the destination IP address and address ranges to inspect for, in CIDR notation. If not specified, this matches with any destination address. See Destination below for details. */ destinations: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeDestination[]; /** * Set of protocols to inspect for, specified using the protocol's assigned IP number (IANA). Network Firewall currently supports TCP only. Valid values: `6` */ protocols: number[]; /** * Set of configuration blocks describing the source ports to inspect for. If not specified, this matches with any source port. See Source Ports below for details. */ sourcePorts?: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeSourcePort[]; /** * Set of configuration blocks describing the source IP address and address ranges to inspect for, in CIDR notation. If not specified, this matches with any source address. See Source below for details. */ sources?: outputs.networkfirewall.TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeSource[]; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeDestination { /** * An IP address or a block of IP addresses in CIDR notation. AWS Network Firewall supports all address ranges for IPv4. */ addressDefinition: string; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeDestinationPort { /** * The lower limit of the port range. This must be less than or equal to the `toPort`. */ fromPort: number; /** * The upper limit of the port range. This must be greater than or equal to the `fromPort`. */ toPort: number; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeSource { /** * An IP address or a block of IP addresses in CIDR notation. AWS Network Firewall supports all address ranges for IPv4. */ addressDefinition: string; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationScopeSourcePort { /** * The lower limit of the port range. This must be less than or equal to the `toPort`. */ fromPort: number; /** * The upper limit of the port range. This must be greater than or equal to the `fromPort`. */ toPort: number; } interface TlsInspectionConfigurationTlsInspectionConfigurationServerCertificateConfigurationServerCertificate { /** * ARN of the Certificate Manager SSL/TLS server certificate that's used for inbound SSL/TLS inspection. */ resourceArn?: string; } interface VpcEndpointAssociationSubnetMapping { /** * The subnet's IP address type. Valid values: `"DUALSTACK"`, `"IPV4"`. */ ipAddressType: string; /** * The unique identifier for the subnet. */ subnetId: string; } interface VpcEndpointAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface VpcEndpointAssociationVpcEndpointAssociationStatus { /** * Set of subnets configured for use by the VPC Endpoint Association. */ associationSyncStates: outputs.networkfirewall.VpcEndpointAssociationVpcEndpointAssociationStatusAssociationSyncState[]; } interface VpcEndpointAssociationVpcEndpointAssociationStatusAssociationSyncState { /** * Nested list describing the attachment status of the firewall's VPC Endpoint Association with a single VPC subnet. */ attachments: outputs.networkfirewall.VpcEndpointAssociationVpcEndpointAssociationStatusAssociationSyncStateAttachment[]; /** * The Availability Zone where the subnet is configured. */ availabilityZone: string; } interface VpcEndpointAssociationVpcEndpointAssociationStatusAssociationSyncStateAttachment { /** * The identifier of the VPC endpoint that AWS Network Firewall has instantiated in the subnet. You use this to identify the firewall endpoint in the VPC route tables, when you redirect the VPC traffic through the endpoint. */ endpointId: string; status: string; statusMessage: string; /** * The unique identifier of the subnet that you've specified to be used for a VPC Endpoint Association endpoint. */ subnetId: string; } } export declare namespace networkflowmonitor { interface MonitorLocalResource { /** * The identifier of the resource. For VPC resources, this is the VPC ARN. */ identifier: string; /** * The type of the resource. Valid values are `AWS::EC2::VPC`, `AWS::EC2::Subnet`, `AWS::EC2::AvailabilityZone`, `AWS::EC2::Region`, and `AWS::EKS::Cluster`. */ type: string; } interface MonitorRemoteResource { /** * The identifier of the resource. For VPC resources, this is the VPC ARN. */ identifier: string; /** * The type of the resource. Valid values are `AWS::EC2::VPC`, `AWS::EC2::Subnet`, `AWS::EC2::AvailabilityZone`, `AWS::EC2::Region`, and `AWS::EKS::Cluster`. */ type: string; } interface MonitorTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ScopeTarget { /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * A target identifier is a pair of identifying information for a scope. */ targetIdentifier: outputs.networkflowmonitor.ScopeTargetTargetIdentifier; } interface ScopeTargetTargetIdentifier { /** * The identifier for a target, which is currently always an account ID. */ targetId: outputs.networkflowmonitor.ScopeTargetTargetIdentifierTargetId; /** * The type of a target. A target type is currently always `ACCOUNT`. */ targetType: string; } interface ScopeTargetTargetIdentifierTargetId { /** * AWS account ID. */ accountId: string; } interface ScopeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace networkmanager { interface ConnectAttachmentOptions { /** * Protocol used for the attachment connection. Valid values: `GRE`, `NO_ENCAP`. */ protocol?: string; } interface ConnectPeerBgpOptions { /** * Peer ASN. Supports 2-byte and 4-byte ASNs (1 to 4294967295). */ peerAsn: string; } interface ConnectPeerConfiguration { bgpConfigurations: outputs.networkmanager.ConnectPeerConfigurationBgpConfiguration[]; /** * Connect peer core network address. */ coreNetworkAddress: string; /** * Inside IP addresses used for BGP peering. Required when the Connect attachment protocol is `GRE`. See `aws.networkmanager.ConnectAttachment` for details. */ insideCidrBlocks: string[]; /** * Connect peer address. * * The following arguments are optional: */ peerAddress: string; protocol: string; } interface ConnectPeerConfigurationBgpConfiguration { /** * Connect peer core network address. */ coreNetworkAddress: string; coreNetworkAsn: number; /** * Connect peer address. * * The following arguments are optional: */ peerAddress: string; /** * Peer ASN. Supports 2-byte and 4-byte ASNs (1 to 4294967295). */ peerAsn: string; } interface CoreNetworkEdge { /** * ASN of a core network edge. */ asn: number; /** * Region where a core network edge is located. */ edgeLocation: string; /** * Inside IP addresses used for core network edges. */ insideCidrBlocks: string[]; } interface CoreNetworkSegment { /** * Regions where the edges are located. */ edgeLocations: string[]; /** * Name of a core network segment. */ name: string; /** * Shared segments of a core network. */ sharedSegments: string[]; } interface DeviceAwsLocation { /** * ARN of the subnet that the device is located in. */ subnetArn?: string; /** * Zone that the device is located in. Specify the ID of an Availability Zone, Local Zone, Wavelength Zone, or an Outpost. */ zone?: string; } interface DeviceLocation { /** * Physical address. */ address?: string; /** * Latitude. */ latitude?: string; /** * Longitude. */ longitude?: string; } interface DxGatewayAttachmentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GetCoreNetworkEdge { /** * ASN of the core network edge. */ asn: number; /** * AWS region where the edge is located. */ edgeLocation: string; /** * Inside IP addresses used for core network edges. */ insideCidrBlocks: string[]; } interface GetCoreNetworkNetworkFunctionGroup { /** * AWS regions where the edges are located. */ edgeLocations: string[]; /** * Name of the core network segment. */ name: string; /** * Segments associated with the network function group. See `network_function_groups.segments` Attribute Reference for details. */ segments: outputs.networkmanager.GetCoreNetworkNetworkFunctionGroupSegment[]; } interface GetCoreNetworkNetworkFunctionGroupSegment { /** * List of segments associated with the `send-to` action. */ sendTos: string[]; /** * List of segments associated with the `send-via` action. */ sendVias: string[]; } interface GetCoreNetworkPolicyDocumentAttachmentPolicy { /** * Action to take when a condition is true. Detailed Below. */ action: outputs.networkmanager.GetCoreNetworkPolicyDocumentAttachmentPolicyAction; /** * Valid values include `and` or `or`. This is a mandatory parameter only if you have more than one condition. The `conditionLogic` apply to all of the conditions for a rule, which also means nested conditions of `and` or `or` are not supported. Use `or` if you want to associate the attachment with the segment by either the segment name or attachment tag value, or by the chosen conditions. Use `and` if you want to associate the attachment with the segment by either the segment name or attachment tag value and by the chosen conditions. Detailed Below. */ conditionLogic?: string; /** * A block argument. Detailed Below. */ conditions: outputs.networkmanager.GetCoreNetworkPolicyDocumentAttachmentPolicyCondition[]; /** * A user-defined description that further helps identify the rule. */ description?: string; /** * An integer from `1` to `65535` indicating the rule's order number. Rules are processed in order from the lowest numbered rule to the highest. Rules stop processing when a rule is matched. It's important to make sure that you number your rules in the exact order that you want them processed. */ ruleNumber: number; } interface GetCoreNetworkPolicyDocumentAttachmentPolicyAction { /** * The name of the network function group to attach to the attachment policy. */ addToNetworkFunctionGroup?: string; /** * Defines how a segment is mapped. Values can be `constant` or `tag`. `constant` statically defines the segment to associate the attachment to. `tag` uses the value of a tag to dynamically try to map to a segment.reference_policies_elements_condition_operators.html) to evaluate. */ associationMethod?: string; /** * Determines if this mapping should override the segment value for `requireAttachmentAcceptance`. You can only set this to `true`, indicating that this setting applies only to segments that have `requireAttachmentAcceptance` set to `false`. If the segment already has the default `requireAttachmentAcceptance`, you can set this to inherit segment’s acceptance value. */ requireAcceptance?: boolean; /** * Name of the `segment` to share as defined in the `segments` section. This is used only when the `associationMethod` is `constant`. */ segment?: string; /** * Maps the attachment to the value of a known key. This is used with the `associationMethod` is `tag`. For example a `tag` of `stage = “test”`, will map to a segment named `test`. The value must exactly match the name of a segment. This allows you to have many segments, but use only a single rule without having to define multiple nearly identical conditions. This prevents creating many similar conditions that all use the same keys to map to segments. */ tagValueOfKey?: string; } interface GetCoreNetworkPolicyDocumentAttachmentPolicyCondition { /** * string value */ key?: string; /** * Valid values include: `equals`, `not-equals`, `contains`, `begins-with`. */ operator?: string; /** * Must be `routing-policy-label`. */ type: string; /** * Routing policy label to match. */ value?: string; } interface GetCoreNetworkPolicyDocumentAttachmentRoutingPolicyRule { /** * Block defining the action to take when conditions match. Detailed below. */ action: outputs.networkmanager.GetCoreNetworkPolicyDocumentAttachmentRoutingPolicyRuleAction; /** * A block argument. Detailed below. */ conditions: outputs.networkmanager.GetCoreNetworkPolicyDocumentAttachmentRoutingPolicyRuleCondition[]; /** * A user-defined description that further helps identify the rule. */ description?: string; /** * A set of AWS Region codes where this rule applies. */ edgeLocations?: string[]; /** * An integer from `1` to `65535` indicating the rule's order number. Rules are processed in order from the lowest numbered rule to the highest. Rules stop processing when a rule is matched. */ ruleNumber: number; } interface GetCoreNetworkPolicyDocumentAttachmentRoutingPolicyRuleAction { /** * Set of routing policy names to associate when the conditions match. */ associateRoutingPolicies: string[]; } interface GetCoreNetworkPolicyDocumentAttachmentRoutingPolicyRuleCondition { /** * Must be `routing-policy-label`. */ type: string; /** * Routing policy label to match. */ value: string; } interface GetCoreNetworkPolicyDocumentCoreNetworkConfiguration { /** * List of strings containing Autonomous System Numbers (ASNs) to assign to Core Network Edges. By default, the core network automatically assigns an ASN for each Core Network Edge but you can optionally define the ASN in the edge-locations for each Region. The ASN uses an array of integer ranges only from `64512` to `65534` and `4200000000` to `4294967294` expressed as a string like `"64512-65534"`. No other ASN ranges can be used. */ asnRanges: string[]; /** * Indicates whether DNS resolution is enabled for the core network. The value can be either `true` or `false`. When set to `true`, DNS resolution is enabled for VPCs attached to the core network, allowing resources in different VPCs to resolve each other's domain names. The default is `true`. */ dnsSupport?: boolean; /** * A block value of AWS Region locations where you're creating Core Network Edges. Detailed below. */ edgeLocations: outputs.networkmanager.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocation[]; /** * The Classless Inter-Domain Routing (CIDR) block range used to create tunnels for AWS Transit Gateway Connect. The format is standard AWS CIDR range (for example, `10.0.1.0/24`). You can optionally define the inside CIDR in the Core Network Edges section per Region. The minimum is a `/24` for IPv4 or `/64` for IPv6. You can provide multiple `/24` subnets or a larger CIDR range. If you define a larger CIDR range, new Core Network Edges will be automatically assigned `/24` and `/64` subnets from the larger CIDR. an Inside CIDR block is required for attaching Connect attachments to a Core Network Edge. */ insideCidrBlocks?: string[]; /** * — (Optional) Indicates whether security group referencing is enabled for the core network. The value can be either `true` or `false`. When set to `true`, security groups in one VPC can reference security groups in another VPC attached to the core network, enabling more flexible security configurations across your network. The default is `false`. */ securityGroupReferencingSupport?: boolean; /** * Indicates whether the core network forwards traffic over multiple equal-cost routes using VPN. The value can be either `true` or `false`. The default is `true`. */ vpnEcmpSupport?: boolean; } interface GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocation { /** * ASN of the Core Network Edge in an AWS Region. By default, the ASN will be a single integer automatically assigned from `asnRanges` */ asn?: string; /** * The local CIDR blocks for this Core Network Edge for AWS Transit Gateway Connect attachments. By default, this CIDR block will be one or more optional IPv4 and IPv6 CIDR prefixes auto-assigned from `insideCidrBlocks`. */ insideCidrBlocks?: string[]; location: string; } interface GetCoreNetworkPolicyDocumentNetworkFunctionGroup { /** * Optional description of the network function group. */ description?: string; /** * This identifies the network function group container. */ name: string; /** * This will be either `true`, that attachment acceptance is required, or `false`, that it is not required. */ requireAttachmentAcceptance: boolean; } interface GetCoreNetworkPolicyDocumentRoutingPolicy { /** * Description of the routing policy. */ routingPolicyDescription?: string; /** * Direction of the routing policy. Valid values: `inbound`, `outbound`. */ routingPolicyDirection: string; /** * Name of the routing policy. Must be 1-100 alphanumeric characters. */ routingPolicyName: string; /** * Priority number for the routing policy. Must be between 1 and 9999. Lower numbers are evaluated first. */ routingPolicyNumber: number; /** * List of routing policy rules. Each rule defines match conditions and actions. Detailed below. */ routingPolicyRules: outputs.networkmanager.GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRule[]; } interface GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRule { /** * Defines the match conditions and actions for the rule. Detailed below. */ ruleDefinition: outputs.networkmanager.GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRuleRuleDefinition; /** * Priority number for the rule within the routing policy. Must be between 1 and 9999. Lower numbers are evaluated first. */ ruleNumber: number; } interface GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRuleRuleDefinition { /** * Block defining the action to take when conditions match. Detailed below. */ action: outputs.networkmanager.GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRuleRuleDefinitionAction; /** * Logic to apply when multiple match conditions are present. Valid values: `and`, `or`. */ conditionLogic?: string; /** * List of conditions to match against routes. Detailed below. */ matchConditions?: outputs.networkmanager.GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRuleRuleDefinitionMatchCondition[]; } interface GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRuleRuleDefinitionAction { /** * Type of action to perform. Valid values: `drop`, `allow`, `summarize`, `prepend-asn-list`, `remove-asn-list`, `replace-asn-list`, `add-community`, `remove-community`, `set-med`, `set-local-preference`. */ type: string; /** * Value for the action, required for certain action types. */ value?: string; } interface GetCoreNetworkPolicyDocumentRoutingPolicyRoutingPolicyRuleRuleDefinitionMatchCondition { /** * Type of condition to match. Valid values: `prefix-equals`, `prefix-in-cidr`, `prefix-in-prefix-list`, `asn-in-as-path`, `community-in-list`, `med-equals`. */ type: string; /** * Value to match against, depending on the condition type. */ value: string; } interface GetCoreNetworkPolicyDocumentSegment { /** * List of strings of segment names that explicitly allows only routes from the segments that are listed in the array. Use the `allowFilter` setting if a segment has a well-defined group of other segments that connectivity should be restricted to. It is applied after routes have been shared in `segmentActions`. If a segment is listed in `allowFilter`, attachments between the two segments will have routes if they are also shared in the segment-actions area. For example, you might have a segment named "video-producer" that should only ever share routes with a "video-distributor" segment, no matter how many other share statements are created. */ allowFilters?: string[]; /** * An array of segments that disallows routes from the segments listed in the array. It is applied only after routes have been shared in `segmentActions`. If a segment is listed in the `denyFilter`, attachments between the two segments will never have routes shared across them. For example, you might have a "financial" payment segment that should never share routes with a "development" segment, regardless of how many other share statements are created. Adding the payments segment to the deny-filter parameter prevents any shared routes from being created with other segments. */ denyFilters?: string[]; /** * A user-defined string describing the segment. */ description?: string; /** * A list of strings of AWS Region names. Allows you to define a more restrictive set of Regions for a segment. The edge location must be a subset of the locations that are defined for `edgeLocations` in the `coreNetworkConfiguration`. */ edgeLocations?: string[]; /** * This Boolean setting determines whether attachments on the same segment can communicate with each other. If set to `true`, the only routes available will be either shared routes through the share actions, which are attachments in other segments, or static routes. The default value is `false`. For example, you might have a segment dedicated to "development" that should never allow VPCs to talk to each other, even if they’re on the same segment. In this example, you would keep the default parameter of `false`. */ isolateAttachments?: boolean; /** * Unique name for a segment. The name is a string used in other parts of the policy document, as well as in the console for metrics and other reference points. Valid characters are a–z, and 0–9. */ name: string; /** * This Boolean setting determines whether attachment requests are automatically approved or require acceptance. The default is `true`, indicating that attachment requests require acceptance. For example, you might use this setting to allow a "sandbox" segment to allow any attachment request so that a core network or attachment administrator does not need to review and approve attachment requests. In this example, `requireAttachmentAcceptance` is set to `false`. */ requireAttachmentAcceptance?: boolean; } interface GetCoreNetworkPolicyDocumentSegmentAction { /** * Action to take for the chosen segment. Valid values: `create-route`, `share`, `send-via`, `send-to`, and `associate-routing-policy` (available in policy version `2025.11` and later). */ action: string; /** * A user-defined string describing the segment action. */ description?: string; /** * List of strings containing CIDRs. You can define the IPv4 and IPv6 CIDR notation for each AWS Region. For example, `10.1.0.0/16` or `2001:db8::/56`. This is an array of CIDR notation strings. */ destinationCidrBlocks?: string[]; /** * A list of strings. Valid values include `["blackhole"]` or a list of attachment ids. */ destinations?: string[]; /** * Associates routing policies with specific edge location pairs. Available in policy version `2025.11` and later. Detailed below. */ edgeLocationAssociation?: outputs.networkmanager.GetCoreNetworkPolicyDocumentSegmentActionEdgeLocationAssociation; /** * String. When `action` is `share`, a `mode` value of `attachment-route` places the attachment and return routes in each of the `shareWith` segments. When `action` is `send-via`, indicates the mode used for packets. Valid values: `attachment-route`, `single-hop`, `dual-hop`. */ mode?: string; /** * A list of routing policy names to apply to segment sharing. The routing policies control how routes are propagated between the shared segments. Only applicable when `action` is `share`. Available in policy version `2025.11` and later. */ routingPolicyNames?: string[]; /** * Name of the segment. */ segment: string; /** * A set subtraction of segments to not share with. */ shareWithExcepts?: string[]; /** * A list of strings to share with. Must be a substring is all segments. Valid values include: `["*"]` or `[""]`. */ shareWiths?: string[]; /** * The network function groups and any edge overrides associated with the action. */ via?: outputs.networkmanager.GetCoreNetworkPolicyDocumentSegmentActionVia; /** * The destination segments for the `send-via` or `send-to` `action`. */ whenSentTo?: outputs.networkmanager.GetCoreNetworkPolicyDocumentSegmentActionWhenSentTo; } interface GetCoreNetworkPolicyDocumentSegmentActionEdgeLocationAssociation { /** * The AWS Region code for the first edge location in the association (e.g., `us-east-1`). */ edgeLocation: string; /** * The AWS Region code for the second edge location in the association (e.g., `us-west-2`). */ peerEdgeLocation: string; /** * A set of routing policy names to apply to this edge location pair. */ routingPolicyNames: string[]; } interface GetCoreNetworkPolicyDocumentSegmentActionVia { /** * A list of strings. The network function group to use for the service insertion action. */ networkFunctionGroups?: string[]; /** * Any edge overrides and the preferred edge to use. */ withEdgeOverrides?: outputs.networkmanager.GetCoreNetworkPolicyDocumentSegmentActionViaWithEdgeOverride[]; } interface GetCoreNetworkPolicyDocumentSegmentActionViaWithEdgeOverride { /** * A list of a list of strings. The list of edges associated with the network function group. */ edgeSets?: string[][]; /** * The preferred edge to use. * * @deprecated use_edge is deprecated. Use useEdgeLocation instead. */ useEdge?: string; /** * The preferred edge to use. */ useEdgeLocation?: string; } interface GetCoreNetworkPolicyDocumentSegmentActionWhenSentTo { /** * A list of strings. The list of segments that the `send-via` `action` uses. */ segments?: string[]; } interface GetCoreNetworkSegment { /** * AWS regions where the edges are located. */ edgeLocations: string[]; /** * Name of the core network segment. */ name: string; /** * Shared segments of the core network. */ sharedSegments: string[]; } interface GetDeviceAwsLocation { /** * ARN of the subnet that the device is located in. */ subnetArn: string; /** * Zone that the device is located in. */ zone: string; } interface GetDeviceLocation { /** * Physical address. */ address: string; /** * Latitude. */ latitude: string; /** * Longitude. */ longitude: string; } interface GetLinkBandwidth { /** * Download speed in Mbps. */ downloadSpeed: number; /** * Upload speed in Mbps. */ uploadSpeed: number; } interface GetSiteLocation { /** * Address of the location. */ address: string; /** * Latitude of the location. */ latitude: string; /** * Longitude of the location. */ longitude: string; } interface LinkBandwidth { /** * Download speed in Mbps. */ downloadSpeed?: number; /** * Upload speed in Mbps. */ uploadSpeed?: number; } interface SiteLocation { /** * Address of the location. */ address?: string; /** * Latitude of the location. */ latitude?: string; /** * Longitude of the location. */ longitude?: string; } interface VpcAttachmentOptions { /** * Whether to enable appliance mode support. If enabled, traffic flow between a source and destination use the same Availability Zone for the VPC attachment for the lifetime of that flow. If the VPC attachment is pending acceptance, changing this value will recreate the resource. */ applianceModeSupport: boolean; /** * Whether to enable DNS support. If the VPC attachment is pending acceptance, changing this value will recreate the resource. */ dnsSupport: boolean; /** * Whether to enable IPv6 support. If the VPC attachment is pending acceptance, changing this value will recreate the resource. */ ipv6Support: boolean; /** * Whether to enable security group referencing support for this VPC attachment. The default is `true`. However, at the core network policy-level the default is set to `false`. If the VPC attachment is pending acceptance, changing this value will recreate the resource. */ securityGroupReferencingSupport: boolean; } } export declare namespace notifications { interface NotificationHubTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface OrganizationsAccessTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace oam { interface GetLinkLinkConfiguration { /** * Configuration for filtering which log groups are to send log events from the source account to the monitoring account. See `logGroupConfiguration` Block for details. */ logGroupConfigurations: outputs.oam.GetLinkLinkConfigurationLogGroupConfiguration[]; /** * Configuration for filtering which metric namespaces are to be shared from the source account to the monitoring account. See `metricConfiguration` Block for details. */ metricConfigurations: outputs.oam.GetLinkLinkConfigurationMetricConfiguration[]; } interface GetLinkLinkConfigurationLogGroupConfiguration { /** * Filter string that specifies which metrics are to be shared with the monitoring account. See [MetricConfiguration](https://docs.aws.amazon.com/OAM/latest/APIReference/API_MetricConfiguration.html) for details. */ filter: string; } interface GetLinkLinkConfigurationMetricConfiguration { /** * Filter string that specifies which metrics are to be shared with the monitoring account. See [MetricConfiguration](https://docs.aws.amazon.com/OAM/latest/APIReference/API_MetricConfiguration.html) for details. */ filter: string; } interface LinkLinkConfiguration { /** * Configuration for filtering which log groups are to send log events from the source account to the monitoring account. See `logGroupConfiguration` Block for details. */ logGroupConfiguration?: outputs.oam.LinkLinkConfigurationLogGroupConfiguration; /** * Configuration for filtering which metric namespaces are to be shared from the source account to the monitoring account. See `metricConfiguration` Block for details. */ metricConfiguration?: outputs.oam.LinkLinkConfigurationMetricConfiguration; } interface LinkLinkConfigurationLogGroupConfiguration { /** * Filter string that specifies which log groups are to share their log events with the monitoring account. See [LogGroupConfiguration](https://docs.aws.amazon.com/OAM/latest/APIReference/API_LogGroupConfiguration.html) for details. */ filter: string; } interface LinkLinkConfigurationMetricConfiguration { /** * Filter string that specifies which metrics are to be shared with the monitoring account. See [MetricConfiguration](https://docs.aws.amazon.com/OAM/latest/APIReference/API_MetricConfiguration.html) for details. */ filter: string; } } export declare namespace observabilityadmin { interface CentralizationRuleForOrganizationRule { /** * Configuration block for the destination where telemetry will be centralized. See `destination` below. */ destination: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestination; /** * Configuration block for the source of logs to be centralized. See `source` below. */ source: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleSource; } interface CentralizationRuleForOrganizationRuleDestination { /** * AWS account ID where telemetry will be centralized. */ account: string; /** * Configuration block for destination logs settings. See `destinationLogsConfiguration` below. */ destinationLogsConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfiguration; /** * Configuration block for destination metrics settings. See `destinationMetricsConfiguration` below. */ destinationMetricsConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationMetricsConfiguration; /** * AWS region where telemetry will be centralized. */ region: string; } interface CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfiguration { /** * Configuration block for backup settings. See `backupConfiguration` below. */ backupConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationBackupConfiguration; /** * Configuration block for a naming pattern for destination log groups created during centralization. See `logGroupNameConfiguration` below. */ logGroupNameConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationLogGroupNameConfiguration; /** * Configuration block for logs encryption settings. See `logsEncryptionConfiguration` below. */ logsEncryptionConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationLogsEncryptionConfiguration; /** * Configuration block for propagating source resource tags to centralized destination log groups. See `tagPropagationConfiguration` below. */ tagPropagationConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationTagPropagationConfiguration; } interface CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationBackupConfiguration { /** * ARN of the KMS key to use for backup encryption. */ kmsKeyArn?: string; /** * AWS region for backup storage. */ region?: string; } interface CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationLogGroupNameConfiguration { /** * Pattern used for generating destination log group names during centralization. The pattern can contain static text and dynamic variables that are replaced with source attributes. For supported dynamic variables, see the [AWS documentation](https://docs.aws.amazon.com/cloudwatch/latest/observabilityadmin/API_LogGroupNameConfiguration.html). Note that `$` used in dynamic variables must be escaped as `$$` in Terraform configuration. */ logGroupNamePattern: string; } interface CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationLogsEncryptionConfiguration { /** * Strategy for resolving encryption conflicts. Valid values: `ALLOW`, `SKIP`. */ encryptionConflictResolutionStrategy?: string; /** * Determines which newly created destination log groups are encrypted with `kmsKeyArn` when `encryptionStrategy` is `CUSTOMER_MANAGED`. Valid values: `ENCRYPTED_SOURCE_ONLY` (default), `NEW_DESTINATION_LOG_GROUPS`. Not valid when `encryptionStrategy` is `AWS_OWNED`. */ encryptionScope: string; /** * Encryption strategy for logs. Valid values: `AWS_OWNED`, `CUSTOMER_MANAGED`. */ encryptionStrategy: string; /** * ARN of the KMS key to use for encryption when `encryptionStrategy` is `CUSTOMER_MANAGED`. */ kmsKeyArn?: string; } interface CentralizationRuleForOrganizationRuleDestinationDestinationLogsConfigurationTagPropagationConfiguration { /** * ARN of the IAM role that the service assumes to propagate source resource tags to centralized destination log groups. */ destinationRoleArn: string; /** * Strategy for resolving tag conflicts when propagating tags to destination log groups. Valid values: `IN_SYNC`, `ADD_ONLY`, `UPDATE_SYNC`. */ tagConflictResolutionStrategy?: string; } interface CentralizationRuleForOrganizationRuleDestinationDestinationMetricsConfiguration { /** * Configuration block for metrics backup settings. See `destinationMetricsBackupConfiguration` below. */ backupConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleDestinationDestinationMetricsConfigurationBackupConfiguration; } interface CentralizationRuleForOrganizationRuleDestinationDestinationMetricsConfigurationBackupConfiguration { /** * AWS region for backup storage. */ region: string; } interface CentralizationRuleForOrganizationRuleSource { /** * Set of AWS regions from which to centralize telemetry. Must contain at least one region. */ regions: string[]; /** * Scope defining which resources to include. Use organization ID format: `OrganizationId = 'o-example123456'`. */ scope: string; /** * Configuration block for source logs settings. See `sourceLogsConfiguration` below. */ sourceLogsConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleSourceSourceLogsConfiguration; /** * Configuration block for source metrics settings. See `sourceMetricsConfiguration` below. */ sourceMetricsConfiguration?: outputs.observabilityadmin.CentralizationRuleForOrganizationRuleSourceSourceMetricsConfiguration; } interface CentralizationRuleForOrganizationRuleSourceSourceLogsConfiguration { /** * Criteria for selecting data sources. Uses the same filter expression format as `logGroupSelectionCriteria`, but operates on Data Source Name and Data Source Type operands. When both `logGroupSelectionCriteria` and `dataSourceSelectionCriteria` are specified, a log event must match both criteria to be centralized. Must be between 1 and 2000 characters. */ dataSourceSelectionCriteria: string; /** * Strategy for handling encrypted log groups. Valid values: `ALLOW`, `SKIP`. */ encryptedLogGroupStrategy: string; /** * Criteria for selecting log groups. Use `*` for all log groups or OAM filter syntax like `LogGroupName LIKE '/aws/lambda%'`. Must be between 1 and 2000 characters. */ logGroupSelectionCriteria: string; } interface CentralizationRuleForOrganizationRuleSourceSourceMetricsConfiguration { /** * Filter expression that selects which source metrics to centralize. Currently, only `*` (all metrics) is supported. */ metricsSelectionCriteria: string; } interface CentralizationRuleForOrganizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface S3TableIntegrationEncryption { /** * ARN of the KMS key to use for encryption. Required when `sseAlgorithm` is `aws:kms`. */ kmsKeyArn?: string; /** * Server-side encryption algorithm. Valid values: `AES256`, `aws:kms`. */ sseAlgorithm: string; } interface S3TableIntegrationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface TelemetryEnrichmentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface TelemetryEvaluationForOrganizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface TelemetryEvaluationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface TelemetryPipelineConfiguration { /** * The pipeline configuration body. This is a YAML-encoded string defining the pipeline source, optional processors, and sinks. */ body: string; } interface TelemetryPipelineTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface TelemetryRuleForOrganizationRule { /** * Whether to replicate the rule to every Region in the partition where CloudWatch Observability Admin is available. Mutually exclusive with `regions`. */ allRegions?: boolean; /** * Whether CloudWatch Observability Admin should detect and remediate configuration drift in managed telemetry resources. Currently supported for `AWS::EC2::VPC` resources (VPC flow logs). */ allowFieldUpdates?: boolean; /** * Configuration block specifying where and how the telemetry data is delivered. See `destinationConfiguration` below. */ destinationConfiguration?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfiguration; /** * Set of Regions to replicate the rule to. Mutually exclusive with `allRegions`. Order is not preserved. */ regions: string[]; /** * AWS resource type to apply the rule to (for example `AWS::EC2::VPC`, `AWS::EKS::Cluster`, `AWS::WAFv2::WebACL`). */ resourceType?: string; /** * Organizational scope to which the rule applies, specified using accounts or organizational units. */ scope?: string; /** * Criteria for selecting which resources the rule applies to, such as resource tags. */ selectionCriteria?: string; /** * List of telemetry source types to configure for the resource (for example `VPC_FLOW_LOGS`, `EKS_AUDIT_LOGS`). Must correlate with the chosen `resourceType`. If not provided, the API may default this value based on `resourceType` (for example `VPC_FLOW_LOGS` for `AWS::EC2::VPC`). */ telemetrySourceTypes: string[]; /** * Type of telemetry data to collect. Valid values: `Logs`, `Metrics`, `Traces`. */ telemetryType: string; } interface TelemetryRuleForOrganizationRuleDestinationConfiguration { /** * CloudTrail-specific parameters when CloudTrail is the source. See `cloudtrailParameters` below. */ cloudtrailParameters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationCloudtrailParameters; /** * Pattern used to generate the destination path or name. May contain alphanumeric characters, the macros `` and ``, and the symbols `_`, `/`, `-`. */ destinationPattern?: string; /** * Destination type for the telemetry data (for example `cloud-watch-logs`). */ destinationType?: string; /** * ELB load balancer logging parameters when the resource is an ELB. See `elbLoadBalancerLoggingParameters` below. */ elbLoadBalancerLoggingParameters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationElbLoadBalancerLoggingParameters; /** * Amazon Bedrock AgentCore log delivery parameters. See `logDeliveryParameters` below. */ logDeliveryParameters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationLogDeliveryParameters; /** * Amazon MSK cluster monitoring parameters. See `mskMonitoringParameters` below. */ mskMonitoringParameters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationMskMonitoringParameters; /** * Number of days to retain the telemetry data in the destination. */ retentionInDays?: number; /** * VPC Flow Logs-specific parameters when the resource is `AWS::EC2::VPC`. See `vpcFlowLogParameters` below. */ vpcFlowLogParameters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationVpcFlowLogParameters; /** * WAF logging parameters when the resource is `AWS::WAFv2::WebACL`. See `wafLoggingParameters` below. */ wafLoggingParameters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParameters; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationCloudtrailParameters { /** * List of advanced event selectors used to filter CloudTrail events. See `advancedEventSelectors` below. */ advancedEventSelectors?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelector[]; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelector { /** * List of field selectors that compose the selector statement. See `fieldSelectors` below. */ fieldSelectors?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelectorFieldSelector[]; /** * Descriptive name for the advanced event selector. */ name?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelectorFieldSelector { /** * Match if the field value ends with one of the specified values. */ endsWiths?: string[]; /** * Match if the field value equals one of the specified values. */ equals?: string[]; /** * Name of the field to use for selection. */ field: string; /** * Match if the field value does not end with one of the specified values. */ notEndsWiths?: string[]; /** * Match if the field value does not equal any of the specified values. */ notEquals?: string[]; /** * Match if the field value does not start with any of the specified values. */ notStartsWiths?: string[]; /** * Match if the field value starts with one of the specified values. */ startsWiths?: string[]; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationElbLoadBalancerLoggingParameters { /** * Delimiter character used to separate fields in ELB access log entries when using plain text format. */ fieldDelimiter?: string; /** * Format for ELB access log entries. Valid values: `plain-text`, `json`. */ outputFormat?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationLogDeliveryParameters { /** * List of log types that the source is sending. */ logTypes?: string[]; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationMskMonitoringParameters { /** * Level of enhanced monitoring for the MSK cluster. Valid values: `DEFAULT`, `PER_BROKER`, `PER_TOPIC_PER_BROKER`, `PER_TOPIC_PER_PARTITION`. */ enhancedMonitoring?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationVpcFlowLogParameters { /** * Format string for VPC Flow Log entries. */ logFormat?: string; /** * Maximum interval (in seconds) between the capture of flow log records. Valid values: `60`, `600`. */ maxAggregationInterval?: number; /** * Type of traffic to log. Valid values: `ACCEPT`, `REJECT`, `ALL`. */ trafficType?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParameters { /** * Type of WAF logs to collect (currently `WAF_LOGS`). */ logType?: string; /** * Filter configuration that determines which WAF log records to include or exclude. See `loggingFilter` below. */ loggingFilter?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilter; /** * List of fields to redact from WAF logs. See `redactedFields` below. */ redactedFields?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersRedactedField[]; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilter { /** * Default action for log records that do not match any filter. Valid values: `KEEP`, `DROP`. */ defaultBehavior?: string; /** * List of filter configurations. See `filters` below. */ filters?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilter[]; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilter { /** * Action to take for matching log records. Valid values: `KEEP`, `DROP`. */ behavior?: string; /** * Conditions that determine if a log record matches this filter. See `conditions` below. */ conditions?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterCondition[]; /** * Whether the log record must meet all conditions or any condition. Valid values: `MEETS_ALL`, `MEETS_ANY`. */ requirement?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterCondition { /** * Condition that matches based on the WAF action. See `actionCondition` below. */ actionCondition?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionActionCondition; /** * Condition that matches based on WAF rule labels. See `labelNameCondition` below. */ labelNameCondition?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionLabelNameCondition; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionActionCondition { /** * WAF action to match against. Valid values: `ALLOW`, `BLOCK`, `COUNT`, `CAPTCHA`, `CHALLENGE`, `EXCLUDED_AS_COUNT`. */ action: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionLabelNameCondition { /** * Label name to match (alphanumeric, underscores, hyphens, and colons; up to 1024 characters). */ labelName?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersRedactedField { /** * Redact the HTTP method from WAF logs. Set to an empty string to enable redaction. */ method?: string; /** * Redact the entire query string from WAF logs. Set to an empty string to enable redaction. */ queryString?: string; /** * Redact a specific header by name from WAF logs. See `singleHeader` below. */ singleHeader?: outputs.observabilityadmin.TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersRedactedFieldSingleHeader; /** * Redact the URI path from WAF logs. Set to an empty string to enable redaction. */ uriPath?: string; } interface TelemetryRuleForOrganizationRuleDestinationConfigurationWafLoggingParametersRedactedFieldSingleHeader { /** * Header name to redact (up to 64 characters). */ name: string; } interface TelemetryRuleForOrganizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface TelemetryRuleRule { /** * Whether to replicate the rule to every Region in the partition where CloudWatch Observability Admin is available. Mutually exclusive with `regions`. */ allRegions?: boolean; /** * Whether CloudWatch Observability Admin should detect and remediate configuration drift in managed telemetry resources. Currently supported for `AWS::EC2::VPC` resources (VPC flow logs). */ allowFieldUpdates?: boolean; /** * Configuration block specifying where and how the telemetry data is delivered. See `destinationConfiguration` below. */ destinationConfiguration?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfiguration; /** * Set of Regions to replicate the rule to. Mutually exclusive with `allRegions`. Order is not preserved. */ regions: string[]; /** * AWS resource type to apply the rule to (for example `AWS::EC2::VPC`, `AWS::EKS::Cluster`, `AWS::WAFv2::WebACL`). */ resourceType?: string; /** * Organizational scope to which the rule applies, specified using accounts or organizational units. */ scope?: string; /** * Criteria for selecting which resources the rule applies to, such as resource tags. */ selectionCriteria?: string; /** * List of telemetry source types to configure for the resource (for example `VPC_FLOW_LOGS`, `EKS_AUDIT_LOGS`). Must correlate with the chosen `resourceType`. If not provided, the API may default this value based on `resourceType` (for example `VPC_FLOW_LOGS` for `AWS::EC2::VPC`). */ telemetrySourceTypes: string[]; /** * Type of telemetry data to collect. Valid values: `Logs`, `Metrics`, `Traces`. */ telemetryType: string; } interface TelemetryRuleRuleDestinationConfiguration { /** * CloudTrail-specific parameters when CloudTrail is the source. See `cloudtrailParameters` below. */ cloudtrailParameters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationCloudtrailParameters; /** * Pattern used to generate the destination path or name. May contain alphanumeric characters, the macros `` and ``, and the symbols `_`, `/`, `-`. */ destinationPattern?: string; /** * Destination type for the telemetry data (for example `cloud-watch-logs`). */ destinationType?: string; /** * ELB load balancer logging parameters when the resource is an ELB. See `elbLoadBalancerLoggingParameters` below. */ elbLoadBalancerLoggingParameters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationElbLoadBalancerLoggingParameters; /** * Amazon Bedrock AgentCore log delivery parameters. See `logDeliveryParameters` below. */ logDeliveryParameters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationLogDeliveryParameters; /** * Amazon MSK cluster monitoring parameters. See `mskMonitoringParameters` below. */ mskMonitoringParameters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationMskMonitoringParameters; /** * Number of days to retain the telemetry data in the destination. */ retentionInDays?: number; /** * VPC Flow Logs-specific parameters when the resource is `AWS::EC2::VPC`. See `vpcFlowLogParameters` below. */ vpcFlowLogParameters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationVpcFlowLogParameters; /** * WAF logging parameters when the resource is `AWS::WAFv2::WebACL`. See `wafLoggingParameters` below. */ wafLoggingParameters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParameters; } interface TelemetryRuleRuleDestinationConfigurationCloudtrailParameters { /** * List of advanced event selectors used to filter CloudTrail events. See `advancedEventSelectors` below. */ advancedEventSelectors?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelector[]; } interface TelemetryRuleRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelector { /** * List of field selectors that compose the selector statement. See `fieldSelectors` below. */ fieldSelectors?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelectorFieldSelector[]; /** * Descriptive name for the advanced event selector. */ name?: string; } interface TelemetryRuleRuleDestinationConfigurationCloudtrailParametersAdvancedEventSelectorFieldSelector { /** * Match if the field value ends with one of the specified values. */ endsWiths?: string[]; /** * Match if the field value equals one of the specified values. */ equals?: string[]; /** * Name of the field to use for selection. */ field: string; /** * Match if the field value does not end with one of the specified values. */ notEndsWiths?: string[]; /** * Match if the field value does not equal any of the specified values. */ notEquals?: string[]; /** * Match if the field value does not start with any of the specified values. */ notStartsWiths?: string[]; /** * Match if the field value starts with one of the specified values. */ startsWiths?: string[]; } interface TelemetryRuleRuleDestinationConfigurationElbLoadBalancerLoggingParameters { /** * Delimiter character used to separate fields in ELB access log entries when using plain text format. */ fieldDelimiter?: string; /** * Format for ELB access log entries. Valid values: `plain-text`, `json`. */ outputFormat?: string; } interface TelemetryRuleRuleDestinationConfigurationLogDeliveryParameters { /** * List of log types that the source is sending. */ logTypes?: string[]; } interface TelemetryRuleRuleDestinationConfigurationMskMonitoringParameters { /** * Level of enhanced monitoring for the MSK cluster. Valid values: `DEFAULT`, `PER_BROKER`, `PER_TOPIC_PER_BROKER`, `PER_TOPIC_PER_PARTITION`. */ enhancedMonitoring?: string; } interface TelemetryRuleRuleDestinationConfigurationVpcFlowLogParameters { /** * Format string for VPC Flow Log entries. */ logFormat?: string; /** * Maximum interval (in seconds) between the capture of flow log records. Valid values: `60`, `600`. */ maxAggregationInterval?: number; /** * Type of traffic to log. Valid values: `ACCEPT`, `REJECT`, `ALL`. */ trafficType?: string; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParameters { /** * Type of WAF logs to collect (currently `WAF_LOGS`). */ logType?: string; /** * Filter configuration that determines which WAF log records to include or exclude. See `loggingFilter` below. */ loggingFilter?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilter; /** * List of fields to redact from WAF logs. See `redactedFields` below. */ redactedFields?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersRedactedField[]; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilter { /** * Default action for log records that do not match any filter. Valid values: `KEEP`, `DROP`. */ defaultBehavior?: string; /** * List of filter configurations. See `filters` below. */ filters?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilter[]; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilter { /** * Action to take for matching log records. Valid values: `KEEP`, `DROP`. */ behavior?: string; /** * Conditions that determine if a log record matches this filter. See `conditions` below. */ conditions?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterCondition[]; /** * Whether the log record must meet all conditions or any condition. Valid values: `MEETS_ALL`, `MEETS_ANY`. */ requirement?: string; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterCondition { /** * Condition that matches based on the WAF action. See `actionCondition` below. */ actionCondition?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionActionCondition; /** * Condition that matches based on WAF rule labels. See `labelNameCondition` below. */ labelNameCondition?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionLabelNameCondition; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionActionCondition { /** * WAF action to match against. Valid values: `ALLOW`, `BLOCK`, `COUNT`, `CAPTCHA`, `CHALLENGE`, `EXCLUDED_AS_COUNT`. */ action: string; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersLoggingFilterFilterConditionLabelNameCondition { /** * Label name to match (alphanumeric, underscores, hyphens, and colons; up to 1024 characters). */ labelName?: string; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersRedactedField { /** * Redact the HTTP method from WAF logs. Set to an empty string to enable redaction. */ method?: string; /** * Redact the entire query string from WAF logs. Set to an empty string to enable redaction. */ queryString?: string; /** * Redact a specific header by name from WAF logs. See `singleHeader` below. */ singleHeader?: outputs.observabilityadmin.TelemetryRuleRuleDestinationConfigurationWafLoggingParametersRedactedFieldSingleHeader; /** * Redact the URI path from WAF logs. Set to an empty string to enable redaction. */ uriPath?: string; } interface TelemetryRuleRuleDestinationConfigurationWafLoggingParametersRedactedFieldSingleHeader { /** * Header name to redact (up to 64 characters). */ name: string; } interface TelemetryRuleTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace odb { interface CloudAutonomousVmClusterMaintenanceWindow { /** * Days of the week when maintenance can be performed. Changing this will force terraform to create new resource. See `daysOfWeek` Block below. */ daysOfWeeks?: outputs.odb.CloudAutonomousVmClusterMaintenanceWindowDaysOfWeek[]; /** * Hours of the day when maintenance can be performed. Changing this will force terraform to create new resource. */ hoursOfDays?: number[]; /** * Lead time in weeks before the maintenance window. Changing this will force terraform to create new resource. */ leadTimeInWeeks?: number; /** * Months when maintenance can be performed. Changing this will force terraform to create new resource. See `months` Block below. */ months?: outputs.odb.CloudAutonomousVmClusterMaintenanceWindowMonth[]; /** * Preference for the maintenance window scheduling. Changing this will force terraform to create new resource. */ preference: string; /** * Whether to skip release updates during maintenance. Changing this will force terraform to create new resource. */ weeksOfMonths?: number[]; } interface CloudAutonomousVmClusterMaintenanceWindowDaysOfWeek { /** * Name of the day of the week. Valid values are `MONDAY`, `TUESDAY`, `WEDNESDAY`, `THURSDAY`, `FRIDAY`, `SATURDAY`, and `SUNDAY`. */ name: string; } interface CloudAutonomousVmClusterMaintenanceWindowMonth { /** * Name of the month. Valid values are `JANUARY`, `FEBRUARY`, `MARCH`, `APRIL`, `MAY`, `JUNE`, `JULY`, `AUGUST`, `SEPTEMBER`, `OCTOBER`, `NOVEMBER`, and `DECEMBER`. */ name: string; } interface CloudAutonomousVmClusterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface CloudExadataInfrastructureCustomerContactsToSendToOci { /** * Email address of the contact. */ email: string; } interface CloudExadataInfrastructureMaintenanceWindow { /** * Custom action timeout in minutes for the maintenance window. */ customActionTimeoutInMins: number; /** * Days of the week when maintenance can be performed. See `daysOfWeek` Block below. */ daysOfWeeks: outputs.odb.CloudExadataInfrastructureMaintenanceWindowDaysOfWeek[]; /** * Hours of the day when maintenance can be performed. */ hoursOfDays: number[]; /** * Whether custom action timeout is enabled for the maintenance window. */ isCustomActionTimeoutEnabled: boolean; /** * Lead time in weeks before the maintenance window. */ leadTimeInWeeks: number; /** * Months when maintenance can be performed. See `months` Block below. */ months: outputs.odb.CloudExadataInfrastructureMaintenanceWindowMonth[]; /** * Patching mode for the maintenance window. */ patchingMode: string; /** * Preference for the maintenance window scheduling. */ preference: string; /** * Weeks of the month when maintenance can be performed. */ weeksOfMonths: number[]; } interface CloudExadataInfrastructureMaintenanceWindowDaysOfWeek { /** * Name of the day of the week. Valid values are `MONDAY`, `TUESDAY`, `WEDNESDAY`, `THURSDAY`, `FRIDAY`, `SATURDAY`, and `SUNDAY`. */ name: string; } interface CloudExadataInfrastructureMaintenanceWindowMonth { /** * Name of the month. Valid values are `JANUARY`, `FEBRUARY`, `MARCH`, `APRIL`, `MAY`, `JUNE`, `JULY`, `AUGUST`, `SEPTEMBER`, `OCTOBER`, `NOVEMBER`, and `DECEMBER`. */ name: string; } interface CloudExadataInfrastructureTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface CloudVmClusterDataCollectionOptions { /** * Whether to enable diagnostic events for the VM cluster. Changing this will create a new resource. */ isDiagnosticsEventsEnabled: boolean; /** * Whether to enable health monitoring for the VM cluster. Changing this will create a new resource. */ isHealthMonitoringEnabled: boolean; /** * Whether to enable incident logs for the VM cluster. Changing this will create a new resource. */ isIncidentLogsEnabled: boolean; } interface CloudVmClusterIormConfigCache { /** * List of IORM (I/O Resource Manager) database plans for the VM cluster. See `dbPlans` Block below. */ dbPlans: outputs.odb.CloudVmClusterIormConfigCacheDbPlan[]; /** * Additional information about the current lifecycle state of the IORM configuration. */ lifecycleDetails: string; /** * Current lifecycle state of the IORM configuration. */ lifecycleState: string; /** * Current value for the IORM objective. */ objective: string; } interface CloudVmClusterIormConfigCacheDbPlan { /** * Database name to which the IORM plan applies. */ dbName: string; /** * Flash cache limit for the database plan. */ flashCacheLimit: string; /** * Relative priority of the database in the IORM plan. */ share: number; } interface CloudVmClusterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GetCloudAutonomousVmClusterMaintenanceWindow { daysOfWeeks: outputs.odb.GetCloudAutonomousVmClusterMaintenanceWindowDaysOfWeek[]; hoursOfDays: number[]; leadTimeInWeeks: number; months: outputs.odb.GetCloudAutonomousVmClusterMaintenanceWindowMonth[]; preference: string; weeksOfMonths: number[]; } interface GetCloudAutonomousVmClusterMaintenanceWindowDaysOfWeek { name: string; } interface GetCloudAutonomousVmClusterMaintenanceWindowMonth { name: string; } interface GetCloudAutonomousVmClustersCloudAutonomousVmCluster { /** * ARN for the Exadata infrastructure. */ arn: string; /** * Cloud exadata infrastructure id associated with this cloud autonomous VM cluster. */ cloudExadataInfrastructureId: string; /** * Display name of the Autonomous VM cluster. */ displayName: string; /** * Unique identifier of the cloud autonomous vm cluster. */ id: string; /** * Name of the OCI resource anchor associated with this Autonomous VM cluster. */ ociResourceAnchorName: string; /** * URL for accessing the OCI console page for this Autonomous VM cluster. */ ociUrl: string; /** * Oracle Cloud Identifier (OCID) of the Autonomous VM cluster. */ ocid: string; /** * Unique identifier of the ODB network associated with this Autonomous VM cluster. */ odbNetworkId: string; } interface GetCloudExadataInfrastructureCustomerContactsToSendToOci { email: string; } interface GetCloudExadataInfrastructureMaintenanceWindow { customActionTimeoutInMins: number; daysOfWeeks: outputs.odb.GetCloudExadataInfrastructureMaintenanceWindowDaysOfWeek[]; hoursOfDays: number[]; isCustomActionTimeoutEnabled: boolean; leadTimeInWeeks: number; months: outputs.odb.GetCloudExadataInfrastructureMaintenanceWindowMonth[]; patchingMode: string; preference: string; weeksOfMonths: number[]; } interface GetCloudExadataInfrastructureMaintenanceWindowDaysOfWeek { name: string; } interface GetCloudExadataInfrastructureMaintenanceWindowMonth { name: string; } interface GetCloudExadataInfrastructuresCloudExadataInfrastructure { /** * ARN for the Exadata infrastructure. */ arn: string; /** * Display name of the Exadata infrastructure. */ displayName: string; /** * Unique identifier of the Exadata infrastructure. */ id: string; /** * Name of the OCI resource anchor for the Exadata infrastructure. */ ociResourceAnchorName: string; /** * HTTPS link to the Exadata infrastructure in OCI. */ ociUrl: string; /** * OCID of the Exadata infrastructure in OCI. */ ocid: string; } interface GetCloudVmClusterDataCollectionOption { isDiagnosticsEventsEnabled: boolean; isHealthMonitoringEnabled: boolean; isIncidentLogsEnabled: boolean; } interface GetCloudVmClusterIormConfigCache { dbPlans: outputs.odb.GetCloudVmClusterIormConfigCacheDbPlan[]; lifecycleDetails: string; lifecycleState: string; objective: string; } interface GetCloudVmClusterIormConfigCacheDbPlan { dbName: string; flashCacheLimit: string; share: number; } interface GetCloudVmClustersCloudVmCluster { /** * ARN for the cloud vm cluster. */ arn: string; /** * ID of the Cloud Exadata Infrastructure. */ cloudExadataInfrastructureId: string; /** * Display name of the VM cluster. */ displayName: string; /** * Unique identifier of the cloud vm cluster. */ id: string; /** * Name of the OCI Resource Anchor. */ ociResourceAnchorName: string; /** * HTTPS link to the VM cluster in OCI. */ ociUrl: string; /** * OCID of the VM cluster. */ ocid: string; /** * ID of the ODB network. */ odbNetworkId: string; } interface GetDbNodesDbNode { /** * Additional information about the planned maintenance. */ additionalDetails: string; /** * ARN of the DB node. */ arn: string; /** * Oracle Cloud ID (OCID) of the backup IP address that's associated with the DB node. */ backupIpId: string; /** * OCID of the second backup virtual network interface card (VNIC) for the DB node. */ backupVnic2Id: string; /** * OCID of the backup VNIC for the DB node. */ backupVnicId: string; /** * Number of CPU cores enabled on the DB node. */ cpuCoreCount: number; /** * Date and time when the DB node was created. */ createdAt: string; /** * Amount of local node storage, in gigabytes (GB), that's allocated on the DB node. */ dbNodeStorageSize: number; /** * Unique identifier of the database server that's associated with the DB node. */ dbServerId: string; /** * OCID of the DB system. */ dbSystemId: string; /** * Name of the fault domain where the DB node is located. */ faultDomain: string; /** * OCID of the host IP address that's associated with the DB node. */ hostIpId: string; /** * Host name for the DB node. */ hostname: string; /** * Unique identifier of the DB node. */ id: string; /** * Type of maintenance the DB node is undergoing. */ maintenanceType: string; /** * Amount of memory, in gigabytes (GB), that's allocated on the DB node. */ memorySize: number; /** * Name of the OCI resource anchor for the DB node. */ ociResourceAnchorName: string; /** * OCID of the DB node. */ ocid: string; /** * Size of the block storage volume, in gigabytes (GB), that's allocated for the DB system. This attribute applies only for virtual machine DB systems. */ softwareStorageSize: number; /** * Current status of the DB node. */ status: string; /** * Additional information about the status of the DB node. */ statusReason: string; /** * End date and time of the maintenance window. */ timeMaintenanceWindowEnd: string; /** * Start date and time of the maintenance window. */ timeMaintenanceWindowStart: string; /** * Total number of CPU cores reserved on the DB node. */ totalCpuCoreCount: number; /** * OCID of the second VNIC. */ vnic2Id: string; /** * OCID of the VNIC. */ vnicId: string; } interface GetDbServerDbServerPatchingDetail { /** * Estimated time, in minutes, that it takes to patch the database server. */ estimatedPatchDuration: number; /** * Status of the patching operation. */ patchingStatus: string; /** * Date and time when the patching operation ended. */ timePatchingEnded: string; /** * Date and time when the patching operation started. */ timePatchingStarted: string; } interface GetDbServersDbServer { /** * List of unique identifiers for the Autonomous VMs. */ autonomousVirtualMachineIds: string[]; /** * List of identifiers for the Autonomous VM clusters. */ autonomousVmClusterIds: string[]; /** * OCI compute model used when you create or clone an instance: **ECPU** or **OCPU**. ECPUs are based on the number of cores elastically allocated from a pool of compute and storage servers, while OCPUs are based on the physical core of a processor with hyper-threading enabled. */ computeModel: string; /** * Number of CPU cores enabled on the database server. */ cpuCoreCount: number; /** * Date and time when the database server was created. */ createdAt: string; /** * Amount of local node storage, in gigabytes (GB), that's allocated on the database server. */ dbNodeStorageSizeInGbs: number; /** * Scheduling details for the quarterly maintenance window. Patching and system updates take place during the maintenance window. */ dbServerPatchingDetails: outputs.odb.GetDbServersDbServerDbServerPatchingDetail[]; /** * User-friendly name of the database server. The name doesn't need to be unique. */ displayName: string; /** * ID of the Exadata infrastructure that hosts the database server. */ exadataInfrastructureId: string; /** * Unique identifier of the database server. */ id: string; /** * Total number of CPU cores available on the database server. */ maxCpuCount: number; /** * Total amount of local node storage, in gigabytes (GB), that's available on the database server. */ maxDbNodeStorageInGbs: number; /** * Total amount of memory, in gigabytes (GB), that's available on the database server. */ maxMemoryInGbs: number; /** * Amount of memory, in gigabytes (GB), that's allocated on the database server. */ memorySizeInGbs: number; /** * Name of the OCI resource anchor for the database server. */ ociResourceAnchorName: string; /** * OCID of the database server. */ ocid: string; /** * Hardware system model of the Exadata infrastructure that the database server is hosted on. The shape determines the amount of CPU, storage, and memory resources available. */ shape: string; /** * Current status of the database server. */ status: string; /** * Additional information about the status of the database server. */ statusReason: string; /** * IDs of the VM clusters that are associated with the database server. */ vmClusterIds: string[]; } interface GetDbServersDbServerDbServerPatchingDetail { /** * Estimated time, in minutes, that it takes to patch the database server. */ estimatedPatchDuration: number; /** * Status of the patching operation. */ patchingStatus: string; /** * Date and time when the patching operation ended. */ timePatchingEnded: string; /** * Date and time when the patching operation started. */ timePatchingStarted: string; } interface GetDbSystemShapesDbSystemShape { /** * Maximum number of CPU cores that can be enabled for the shape. */ availableCoreCount: number; /** * Maximum number of CPU cores per DB node that can be enabled for the shape. */ availableCoreCountPerNode: number; /** * Maximum amount of data storage, in terabytes (TB), that can be enabled for the shape. */ availableDataStorageInTbs: number; /** * Maximum amount of data storage, in terabytes (TB), that's available per storage server for the shape. */ availableDataStoragePerServerInTbs: number; /** * Maximum amount of DB node storage, in gigabytes (GB), that's available per DB node for the shape. */ availableDbNodePerNodeInGbs: number; /** * Maximum amount of DB node storage, in gigabytes (GB), that can be enabled for the shape. */ availableDbNodeStorageInGbs: number; /** * Maximum amount of memory, in gigabytes (GB), that can be enabled for the shape. */ availableMemoryInGbs: number; /** * Maximum amount of memory, in gigabytes (GB), that's available per DB node for the shape. */ availableMemoryPerNodeInGbs: number; /** * Discrete number by which the CPU core count for the shape can be increased or decreased. */ coreCountIncrement: number; /** * Maximum number of Exadata storage servers available for the shape. */ maxStorageCount: number; /** * Maximum number of compute servers available for the shape. */ maximumNodeCount: number; /** * Minimum number of CPU cores that can be enabled per node for the shape. */ minCoreCountPerNode: number; /** * Minimum amount of data storage, in terabytes (TB), that must be allocated for the shape. */ minDataStorageInTbs: number; /** * Minimum amount of DB node storage, in gigabytes (GB), that must be allocated per DB node for the shape. */ minDbNodeStoragePerNodeInGbs: number; /** * Minimum amount of memory, in gigabytes (GB), that must be allocated per DB node for the shape. */ minMemoryPerNodeInGbs: number; /** * Minimum number of Exadata storage servers available for the shape. */ minStorageCount: number; /** * Minimum number of CPU cores that can be enabled for the shape. */ minimumCoreCount: number; /** * Minimum number of compute servers available for the shape. */ minimumNodeCount: number; /** * Name of the shape. */ name: string; /** * Runtime minimum number of CPU cores that can be enabled for the shape. */ runtimeMinimumCoreCount: number; /** * Family of the shape. */ shapeFamily: string; /** * Shape type, determined by the CPU hardware. */ shapeType: string; } interface GetGiVersionsGiVersion { /** * GI software version. */ version: string; } interface GetNetworkManagedService { crossRegionS3RestoreSourcesAccesses: outputs.odb.GetNetworkManagedServiceCrossRegionS3RestoreSourcesAccess[]; kmsAccesses: outputs.odb.GetNetworkManagedServiceKmsAccess[]; managedS3BackupAccesses: outputs.odb.GetNetworkManagedServiceManagedS3BackupAccess[]; managedServiceIpv4Cidrs: string[]; resourceGatewayArn: string; s3Accesses: outputs.odb.GetNetworkManagedServiceS3Access[]; serviceNetworkArn: string; serviceNetworkEndpoints: outputs.odb.GetNetworkManagedServiceServiceNetworkEndpoint[]; stsAccesses: outputs.odb.GetNetworkManagedServiceStsAccess[]; zeroTlAccesses: outputs.odb.GetNetworkManagedServiceZeroTlAccess[]; } interface GetNetworkManagedServiceCrossRegionS3RestoreSourcesAccess { ipv4Addresses: string[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Status of the network resource. */ status: string; } interface GetNetworkManagedServiceKmsAccess { domainName: string; ipv4Addresses: string[]; kmsPolicyDocument: string; /** * Status of the network resource. */ status: string; } interface GetNetworkManagedServiceManagedS3BackupAccess { ipv4Addresses: string[]; /** * Status of the network resource. */ status: string; } interface GetNetworkManagedServiceS3Access { domainName: string; ipv4Addresses: string[]; s3PolicyDocument: string; /** * Status of the network resource. */ status: string; } interface GetNetworkManagedServiceServiceNetworkEndpoint { vpcEndpointId: string; vpcEndpointType: string; } interface GetNetworkManagedServiceStsAccess { domainName: string; ipv4Addresses: string[]; /** * Status of the network resource. */ status: string; stsPolicyDocument: string; } interface GetNetworkManagedServiceZeroTlAccess { cidr: string; /** * Status of the network resource. */ status: string; } interface GetNetworkOciDnsForwardingConfig { domainName: string; ociDnsListenerIp: string; } interface GetNetworkPeeringConnectionsOdbPeeringConnection { /** * ARN for the ODB network peering connection. */ arn: string; /** * Display name of the ODB network peering connection. */ displayName: string; /** * Unique identifier of the ODB network peering connection. */ id: string; /** * ARN of the ODB network peering connection. */ odbNetworkArn: string; /** * ARN of the peer network peering connection. */ peerNetworkArn: string; } interface GetNetworksOdbNetwork { /** * ARN of the odb network resource. */ arn: string; /** * Display name for the network resource. */ displayName: string; /** * Unique identifier of the odb network resource. */ id: string; /** * Unique identifier of the OCI network anchor for the ODB network. */ ociNetworkAnchorId: string; /** * Unique identifier Oracle Cloud ID (OCID) of the OCI VCN for the ODB network. */ ociVcnId: string; /** * URL of the OCI VCN for the ODB network. */ ociVcnUrl: string; } interface IamRoleAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface NetworkManagedService { /** * List of regions enabled for cross-region restore in the ODB network. */ crossRegionS3RestoreSourcesAccesses: outputs.odb.NetworkManagedServiceCrossRegionS3RestoreSourcesAccess[]; /** * Configuration for KMS access from the ODB network. */ kmsAccesses: outputs.odb.NetworkManagedServiceKmsAccess[]; /** * Managed S3 backup access configuration. See `managedS3BackupAccess` Block below. */ managedS3BackupAccesses: outputs.odb.NetworkManagedServiceManagedS3BackupAccess[]; /** * List of IPv4 CIDR ranges used by the managed services. */ managedServiceIpv4Cidrs: string[]; /** * ARN of the resource gateway. */ resourceGatewayArn: string; /** * Configuration for Amazon S3 access from the ODB network. */ s3Accesses: outputs.odb.NetworkManagedServiceS3Access[]; /** * ARN of the service network. */ serviceNetworkArn: string; /** * Service network endpoint configuration. See `serviceNetworkEndpoint` Block below. */ serviceNetworkEndpoints: outputs.odb.NetworkManagedServiceServiceNetworkEndpoint[]; /** * Configuration for STS access from the ODB network. */ stsAccesses: outputs.odb.NetworkManagedServiceStsAccess[]; /** * Configuration for Zero-ETL access from the ODB network. * * The following arguments are optional: */ zeroEtlAccesses: outputs.odb.NetworkManagedServiceZeroEtlAccess[]; } interface NetworkManagedServiceCrossRegionS3RestoreSourcesAccess { /** * List of IPv4 addresses for the Amazon STS access. */ ipv4Addresses: string[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Status of the Zero-ETL access. */ status: string; } interface NetworkManagedServiceKmsAccess { /** * Domain name for which the DNS queries are forwarded. */ domainName: string; /** * List of IPv4 addresses for the Amazon STS access. */ ipv4Addresses: string[]; /** * Endpoint policy for KMS access from the ODB network. */ kmsPolicyDocument: string; /** * Status of the Zero-ETL access. */ status: string; } interface NetworkManagedServiceManagedS3BackupAccess { /** * List of IPv4 addresses for the Amazon STS access. */ ipv4Addresses: string[]; /** * Status of the Zero-ETL access. */ status: string; } interface NetworkManagedServiceS3Access { /** * Domain name for which the DNS queries are forwarded. */ domainName: string; /** * List of IPv4 addresses for the Amazon STS access. */ ipv4Addresses: string[]; /** * Endpoint policy for Amazon S3 access from the ODB network. */ s3PolicyDocument: string; /** * Status of the Zero-ETL access. */ status: string; } interface NetworkManagedServiceServiceNetworkEndpoint { /** * Unique identifier of the VPC endpoint. */ vpcEndpointId: string; /** * Type of the VPC endpoint. */ vpcEndpointType: string; } interface NetworkManagedServiceStsAccess { /** * Domain name for which the DNS queries are forwarded. */ domainName: string; /** * List of IPv4 addresses for the Amazon STS access. */ ipv4Addresses: string[]; /** * Status of the Zero-ETL access. */ status: string; /** * Endpoint policy for STS access from the ODB network. */ stsPolicyDocument: string; } interface NetworkManagedServiceZeroEtlAccess { /** * CIDR range for the Zero-ETL access. */ cidr: string; /** * Status of the Zero-ETL access. */ status: string; } interface NetworkOciDnsForwardingConfig { /** * Domain name for which the DNS queries are forwarded. */ domainName: string; /** * IP address of the OCI DNS listener. */ ociDnsListenerIp: string; } interface NetworkPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface NetworkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace opensearch { interface ApplicationAppConfig { /** * The configuration item to set. Valid values are `opensearchDashboards.dashboardAdmin.users` and `opensearchDashboards.dashboardAdmin.groups`. */ key?: string; /** * The value assigned to the configuration key, such as an IAM user ARN or group name. Must be between 1 and 4096 characters. */ value?: string; } interface ApplicationDataSource { /** * ARN of the OpenSearch domain or collection. Must be between 20 and 2048 characters. */ dataSourceArn?: string; /** * A detailed description of the data source. Must be at most 1000 characters and contain only alphanumeric characters, underscores, spaces, and the following special characters: `@#%*+=:?./!-`. */ dataSourceDescription?: string; } interface ApplicationIamIdentityCenterOptions { /** * Specifies whether IAM Identity Center is enabled or disabled. */ enabled?: boolean; iamIdentityCenterApplicationArn: string; /** * ARN of the IAM Identity Center instance. Must be between 20 and 2048 characters. */ iamIdentityCenterInstanceArn?: string; /** * The ARN of the IAM role associated with the IAM Identity Center application. Must be between 20 and 2048 characters and match the pattern for IAM role ARNs. */ iamRoleForIdentityCenterApplicationArn?: string; } interface ApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AuthorizeVpcEndpointAccessAuthorizedPrincipal { /** * IAM principal that is allowed to access to the domain. */ principal: string; /** * Type of principal. */ principalType: string; } interface DomainAdvancedSecurityOptions { /** * Whether Anonymous auth is enabled. Enables fine-grained access control on an existing domain. Ignored unless `advancedSecurityOptions` are enabled. _Can only be enabled on an existing domain._ */ anonymousAuthEnabled: boolean; /** * Whether advanced security is enabled. */ enabled: boolean; /** * Whether the internal user database is enabled. Default is `false`. */ internalUserDatabaseEnabled?: boolean; /** * Configuration block for JWT authentication. Requires OpenSearch 2.11 or later. Detailed below. */ jwtOptions?: outputs.opensearch.DomainAdvancedSecurityOptionsJwtOptions; /** * Configuration block for the main user. Detailed below. */ masterUserOptions?: outputs.opensearch.DomainAdvancedSecurityOptionsMasterUserOptions; } interface DomainAdvancedSecurityOptionsJwtOptions { /** * Whether JWT authentication is enabled. */ enabled: boolean; /** * URL endpoint that hosts the JSON Web Key Set (JWKS) containing public keys used to verify JWT signatures. This argument can be specified only with OpenSearch versions 3.3 and later. At least one of `jwksUrl` or `publicKey` must be specified when `enabled` is set to `true`. */ jwksUrl?: string; /** * PEM-encoded public key used to verify JWT signatures. At least one of `jwksUrl` or `publicKey` must be specified when `enabled` is set to `true`. If both `jwksUrl` and `publicKey` are specified, `publicKey` is ignored. */ publicKey: string; /** * Element of the JWT assertion to use for roles. Default is `roles`. */ rolesKey: string; /** * Element of the JWT assertion to use for the user name. Default is `sub`. */ subjectKey: string; } interface DomainAdvancedSecurityOptionsMasterUserOptions { /** * ARN for the main user. Only specify if `internalUserDatabaseEnabled` is not set or set to `false`. */ masterUserArn?: string; /** * Main user's username, which is stored in the Amazon OpenSearch Service domain's internal database. Only specify if `internalUserDatabaseEnabled` is set to `true`. */ masterUserName?: string; /** * Main user's password, which is stored in the Amazon OpenSearch Service domain's internal database. Only specify if `internalUserDatabaseEnabled` is set to `true`. */ masterUserPassword?: string; } interface DomainAimlOptions { /** * Configuration block for parameters required for natural language query generation on the specified domain. */ naturalLanguageQueryGenerationOptions: outputs.opensearch.DomainAimlOptionsNaturalLanguageQueryGenerationOptions; /** * Configuration block for parameters required to enable S3 vectors engine features on the specified domain. */ s3VectorsEngine: outputs.opensearch.DomainAimlOptionsS3VectorsEngine; /** * Configuration block for parameters required to enable GPU-accelerated vector search on the specified domain. */ serverlessVectorAcceleration: outputs.opensearch.DomainAimlOptionsServerlessVectorAcceleration; } interface DomainAimlOptionsNaturalLanguageQueryGenerationOptions { /** * The desired state of the natural language query generation feature. Valid values are `ENABLED` and `DISABLED`. */ desiredState: string; } interface DomainAimlOptionsS3VectorsEngine { /** * Enables S3 vectors engine features. */ enabled: boolean; } interface DomainAimlOptionsServerlessVectorAcceleration { /** * Enables GPU-accelerated vector search for improved performance on vector workloads. */ enabled: boolean; } interface DomainAutoTuneOptions { /** * Auto-Tune desired state for the domain. Valid values: `ENABLED` or `DISABLED`. */ desiredState: string; /** * Configuration block for Auto-Tune maintenance windows. Can be specified multiple times for each maintenance window. Detailed below. * * **NOTE:** Maintenance windows are deprecated and have been replaced with [off-peak windows](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/off-peak.html). Consequently, `maintenanceSchedule` configuration blocks cannot be specified when `useOffPeakWindow` is set to `true`. */ maintenanceSchedules?: outputs.opensearch.DomainAutoTuneOptionsMaintenanceSchedule[]; /** * Whether to roll back to default Auto-Tune settings when disabling Auto-Tune. Valid values: `DEFAULT_ROLLBACK` or `NO_ROLLBACK`. */ rollbackOnDisable: string; /** * Whether to schedule Auto-Tune optimizations that require blue/green deployments during the domain's configured daily off-peak window. Defaults to `false`. */ useOffPeakWindow?: boolean; } interface DomainAutoTuneOptionsMaintenanceSchedule { /** * A cron expression specifying the recurrence pattern for an Auto-Tune maintenance schedule. */ cronExpressionForRecurrence: string; /** * Configuration block for the duration of the Auto-Tune maintenance window. Detailed below. */ duration: outputs.opensearch.DomainAutoTuneOptionsMaintenanceScheduleDuration; /** * Date and time at which to start the Auto-Tune maintenance schedule in [RFC3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ startAt: string; } interface DomainAutoTuneOptionsMaintenanceScheduleDuration { /** * Unit of time specifying the duration of an Auto-Tune maintenance window. Valid values: `HOURS`. */ unit: string; /** * An integer specifying the value of the duration of an Auto-Tune maintenance window. */ value: number; } interface DomainClusterConfig { /** * Configuration block containing cold storage configuration. Detailed below. */ coldStorageOptions: outputs.opensearch.DomainClusterConfigColdStorageOptions; /** * Number of dedicated main nodes in the cluster. */ dedicatedMasterCount?: number; /** * Whether dedicated main nodes are enabled for the cluster. */ dedicatedMasterEnabled?: boolean; /** * Instance type of the dedicated main nodes in the cluster. */ dedicatedMasterType?: string; /** * Number of instances in the cluster. */ instanceCount?: number; /** * Instance type of data nodes in the cluster. */ instanceType?: string; /** * Whether a multi-AZ domain is turned on with a standby AZ. For more information, see [Configuring a multi-AZ domain in Amazon OpenSearch Service](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/managedomains-multiaz.html). */ multiAzWithStandbyEnabled?: boolean; /** * List of node options for the domain. */ nodeOptions: outputs.opensearch.DomainClusterConfigNodeOption[]; /** * Number of warm nodes in the cluster. Valid values are between `2` and `150`. `warmCount` can be only and must be set when `warmEnabled` is set to `true`. */ warmCount?: number; /** * Whether to enable warm storage. */ warmEnabled?: boolean; /** * Instance type for the OpenSearch cluster's warm nodes. Valid values are `ultrawarm1.medium.search`, `ultrawarm1.large.search` and `ultrawarm1.xlarge.search`. `warmType` can be only and must be set when `warmEnabled` is set to `true`. */ warmType?: string; /** * Configuration block containing zone awareness settings. Detailed below. */ zoneAwarenessConfig?: outputs.opensearch.DomainClusterConfigZoneAwarenessConfig; /** * Whether zone awareness is enabled, set to `true` for multi-az deployment. To enable awareness with three Availability Zones, the `availabilityZoneCount` within the `zoneAwarenessConfig` must be set to `3`. */ zoneAwarenessEnabled?: boolean; } interface DomainClusterConfigColdStorageOptions { /** * Boolean to enable cold storage for an OpenSearch domain. Defaults to `false`. Master and ultrawarm nodes must be enabled for cold storage. */ enabled: boolean; } interface DomainClusterConfigNodeOption { /** * Container to specify sizing of a node type. */ nodeConfig: outputs.opensearch.DomainClusterConfigNodeOptionNodeConfig; /** * Type of node this configuration describes. Valid values: `coordinator`. */ nodeType: string; } interface DomainClusterConfigNodeOptionNodeConfig { /** * Number of nodes of a particular node type in the cluster. */ count: number; /** * Whether a particular node type is enabled. */ enabled: boolean; /** * The instance type of a particular node type in the cluster. */ type: string; } interface DomainClusterConfigZoneAwarenessConfig { /** * Number of Availability Zones for the domain to use with `zoneAwarenessEnabled`. Defaults to `2`. Valid values: `2` or `3`. */ availabilityZoneCount?: number; } interface DomainCognitoOptions { /** * Whether Amazon Cognito authentication with Dashboard is enabled or not. Default is `false`. */ enabled?: boolean; /** * ID of the Cognito Identity Pool to use. */ identityPoolId: string; /** * ARN of the IAM role that has the AmazonOpenSearchServiceCognitoAccess policy attached. */ roleArn: string; /** * ID of the Cognito User Pool to use. */ userPoolId: string; } interface DomainDeploymentStrategyOptions { /** * Deployment strategy for the domain. Valid values: `Default` and `CapacityOptimized`. */ deploymentStrategy: string; } interface DomainDomainEndpointOptions { /** * Fully qualified domain for your custom endpoint. */ customEndpoint?: string; /** * ACM certificate ARN for your custom endpoint. */ customEndpointCertificateArn?: string; /** * Whether to enable custom endpoint for the OpenSearch domain. */ customEndpointEnabled?: boolean; /** * Whether or not to require HTTPS. Defaults to `true`. */ enforceHttps?: boolean; /** * Name of the TLS security policy that needs to be applied to the HTTPS endpoint. For valid values, refer to the [AWS documentation](https://docs.aws.amazon.com/opensearch-service/latest/APIReference/API_DomainEndpointOptions.html#opensearchservice-Type-DomainEndpointOptions-TLSSecurityPolicy). Pulumi will only perform drift detection if a configuration value is provided. */ tlsSecurityPolicy: string; } interface DomainEbsOptions { /** * Whether EBS volumes are attached to data nodes in the domain. */ ebsEnabled: boolean; /** * Baseline input/output (I/O) performance of EBS volumes attached to data nodes. Applicable only for the GP3 and Provisioned IOPS EBS volume types. */ iops: number; /** * Specifies the throughput (in MiB/s) of the EBS volumes attached to data nodes. Applicable only for the gp3 volume type. */ throughput: number; /** * Size of EBS volumes attached to data nodes (in GiB). */ volumeSize?: number; /** * Type of EBS volumes attached to data nodes. */ volumeType: string; } interface DomainEncryptAtRest { /** * Whether to enable encryption at rest. If the `encryptAtRest` block is not provided then this defaults to `false`. Enabling encryption on new domains requires an `engineVersion` of `OpenSearch_X.Y` or `Elasticsearch_5.1` or greater. */ enabled: boolean; /** * KMS key ARN to encrypt the Elasticsearch domain with. If not specified then it defaults to using the `aws/es` service KMS key. Note that KMS will accept a KMS key ID but will return the key ARN. To prevent the provider detecting unwanted changes, use the key ARN instead. */ kmsKeyId: string; } interface DomainIdentityCenterOptions { enabledApiAccess?: boolean; identityCenterInstanceArn?: string; /** * Element of the JWT assertion to use for roles. Default is `roles`. */ rolesKey: string; /** * Element of the JWT assertion to use for the user name. Default is `sub`. */ subjectKey: string; } interface DomainLogPublishingOption { /** * ARN of the Cloudwatch log group to which log needs to be published. */ cloudwatchLogGroupArn: string; /** * Whether given log publishing option is enabled or not. */ enabled?: boolean; /** * Type of OpenSearch log. Valid values: `INDEX_SLOW_LOGS`, `SEARCH_SLOW_LOGS`, `ES_APPLICATION_LOGS`, `AUDIT_LOGS`. */ logType: string; } interface DomainNodeToNodeEncryption { /** * Whether to enable node-to-node encryption. If the `nodeToNodeEncryption` block is not provided then this defaults to `false`. Enabling node-to-node encryption of a new domain requires an `engineVersion` of `OpenSearch_X.Y` or `Elasticsearch_6.0` or greater. */ enabled: boolean; } interface DomainOffPeakWindowOptions { /** * Enabled disabled toggle for off-peak update window. */ enabled: boolean; offPeakWindow: outputs.opensearch.DomainOffPeakWindowOptionsOffPeakWindow; } interface DomainOffPeakWindowOptionsOffPeakWindow { /** * 10h window for updates */ windowStartTime: outputs.opensearch.DomainOffPeakWindowOptionsOffPeakWindowWindowStartTime; } interface DomainOffPeakWindowOptionsOffPeakWindowWindowStartTime { /** * Starting hour of the 10-hour window for updates */ hours: number; /** * Starting minute of the 10-hour window for updates */ minutes: number; } interface DomainSamlOptionsSamlOptions { /** * Whether SAML authentication is enabled. */ enabled?: boolean; /** * Information from your identity provider. */ idp?: outputs.opensearch.DomainSamlOptionsSamlOptionsIdp; /** * This backend role from the SAML IdP receives full permissions to the cluster, equivalent to a new master user. */ masterBackendRole?: string; /** * This username from the SAML IdP receives full permissions to the cluster, equivalent to a new master user. */ masterUserName?: string; /** * Element of the SAML assertion to use for backend roles. Default is roles. */ rolesKey?: string; /** * Duration of a session in minutes after a user logs in. Default is 60. Maximum value is 1,440. */ sessionTimeoutMinutes?: number; /** * Element of the SAML assertion to use for username. Default is NameID. */ subjectKey?: string; } interface DomainSamlOptionsSamlOptionsIdp { /** * Unique Entity ID of the application in SAML Identity Provider. */ entityId: string; /** * Metadata of the SAML application in xml format. */ metadataContent: string; } interface DomainSnapshotOptions { /** * Hour during which the service takes an automated daily snapshot of the indices in the domain. */ automatedSnapshotStartHour: number; } interface DomainSoftwareUpdateOptions { /** * Whether automatic service software updates are enabled for the domain. Defaults to `false`. */ autoSoftwareUpdateEnabled: boolean; } interface DomainVpcOptions { /** * If the domain was created inside a VPC, the names of the availability zones the configured `subnetIds` were created inside. */ availabilityZones: string[]; /** * List of VPC Security Group IDs to be applied to the OpenSearch domain endpoints. If omitted, the default Security Group for the VPC will be used. */ securityGroupIds?: string[]; /** * List of VPC Subnet IDs for the OpenSearch domain endpoints to be created in. */ subnetIds?: string[]; /** * If the domain was created inside a VPC, the ID of the VPC. */ vpcId: string; } interface GetDomainAdvancedSecurityOption { /** * Whether Anonymous auth is enabled. */ anonymousAuthEnabled: boolean; /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; /** * Whether the internal user database is enabled. */ internalUserDatabaseEnabled: boolean; /** * Block for JWT authentication. */ jwtOptions: outputs.opensearch.GetDomainAdvancedSecurityOptionJwtOption[]; } interface GetDomainAdvancedSecurityOptionJwtOption { /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; /** * URL endpoint that hosts the JSON Web Key Set (JWKS) containing public keys used to verify JWT signatures. */ jwksUrl: string; /** * PEM-encoded public key used to verify JWT signatures. */ publicKey: string; /** * Attribute that contains the backend role identifier (such as group name or group ID) in IAM Identity Center. */ rolesKey: string; /** * Attribute that contains the subject identifier (such as username, user ID, or email) in IAM Identity Center. */ subjectKey: string; } interface GetDomainAutoTuneOption { /** * Auto-Tune desired state for the domain. */ desiredState: string; /** * A list of the nested configurations for the Auto-Tune maintenance windows of the domain. */ maintenanceSchedules: outputs.opensearch.GetDomainAutoTuneOptionMaintenanceSchedule[]; /** * Whether the domain is set to roll back to default Auto-Tune settings when disabling Auto-Tune. */ rollbackOnDisable: string; /** * Whether to schedule Auto-Tune optimizations that require blue/green deployments during the domain's configured daily off-peak window. */ useOffPeakWindow: boolean; } interface GetDomainAutoTuneOptionMaintenanceSchedule { /** * Cron expression for an Auto-Tune maintenance schedule. */ cronExpressionForRecurrence: string; /** * Configuration block for the duration of the Auto-Tune maintenance window. */ durations: outputs.opensearch.GetDomainAutoTuneOptionMaintenanceScheduleDuration[]; /** * Date and time at which the Auto-Tune maintenance schedule starts in [RFC3339 format](https://tools.ietf.org/html/rfc3339#section-5.8). */ startAt: string; } interface GetDomainAutoTuneOptionMaintenanceScheduleDuration { /** * Unit of time. */ unit: string; /** * Duration of an Auto-Tune maintenance window. */ value: number; } interface GetDomainClusterConfig { /** * Configuration block containing cold storage configuration. */ coldStorageOptions: outputs.opensearch.GetDomainClusterConfigColdStorageOption[]; /** * Number of dedicated master nodes in the cluster. */ dedicatedMasterCount: number; /** * Indicates whether dedicated master nodes are enabled for the cluster. */ dedicatedMasterEnabled: boolean; /** * Instance type of the dedicated master nodes in the cluster. */ dedicatedMasterType: string; /** * Number of instances in the cluster. */ instanceCount: number; /** * Instance type of data nodes in the cluster. */ instanceType: string; /** * Whether a multi-AZ domain is turned on with a standby AZ. */ multiAzWithStandbyEnabled: boolean; /** * List of node options for the domain. */ nodeOptions: outputs.opensearch.GetDomainClusterConfigNodeOption[]; /** * Number of warm nodes in the cluster. */ warmCount: number; /** * Warm storage is enabled. */ warmEnabled?: boolean; /** * Instance type for the OpenSearch cluster's warm nodes. */ warmType: string; /** * Configuration block containing zone awareness settings. */ zoneAwarenessConfigs: outputs.opensearch.GetDomainClusterConfigZoneAwarenessConfig[]; /** * Indicates whether zone awareness is enabled. */ zoneAwarenessEnabled: boolean; } interface GetDomainClusterConfigColdStorageOption { /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; } interface GetDomainClusterConfigNodeOption { /** * Sizing of a node type. */ nodeConfigs: outputs.opensearch.GetDomainClusterConfigNodeOptionNodeConfig[]; /** * Type of node this configuration describes. */ nodeType: string; } interface GetDomainClusterConfigNodeOptionNodeConfig { /** * Number of nodes of a particular node type in the cluster. */ count: number; /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; /** * The instance type of a particular node type in the cluster. */ type: string; } interface GetDomainClusterConfigZoneAwarenessConfig { /** * Number of availability zones used. */ availabilityZoneCount: number; } interface GetDomainCognitoOption { /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; /** * Cognito Identity pool used by the domain. */ identityPoolId: string; /** * IAM Role with the AmazonOpenSearchServiceCognitoAccess policy attached. */ roleArn: string; /** * Cognito User pool used by the domain. */ userPoolId: string; } interface GetDomainDeploymentStrategyOption { /** * Deployment strategy for the domain. */ deploymentStrategy: string; } interface GetDomainEbsOption { /** * Whether EBS volumes are attached to data nodes in the domain. */ ebsEnabled: boolean; /** * Baseline input/output (I/O) performance of EBS volumes attached to data nodes. */ iops: number; /** * The throughput (in MiB/s) of the EBS volumes attached to data nodes. */ throughput: number; /** * Size of EBS volumes attached to data nodes (in GB). */ volumeSize: number; /** * Type of EBS volumes attached to data nodes. */ volumeType: string; } interface GetDomainEncryptionAtRest { /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; /** * KMS key id used to encrypt data at rest. */ kmsKeyId: string; } interface GetDomainIdentityCenterOption { /** * Boolean whether IAM Identity Center is enabled for API access. */ enabledApiAccess: boolean; /** * ARN of the IAM Identity Center instance to create an OpenSearch UI application that uses IAM Identity Center for authentication. */ identityCenterInstanceArn: string; /** * Attribute that contains the backend role identifier (such as group name or group ID) in IAM Identity Center. */ rolesKey: string; /** * Attribute that contains the subject identifier (such as username, user ID, or email) in IAM Identity Center. */ subjectKey: string; } interface GetDomainLogPublishingOption { /** * CloudWatch Log Group where the logs are published. */ cloudwatchLogGroupArn: string; /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; /** * Type of OpenSearch log being published. */ logType: string; } interface GetDomainNodeToNodeEncryption { /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; } interface GetDomainOffPeakWindowOptions { /** * Enabled disabled toggle for off-peak update window */ enabled: boolean; offPeakWindows: outputs.opensearch.GetDomainOffPeakWindowOptionsOffPeakWindow[]; } interface GetDomainOffPeakWindowOptionsOffPeakWindow { /** * 10h window for updates */ windowStartTimes: outputs.opensearch.GetDomainOffPeakWindowOptionsOffPeakWindowWindowStartTime[]; } interface GetDomainOffPeakWindowOptionsOffPeakWindowWindowStartTime { /** * Starting hour of the 10-hour window for updates */ hours: number; /** * Starting minute of the 10-hour window for updates */ minutes: number; } interface GetDomainSnapshotOption { /** * Hour during which the service takes an automated daily snapshot of the indices in the domain. */ automatedSnapshotStartHour: number; } interface GetDomainSoftwareUpdateOption { /** * Enabled or disabled. */ autoSoftwareUpdateEnabled: boolean; } interface GetDomainVpcOption { /** * Availability zones used by the domain. */ availabilityZones: string[]; /** * Security groups used by the domain. */ securityGroupIds: string[]; /** * Subnets used by the domain. */ subnetIds: string[]; /** * VPC used by the domain. */ vpcId: string; } interface GetServerlessCollectionGroupCapacityLimit { /** * Maximum indexing capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ maxIndexingCapacityInOcu: number; /** * Maximum search capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ maxSearchCapacityInOcu: number; /** * Minimum indexing capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ minIndexingCapacityInOcu: number; /** * Minimum search capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ minSearchCapacityInOcu: number; } interface GetServerlessCollectionGroupsCollectionGroupSummary { /** * ARN of the collection group. */ arn: string; /** * Capacity limits configured for the collection group. See `capacityLimits` below for details. */ capacityLimits: outputs.opensearch.GetServerlessCollectionGroupsCollectionGroupSummaryCapacityLimit[]; /** * Epoch time, in milliseconds, when the collection group was created. */ createdDate: string; /** * Unique identifier for the collection group. */ id: string; /** * Name of the collection group. */ name: string; /** * Number of collections currently associated with the collection group. */ numberOfCollections: number; /** * Indicates whether standby replicas are used for collections in the group. */ standbyReplicas: string; } interface GetServerlessCollectionGroupsCollectionGroupSummaryCapacityLimit { /** * Maximum indexing capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ maxIndexingCapacityInOcu: number; /** * Maximum search capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ maxSearchCapacityInOcu: number; /** * Minimum indexing capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ minIndexingCapacityInOcu: number; /** * Minimum search capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ minSearchCapacityInOcu: number; } interface GetServerlessSecurityConfigIamFederationOption { /** * Group attribute for this SAML integration. */ groupAttribute: string; /** * User attribute for this SAML integration. */ userAttribute: string; } interface GetServerlessSecurityConfigIamIdentityCenterOption { /** * Group attribute for this SAML integration. */ groupAttribute: string; /** * ARN of the IAM Identity Center instance used to integrate with OpenSearch Serverless. */ instanceArn: string; /** * User attribute for this SAML integration. */ userAttribute: string; } interface GetServerlessSecurityConfigSamlOption { /** * Group attribute for this SAML integration. */ groupAttribute: string; /** * XML IdP metadata file generated from your identity provider. */ metadata: string; /** * Session timeout, in minutes. Minimum is 5 minutes and maximum is 720 minutes (12 hours). Default is 60 minutes. */ sessionTimeout: number; /** * User attribute for this SAML integration. */ userAttribute: string; } interface OutboundConnectionConnectionProperties { /** * Configuration block for cross cluster search. */ crossClusterSearch?: outputs.opensearch.OutboundConnectionConnectionPropertiesCrossClusterSearch; /** * The endpoint of the remote domain, is only set when `connectionMode` is `VPC_ENDPOINT` and `acceptConnection` is `TRUE`. */ endpoint: string; } interface OutboundConnectionConnectionPropertiesCrossClusterSearch { /** * Skips unavailable clusters and can only be used for cross-cluster searches. Accepted values are `ENABLED` or `DISABLED`. */ skipUnavailable?: string; } interface OutboundConnectionLocalDomainInfo { /** * The name of the local domain. */ domainName: string; /** * The Account ID of the owner of the local domain. */ ownerId: string; /** * The region of the local domain. */ region: string; } interface OutboundConnectionRemoteDomainInfo { /** * The name of the remote domain. */ domainName: string; /** * The Account ID of the owner of the remote domain. */ ownerId: string; /** * The region of the remote domain. */ region: string; } interface PackagePackageSource { /** * The name of the Amazon S3 bucket containing the package. */ s3BucketName: string; /** * Key (file name) of the package. */ s3Key: string; } interface ServerlessCollectionEncryptionConfig { /** * Whether to use an AWS owned key for collection encryption. */ awsOwnedKey: boolean; /** * ARN of the AWS KMS key to use for collection encryption. */ kmsKeyArn: string; } interface ServerlessCollectionGroupCapacityLimit { /** * Maximum indexing capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ maxIndexingCapacityInOcu: number; /** * Maximum search capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ maxSearchCapacityInOcu: number; /** * Minimum indexing capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ minIndexingCapacityInOcu: number; /** * Minimum search capacity, in OpenSearch Compute Units (OCUs), for the collection group. */ minSearchCapacityInOcu: number; } interface ServerlessCollectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface ServerlessCollectionVectorOption { /** * Status of serverless vector acceleration for the collection. One of `ENABLED`, `DISABLED`, or `ALLOWED`. */ serverlessVectorAcceleration: string; } interface ServerlessSecurityConfigIamFederationOptions { /** * Group attribute for this IAM federation integration. At least one of `groupAttribute` or `userAttribute` must be specified. */ groupAttribute?: string; /** * User attribute for this IAM federation integration. At least one of `groupAttribute` or `userAttribute` must be specified. */ userAttribute?: string; } interface ServerlessSecurityConfigIamIdentityCenterOptions { /** * Group attribute for this IAM Identity Center integration. Valid values are `GroupId` and `GroupName`. Defaults to `GroupId`. */ groupAttribute: string; /** * ARN of the IAM Identity Center instance used to integrate with OpenSearch Serverless. */ instanceArn: string; /** * User attribute for this IAM Identity Center integration. Valid values are `UserId`, `UserName` and `Email`. Defaults to `UserId`. */ userAttribute: string; } interface ServerlessSecurityConfigSamlOptions { /** * Group attribute for this SAML integration. */ groupAttribute?: string; /** * XML IdP metadata file generated from your identity provider. */ metadata: string; /** * Session timeout, in minutes. Minimum is 5 minutes and maximum is 720 minutes (12 hours). Default is 60 minutes. */ sessionTimeout: number; /** * User attribute for this SAML integration. */ userAttribute?: string; } interface ServerlessVpcEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface VpcEndpointVpcOptions { availabilityZones: string[]; /** * The list of security group IDs associated with the VPC endpoints for the domain. If you do not provide a security group ID, OpenSearch Service uses the default security group for the VPC. */ securityGroupIds: string[]; /** * A list of subnet IDs associated with the VPC endpoints for the domain. If your domain uses multiple Availability Zones, you need to provide two subnet IDs, one per zone. Otherwise, provide only one. */ subnetIds: string[]; vpcId: string; } } export declare namespace opensearchingest { interface PipelineBufferOptions { /** * Whether persistent buffering should be enabled. */ persistentBufferEnabled: boolean; } interface PipelineEncryptionAtRestOptions { /** * The ARN of the KMS key used to encrypt data-at-rest in OpenSearch Ingestion. By default, data is encrypted using an AWS owned key. */ kmsKeyArn: string; } interface PipelineEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface PipelineEndpointVpcOptions { /** * List of security groups associated with the VPC endpoint. */ securityGroupIds?: string[]; /** * List of subnet IDs associated with the VPC endpoint. */ subnetIds: string[]; } interface PipelineLogPublishingOptions { /** * The destination for OpenSearch Ingestion logs sent to Amazon CloudWatch Logs. This parameter is required if IsLoggingEnabled is set to true. See `cloudwatchLogDestination` below. */ cloudwatchLogDestination?: outputs.opensearchingest.PipelineLogPublishingOptionsCloudwatchLogDestination; /** * Whether logs should be published. */ isLoggingEnabled?: boolean; } interface PipelineLogPublishingOptionsCloudwatchLogDestination { /** * The name of the CloudWatch Logs group to send pipeline logs to. You can specify an existing log group or create a new one. For example, /aws/OpenSearchService/IngestionService/my-pipeline. */ logGroup: string; } interface PipelineTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface PipelineVpcOptions { /** * A list of security groups associated with the VPC endpoint. */ securityGroupIds?: string[]; /** * A list of subnet IDs associated with the VPC endpoint. */ subnetIds: string[]; /** * Whether you or Amazon OpenSearch Ingestion service create and manage the VPC endpoint configured for the pipeline. Valid values are `CUSTOMER` or `SERVICE` */ vpcEndpointManagement?: string; } } export declare namespace organizations { interface GetDelegatedAdministratorsDelegatedAdministrator { /** * The ARN of the delegated administrator's account. */ arn: string; /** * The date when the account was made a delegated administrator. */ delegationEnabledDate: string; /** * The email address that is associated with the delegated administrator's AWS account. */ email: string; /** * The unique identifier (ID) of the delegated administrator's account. */ id: string; /** * The method by which the delegated administrator's account joined the organization. */ joinedMethod: string; /** * The date when the delegated administrator's account became a part of the organization. */ joinedTimestamp: string; /** * The friendly name of the delegated administrator's account. */ name: string; /** * The status of the delegated administrator's account in the organization. */ status: string; } interface GetDelegatedServicesDelegatedService { /** * The date that the account became a delegated administrator for this service. */ delegationEnabledDate: string; /** * The name of an AWS service that can request an operation for the specified service. */ servicePrincipal: string; } interface GetOrganizationAccount { /** * ARN of the root. */ arn: string; /** * Email of the account. */ email: string; /** * Identifier of the root. */ id: string; /** * Method by which the account joined the organization. */ joinedMethod: string; /** * Date the account became a part of the organization. */ joinedTimestamp: string; /** * Name of the policy type. */ name: string; /** * State of the account. */ state: string; /** * Status of the policy type as it relates to the associated root. * * @deprecated status is deprecated. Use state instead. */ status: string; } interface GetOrganizationNonMasterAccount { /** * ARN of the root. */ arn: string; /** * Email of the account. */ email: string; /** * Identifier of the root. */ id: string; /** * Method by which the account joined the organization. */ joinedMethod: string; /** * Date the account became a part of the organization. */ joinedTimestamp: string; /** * Name of the policy type. */ name: string; /** * State of the account. */ state: string; /** * Status of the policy type as it relates to the associated root. * * @deprecated status is deprecated. Use state instead. */ status: string; } interface GetOrganizationRoot { /** * ARN of the root. */ arn: string; /** * Identifier of the root. */ id: string; /** * Name of the policy type. */ name: string; /** * List of policy types enabled for this root. All elements have these attributes: */ policyTypes: outputs.organizations.GetOrganizationRootPolicyType[]; } interface GetOrganizationRootPolicyType { /** * Status of the policy type as it relates to the associated root. */ status: string; type: string; } interface GetOrganizationalUnitChildAccountsAccount { /** * The ARN of the account. */ arn: string; /** * The email address associated with the AWS account. */ email: string; /** * Parent identifier of the organizational units. */ id: string; /** * Method by which the account joined the organization. */ joinedMethod: string; /** * Date the account became a part of the organization. */ joinedTimestamp: string; /** * The friendly name of the account. */ name: string; /** * State of the account in the organization. */ state: string; /** * (**Deprecated** use `state` instead) Status of the account in the organization. * * @deprecated status is deprecated. Use state instead. */ status: string; } interface GetOrganizationalUnitDescendantAccountsAccount { /** * The ARN of the account. */ arn: string; /** * The email address associated with the AWS account. */ email: string; /** * Parent identifier of the organizational units. */ id: string; /** * Method by which the account joined the organization. */ joinedMethod: string; /** * Date the account became a part of the organization. */ joinedTimestamp: string; /** * Friendly name of the account. */ name: string; /** * State of the account in the organization. */ state: string; /** * (**Deprecated** use `state` instead) Status of the account in the organization. * * @deprecated status is deprecated. Use state instead. */ status: string; } interface GetOrganizationalUnitDescendantOrganizationalUnitsChildren { /** * ARN of the organizational unit */ arn: string; /** * Parent identifier of the organizational units. */ id: string; /** * Name of the organizational unit */ name: string; } interface GetOrganizationalUnitsChild { /** * ARN of the organizational unit */ arn: string; /** * Parent identifier of the organizational units. */ id: string; /** * Name of the organizational unit */ name: string; } interface OrganizationAccount { /** * ARN of the root. */ arn: string; /** * Email of the account. */ email: string; /** * Identifier of the root. */ id: string; /** * Method by which the account joined the organization. */ joinedMethod: string; /** * Date the account became a part of the organization. */ joinedTimestamp: string; /** * Name of the policy type. */ name: string; /** * State of the account. */ state: string; /** * Status of the policy type as it relates to the associated root. * * @deprecated status is deprecated. Use state instead. */ status: string; } interface OrganizationNonMasterAccount { /** * ARN of the root. */ arn: string; /** * Email of the account. */ email: string; /** * Identifier of the root. */ id: string; /** * Method by which the account joined the organization. */ joinedMethod: string; /** * Date the account became a part of the organization. */ joinedTimestamp: string; /** * Name of the policy type. */ name: string; /** * State of the account. */ state: string; /** * Status of the policy type as it relates to the associated root. * * @deprecated status is deprecated. Use state instead. */ status: string; } interface OrganizationRoot { /** * ARN of the root. */ arn: string; /** * Identifier of the root. */ id: string; /** * Name of the policy type. */ name: string; /** * List of policy types enabled for this root. All elements have these attributes: */ policyTypes: outputs.organizations.OrganizationRootPolicyType[]; } interface OrganizationRootPolicyType { /** * Status of the policy type as it relates to the associated root. */ status: string; type: string; } interface OrganizationalUnitAccount { /** * ARN of the organizational unit */ arn: string; /** * Email of the account */ email: string; /** * Identifier of the organization unit */ id: string; /** * The name for the organizational unit */ name: string; } } export declare namespace outposts { interface CapacityTaskInstancePool { /** * Number of instances of `instanceType` that should be present after the task completes. Must be at least `1`. Changing this value forces a new resource. */ count: number; /** * Instance type for this pool entry. Must be an instance type supported by the target Outpost. Changing this value forces a new resource. */ instanceType: string; } interface CapacityTaskInstancesToExclude { /** * Set of EC2 instance IDs (of user-owned instances running on the Outpost) that the capacity task must not stop. At least one instance ID is required. */ instances: string[]; } interface CapacityTaskTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * > **Long-running capacity tasks.** The default `create` timeout of `60m` is sufficient for most re-balancing operations on small to medium instance types. However, capacity tasks that change the configuration of bare-metal instance types (`*.metal`) or very large instance types (`24xlarge`, `48xlarge`, etc.) in the current or target state can take **8 to 12 hours** to complete, because AWS must stop, reconfigure, and re-start the underlying hardware. If your `instancePool` configuration or the current state of the Outpost involves one of these instance types, override the `create` timeout accordingly — for example: */ delete?: string; } } export declare namespace paymentcryptography { interface KeyKeyAttribute { /** * Key algorithm to be use during creation of an AWS Payment Cryptography key. */ keyAlgorithm: string; /** * Type of AWS Payment Cryptography key to create. */ keyClass: string; /** * List of cryptographic operations that you can perform using the key. */ keyModesOfUses?: outputs.paymentcryptography.KeyKeyAttributeKeyModesOfUse[]; /** * Cryptographic usage of an AWS Payment Cryptography key as defined in section A.5.2 of the TR-31 spec. */ keyUsage: string; } interface KeyKeyAttributeKeyModesOfUse { /** * Whether an AWS Payment Cryptography key can be used to decrypt data. */ decrypt: boolean; /** * Whether an AWS Payment Cryptography key can be used to derive new keys. */ deriveKey: boolean; /** * Whether an AWS Payment Cryptography key can be used to encrypt data. */ encrypt: boolean; /** * Whether an AWS Payment Cryptography key can be used to generate and verify other card and PIN verification keys. */ generate: boolean; /** * Whether an AWS Payment Cryptography key has no special restrictions other than the restrictions implied by KeyUsage. */ noRestrictions: boolean; /** * Whether an AWS Payment Cryptography key can be used for signing. */ sign: boolean; /** * Whether an AWS Payment Cryptography key can be used to unwrap other keys. */ unwrap: boolean; /** * Whether an AWS Payment Cryptography key can be used to verify signatures. */ verify: boolean; /** * Whether an AWS Payment Cryptography key can be used to wrap other keys. */ wrap: boolean; } interface KeyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace pinpoint { interface AppCampaignHook { /** * Lambda function name or ARN to be called for delivery. Conflicts with `webUrl`. */ lambdaFunctionName?: string; /** * What mode Lambda should be invoked in. Valid values for this parameter are `DELIVERY`, `FILTER`. */ mode?: string; /** * Web URL to call for hook. If the URL has authentication specified it will be added as authentication to the request. Conflicts with `lambdaFunctionName`. */ webUrl?: string; } interface AppLimits { /** * Maximum number of messages that the campaign can send daily. */ daily?: number; /** * Length of time (in seconds) that the campaign can run before it ends and message deliveries stop. This duration begins at the scheduled start time for the campaign. Minimum value is 60. */ maximumDuration?: number; /** * Number of messages that the campaign can send per second. Minimum value is 50, and the maximum is 20000. */ messagesPerSecond?: number; /** * Maximum total number of messages that the campaign can send. */ total?: number; } interface AppQuietTime { /** * Default end time for quiet time in ISO 8601 format. Required if `start` is set. */ end?: string; /** * Default start time for quiet time in ISO 8601 format. Required if `end` is set. */ start?: string; } interface EmailTemplateEmailTemplate { /** * JSON object that specifies the default values to use for message variables in the message template. This object is a set of key-value pairs. Each key defines a message variable in the template. The corresponding value defines the default value for that variable. When you create a message that's based on the template, you can override these defaults with message-specific and address-specific variables and values. */ defaultSubstitutions?: string; /** * Custom description of the message template. */ description?: string; /** * List of [MessageHeaders](https://docs.aws.amazon.com/pinpoint/latest/apireference/templates-template-name-email.html#templates-template-name-email-model-messageheader) for the email. You can have up to 15 Headers. See below. */ headers?: outputs.pinpoint.EmailTemplateEmailTemplateHeader[]; /** * Message body, in HTML format, to use in email messages that are based on the message template. We recommend using HTML format for email clients that render HTML content. You can include links, formatted text, and more in an HTML message. */ htmlPart?: string; /** * Unique identifier for the recommender model to use for the message template. AWS End User Messaging uses this value to determine how to retrieve and process data from a recommender model when it sends messages that use the template, if the template contains message variables for recommendation data. */ recommenderId?: string; /** * Subject line, or title, to use in email messages that are based on the message template. */ subject?: string; /** * Message body, in plain text format, to use in email messages that are based on the message template. We recommend using plain text format for email clients that don't render HTML content and clients that are connected to high-latency networks, such as mobile devices. */ textPart?: string; } interface EmailTemplateEmailTemplateHeader { /** * Name of the message header. The header name can contain up to 126 characters. */ name?: string; /** * Value of the message header. The header value can contain up to 870 characters, including the length of any rendered attributes. For example if you add the {CreationDate} attribute, it renders as YYYY-MM-DDTHH:MM:SS.SSSZ and is 24 characters in length. */ value?: string; } interface Smsvoicev2EventDestinationCloudwatchLogsDestination { /** * ARN of the IAM role that End User Messaging SMS assumes to write to the log group. */ iamRoleArn: string; /** * ARN of the Amazon CloudWatch log group that receives the events. */ logGroupArn: string; } interface Smsvoicev2EventDestinationKinesisFirehoseDestination { /** * ARN of the Amazon Data Firehose delivery stream that receives the events. */ deliveryStreamArn: string; /** * ARN of the IAM role that End User Messaging SMS assumes to write to the delivery stream. */ iamRoleArn: string; } interface Smsvoicev2EventDestinationSnsDestination { /** * ARN of the Amazon SNS topic that receives the events. */ topicArn: string; } interface Smsvoicev2PhoneNumberTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface Smsvoicev2PoolTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface Smsvoicev2SenderIdTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace pipes { interface PipeEnrichmentParameters { /** * Contains the HTTP parameters to use when the target is a API Gateway REST endpoint or EventBridge ApiDestination. If you specify an API Gateway REST API or EventBridge ApiDestination as a target, you can use this parameter to specify headers, path parameters, and query string keys/values as part of your target invoking request. If you're using ApiDestinations, the corresponding Connection can also have these values configured. In case of any conflicting keys, values from the Connection take precedence. Detailed below. */ httpParameters?: outputs.pipes.PipeEnrichmentParametersHttpParameters; /** * Valid JSON text passed to the target. In this case, nothing from the event itself is passed to the target. Maximum length of 8192 characters. */ inputTemplate?: string; } interface PipeEnrichmentParametersHttpParameters { headerParameters?: { [key: string]: string; }; pathParameterValues?: string; queryStringParameters?: { [key: string]: string; }; } interface PipeLogConfiguration { /** * Amazon CloudWatch Logs logging configuration settings for the pipe. Detailed below. */ cloudwatchLogsLogDestination?: outputs.pipes.PipeLogConfigurationCloudwatchLogsLogDestination; /** * Amazon Kinesis Data Firehose logging configuration settings for the pipe. Detailed below. */ firehoseLogDestination?: outputs.pipes.PipeLogConfigurationFirehoseLogDestination; /** * String list that specifies whether the execution data (specifically, the `payload`, `awsRequest`, and `awsResponse` fields) is included in the log messages for this pipe. This applies to all log destinations for the pipe. Valid values `ALL`. */ includeExecutionDatas?: string[]; /** * The level of logging detail to include. Valid values `OFF`, `ERROR`, `INFO` and `TRACE`. */ level: string; /** * Amazon S3 logging configuration settings for the pipe. Detailed below. */ s3LogDestination?: outputs.pipes.PipeLogConfigurationS3LogDestination; } interface PipeLogConfigurationCloudwatchLogsLogDestination { /** * Amazon Web Services Resource Name (ARN) for the CloudWatch log group to which EventBridge sends the log records. */ logGroupArn: string; } interface PipeLogConfigurationFirehoseLogDestination { /** * ARN of the Kinesis Data Firehose delivery stream to which EventBridge delivers the pipe log records. */ deliveryStreamArn: string; } interface PipeLogConfigurationS3LogDestination { /** * Name of the Amazon S3 bucket to which EventBridge delivers the log records for the pipe. */ bucketName: string; /** * Amazon Web Services account that owns the Amazon S3 bucket to which EventBridge delivers the log records for the pipe. */ bucketOwner: string; /** * EventBridge format for the log records. Valid values `json`, `plain` and `w3c`. */ outputFormat?: string; /** * Prefix text with which to begin Amazon S3 log object names. */ prefix?: string; } interface PipeSourceParameters { /** * The parameters for using an Active MQ broker as a source. Detailed below. */ activemqBrokerParameters: outputs.pipes.PipeSourceParametersActivemqBrokerParameters; /** * The parameters for using a DynamoDB stream as a source. Detailed below. */ dynamodbStreamParameters: outputs.pipes.PipeSourceParametersDynamodbStreamParameters; /** * The collection of event patterns used to [filter events](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-pipes-event-filtering.html). Detailed below. */ filterCriteria?: outputs.pipes.PipeSourceParametersFilterCriteria; /** * The parameters for using a Kinesis stream as a source. Detailed below. */ kinesisStreamParameters: outputs.pipes.PipeSourceParametersKinesisStreamParameters; /** * The parameters for using an MSK stream as a source. Detailed below. */ managedStreamingKafkaParameters: outputs.pipes.PipeSourceParametersManagedStreamingKafkaParameters; /** * The parameters for using a Rabbit MQ broker as a source. Detailed below. */ rabbitmqBrokerParameters: outputs.pipes.PipeSourceParametersRabbitmqBrokerParameters; /** * The parameters for using a self-managed Apache Kafka stream as a source. Detailed below. */ selfManagedKafkaParameters: outputs.pipes.PipeSourceParametersSelfManagedKafkaParameters; /** * The parameters for using a Amazon SQS stream as a source. Detailed below. */ sqsQueueParameters: outputs.pipes.PipeSourceParametersSqsQueueParameters; } interface PipeSourceParametersActivemqBrokerParameters { /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * The credentials needed to access the resource. Detailed below. */ credentials: outputs.pipes.PipeSourceParametersActivemqBrokerParametersCredentials; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; /** * The name of the destination queue to consume. Maximum length of 1000. */ queueName: string; } interface PipeSourceParametersActivemqBrokerParametersCredentials { /** * The ARN of the Secrets Manager secret containing the credentials. */ basicAuth: string; } interface PipeSourceParametersDynamodbStreamParameters { /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * Define the target queue to send dead-letter queue events to. Detailed below. */ deadLetterConfig?: outputs.pipes.PipeSourceParametersDynamodbStreamParametersDeadLetterConfig; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; /** * Discard records older than the specified age. The default value is -1, which sets the maximum age to infinite. When the value is set to infinite, EventBridge never discards old records. Maximum value of 604,800. */ maximumRecordAgeInSeconds: number; /** * Discard records after the specified number of retries. The default value is -1, which sets the maximum number of retries to infinite. When MaximumRetryAttempts is infinite, EventBridge retries failed records until the record expires in the event source. Maximum value of 10,000. */ maximumRetryAttempts?: number; /** * Define how to handle item process failures. AUTOMATIC_BISECT halves each batch and retry each half until all the records are processed or there is one failed message left in the batch. Valid values: AUTOMATIC_BISECT. */ onPartialBatchItemFailure?: string; /** * The number of batches to process concurrently from each shard. The default value is 1. Maximum value of 10. */ parallelizationFactor: number; /** * The position in a stream from which to start reading. Valid values: TRIM_HORIZON, LATEST. */ startingPosition: string; } interface PipeSourceParametersDynamodbStreamParametersDeadLetterConfig { /** * ARN of this pipe. */ arn?: string; } interface PipeSourceParametersFilterCriteria { /** * An array of up to 5 event patterns. Detailed below. */ filters?: outputs.pipes.PipeSourceParametersFilterCriteriaFilter[]; } interface PipeSourceParametersFilterCriteriaFilter { /** * The event pattern. At most 4096 characters. */ pattern: string; } interface PipeSourceParametersKinesisStreamParameters { /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * Define the target queue to send dead-letter queue events to. Detailed below. */ deadLetterConfig?: outputs.pipes.PipeSourceParametersKinesisStreamParametersDeadLetterConfig; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; /** * Discard records older than the specified age. The default value is -1, which sets the maximum age to infinite. When the value is set to infinite, EventBridge never discards old records. Maximum value of 604,800. */ maximumRecordAgeInSeconds: number; /** * Discard records after the specified number of retries. The default value is -1, which sets the maximum number of retries to infinite. When MaximumRetryAttempts is infinite, EventBridge retries failed records until the record expires in the event source. Maximum value of 10,000. */ maximumRetryAttempts?: number; /** * Define how to handle item process failures. AUTOMATIC_BISECT halves each batch and retry each half until all the records are processed or there is one failed message left in the batch. Valid values: AUTOMATIC_BISECT. */ onPartialBatchItemFailure?: string; /** * The number of batches to process concurrently from each shard. The default value is 1. Maximum value of 10. */ parallelizationFactor: number; /** * The position in a stream from which to start reading. Valid values: TRIM_HORIZON, LATEST. */ startingPosition: string; /** * With StartingPosition set to AT_TIMESTAMP, the time from which to start reading, in Unix time seconds. */ startingPositionTimestamp?: string; } interface PipeSourceParametersKinesisStreamParametersDeadLetterConfig { /** * ARN of this pipe. */ arn?: string; } interface PipeSourceParametersManagedStreamingKafkaParameters { /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * The name of the destination queue to consume. Maximum value of 200. */ consumerGroupId?: string; /** * The credentials needed to access the resource. Detailed below. */ credentials?: outputs.pipes.PipeSourceParametersManagedStreamingKafkaParametersCredentials; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; /** * The position in a stream from which to start reading. Valid values: TRIM_HORIZON, LATEST. */ startingPosition?: string; /** * The name of the topic that the pipe will read from. Maximum length of 249. */ topicName: string; } interface PipeSourceParametersManagedStreamingKafkaParametersCredentials { /** * The ARN of the Secrets Manager secret containing the credentials. */ clientCertificateTlsAuth?: string; /** * The ARN of the Secrets Manager secret containing the credentials. */ saslScram512Auth?: string; } interface PipeSourceParametersRabbitmqBrokerParameters { /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * The credentials needed to access the resource. Detailed below. */ credentials: outputs.pipes.PipeSourceParametersRabbitmqBrokerParametersCredentials; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; /** * The name of the destination queue to consume. Maximum length of 1000. */ queueName: string; /** * The name of the virtual host associated with the source broker. Maximum length of 200. */ virtualHost?: string; } interface PipeSourceParametersRabbitmqBrokerParametersCredentials { /** * The ARN of the Secrets Manager secret containing the credentials. */ basicAuth: string; } interface PipeSourceParametersSelfManagedKafkaParameters { /** * An array of server URLs. Maximum number of 2 items, each of maximum length 300. */ additionalBootstrapServers?: string[]; /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * The name of the destination queue to consume. Maximum value of 200. */ consumerGroupId?: string; /** * The credentials needed to access the resource. Detailed below. */ credentials?: outputs.pipes.PipeSourceParametersSelfManagedKafkaParametersCredentials; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; /** * The ARN of the Secrets Manager secret used for certification. */ serverRootCaCertificate?: string; /** * The position in a stream from which to start reading. Valid values: TRIM_HORIZON, LATEST. */ startingPosition?: string; /** * The name of the topic that the pipe will read from. Maximum length of 249. */ topicName: string; /** * This structure specifies the VPC subnets and security groups for the stream, and whether a public IP address is to be used. Detailed below. */ vpc?: outputs.pipes.PipeSourceParametersSelfManagedKafkaParametersVpc; } interface PipeSourceParametersSelfManagedKafkaParametersCredentials { /** * The ARN of the Secrets Manager secret containing the credentials. */ basicAuth?: string; /** * The ARN of the Secrets Manager secret containing the credentials. */ clientCertificateTlsAuth?: string; /** * The ARN of the Secrets Manager secret containing the credentials. */ saslScram256Auth?: string; /** * The ARN of the Secrets Manager secret containing the credentials. */ saslScram512Auth?: string; } interface PipeSourceParametersSelfManagedKafkaParametersVpc { securityGroups?: string[]; subnets?: string[]; } interface PipeSourceParametersSqsQueueParameters { /** * The maximum number of records to include in each batch. Maximum value of 10000. */ batchSize: number; /** * The maximum length of a time to wait for events. Maximum value of 300. */ maximumBatchingWindowInSeconds: number; } interface PipeTargetParameters { /** * The parameters for using an AWS Batch job as a target. Detailed below. */ batchJobParameters?: outputs.pipes.PipeTargetParametersBatchJobParameters; /** * The parameters for using an CloudWatch Logs log stream as a target. Detailed below. */ cloudwatchLogsParameters?: outputs.pipes.PipeTargetParametersCloudwatchLogsParameters; /** * The parameters for using an Amazon ECS task as a target. Detailed below. */ ecsTaskParameters?: outputs.pipes.PipeTargetParametersEcsTaskParameters; /** * The parameters for using an EventBridge event bus as a target. Detailed below. */ eventbridgeEventBusParameters?: outputs.pipes.PipeTargetParametersEventbridgeEventBusParameters; /** * These are custom parameter to be used when the target is an API Gateway REST APIs or EventBridge ApiDestinations. Detailed below. */ httpParameters?: outputs.pipes.PipeTargetParametersHttpParameters; /** * Valid JSON text passed to the target. In this case, nothing from the event itself is passed to the target. Maximum length of 8192 characters. */ inputTemplate?: string; /** * The parameters for using a Kinesis stream as a source. Detailed below. */ kinesisStreamParameters?: outputs.pipes.PipeTargetParametersKinesisStreamParameters; /** * The parameters for using a Lambda function as a target. Detailed below. */ lambdaFunctionParameters?: outputs.pipes.PipeTargetParametersLambdaFunctionParameters; /** * These are custom parameters to be used when the target is a Amazon Redshift cluster to invoke the Amazon Redshift Data API BatchExecuteStatement. Detailed below. */ redshiftDataParameters?: outputs.pipes.PipeTargetParametersRedshiftDataParameters; /** * The parameters for using a SageMaker AI pipeline as a target. Detailed below. */ sagemakerPipelineParameters?: outputs.pipes.PipeTargetParametersSagemakerPipelineParameters; /** * The parameters for using a Amazon SQS stream as a target. Detailed below. */ sqsQueueParameters?: outputs.pipes.PipeTargetParametersSqsQueueParameters; /** * The parameters for using a Step Functions state machine as a target. Detailed below. */ stepFunctionStateMachineParameters?: outputs.pipes.PipeTargetParametersStepFunctionStateMachineParameters; } interface PipeTargetParametersBatchJobParameters { /** * The array properties for the submitted job, such as the size of the array. The array size can be between 2 and 10,000. If you specify array properties for a job, it becomes an array job. This parameter is used only if the target is an AWS Batch job. Detailed below. */ arrayProperties?: outputs.pipes.PipeTargetParametersBatchJobParametersArrayProperties; /** * The overrides that are sent to a container. Detailed below. */ containerOverrides?: outputs.pipes.PipeTargetParametersBatchJobParametersContainerOverrides; /** * A list of dependencies for the job. A job can depend upon a maximum of 20 jobs. You can specify a SEQUENTIAL type dependency without specifying a job ID for array jobs so that each child array job completes sequentially, starting at index 0. You can also specify an N_TO_N type dependency with a job ID for array jobs. In that case, each index child of this job must wait for the corresponding index child of each dependency to complete before it can begin. Detailed below. */ dependsOns?: outputs.pipes.PipeTargetParametersBatchJobParametersDependsOn[]; /** * Job definition used by this job. This value can be one of name, name:revision, or the ARN for the job definition. If name is specified without a revision then the latest active revision is used. */ jobDefinition: string; /** * The name of the job. It can be up to 128 letters long. */ jobName: string; /** * Additional parameters passed to the job that replace parameter substitution placeholders that are set in the job definition. Parameters are specified as a key and value pair mapping. Parameters included here override any corresponding parameter defaults from the job definition. Detailed below. */ parameters?: { [key: string]: string; }; /** * The retry strategy to use for failed jobs. When a retry strategy is specified here, it overrides the retry strategy defined in the job definition. Detailed below. */ retryStrategy?: outputs.pipes.PipeTargetParametersBatchJobParametersRetryStrategy; } interface PipeTargetParametersBatchJobParametersArrayProperties { /** * The size of the array, if this is an array batch job. Minimum value of 2. Maximum value of 10,000. */ size?: number; } interface PipeTargetParametersBatchJobParametersContainerOverrides { /** * List of commands to send to the container that overrides the default command from the Docker image or the task definition. You must also specify a container name. */ commands?: string[]; /** * The environment variables to send to the container. You can add new environment variables, which are added to the container at launch, or you can override the existing environment variables from the Docker image or the task definition. You must also specify a container name. Detailed below. */ environments?: outputs.pipes.PipeTargetParametersBatchJobParametersContainerOverridesEnvironment[]; /** * The instance type to use for a multi-node parallel job. This parameter isn't applicable to single-node container jobs or jobs that run on Fargate resources, and shouldn't be provided. */ instanceType?: string; /** * The type and amount of a resource to assign to a container, instead of the default value from the task definition. The only supported resource is a GPU. Detailed below. */ resourceRequirements?: outputs.pipes.PipeTargetParametersBatchJobParametersContainerOverridesResourceRequirement[]; } interface PipeTargetParametersBatchJobParametersContainerOverridesEnvironment { /** * Name of the pipe. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name?: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. Maximum length of 1024. */ value?: string; } interface PipeTargetParametersBatchJobParametersContainerOverridesResourceRequirement { /** * The type of placement strategy. The random placement strategy randomly places tasks on available candidates. The spread placement strategy spreads placement across available candidates evenly based on the field parameter. The binpack strategy places tasks on available candidates that have the least available amount of the resource that is specified with the field parameter. For example, if you binpack on memory, a task is placed on the instance with the least amount of remaining memory (but still enough to run the task). Valid Values: random, spread, binpack. */ type: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. Maximum length of 1024. */ value: string; } interface PipeTargetParametersBatchJobParametersDependsOn { /** * The job ID of the AWS Batch job that's associated with this dependency. */ jobId?: string; /** * The type of placement strategy. The random placement strategy randomly places tasks on available candidates. The spread placement strategy spreads placement across available candidates evenly based on the field parameter. The binpack strategy places tasks on available candidates that have the least available amount of the resource that is specified with the field parameter. For example, if you binpack on memory, a task is placed on the instance with the least amount of remaining memory (but still enough to run the task). Valid Values: random, spread, binpack. */ type?: string; } interface PipeTargetParametersBatchJobParametersRetryStrategy { /** * The number of times to move a job to the RUNNABLE status. If the value of attempts is greater than one, the job is retried on failure the same number of attempts as the value. Maximum value of 10. */ attempts?: number; } interface PipeTargetParametersCloudwatchLogsParameters { /** * The name of the log stream. */ logStreamName?: string; /** * The time the event occurred, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC. This is the JSON path to the field in the event e.g. $.detail.timestamp */ timestamp?: string; } interface PipeTargetParametersEcsTaskParameters { /** * List of capacity provider strategies to use for the task. If a capacityProviderStrategy is specified, the launchType parameter must be omitted. If no capacityProviderStrategy or launchType is specified, the defaultCapacityProviderStrategy for the cluster is used. Detailed below. */ capacityProviderStrategies?: outputs.pipes.PipeTargetParametersEcsTaskParametersCapacityProviderStrategy[]; /** * Specifies whether to enable Amazon ECS managed tags for the task. Valid values: true, false. */ enableEcsManagedTags?: boolean; /** * Whether or not to enable the execute command functionality for the containers in this task. If true, this enables execute command functionality on all containers in the task. Valid values: true, false. */ enableExecuteCommand?: boolean; /** * Specifies an Amazon ECS task group for the task. The maximum length is 255 characters. */ group?: string; /** * Specifies the launch type on which your task is running. The launch type that you specify here must match one of the launch type (compatibilities) of the target task. The FARGATE value is supported only in the Regions where AWS Fargate with Amazon ECS is supported. Valid Values: EC2, FARGATE, EXTERNAL */ launchType?: string; /** * Use this structure if the Amazon ECS task uses the awsvpc network mode. This structure specifies the VPC subnets and security groups associated with the task, and whether a public IP address is to be used. This structure is required if LaunchType is FARGATE because the awsvpc mode is required for Fargate tasks. If you specify NetworkConfiguration when the target ECS task does not use the awsvpc network mode, the task fails. Detailed below. */ networkConfiguration?: outputs.pipes.PipeTargetParametersEcsTaskParametersNetworkConfiguration; /** * The overrides that are associated with a task. Detailed below. */ overrides?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverrides; /** * An array of placement constraint objects to use for the task. You can specify up to 10 constraints per task (including constraints in the task definition and those specified at runtime). Detailed below. */ placementConstraints?: outputs.pipes.PipeTargetParametersEcsTaskParametersPlacementConstraint[]; /** * The placement strategy objects to use for the task. You can specify a maximum of five strategy rules per task. Detailed below. */ placementStrategies?: outputs.pipes.PipeTargetParametersEcsTaskParametersPlacementStrategy[]; /** * Specifies the platform version for the task. Specify only the numeric portion of the platform version, such as 1.1.0. This structure is used only if LaunchType is FARGATE. */ platformVersion?: string; /** * Specifies whether to propagate the tags from the task definition to the task. If no value is specified, the tags are not propagated. Tags can only be propagated to the task during task creation. To add tags to a task after task creation, use the TagResource API action. Valid Values: TASK_DEFINITION */ propagateTags?: string; /** * The reference ID to use for the task. Maximum length of 1,024. */ referenceId?: string; /** * Key-value mapping of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: { [key: string]: string; }; /** * The number of tasks to create based on TaskDefinition. The default is 1. */ taskCount?: number; /** * The ARN of the task definition to use if the event target is an Amazon ECS task. */ taskDefinitionArn: string; } interface PipeTargetParametersEcsTaskParametersCapacityProviderStrategy { /** * The base value designates how many tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. If no value is specified, the default value of 0 is used. Maximum value of 100,000. */ base?: number; /** * The short name of the capacity provider. Maximum value of 255. */ capacityProvider: string; /** * The weight value designates the relative percentage of the total number of tasks launched that should use the specified capacity provider. The weight value is taken into consideration after the base value, if defined, is satisfied. Maximum value of 1,000. */ weight?: number; } interface PipeTargetParametersEcsTaskParametersNetworkConfiguration { /** * Use this structure to specify the VPC subnets and security groups for the task, and whether a public IP address is to be used. This structure is relevant only for ECS tasks that use the awsvpc network mode. Detailed below. */ awsVpcConfiguration?: outputs.pipes.PipeTargetParametersEcsTaskParametersNetworkConfigurationAwsVpcConfiguration; } interface PipeTargetParametersEcsTaskParametersNetworkConfigurationAwsVpcConfiguration { /** * Specifies whether the task's elastic network interface receives a public IP address. You can specify ENABLED only when LaunchType in EcsParameters is set to FARGATE. Valid Values: ENABLED, DISABLED. */ assignPublicIp?: string; securityGroups?: string[]; subnets?: string[]; } interface PipeTargetParametersEcsTaskParametersOverrides { /** * One or more container overrides that are sent to a task. Detailed below. */ containerOverrides?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverridesContainerOverride[]; /** * The number of cpu units reserved for the container, instead of the default value from the task definition. You must also specify a container name. */ cpu?: string; /** * The ephemeral storage setting override for the task. Detailed below. */ ephemeralStorage?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverridesEphemeralStorage; /** * ARN of the task execution IAM role override for the task. */ executionRoleArn?: string; /** * List of Elastic Inference accelerator overrides for the task. Detailed below. */ inferenceAcceleratorOverrides?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverridesInferenceAcceleratorOverride[]; /** * The hard limit (in MiB) of memory to present to the container, instead of the default value from the task definition. If your container attempts to exceed the memory specified here, the container is killed. You must also specify a container name. */ memory?: string; /** * ARN of the IAM role that containers in this task can assume. All containers in this task are granted the permissions that are specified in this role. */ taskRoleArn?: string; } interface PipeTargetParametersEcsTaskParametersOverridesContainerOverride { /** * List of commands to send to the container that overrides the default command from the Docker image or the task definition. You must also specify a container name. */ commands?: string[]; /** * The number of cpu units reserved for the container, instead of the default value from the task definition. You must also specify a container name. */ cpu?: number; /** * A list of files containing the environment variables to pass to a container, instead of the value from the container definition. Detailed below. */ environmentFiles?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverridesContainerOverrideEnvironmentFile[]; /** * The environment variables to send to the container. You can add new environment variables, which are added to the container at launch, or you can override the existing environment variables from the Docker image or the task definition. You must also specify a container name. Detailed below. */ environments?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverridesContainerOverrideEnvironment[]; /** * The hard limit (in MiB) of memory to present to the container, instead of the default value from the task definition. If your container attempts to exceed the memory specified here, the container is killed. You must also specify a container name. */ memory?: number; /** * The soft limit (in MiB) of memory to reserve for the container, instead of the default value from the task definition. You must also specify a container name. */ memoryReservation?: number; /** * Name of the pipe. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name?: string; /** * The type and amount of a resource to assign to a container, instead of the default value from the task definition. The only supported resource is a GPU. Detailed below. */ resourceRequirements?: outputs.pipes.PipeTargetParametersEcsTaskParametersOverridesContainerOverrideResourceRequirement[]; } interface PipeTargetParametersEcsTaskParametersOverridesContainerOverrideEnvironment { /** * Name of the pipe. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name?: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. Maximum length of 1024. */ value?: string; } interface PipeTargetParametersEcsTaskParametersOverridesContainerOverrideEnvironmentFile { /** * The type of placement strategy. The random placement strategy randomly places tasks on available candidates. The spread placement strategy spreads placement across available candidates evenly based on the field parameter. The binpack strategy places tasks on available candidates that have the least available amount of the resource that is specified with the field parameter. For example, if you binpack on memory, a task is placed on the instance with the least amount of remaining memory (but still enough to run the task). Valid Values: random, spread, binpack. */ type: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. Maximum length of 1024. */ value: string; } interface PipeTargetParametersEcsTaskParametersOverridesContainerOverrideResourceRequirement { /** * The type of placement strategy. The random placement strategy randomly places tasks on available candidates. The spread placement strategy spreads placement across available candidates evenly based on the field parameter. The binpack strategy places tasks on available candidates that have the least available amount of the resource that is specified with the field parameter. For example, if you binpack on memory, a task is placed on the instance with the least amount of remaining memory (but still enough to run the task). Valid Values: random, spread, binpack. */ type: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. Maximum length of 1024. */ value: string; } interface PipeTargetParametersEcsTaskParametersOverridesEphemeralStorage { /** * The total amount, in GiB, of ephemeral storage to set for the task. The minimum supported value is 21 GiB and the maximum supported value is 200 GiB. */ sizeInGib: number; } interface PipeTargetParametersEcsTaskParametersOverridesInferenceAcceleratorOverride { /** * The Elastic Inference accelerator device name to override for the task. This parameter must match a deviceName specified in the task definition. */ deviceName?: string; /** * The Elastic Inference accelerator type to use. */ deviceType?: string; } interface PipeTargetParametersEcsTaskParametersPlacementConstraint { /** * A cluster query language expression to apply to the constraint. You cannot specify an expression if the constraint type is distinctInstance. Maximum length of 2,000. */ expression?: string; /** * The type of placement strategy. The random placement strategy randomly places tasks on available candidates. The spread placement strategy spreads placement across available candidates evenly based on the field parameter. The binpack strategy places tasks on available candidates that have the least available amount of the resource that is specified with the field parameter. For example, if you binpack on memory, a task is placed on the instance with the least amount of remaining memory (but still enough to run the task). Valid Values: random, spread, binpack. */ type?: string; } interface PipeTargetParametersEcsTaskParametersPlacementStrategy { /** * The field to apply the placement strategy against. For the spread placement strategy, valid values are instanceId (or host, which has the same effect), or any platform or custom attribute that is applied to a container instance, such as attribute:ecs.availability-zone. For the binpack placement strategy, valid values are cpu and memory. For the random placement strategy, this field is not used. Maximum length of 255. */ field?: string; /** * The type of placement strategy. The random placement strategy randomly places tasks on available candidates. The spread placement strategy spreads placement across available candidates evenly based on the field parameter. The binpack strategy places tasks on available candidates that have the least available amount of the resource that is specified with the field parameter. For example, if you binpack on memory, a task is placed on the instance with the least amount of remaining memory (but still enough to run the task). Valid Values: random, spread, binpack. */ type?: string; } interface PipeTargetParametersEventbridgeEventBusParameters { /** * A free-form string, with a maximum of 128 characters, used to decide what fields to expect in the event detail. */ detailType?: string; /** * The URL subdomain of the endpoint. For example, if the URL for Endpoint is https://abcde.veo.endpoints.event.amazonaws.com, then the EndpointId is abcde.veo. */ endpointId?: string; /** * List of AWS resources, identified by ARN, which the event primarily concerns. Any number, including zero, may be present. */ resources?: string[]; /** * Source resource of the pipe. This field typically requires an ARN. However, when using a self-managed Kafka cluster, you should use a different format. Instead of an ARN, use 'smk://' followed by the bootstrap server's address. */ source?: string; /** * The time stamp of the event, per RFC3339. If no time stamp is provided, the time stamp of the PutEvents call is used. This is the JSON path to the field in the event e.g. $.detail.timestamp */ time?: string; } interface PipeTargetParametersHttpParameters { headerParameters?: { [key: string]: string; }; pathParameterValues?: string; queryStringParameters?: { [key: string]: string; }; } interface PipeTargetParametersKinesisStreamParameters { /** * Determines which shard in the stream the data record is assigned to. Partition keys are Unicode strings with a maximum length limit of 256 characters for each key. Amazon Kinesis Data Streams uses the partition key as input to a hash function that maps the partition key and associated data to a specific shard. Specifically, an MD5 hash function is used to map partition keys to 128-bit integer values and to map associated data records to shards. As a result of this hashing mechanism, all data records with the same partition key map to the same shard within the stream. */ partitionKey: string; } interface PipeTargetParametersLambdaFunctionParameters { /** * Specify whether to invoke the function synchronously or asynchronously. Valid Values: REQUEST_RESPONSE, FIRE_AND_FORGET. */ invocationType: string; } interface PipeTargetParametersRedshiftDataParameters { /** * The name of the database. Required when authenticating using temporary credentials. */ database: string; /** * The database user name. Required when authenticating using temporary credentials. */ dbUser?: string; /** * The name or ARN of the secret that enables access to the database. Required when authenticating using Secrets Manager. */ secretManagerArn?: string; /** * List of SQL statements text to run, each of maximum length of 100,000. */ sqls: string[]; /** * The name of the SQL statement. You can name the SQL statement when you create it to identify the query. */ statementName?: string; /** * Indicates whether to send an event back to EventBridge after the SQL statement runs. */ withEvent?: boolean; } interface PipeTargetParametersSagemakerPipelineParameters { /** * List of Parameter names and values for SageMaker AI Model Building Pipeline execution. Detailed below. */ pipelineParameters?: outputs.pipes.PipeTargetParametersSagemakerPipelineParametersPipelineParameter[]; } interface PipeTargetParametersSagemakerPipelineParametersPipelineParameter { /** * Name of the pipe. If omitted, the provider will assign a random, unique name. Conflicts with `namePrefix`. */ name: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. Maximum length of 1024. */ value: string; } interface PipeTargetParametersSqsQueueParameters { /** * This parameter applies only to FIFO (first-in-first-out) queues. The token used for deduplication of sent messages. */ messageDeduplicationId?: string; /** * The FIFO message group ID to use as the target. */ messageGroupId?: string; } interface PipeTargetParametersStepFunctionStateMachineParameters { /** * Specify whether to invoke the function synchronously or asynchronously. Valid Values: REQUEST_RESPONSE, FIRE_AND_FORGET. */ invocationType: string; } } export declare namespace polly { interface GetVoicesVoice { /** * Additional codes for languages available for the specified voice in addition to its default language. */ additionalLanguageCodes: string[]; /** * Gender of the voice. */ gender: string; /** * Amazon Polly assigned voice ID. */ id: string; /** * Language identification tag for filtering the list of voices returned. If not specified, all available voices are returned. */ languageCode: string; /** * Human readable name of the language in English. */ languageName: string; /** * Name of the voice. */ name: string; /** * Specifies which engines are supported by a given voice. */ supportedEngines: string[]; } } export declare namespace pricing { interface GetProductFilter { /** * Product attribute name that you want to filter on. */ field: string; /** * Product attribute value that you want to filter on. */ value: string; } } export declare namespace qbusiness { interface ApplicationAttachmentsConfiguration { /** * Status information about whether file upload functionality is activated or deactivated for your end user. Valid values are `ENABLED` and `DISABLED`. */ attachmentsControlMode: string; } interface ApplicationEncryptionConfiguration { /** * Identifier of the AWS KMS key that is used to encrypt your data. Amazon Q doesn't support asymmetric keys. */ kmsKeyId: string; } interface ApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace qldb { interface StreamKinesisConfiguration { /** * Enables QLDB to publish multiple data records in a single Kinesis Data Streams record, increasing the number of records sent per API call. Default: `true`. */ aggregationEnabled?: boolean; /** * ARN of the Kinesis Data Streams resource. */ streamArn: string; } } export declare namespace quicksight { interface AccountSettingsTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface AnalysisParameters { /** * A list of parameters that have a data type of date-time. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_DateTimeParameter.html). */ dateTimeParameters?: outputs.quicksight.AnalysisParametersDateTimeParameter[]; /** * A list of parameters that have a data type of decimal. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_DecimalParameter.html). */ decimalParameters?: outputs.quicksight.AnalysisParametersDecimalParameter[]; /** * A list of parameters that have a data type of integer. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_IntegerParameter.html). */ integerParameters?: outputs.quicksight.AnalysisParametersIntegerParameter[]; /** * A list of parameters that have a data type of string. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_StringParameter.html). */ stringParameters?: outputs.quicksight.AnalysisParametersStringParameter[]; } interface AnalysisParametersDateTimeParameter { /** * Display name for the analysis. * * The following arguments are optional: */ name: string; values: string[]; } interface AnalysisParametersDecimalParameter { /** * Display name for the analysis. * * The following arguments are optional: */ name: string; values: number[]; } interface AnalysisParametersIntegerParameter { /** * Display name for the analysis. * * The following arguments are optional: */ name: string; values: number[]; } interface AnalysisParametersStringParameter { /** * Display name for the analysis. * * The following arguments are optional: */ name: string; values: string[]; } interface AnalysisPermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface AnalysisSourceEntity { /** * The source template. See source_template. */ sourceTemplate?: outputs.quicksight.AnalysisSourceEntitySourceTemplate; } interface AnalysisSourceEntitySourceTemplate { /** * ARN of the resource. */ arn: string; /** * List of dataset references. See data_set_references. */ dataSetReferences: outputs.quicksight.AnalysisSourceEntitySourceTemplateDataSetReference[]; } interface AnalysisSourceEntitySourceTemplateDataSetReference { /** * Dataset ARN. */ dataSetArn: string; /** * Dataset placeholder. */ dataSetPlaceholder: string; } interface CustomPermissionsCapabilities { /** * The ability to add or run anomaly detection. Valid values: `DENY`. */ addOrRunAnomalyDetectionForAnalyses?: string; /** * The ability to create and update email reports. Valid values: `DENY`. */ createAndUpdateDashboardEmailReports?: string; /** * The ability to create and update data sources. Valid values: `DENY`. */ createAndUpdateDataSources?: string; /** * The ability to create and update datasets. Valid values: `DENY`. */ createAndUpdateDatasets?: string; /** * The ability to export to create and update themes. Valid values: `DENY`. */ createAndUpdateThemes?: string; /** * The ability to create and update threshold alerts. Valid values: `DENY`. */ createAndUpdateThresholdAlerts?: string; /** * The ability to create shared folders. Valid values: `DENY`. */ createSharedFolders?: string; /** * The ability to create a SPICE dataset. Valid values: `DENY`. */ createSpiceDataset?: string; /** * The ability to export to CSV files from the UI. Valid values: `DENY`. */ exportToCsv?: string; /** * The ability to export to CSV files in scheduled email reports. Valid values: `DENY`. */ exportToCsvInScheduledReports?: string; /** * The ability to export to Excel files from the UI. Valid values: `DENY`. */ exportToExcel?: string; /** * The ability to export to Excel files in scheduled email reports. Valid values: `DENY`. */ exportToExcelInScheduledReports?: string; /** * The ability to export to PDF files from the UI. Valid values: `DENY`. */ exportToPdf?: string; /** * The ability to export to PDF files in scheduled email reports. Valid values: `DENY`. */ exportToPdfInScheduledReports?: string; /** * The ability to include content in scheduled email reports. Valid values: `DENY`. */ includeContentInScheduledReportsEmail?: string; /** * The ability to print reports. Valid values: `DENY`. */ printReports?: string; /** * The ability to rename shared folders. Valid values: `DENY`. */ renameSharedFolders?: string; /** * The ability to share analyses. Valid values: `DENY`. */ shareAnalyses?: string; /** * The ability to share dashboards. Valid values: `DENY`. */ shareDashboards?: string; /** * The ability to share data sources. Valid values: `DENY`. */ shareDataSources?: string; /** * The ability to share datasets. Valid values: `DENY`. */ shareDatasets?: string; /** * The ability to subscribe to email reports. Valid values: `DENY`. */ subscribeDashboardEmailReports?: string; /** * The ability to view account SPICE capacity. Valid values: `DENY`. */ viewAccountSpiceCapacity?: string; } interface DashboardDashboardPublishOptions { /** * Ad hoc (one-time) filtering option. See ad_hoc_filtering_option. */ adHocFilteringOption?: outputs.quicksight.DashboardDashboardPublishOptionsAdHocFilteringOption; /** * The drill-down options of data points in a dashboard. See data_point_drill_up_down_option. */ dataPointDrillUpDownOption?: outputs.quicksight.DashboardDashboardPublishOptionsDataPointDrillUpDownOption; /** * The data point menu label options of a dashboard. See data_point_menu_label_option. */ dataPointMenuLabelOption?: outputs.quicksight.DashboardDashboardPublishOptionsDataPointMenuLabelOption; /** * The data point tool tip options of a dashboard. See data_point_tooltip_option. */ dataPointTooltipOption?: outputs.quicksight.DashboardDashboardPublishOptionsDataPointTooltipOption; /** * Export to .csv option. See export_to_csv_option. */ exportToCsvOption?: outputs.quicksight.DashboardDashboardPublishOptionsExportToCsvOption; /** * Determines if hidden fields are exported with a dashboard. See export_with_hidden_fields_option. */ exportWithHiddenFieldsOption?: outputs.quicksight.DashboardDashboardPublishOptionsExportWithHiddenFieldsOption; /** * Sheet controls option. See sheet_controls_option. */ sheetControlsOption?: outputs.quicksight.DashboardDashboardPublishOptionsSheetControlsOption; /** * The sheet layout maximization options of a dashboard. See sheet_layout_element_maximization_option. */ sheetLayoutElementMaximizationOption?: outputs.quicksight.DashboardDashboardPublishOptionsSheetLayoutElementMaximizationOption; /** * The axis sort options of a dashboard. See visual_axis_sort_option. */ visualAxisSortOption?: outputs.quicksight.DashboardDashboardPublishOptionsVisualAxisSortOption; /** * The menu options of a visual in a dashboard. See visual_menu_option. */ visualMenuOption?: outputs.quicksight.DashboardDashboardPublishOptionsVisualMenuOption; } interface DashboardDashboardPublishOptionsAdHocFilteringOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsDataPointDrillUpDownOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsDataPointMenuLabelOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsDataPointTooltipOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsExportToCsvOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsExportWithHiddenFieldsOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsSheetControlsOption { /** * Visibility state. Possibles values: EXPANDED, COLLAPSED. */ visibilityState?: string; } interface DashboardDashboardPublishOptionsSheetLayoutElementMaximizationOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsVisualAxisSortOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardDashboardPublishOptionsVisualMenuOption { /** * Availability status. Possibles values: ENABLED, DISABLED. */ availabilityStatus?: string; } interface DashboardParameters { /** * A list of parameters that have a data type of date-time. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_DateTimeParameter.html). */ dateTimeParameters?: outputs.quicksight.DashboardParametersDateTimeParameter[]; /** * A list of parameters that have a data type of decimal. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_DecimalParameter.html). */ decimalParameters?: outputs.quicksight.DashboardParametersDecimalParameter[]; /** * A list of parameters that have a data type of integer. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_IntegerParameter.html). */ integerParameters?: outputs.quicksight.DashboardParametersIntegerParameter[]; /** * A list of parameters that have a data type of string. See [AWS API Documentation for complete description](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_StringParameter.html). */ stringParameters?: outputs.quicksight.DashboardParametersStringParameter[]; } interface DashboardParametersDateTimeParameter { /** * Display name for the dashboard. */ name: string; values: string[]; } interface DashboardParametersDecimalParameter { /** * Display name for the dashboard. */ name: string; values: number[]; } interface DashboardParametersIntegerParameter { /** * Display name for the dashboard. */ name: string; values: number[]; } interface DashboardParametersStringParameter { /** * Display name for the dashboard. */ name: string; values: string[]; } interface DashboardPermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface DashboardSourceEntity { /** * The source template. See source_template. */ sourceTemplate?: outputs.quicksight.DashboardSourceEntitySourceTemplate; } interface DashboardSourceEntitySourceTemplate { /** * ARN of the resource. */ arn: string; /** * List of dataset references. See data_set_references. */ dataSetReferences: outputs.quicksight.DashboardSourceEntitySourceTemplateDataSetReference[]; } interface DashboardSourceEntitySourceTemplateDataSetReference { /** * Dataset ARN. */ dataSetArn: string; /** * Dataset placeholder. */ dataSetPlaceholder: string; } interface DataSetColumnGroup { /** * Geospatial column group that denotes a hierarchy. See geo_spatial_column_group. */ geoSpatialColumnGroup?: outputs.quicksight.DataSetColumnGroupGeoSpatialColumnGroup; } interface DataSetColumnGroupGeoSpatialColumnGroup { /** * Columns in this hierarchy. */ columns: string[]; /** * Country code. Valid values are `US`. */ countryCode: string; /** * A display name for the hierarchy. */ name: string; } interface DataSetColumnLevelPermissionRule { /** * An array of column names. */ columnNames?: string[]; /** * An array of ARNs for Amazon QuickSight users or groups. */ principals?: string[]; } interface DataSetDataSetUsageConfiguration { /** * Controls whether a child dataset of a direct query can use this dataset as a source. */ disableUseAsDirectQuerySource: boolean; /** * Controls whether a child dataset that's stored in QuickSight can use this dataset as a source. */ disableUseAsImportedSource: boolean; } interface DataSetFieldFolder { /** * An array of column names to add to the folder. A column can only be in one folder. */ columns?: string[]; /** * Field folder description. */ description?: string; /** * Key of the field folder map. */ fieldFoldersId: string; } interface DataSetLogicalTableMap { /** * A display name for the logical table. */ alias: string; /** * Transform operations that act on this logical table. For this structure to be valid, only one of the attributes can be non-null. See data_transforms. */ dataTransforms: outputs.quicksight.DataSetLogicalTableMapDataTransform[]; /** * Key of the logical table map. */ logicalTableMapId: string; /** * Source of this logical table. See source. */ source: outputs.quicksight.DataSetLogicalTableMapSource; } interface DataSetLogicalTableMapDataTransform { /** * A transform operation that casts a column to a different type. See cast_column_type_operation. */ castColumnTypeOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformCastColumnTypeOperation; /** * An operation that creates calculated columns. Columns created in one such operation form a lexical closure. See create_columns_operation. */ createColumnsOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformCreateColumnsOperation; /** * An operation that filters rows based on some condition. See filter_operation. */ filterOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformFilterOperation; /** * An operation that projects columns. Operations that come after a projection can only refer to projected columns. See project_operation. */ projectOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformProjectOperation; /** * An operation that renames a column. See rename_column_operation. */ renameColumnOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformRenameColumnOperation; /** * An operation that tags a column with additional information. See tag_column_operation. */ tagColumnOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformTagColumnOperation; /** * A transform operation that removes tags associated with a column. See untag_column_operation. */ untagColumnOperation: outputs.quicksight.DataSetLogicalTableMapDataTransformUntagColumnOperation; } interface DataSetLogicalTableMapDataTransformCastColumnTypeOperation { /** * Column name. */ columnName: string; /** * When casting a column from string to datetime type, you can supply a string in a format supported by Amazon QuickSight to denote the source data format. */ format: string; /** * New column data type. Valid values are `STRING`, `INTEGER`, `DECIMAL`, `DATETIME`. */ newColumnType: string; } interface DataSetLogicalTableMapDataTransformCreateColumnsOperation { /** * Calculated columns to create. See columns. */ columns: outputs.quicksight.DataSetLogicalTableMapDataTransformCreateColumnsOperationColumn[]; } interface DataSetLogicalTableMapDataTransformCreateColumnsOperationColumn { /** * A unique ID to identify a calculated column. During a dataset update, if the column ID of a calculated column matches that of an existing calculated column, Amazon QuickSight preserves the existing calculated column. */ columnId: string; /** * Column name. */ columnName: string; /** * An expression that defines the calculated column. */ expression: string; } interface DataSetLogicalTableMapDataTransformFilterOperation { /** * An expression that must evaluate to a Boolean value. Rows for which the expression evaluates to true are kept in the dataset. */ conditionExpression: string; } interface DataSetLogicalTableMapDataTransformProjectOperation { /** * Projected columns. */ projectedColumns: string[]; } interface DataSetLogicalTableMapDataTransformRenameColumnOperation { /** * Column to be renamed. */ columnName: string; /** * New name for the column. */ newColumnName: string; } interface DataSetLogicalTableMapDataTransformTagColumnOperation { /** * Column name. */ columnName: string; /** * The dataset column tag, currently only used for geospatial type tagging. See tags. */ tags: outputs.quicksight.DataSetLogicalTableMapDataTransformTagColumnOperationTag[]; } interface DataSetLogicalTableMapDataTransformTagColumnOperationTag { /** * A description for a column. See column_description. */ columnDescription: outputs.quicksight.DataSetLogicalTableMapDataTransformTagColumnOperationTagColumnDescription; /** * A geospatial role for a column. Valid values are `COUNTRY`, `STATE`, `COUNTY`, `CITY`, `POSTCODE`, `LONGITUDE`, and `LATITUDE`. */ columnGeographicRole: string; } interface DataSetLogicalTableMapDataTransformTagColumnOperationTagColumnDescription { /** * The text of a description for a column. */ text: string; } interface DataSetLogicalTableMapDataTransformUntagColumnOperation { /** * Column name. */ columnName: string; /** * The column tags to remove from this column. */ tagNames: string[]; } interface DataSetLogicalTableMapSource { /** * ARN of the parent data set. */ dataSetArn: string; /** * Specifies the result of a join of two logical tables. See join_instruction. */ joinInstruction: outputs.quicksight.DataSetLogicalTableMapSourceJoinInstruction; /** * Physical table ID. */ physicalTableId: string; } interface DataSetLogicalTableMapSourceJoinInstruction { /** * Join key properties of the left operand. See left_join_key_properties. */ leftJoinKeyProperties: outputs.quicksight.DataSetLogicalTableMapSourceJoinInstructionLeftJoinKeyProperties; /** * Operand on the left side of a join. */ leftOperand: string; /** * Join instructions provided in the ON clause of a join. */ onClause: string; /** * Join key properties of the right operand. See right_join_key_properties. */ rightJoinKeyProperties: outputs.quicksight.DataSetLogicalTableMapSourceJoinInstructionRightJoinKeyProperties; /** * Operand on the right side of a join. */ rightOperand: string; /** * Type of join. Valid values are `INNER`, `OUTER`, `LEFT`, and `RIGHT`. */ type: string; } interface DataSetLogicalTableMapSourceJoinInstructionLeftJoinKeyProperties { /** * A value that indicates that a row in a table is uniquely identified by the columns in a join key. This is used by Amazon QuickSight to optimize query performance. */ uniqueKey: boolean; } interface DataSetLogicalTableMapSourceJoinInstructionRightJoinKeyProperties { /** * A value that indicates that a row in a table is uniquely identified by the columns in a join key. This is used by Amazon QuickSight to optimize query performance. */ uniqueKey: boolean; } interface DataSetOutputColumn { /** * The description of the column. */ description: string; /** * Display name for the dataset. * * The following arguments are optional: */ name: string; /** * The data type of the column. */ type: string; } interface DataSetPermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface DataSetPhysicalTableMap { /** * A physical table type built from the results of the custom SQL query. See custom_sql. */ customSql?: outputs.quicksight.DataSetPhysicalTableMapCustomSql; /** * Key of the physical table map. */ physicalTableMapId: string; /** * A physical table type for relational data sources. See relational_table. */ relationalTable?: outputs.quicksight.DataSetPhysicalTableMapRelationalTable; /** * A physical table type for as S3 data source. See s3_source. */ s3Source: outputs.quicksight.DataSetPhysicalTableMapS3Source; } interface DataSetPhysicalTableMapCustomSql { /** * Column schema from the SQL query result set. See columns. */ columns?: outputs.quicksight.DataSetPhysicalTableMapCustomSqlColumn[]; /** * ARN of the data source. */ dataSourceArn: string; /** * Display name for the SQL query result. */ name: string; /** * SQL query. */ sqlQuery: string; } interface DataSetPhysicalTableMapCustomSqlColumn { /** * Name of this column in the underlying data source. */ name: string; /** * Data type of the column. */ type: string; } interface DataSetPhysicalTableMapRelationalTable { /** * Catalog associated with the table. */ catalog?: string; /** * ARN of the data source. */ dataSourceArn: string; /** * Column schema of the table. See input_columns. */ inputColumns: outputs.quicksight.DataSetPhysicalTableMapRelationalTableInputColumn[]; /** * Name of the relational table. */ name: string; /** * Schema name. This name applies to certain relational database engines. */ schema?: string; } interface DataSetPhysicalTableMapRelationalTableInputColumn { /** * Name of this column in the underlying data source. */ name: string; /** * Data type of the column. */ type: string; } interface DataSetPhysicalTableMapS3Source { /** * ARN of the data source. */ dataSourceArn: string; /** * Column schema of the table. See input_columns. */ inputColumns: outputs.quicksight.DataSetPhysicalTableMapS3SourceInputColumn[]; /** * Information about the format for the S3 source file or files. See upload_settings. */ uploadSettings: outputs.quicksight.DataSetPhysicalTableMapS3SourceUploadSettings; } interface DataSetPhysicalTableMapS3SourceInputColumn { /** * Name of this column in the underlying data source. */ name: string; /** * Data type of the column. */ type: string; } interface DataSetPhysicalTableMapS3SourceUploadSettings { /** * Whether the file has a header row, or the files each have a header row. */ containsHeader: boolean; /** * Delimiter between values in the file. */ delimiter: string; /** * File format. Valid values are `CSV`, `TSV`, `CLF`, `ELF`, `XLSX`, and `JSON`. */ format: string; /** * A row number to start reading data from. */ startFromRow: number; /** * Text qualifier. Valid values are `DOUBLE_QUOTE` and `SINGLE_QUOTE`. */ textQualifier: string; } interface DataSetRefreshProperties { /** * The refresh configuration for the data set. See refresh_configuration. */ refreshConfiguration: outputs.quicksight.DataSetRefreshPropertiesRefreshConfiguration; } interface DataSetRefreshPropertiesRefreshConfiguration { /** * The incremental refresh for the data set. See incremental_refresh. */ incrementalRefresh: outputs.quicksight.DataSetRefreshPropertiesRefreshConfigurationIncrementalRefresh; } interface DataSetRefreshPropertiesRefreshConfigurationIncrementalRefresh { /** * The lookback window setup for an incremental refresh configuration. See lookback_window. */ lookbackWindow: outputs.quicksight.DataSetRefreshPropertiesRefreshConfigurationIncrementalRefreshLookbackWindow; } interface DataSetRefreshPropertiesRefreshConfigurationIncrementalRefreshLookbackWindow { /** * The name of the lookback window column. */ columnName: string; /** * The lookback window column size. */ size: number; /** * The size unit that is used for the lookback window column. Valid values for this structure are `HOUR`, `DAY`, and `WEEK`. */ sizeUnit: string; } interface DataSetRowLevelPermissionDataSet { /** * ARN of the dataset that contains permissions for RLS. */ arn: string; /** * User or group rules associated with the dataset that contains permissions for RLS. */ formatVersion?: string; /** * Namespace associated with the dataset that contains permissions for RLS. */ namespace?: string; /** * Type of permissions to use when interpreting the permissions for RLS. Valid values are `GRANT_ACCESS` and `DENY_ACCESS`. */ permissionPolicy: string; /** * Status of the row-level security permission dataset. If enabled, the status is `ENABLED`. If disabled, the status is `DISABLED`. */ status?: string; } interface DataSetRowLevelPermissionTagConfiguration { /** * The status of row-level security tags. If enabled, the status is `ENABLED`. If disabled, the status is `DISABLED`. */ status?: string; /** * A set of rules associated with row-level security, such as the tag names and columns that they are assigned to. See tag_rules. */ tagRules: outputs.quicksight.DataSetRowLevelPermissionTagConfigurationTagRule[]; } interface DataSetRowLevelPermissionTagConfigurationTagRule { /** * Column name that a tag key is assigned to. */ columnName: string; /** * A string that you want to use to filter by all the values in a column in the dataset and don’t want to list the values one by one. */ matchAllValue?: string; /** * Unique key for a tag. */ tagKey: string; /** * A string that you want to use to delimit the values when you pass the values at run time. */ tagMultiValueDelimiter?: string; } interface DataSourceCredentials { /** * The ARN of a data source that has the credential pair that you want to use. * When the value is not null, the `credentialPair` from the data source in the ARN is used. */ copySourceArn?: string; /** * Credential pair. See Credential Pair below for more details. */ credentialPair?: outputs.quicksight.DataSourceCredentialsCredentialPair; /** * The ARN of the secret associated with the data source in Amazon Secrets Manager. */ secretArn?: string; } interface DataSourceCredentialsCredentialPair { /** * Password, maximum length of 1024 characters. */ password: string; /** * User name, maximum length of 64 characters. */ username: string; } interface DataSourceParameters { /** * Parameters for connecting to Amazon Elasticsearch. */ amazonElasticsearch?: outputs.quicksight.DataSourceParametersAmazonElasticsearch; /** * Parameters for connecting to Athena. */ athena?: outputs.quicksight.DataSourceParametersAthena; /** * Parameters for connecting to Aurora MySQL. */ aurora?: outputs.quicksight.DataSourceParametersAurora; /** * Parameters for connecting to Aurora Postgresql. */ auroraPostgresql?: outputs.quicksight.DataSourceParametersAuroraPostgresql; /** * Parameters for connecting to AWS IOT Analytics. */ awsIotAnalytics?: outputs.quicksight.DataSourceParametersAwsIotAnalytics; /** * Parameters for connecting to Databricks. */ databricks?: outputs.quicksight.DataSourceParametersDatabricks; /** * Parameters for connecting to Jira. */ jira?: outputs.quicksight.DataSourceParametersJira; /** * Parameters for connecting to MariaDB. */ mariaDb?: outputs.quicksight.DataSourceParametersMariaDb; /** * Parameters for connecting to MySQL. */ mysql?: outputs.quicksight.DataSourceParametersMysql; /** * Parameters for connecting to Oracle. */ oracle?: outputs.quicksight.DataSourceParametersOracle; /** * Parameters for connecting to Postgresql. */ postgresql?: outputs.quicksight.DataSourceParametersPostgresql; /** * Parameters for connecting to Presto. */ presto?: outputs.quicksight.DataSourceParametersPresto; /** * Parameters for connecting to RDS. */ rds?: outputs.quicksight.DataSourceParametersRds; /** * Parameters for connecting to Redshift. */ redshift?: outputs.quicksight.DataSourceParametersRedshift; /** * Parameters for connecting to S3. */ s3?: outputs.quicksight.DataSourceParametersS3; /** * Parameters for connecting to ServiceNow. */ serviceNow?: outputs.quicksight.DataSourceParametersServiceNow; /** * Parameters for connecting to Snowflake. */ snowflake?: outputs.quicksight.DataSourceParametersSnowflake; /** * Parameters for connecting to Spark. */ spark?: outputs.quicksight.DataSourceParametersSpark; /** * Parameters for connecting to SQL Server. */ sqlServer?: outputs.quicksight.DataSourceParametersSqlServer; /** * Parameters for connecting to Teradata. */ teradata?: outputs.quicksight.DataSourceParametersTeradata; /** * Parameters for connecting to Twitter. */ twitter?: outputs.quicksight.DataSourceParametersTwitter; } interface DataSourceParametersAmazonElasticsearch { /** * The OpenSearch domain. */ domain: string; } interface DataSourceParametersAthena { /** * Use the `roleArn` to override an account-wide role for a specific athena data source. */ roleArn?: string; /** * The work-group to which to connect. */ workGroup?: string; } interface DataSourceParametersAurora { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersAuroraPostgresql { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersAwsIotAnalytics { /** * The name of the data set to which to connect. */ dataSetName: string; } interface DataSourceParametersDatabricks { /** * The host name of the Databricks data source. */ host: string; /** * The port for the Databricks data source. */ port: number; /** * The HTTP path of the Databricks data source. */ sqlEndpointPath: string; } interface DataSourceParametersJira { /** * The base URL of the Jira instance's site to which to connect. */ siteBaseUrl: string; } interface DataSourceParametersMariaDb { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersMysql { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersOracle { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersPostgresql { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersPresto { /** * The catalog to which to connect. */ catalog: string; /** * The host to which to connect. */ host: string; /** * The port to which to connect. */ port: number; } interface DataSourceParametersRds { /** * The database to which to connect. */ database: string; /** * The instance ID to which to connect. */ instanceId: string; } interface DataSourceParametersRedshift { /** * The ID of the cluster to which to connect. */ clusterId?: string; /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host?: string; /** * The port to which to connect. */ port?: number; } interface DataSourceParametersS3 { /** * An object containing the S3 location of the S3 manifest file. */ manifestFileLocation: outputs.quicksight.DataSourceParametersS3ManifestFileLocation; /** * Use the `roleArn` to override an account-wide role for a specific S3 data source. For example, say an account administrator has turned off all S3 access with an account-wide role. The administrator can then use `roleArn` to bypass the account-wide role and allow S3 access for the single S3 data source that is specified in the structure, even if the account-wide role forbidding S3 access is still active. */ roleArn?: string; } interface DataSourceParametersS3ManifestFileLocation { /** * The name of the bucket that contains the manifest file. */ bucket: string; /** * The key of the manifest file within the bucket. */ key: string; } interface DataSourceParametersServiceNow { /** * The base URL of the Jira instance's site to which to connect. */ siteBaseUrl: string; } interface DataSourceParametersSnowflake { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The warehouse to which to connect. */ warehouse: string; } interface DataSourceParametersSpark { /** * The host to which to connect. */ host: string; /** * The warehouse to which to connect. */ port: number; } interface DataSourceParametersSqlServer { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The warehouse to which to connect. */ port: number; } interface DataSourceParametersTeradata { /** * The database to which to connect. */ database: string; /** * The host to which to connect. */ host: string; /** * The warehouse to which to connect. */ port: number; } interface DataSourceParametersTwitter { /** * The maximum number of rows to query. */ maxRows: number; /** * The Twitter query to retrieve the data. */ query: string; } interface DataSourcePermission { /** * Set of IAM actions to grant or revoke permissions on. Max of 16 items. */ actions: string[]; /** * ARN of the principal. */ principal: string; } interface DataSourceSslProperties { /** * A Boolean option to control whether SSL should be disabled. */ disableSsl: boolean; } interface DataSourceVpcConnectionProperties { /** * ARN for the VPC connection. */ vpcConnectionArn: string; } interface FolderPermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface GetDataSetColumnGroup { geoSpatialColumnGroups: outputs.quicksight.GetDataSetColumnGroupGeoSpatialColumnGroup[]; } interface GetDataSetColumnGroupGeoSpatialColumnGroup { columns: string[]; countryCode: string; name: string; } interface GetDataSetColumnLevelPermissionRule { columnNames: string[]; principals: string[]; } interface GetDataSetDataSetUsageConfiguration { disableUseAsDirectQuerySource: boolean; disableUseAsImportedSource: boolean; } interface GetDataSetFieldFolder { columns: string[]; description: string; fieldFoldersId: string; } interface GetDataSetLogicalTableMap { alias: string; dataTransforms: outputs.quicksight.GetDataSetLogicalTableMapDataTransform[]; logicalTableMapId: string; sources: outputs.quicksight.GetDataSetLogicalTableMapSource[]; } interface GetDataSetLogicalTableMapDataTransform { castColumnTypeOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformCastColumnTypeOperation[]; createColumnsOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformCreateColumnsOperation[]; filterOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformFilterOperation[]; projectOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformProjectOperation[]; renameColumnOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformRenameColumnOperation[]; tagColumnOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformTagColumnOperation[]; untagColumnOperations: outputs.quicksight.GetDataSetLogicalTableMapDataTransformUntagColumnOperation[]; } interface GetDataSetLogicalTableMapDataTransformCastColumnTypeOperation { columnName: string; format: string; newColumnType: string; } interface GetDataSetLogicalTableMapDataTransformCreateColumnsOperation { columns: outputs.quicksight.GetDataSetLogicalTableMapDataTransformCreateColumnsOperationColumn[]; } interface GetDataSetLogicalTableMapDataTransformCreateColumnsOperationColumn { columnId: string; columnName: string; expression: string; } interface GetDataSetLogicalTableMapDataTransformFilterOperation { conditionExpression: string; } interface GetDataSetLogicalTableMapDataTransformProjectOperation { projectedColumns: string[]; } interface GetDataSetLogicalTableMapDataTransformRenameColumnOperation { columnName: string; newColumnName: string; } interface GetDataSetLogicalTableMapDataTransformTagColumnOperation { columnName: string; tags: outputs.quicksight.GetDataSetLogicalTableMapDataTransformTagColumnOperationTag[]; } interface GetDataSetLogicalTableMapDataTransformTagColumnOperationTag { columnDescriptions: outputs.quicksight.GetDataSetLogicalTableMapDataTransformTagColumnOperationTagColumnDescription[]; columnGeographicRole: string; } interface GetDataSetLogicalTableMapDataTransformTagColumnOperationTagColumnDescription { text: string; } interface GetDataSetLogicalTableMapDataTransformUntagColumnOperation { columnName: string; tagNames: string[]; } interface GetDataSetLogicalTableMapSource { dataSetArn: string; joinInstructions: outputs.quicksight.GetDataSetLogicalTableMapSourceJoinInstruction[]; physicalTableId: string; } interface GetDataSetLogicalTableMapSourceJoinInstruction { leftJoinKeyProperties: outputs.quicksight.GetDataSetLogicalTableMapSourceJoinInstructionLeftJoinKeyProperty[]; leftOperand: string; onClause: string; rightJoinKeyProperties: outputs.quicksight.GetDataSetLogicalTableMapSourceJoinInstructionRightJoinKeyProperty[]; rightOperand: string; type: string; } interface GetDataSetLogicalTableMapSourceJoinInstructionLeftJoinKeyProperty { uniqueKey: boolean; } interface GetDataSetLogicalTableMapSourceJoinInstructionRightJoinKeyProperty { uniqueKey: boolean; } interface GetDataSetPermission { actions: string[]; principal: string; } interface GetDataSetPhysicalTableMap { customSqls: outputs.quicksight.GetDataSetPhysicalTableMapCustomSql[]; physicalTableMapId: string; relationalTables: outputs.quicksight.GetDataSetPhysicalTableMapRelationalTable[]; s3Sources: outputs.quicksight.GetDataSetPhysicalTableMapS3Source[]; } interface GetDataSetPhysicalTableMapCustomSql { columns: outputs.quicksight.GetDataSetPhysicalTableMapCustomSqlColumn[]; dataSourceArn: string; name: string; sqlQuery: string; } interface GetDataSetPhysicalTableMapCustomSqlColumn { name: string; type: string; } interface GetDataSetPhysicalTableMapRelationalTable { catalog: string; dataSourceArn: string; inputColumns: outputs.quicksight.GetDataSetPhysicalTableMapRelationalTableInputColumn[]; name: string; schema: string; } interface GetDataSetPhysicalTableMapRelationalTableInputColumn { name: string; type: string; } interface GetDataSetPhysicalTableMapS3Source { dataSourceArn: string; inputColumns: outputs.quicksight.GetDataSetPhysicalTableMapS3SourceInputColumn[]; uploadSettings: outputs.quicksight.GetDataSetPhysicalTableMapS3SourceUploadSetting[]; } interface GetDataSetPhysicalTableMapS3SourceInputColumn { name: string; type: string; } interface GetDataSetPhysicalTableMapS3SourceUploadSetting { containsHeader: boolean; delimiter: string; format: string; startFromRow: number; textQualifier: string; } interface GetDataSetRowLevelPermissionDataSet { arn: string; formatVersion: string; namespace: string; permissionPolicy: string; status: string; } interface GetDataSetRowLevelPermissionTagConfiguration { status: string; tagRules: outputs.quicksight.GetDataSetRowLevelPermissionTagConfigurationTagRule[]; } interface GetDataSetRowLevelPermissionTagConfigurationTagRule { columnName: string; matchAllValue: string; tagKey: string; tagMultiValueDelimiter: string; } interface GetQuicksightAnalysisPermission { actions: string[]; principal: string; } interface GetThemeConfiguration { /** * Color properties that apply to chart data colors. See data_color_palette. */ dataColorPalettes: outputs.quicksight.GetThemeConfigurationDataColorPalette[]; /** * Display options related to sheets. See sheet. */ sheets: outputs.quicksight.GetThemeConfigurationSheet[]; /** * Determines the typography options. See typography. */ typographies: outputs.quicksight.GetThemeConfigurationTypography[]; /** * Color properties that apply to the UI and to charts, excluding the colors that apply to data. See ui_color_palette. */ uiColorPalettes: outputs.quicksight.GetThemeConfigurationUiColorPalette[]; } interface GetThemeConfigurationDataColorPalette { /** * List of hexadecimal codes for the colors. Minimum of 8 items and maximum of 20 items. */ colors: string[]; /** * The hexadecimal code of a color that applies to charts where a lack of data is highlighted. */ emptyFillColor: string; /** * The minimum and maximum hexadecimal codes that describe a color gradient. List of exactly 2 items. */ minMaxGradients: string[]; } interface GetThemeConfigurationSheet { /** * The layout options for tiles. See tile_layout. */ tileLayouts: outputs.quicksight.GetThemeConfigurationSheetTileLayout[]; /** * The display options for tiles. See tile. */ tiles: outputs.quicksight.GetThemeConfigurationSheetTile[]; } interface GetThemeConfigurationSheetTile { /** * The border around a tile. See border. */ borders: outputs.quicksight.GetThemeConfigurationSheetTileBorder[]; } interface GetThemeConfigurationSheetTileBorder { /** * This Boolean value controls whether to display sheet margins. */ show: boolean; } interface GetThemeConfigurationSheetTileLayout { /** * The gutter settings that apply between tiles. See gutter. */ gutters: outputs.quicksight.GetThemeConfigurationSheetTileLayoutGutter[]; /** * The margin settings that apply around the outside edge of sheets. See margin. */ margins: outputs.quicksight.GetThemeConfigurationSheetTileLayoutMargin[]; } interface GetThemeConfigurationSheetTileLayoutGutter { /** * This Boolean value controls whether to display sheet margins. */ show: boolean; } interface GetThemeConfigurationSheetTileLayoutMargin { /** * This Boolean value controls whether to display sheet margins. */ show: boolean; } interface GetThemeConfigurationTypography { /** * Determines the list of font families. Maximum number of 5 items. See font_families. */ fontFamilies: outputs.quicksight.GetThemeConfigurationTypographyFontFamily[]; } interface GetThemeConfigurationTypographyFontFamily { /** * Font family name. */ fontFamily: string; } interface GetThemeConfigurationUiColorPalette { /** * Color (hexadecimal) that applies to selected states and buttons. */ accent: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the accent color. */ accentForeground: string; /** * Color (hexadecimal) that applies to error messages. */ danger: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the error color. */ dangerForeground: string; /** * Color (hexadecimal) that applies to the names of fields that are identified as dimensions. */ dimension: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the dimension color. */ dimensionForeground: string; /** * Color (hexadecimal) that applies to the names of fields that are identified as measures. */ measure: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the measure color. */ measureForeground: string; /** * Color (hexadecimal) that applies to visuals and other high emphasis UI. */ primaryBackground: string; /** * Color (hexadecimal) of text and other foreground elements that appear over the primary background regions, such as grid lines, borders, table banding, icons, and so on. */ primaryForeground: string; /** * Color (hexadecimal) that applies to the sheet background and sheet controls. */ secondaryBackground: string; /** * Color (hexadecimal) that applies to any sheet title, sheet control text, or UI that appears over the secondary background. */ secondaryForeground: string; /** * Color (hexadecimal) that applies to success messages, for example the check mark for a successful download. */ success: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the success color. */ successForeground: string; /** * Color (hexadecimal) that applies to warning and informational messages. */ warning: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the warning color. */ warningForeground: string; } interface GetThemePermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface IamPolicyAssignmentIdentities { /** * Array of Quicksight group names to assign the policy to. */ groups?: string[]; /** * Array of Quicksight user names to assign the policy to. */ users?: string[]; } interface KeyRegistrationKeyRegistration { /** * Whether the key is set as the default key for encryption and decryption use. */ defaultKey: boolean; /** * ARN of the AWS KMS key that is registered for encryption and decryption use. */ keyArn: string; } interface NamespaceTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface RefreshScheduleSchedule { /** * The type of refresh that the dataset undergoes. Valid values are `INCREMENTAL_REFRESH` and `FULL_REFRESH`. */ refreshType: string; /** * The configuration of the [schedule frequency](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_RefreshFrequency.html). See schedule_frequency. */ scheduleFrequency: outputs.quicksight.RefreshScheduleScheduleScheduleFrequency; /** * Time after which the refresh schedule can be started, expressed in `YYYY-MM-DDTHH:MM:SS` format. */ startAfterDateTime: string; } interface RefreshScheduleScheduleScheduleFrequency { /** * The interval between scheduled refreshes. Valid values are `MINUTE15`, `MINUTE30`, `HOURLY`, `DAILY`, `WEEKLY` and `MONTHLY`. */ interval: string; /** * The [refresh on entity](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ScheduleRefreshOnEntity.html) configuration for weekly or monthly schedules. See refresh_on_day. */ refreshOnDay?: outputs.quicksight.RefreshScheduleScheduleScheduleFrequencyRefreshOnDay; /** * The time of day that you want the dataset to refresh. This value is expressed in `HH:MM` format. This field is not required for schedules that refresh hourly. */ timeOfTheDay: string; /** * The timezone that you want the refresh schedule to use. */ timezone: string; } interface RefreshScheduleScheduleScheduleFrequencyRefreshOnDay { /** * The day of the month that you want to schedule refresh on. */ dayOfMonth?: string; /** * The day of the week that you want to schedule a refresh on. Valid values are `SUNDAY`, `MONDAY`, `TUESDAY`, `WEDNESDAY`, `THURSDAY`, `FRIDAY` and `SATURDAY`. */ dayOfWeek?: string; } interface TemplatePermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface TemplateSourceEntity { /** * The source analysis, if it is based on an analysis.. Only one of `sourceAnalysis` or `sourceTemplate` should be configured. See source_analysis. */ sourceAnalysis?: outputs.quicksight.TemplateSourceEntitySourceAnalysis; /** * The source template, if it is based on an template.. Only one of `sourceAnalysis` or `sourceTemplate` should be configured. See source_template. */ sourceTemplate?: outputs.quicksight.TemplateSourceEntitySourceTemplate; } interface TemplateSourceEntitySourceAnalysis { /** * ARN of the resource. */ arn: string; /** * A list of dataset references used as placeholders in the template. See data_set_references. */ dataSetReferences: outputs.quicksight.TemplateSourceEntitySourceAnalysisDataSetReference[]; } interface TemplateSourceEntitySourceAnalysisDataSetReference { /** * Dataset ARN. */ dataSetArn: string; /** * Dataset placeholder. */ dataSetPlaceholder: string; } interface TemplateSourceEntitySourceTemplate { /** * ARN of the resource. */ arn: string; } interface ThemeConfiguration { /** * Color properties that apply to chart data colors. See data_color_palette. */ dataColorPalette?: outputs.quicksight.ThemeConfigurationDataColorPalette; /** * Display options related to sheets. See sheet. */ sheet?: outputs.quicksight.ThemeConfigurationSheet; /** * Determines the typography options. See typography. */ typography?: outputs.quicksight.ThemeConfigurationTypography; /** * Color properties that apply to the UI and to charts, excluding the colors that apply to data. See ui_color_palette. */ uiColorPalette?: outputs.quicksight.ThemeConfigurationUiColorPalette; } interface ThemeConfigurationDataColorPalette { /** * List of hexadecimal codes for the colors. Minimum of 8 items and maximum of 20 items. */ colors?: string[]; /** * The hexadecimal code of a color that applies to charts where a lack of data is highlighted. */ emptyFillColor?: string; /** * The minimum and maximum hexadecimal codes that describe a color gradient. List of exactly 2 items. */ minMaxGradients?: string[]; } interface ThemeConfigurationSheet { /** * The display options for tiles. See tile. */ tile?: outputs.quicksight.ThemeConfigurationSheetTile; /** * The layout options for tiles. See tile_layout. */ tileLayout?: outputs.quicksight.ThemeConfigurationSheetTileLayout; } interface ThemeConfigurationSheetTile { /** * The border around a tile. See border. */ border?: outputs.quicksight.ThemeConfigurationSheetTileBorder; } interface ThemeConfigurationSheetTileBorder { /** * The option to enable display of borders for visuals. */ show?: boolean; } interface ThemeConfigurationSheetTileLayout { /** * The gutter settings that apply between tiles. See gutter. */ gutter?: outputs.quicksight.ThemeConfigurationSheetTileLayoutGutter; /** * The margin settings that apply around the outside edge of sheets. See margin. */ margin?: outputs.quicksight.ThemeConfigurationSheetTileLayoutMargin; } interface ThemeConfigurationSheetTileLayoutGutter { /** * This Boolean value controls whether to display a gutter space between sheet tiles. */ show?: boolean; } interface ThemeConfigurationSheetTileLayoutMargin { /** * This Boolean value controls whether to display sheet margins. */ show?: boolean; } interface ThemeConfigurationTypography { /** * Determines the list of font families. Maximum number of 5 items. See font_families. */ fontFamilies?: outputs.quicksight.ThemeConfigurationTypographyFontFamily[]; } interface ThemeConfigurationTypographyFontFamily { /** * Font family name. */ fontFamily?: string; } interface ThemeConfigurationUiColorPalette { /** * Color (hexadecimal) that applies to selected states and buttons. */ accent?: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the accent color. */ accentForeground?: string; /** * Color (hexadecimal) that applies to error messages. */ danger?: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the error color. */ dangerForeground?: string; /** * Color (hexadecimal) that applies to the names of fields that are identified as dimensions. */ dimension?: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the dimension color. */ dimensionForeground?: string; /** * Color (hexadecimal) that applies to the names of fields that are identified as measures. */ measure?: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the measure color. */ measureForeground?: string; /** * Color (hexadecimal) that applies to visuals and other high emphasis UI. */ primaryBackground?: string; /** * Color (hexadecimal) of text and other foreground elements that appear over the primary background regions, such as grid lines, borders, table banding, icons, and so on. */ primaryForeground?: string; /** * Color (hexadecimal) that applies to the sheet background and sheet controls. */ secondaryBackground?: string; /** * Color (hexadecimal) that applies to any sheet title, sheet control text, or UI that appears over the secondary background. */ secondaryForeground?: string; /** * Color (hexadecimal) that applies to success messages, for example the check mark for a successful download. */ success?: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the success color. */ successForeground?: string; /** * Color (hexadecimal) that applies to warning and informational messages. */ warning?: string; /** * Color (hexadecimal) that applies to any text or other elements that appear over the warning color. */ warningForeground?: string; } interface ThemePermission { /** * List of IAM actions to grant or revoke permissions on. */ actions: string[]; /** * ARN of the principal. See the [ResourcePermission documentation](https://docs.aws.amazon.com/quicksight/latest/APIReference/API_ResourcePermission.html) for the applicable ARN values. */ principal: string; } interface VpcConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace ram { interface GetResourceShareFilter { /** * Name of the tag key to filter on. */ name: string; /** * Value of the tag key. */ values: string[]; } interface PermissionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface ResourceShareResourceShareConfiguration { /** * Whether consumer account retains access to resource share after leaving AWS organization. */ retainSharingOnAccountLeaveOrganization: boolean; } } export declare namespace rbin { interface RuleExcludeResourceTag { /** * Tag key. * * The following argument is optional: */ resourceTagKey: string; /** * Tag value. */ resourceTagValue?: string; } interface RuleLockConfiguration { /** * Information about the retention rule unlock delay. See `unlockDelay` below. */ unlockDelay: outputs.rbin.RuleLockConfigurationUnlockDelay; } interface RuleLockConfigurationUnlockDelay { /** * Unit of time in which to measure the unlock delay. Currently, the unlock delay can be measure only in days. */ unlockDelayUnit: string; /** * Unlock delay period, measured in the unit specified for UnlockDelayUnit. */ unlockDelayValue: number; } interface RuleResourceTag { /** * Tag key. * * The following argument is optional: */ resourceTagKey: string; /** * Tag value. */ resourceTagValue?: string; } interface RuleRetentionPeriod { /** * Unit of time in which the retention period is measured. Currently, only DAYS is supported. */ retentionPeriodUnit: string; /** * Period value for which the retention rule is to retain resources. The period is measured using the unit specified for RetentionPeriodUnit. */ retentionPeriodValue: number; } } export declare namespace rds { interface ClusterMasterUserSecret { /** * ARN for the KMS encryption key. When specifying `kmsKeyId`, `storageEncrypted` needs to be set to true. */ kmsKeyId: string; /** * ARN of the secret. */ secretArn: string; /** * Status of the secret. Valid Values: `creating` | `active` | `rotating` | `impaired`. */ secretStatus: string; } interface ClusterParameterGroupParameter { /** * "immediate" (default), or "pending-reboot". Some engines can't apply some parameters without a reboot, and you will need to specify "pending-reboot" here. */ applyMethod?: string; /** * Name of the DB parameter. */ name: string; /** * Value of the DB parameter. */ value: string; } interface ClusterRestoreToPointInTime { /** * Date and time in UTC format to restore the database cluster to. Conflicts with `useLatestRestorableTime`. */ restoreToTime?: string; /** * Type of restore to be performed. Valid options are `full-copy` (default) and `copy-on-write`. */ restoreType?: string; /** * Identifier of the source database cluster from which to restore. When restoring from a cluster in another AWS account, the identifier is the ARN of that cluster. */ sourceClusterIdentifier?: string; /** * Cluster resource ID of the source database cluster from which to restore. To be used for restoring a deleted cluster in the same account which still has a retained automatic backup available. */ sourceClusterResourceId?: string; /** * Set to true to restore the database cluster to the latest restorable backup time. Defaults to false. Conflicts with `restoreToTime`. */ useLatestRestorableTime?: boolean; } interface ClusterS3Import { /** * Bucket name where your backup is stored */ bucketName: string; /** * Can be blank, but is the path to your backup */ bucketPrefix?: string; /** * Role applied to load the data. */ ingestionRole: string; /** * Source engine for the backup */ sourceEngine: string; /** * Version of the source engine used to make the backup */ sourceEngineVersion: string; } interface ClusterScalingConfiguration { /** * Whether to enable automatic pause. A DB cluster can be paused only when it's idle (it has no connections). If a DB cluster is paused for more than seven days, the DB cluster might be backed up with a snapshot. In this case, the DB cluster is restored when there is a request to connect to it. Defaults to `true`. */ autoPause?: boolean; /** * Maximum capacity for an Aurora DB cluster in `serverless` DB engine mode. The maximum capacity must be greater than or equal to the minimum capacity. Valid Aurora MySQL capacity values are `1`, `2`, `4`, `8`, `16`, `32`, `64`, `128`, `256`. Valid Aurora PostgreSQL capacity values are (`2`, `4`, `8`, `16`, `32`, `64`, `192`, and `384`). Defaults to `16`. */ maxCapacity?: number; /** * Minimum capacity for an Aurora DB cluster in `serverless` DB engine mode. The minimum capacity must be lesser than or equal to the maximum capacity. Valid Aurora MySQL capacity values are `1`, `2`, `4`, `8`, `16`, `32`, `64`, `128`, `256`. Valid Aurora PostgreSQL capacity values are (`2`, `4`, `8`, `16`, `32`, `64`, `192`, and `384`). Defaults to `1`. */ minCapacity?: number; /** * Amount of time, in seconds, that Aurora Serverless v1 tries to find a scaling point to perform seamless scaling before enforcing the timeout action. Valid values are `60` through `600`. Defaults to `300`. */ secondsBeforeTimeout?: number; /** * Time, in seconds, before an Aurora DB cluster in serverless mode is paused. Valid values are `300` through `86400`. Defaults to `300`. */ secondsUntilAutoPause?: number; /** * Action to take when the timeout is reached. Valid values: `ForceApplyCapacityChange`, `RollbackCapacityChange`. Defaults to `RollbackCapacityChange`. See [documentation](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-serverless-v1.how-it-works.html#aurora-serverless.how-it-works.timeout-action). */ timeoutAction?: string; } interface ClusterServerlessv2ScalingConfiguration { /** * Maximum capacity for an Aurora DB cluster in `provisioned` DB engine mode. The maximum capacity must be greater than or equal to the minimum capacity. Valid capacity values are in a range of `0` up to `256` in steps of `0.5`. */ maxCapacity: number; /** * Minimum capacity for an Aurora DB cluster in `provisioned` DB engine mode. The minimum capacity must be lesser than or equal to the maximum capacity. Valid capacity values are in a range of `0` up to `256` in steps of `0.5`. */ minCapacity: number; /** * Time, in seconds, before an Aurora DB cluster in `provisioned` DB engine mode is paused. Valid values are `300` through `86400`. */ secondsUntilAutoPause: number; } interface ClusterSnapshotCopyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface ExportTaskTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface GetClusterMasterUserSecret { /** * Amazon Web Services KMS key identifier that is used to encrypt the secret. */ kmsKeyId: string; /** * ARN of the secret. */ secretArn: string; /** * Status of the secret. */ secretStatus: string; } interface GetClustersFilter { /** * Name of the filter field. Valid values can be found in the [RDS DescribeDBClusters API Reference](https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DescribeDBClusters.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetEngineVersionFilter { /** * Name of the filter field. Valid values can be found in the [describe-db-engine-versions AWS CLI reference](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/rds/describe-db-engine-versions.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetEventsEvent { /** * Date and time of the event, in RFC3339 format. */ date: string; /** * Set of event categories to filter on, e.g. `failure`, `maintenance`, `configuration change`. Defaults to all categories. */ eventCategories: string[]; /** * Text of the event. */ message: string; /** * ARN of the event source. */ sourceArn: string; /** * Identifier of the source, such as a DB instance or DB cluster identifier. Requires `sourceType` to also be set. */ sourceIdentifier: string; /** * Type of source. Valid values include `db-instance`, `db-cluster`, `db-snapshot`, `db-parameter-group`, `db-security-group`, `db-cluster-snapshot`, `custom-engine-version`, `db-proxy`, `blue-green-deployment`, `db-shard-group`, and `zero-etl`. */ sourceType: string; } interface GetGlobalClusterMember { /** * ARN of member DB Cluster */ dbClusterArn: string; /** * Whether the member is the primary DB Cluster */ isWriter: boolean; } interface GetInstanceMasterUserSecret { /** * Amazon Web Services KMS key identifier that is used to encrypt the secret. */ kmsKeyId: string; /** * ARN of the secret. */ secretArn: string; /** * Status of the secret. Valid Values: `creating` | `active` | `rotating` | `impaired`. */ secretStatus: string; } interface GetInstancesFilter { /** * Name of the filter field. Valid values can be found in the [RDS DescribeDBClusters API Reference](https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DescribeDBClusters.html) or [RDS DescribeDBInstances API Reference](https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DescribeDBInstances.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetProxyAuth { /** * Type of authentication that the proxy uses for connections from the proxy to the underlying database. */ authScheme: string; /** * Type of authentication the proxy uses for connections from clients. */ clientPasswordAuthType: string; /** * User-specified description about the authentication used by a proxy to log in as a specific database user. */ description: string; /** * Whether to require or disallow AWS Identity and Access Management (IAM) authentication for connections to the proxy. */ iamAuth: string; /** * ARN representing the secret that the proxy uses to authenticate to the RDS DB instance or Aurora DB cluster. */ secretArn: string; /** * Name of the database user to which the proxy connects. */ username: string; } interface GetSnapshotsFilter { /** * Name of the filter field. Valid values can be found in the RDS DescribeDBSnapshots API Reference. */ name: string; /** * Set of values accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetSnapshotsSnapshot { /** * Allocated storage size in gigabytes (GB). */ allocatedStorage: number; /** * Name of the Availability Zone the DB instance was located in at the time of the DB snapshot. */ availabilityZone: string; /** * Returns the list of snapshots created by the specific db_instance. */ dbInstanceIdentifier: string; /** * ARN for the DB snapshot. */ dbSnapshotArn: string; /** * Returns information on a specific snapshot_id. */ dbSnapshotIdentifier: string; /** * Whether the DB snapshot is encrypted. */ encrypted: boolean; /** * Name of the database engine. */ engine: string; /** * Version of the database engine. */ engineVersion: string; /** * Provisioned IOPS (I/O operations per second) value of the DB instance at the time of the snapshot. */ iops: number; /** * ARN for the KMS encryption key. */ kmsKeyId: string; /** * License model information for the restored DB instance. */ licenseModel: string; /** * Option group name for the DB snapshot. */ optionGroupName: string; /** * Time when the snapshot was taken, in Universal Coordinated Time (UTC). Doesn't change when the snapshot is copied. */ originalSnapshotCreateTime: string; /** * Port that the database engine was listening on at the time of the snapshot. */ port: number; /** * Time when the snapshot was taken, in Universal Coordinated Time (UTC). Changes when the snapshot is copied. */ snapshotCreateTime: string; /** * Type of snapshots to be returned. If you don't specify a SnapshotType value, then both automated and manual snapshots are returned. Shared and public DB snapshots are not included in the returned results by default. Possible values are `automated`, `manual`, `shared`, `public` and `awsbackup`. */ snapshotType: string; /** * DB snapshot ARN that the DB snapshot was copied from. Only set for cross-account or cross-region copies. */ sourceDbSnapshotIdentifier: string; /** * Region that the DB snapshot was created in or copied from. */ sourceRegion: string; /** * Status of this DB snapshot. */ status: string; /** * Storage type associated with the DB snapshot. */ storageType: string; /** * List of tags attached to the DB snapshot. See `tagList` below. */ tagLists: outputs.rds.GetSnapshotsSnapshotTagList[]; /** * ID of the VPC associated with the DB snapshot. */ vpcId: string; } interface GetSnapshotsSnapshotTagList { /** * Key of the tag. */ key: string; /** * Value of the tag. */ value: string; } interface GlobalClusterGlobalClusterMember { /** * ARN of member DB Cluster. */ dbClusterArn: string; /** * Whether the member is the primary DB Cluster. */ isWriter: boolean; } interface InstanceBlueGreenUpdate { /** * Enables low-downtime updates when `true`. Default is `false`. */ enabled?: boolean; } interface InstanceDesiredStateTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface InstanceListenerEndpoint { /** * DNS address of the DB instance. */ address: string; /** * ID that Amazon Route 53 assigns when you create a hosted zone. */ hostedZoneId: string; /** * Port on which the DB accepts connections. */ port: number; } interface InstanceMasterUserSecret { /** * ARN for the KMS encryption key. If creating an encrypted replica, set this to the destination KMS ARN. */ kmsKeyId: string; /** * ARN of the secret. */ secretArn: string; /** * Status of the secret. Valid Values: `creating` | `active` | `rotating` | `impaired`. */ secretStatus: string; } interface InstanceRestoreToPointInTime { /** * Date and time to restore from. Value must be a time in Universal Coordinated Time (UTC) format and must be before the latest restorable time for the DB instance. Cannot be specified with `useLatestRestorableTime`. */ restoreTime?: string; /** * ARN of the automated backup from which to restore. Required if `sourceDbInstanceIdentifier` or `sourceDbiResourceId` is not specified. */ sourceDbInstanceAutomatedBackupsArn?: string; /** * Identifier of the source DB instance from which to restore. Must match the identifier of an existing DB instance. Required if `sourceDbInstanceAutomatedBackupsArn` or `sourceDbiResourceId` is not specified. */ sourceDbInstanceIdentifier?: string; /** * Resource ID of the source DB instance from which to restore. Required if `sourceDbInstanceIdentifier` or `sourceDbInstanceAutomatedBackupsArn` is not specified. */ sourceDbiResourceId?: string; /** * Boolean value that indicates whether the DB instance is restored from the latest backup time. Defaults to `false`. Cannot be specified with `restoreTime`. */ useLatestRestorableTime?: boolean; } interface InstanceS3Import { /** * Bucket name where your backup is stored. */ bucketName: string; /** * Can be blank, but is the path to your backup. */ bucketPrefix?: string; /** * Role applied to load the data. */ ingestionRole: string; /** * Source engine for the backup. */ sourceEngine: string; /** * Version of the source engine used to make the backup. */ sourceEngineVersion: string; } interface IntegrationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface OptionGroupOption { /** * List of DB Security Groups for which the option is enabled. */ dbSecurityGroupMemberships?: string[]; /** * Name of the option (e.g., MEMCACHED). */ optionName: string; /** * Option settings to apply. See `optionSettings` Block below for more details. */ optionSettings?: outputs.rds.OptionGroupOptionOptionSetting[]; /** * Port number when connecting to the option (e.g., 11211). Leaving out or removing `port` from your configuration does not remove or clear a port from the option in AWS. AWS may assign a default port. Not including `port` in your configuration means that the AWS provider will ignore a previously set value, a value set by AWS, and any port changes. */ port?: number; /** * Version of the option (e.g., 13.1.0.0). Leaving out or removing `version` from your configuration does not remove or clear a version from the option in AWS. AWS may assign a default version. Not including `version` in your configuration means that the AWS provider will ignore a previously set value, a value set by AWS, and any version changes. */ version?: string; /** * List of VPC Security Groups for which the option is enabled. */ vpcSecurityGroupMemberships?: string[]; } interface OptionGroupOptionOptionSetting { /** * Name of the setting. */ name: string; /** * Value of the setting. */ value: string; } interface ParameterGroupParameter { /** * "immediate" (default), or "pending-reboot". Some engines can't apply some parameters without a reboot, and you will need to specify "pending-reboot" here. */ applyMethod: string; /** * Name of the DB parameter. */ name: string; /** * Value of the DB parameter. */ value: string; } /** * parameterGroupParameterProvideDefaults sets the appropriate defaults for ParameterGroupParameter */ function parameterGroupParameterProvideDefaults(val: ParameterGroupParameter): ParameterGroupParameter; interface ProxyAuth { /** * Type of authentication that the proxy uses for connections from the proxy to the underlying database. One of `SECRETS`. */ authScheme?: string; /** * Type of authentication the proxy uses for connections from clients. Valid values are `MYSQL_CACHING_SHA2_PASSWORD`, `MYSQL_NATIVE_PASSWORD`, `POSTGRES_SCRAM_SHA_256`, `POSTGRES_MD5`, and `SQL_SERVER_AUTHENTICATION`. */ clientPasswordAuthType: string; /** * User-specified description about the authentication used by a proxy to log in as a specific database user. */ description?: string; /** * Whether to require or disallow AWS Identity and Access Management (IAM) authentication for connections to the proxy. One of `DISABLED`, `REQUIRED`. */ iamAuth?: string; /** * ARN representing the secret that the proxy uses to authenticate to the RDS DB instance or Aurora DB cluster. These secrets are stored within Amazon Secrets Manager. */ secretArn?: string; /** * Name of the database user to which the proxy connects. */ username?: string; } interface ProxyDefaultTargetGroupConnectionPoolConfig { /** * Number of seconds for a proxy to wait for a connection to become available in the connection pool. Only applies when the proxy has opened its maximum number of connections and all connections are busy with client sessions. */ connectionBorrowTimeout?: number; /** * One or more SQL statements for the proxy to run when opening each new database connection. Typically used with `SET` statements to make sure that each connection has identical settings such as time zone and character set. This setting is empty by default. For multiple statements, use semicolons as the separator. You can also include multiple variables in a single `SET` statement, such as `SET x=1, y=2`. */ initQuery?: string; /** * Maximum size of the connection pool for each target in a target group. For Aurora MySQL, it is expressed as a percentage of the maxConnections setting for the RDS DB instance or Aurora DB cluster used by the target group. */ maxConnectionsPercent?: number; /** * Controls how actively the proxy closes idle database connections in the connection pool. A high value enables the proxy to leave a high percentage of idle connections open. A low value causes the proxy to close idle client connections and return the underlying database connections to the connection pool. For Aurora MySQL, it is expressed as a percentage of the maxConnections setting for the RDS DB instance or Aurora DB cluster used by the target group. */ maxIdleConnectionsPercent?: number; /** * Each item in the list represents a class of SQL operations that normally cause all later statements in a session using a proxy to be pinned to the same underlying database connection. Including an item in the list exempts that class of SQL operations from the pinning behavior. This setting is only supported for MySQL engine family databases. Currently, the only allowed value is `EXCLUDE_VARIABLE_SETS`. */ sessionPinningFilters?: string[]; } interface ReservedInstanceRecurringCharge { /** * Amount of the recurring charge. */ recurringChargeAmount: number; /** * Frequency of the recurring charge. */ recurringChargeFrequency: string; } interface ShardGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace redshift { interface ClusterClusterNode { /** * Whether the node is a leader node or a compute node */ nodeRole: string; /** * The private IP address of a node within a cluster */ privateIpAddress: string; /** * The public IP address of a node within a cluster */ publicIpAddress: string; } interface EndpointAccessVpcEndpoint { /** * One or more network interfaces of the endpoint. Also known as an interface endpoint. See details below. */ networkInterfaces: outputs.redshift.EndpointAccessVpcEndpointNetworkInterface[]; /** * The connection endpoint ID for connecting an Amazon Redshift cluster through the proxy. */ vpcEndpointId: string; /** * The VPC identifier that the endpoint is associated. */ vpcId: string; } interface EndpointAccessVpcEndpointNetworkInterface { /** * The Availability Zone. */ availabilityZone: string; /** * The network interface identifier. */ networkInterfaceId: string; /** * The IPv4 address of the network interface within the subnet. */ privateIpAddress: string; /** * The subnet identifier. */ subnetId: string; } interface GetClusterClusterNode { /** * Whether the node is a leader node or a compute node */ nodeRole: string; /** * Private IP address of a node within a cluster */ privateIpAddress: string; /** * Public IP address of a node within a cluster */ publicIpAddress: string; } interface GetDataSharesDataShare { /** * ARN of the data share. */ dataShareArn: string; /** * Identifier of a datashare to show its managing entity. */ managedBy: string; /** * ARN of the producer. */ producerArn: string; } interface GetProducerDataSharesDataShare { /** * ARN of the data share. */ dataShareArn: string; /** * Identifier of a datashare to show its managing entity. */ managedBy: string; /** * ARN of the producer namespace that returns in the list of datashares. * * The following arguments are optional: */ producerArn: string; } interface IdcApplicationAuthorizedTokenIssuer { /** * List of audiences for the authorized token issuer for integrating Amazon Redshift with IDC Identity Center. */ authorizedAudiencesLists?: string[]; /** * ARN for the authorized token issuer for integrating Amazon Redshift with IDC Identity Center. */ trustedTokenIssuerArn?: string; } interface IdcApplicationServiceIntegration { /** * List of scopes set up for Lake Formation integration. Refer to the lakeFormation documentation for more details. */ lakeFormation?: outputs.redshift.IdcApplicationServiceIntegrationLakeFormation; /** * List of scopes set up for Redshift integration. Refer to the redshift documentation for more details. */ redshift?: outputs.redshift.IdcApplicationServiceIntegrationRedshift; /** * List of scopes set up for S3 Access Grants integration. Refer to the s3AccessGrants documentation for more details. */ s3AccessGrants?: outputs.redshift.IdcApplicationServiceIntegrationS3AccessGrants; } interface IdcApplicationServiceIntegrationLakeFormation { /** * Lake formation scope. */ lakeFormationQuery?: outputs.redshift.IdcApplicationServiceIntegrationLakeFormationLakeFormationQuery; } interface IdcApplicationServiceIntegrationLakeFormationLakeFormationQuery { /** * Determines whether the query scope is enabled or disabled. */ authorization: string; } interface IdcApplicationServiceIntegrationRedshift { /** * Amazon Redshift connect service integration scope. */ connect?: outputs.redshift.IdcApplicationServiceIntegrationRedshiftConnect; } interface IdcApplicationServiceIntegrationRedshiftConnect { /** * Determines whether the connect integration is enabled or disabled. */ authorization: string; } interface IdcApplicationServiceIntegrationS3AccessGrants { /** * S3 Access grants integration scope. */ readWriteAccess?: outputs.redshift.IdcApplicationServiceIntegrationS3AccessGrantsReadWriteAccess; } interface IdcApplicationServiceIntegrationS3AccessGrantsReadWriteAccess { /** * Determines whether read/write scope is enabled or disabled. */ authorization: string; } interface IntegrationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ParameterGroupParameter { /** * The name of the Redshift parameter. */ name: string; /** * The value of the Redshift parameter. */ value: string; } interface ScheduledActionTargetAction { /** * An action that runs a `PauseCluster` API operation. Documented below. */ pauseCluster?: outputs.redshift.ScheduledActionTargetActionPauseCluster; /** * An action that runs a `ResizeCluster` API operation. Documented below. */ resizeCluster?: outputs.redshift.ScheduledActionTargetActionResizeCluster; /** * An action that runs a `ResumeCluster` API operation. Documented below. */ resumeCluster?: outputs.redshift.ScheduledActionTargetActionResumeCluster; } interface ScheduledActionTargetActionPauseCluster { /** * The identifier of the cluster to be paused. */ clusterIdentifier: string; } interface ScheduledActionTargetActionResizeCluster { /** * A boolean value indicating whether the resize operation is using the classic resize process. Default: `false`. */ classic?: boolean; /** * The unique identifier for the cluster to resize. */ clusterIdentifier: string; /** * The new cluster type for the specified cluster. */ clusterType?: string; /** * The new node type for the nodes you are adding. */ nodeType?: string; /** * The new number of nodes for the cluster. */ numberOfNodes?: number; } interface ScheduledActionTargetActionResumeCluster { /** * The identifier of the cluster to be resumed. */ clusterIdentifier: string; } } export declare namespace redshiftdata { interface StatementParameter { name: string; value: string; } } export declare namespace redshiftserverless { interface EndpointAccessVpcEndpoint { /** * The network interfaces of the endpoint.. See `Network Interface` below. */ networkInterfaces: outputs.redshiftserverless.EndpointAccessVpcEndpointNetworkInterface[]; /** * The DNS address of the VPC endpoint. */ vpcEndpointId: string; /** * The port that Amazon Redshift Serverless listens on. */ vpcId: string; } interface EndpointAccessVpcEndpointNetworkInterface { /** * The availability Zone. */ availabilityZone: string; /** * The unique identifier of the network interface. */ networkInterfaceId: string; /** * The IPv4 address of the network interface within the subnet. */ privateIpAddress: string; /** * The unique identifier of the subnet. */ subnetId: string; } interface GetWorkgroupEndpoint { /** * The DNS address of the VPC endpoint. */ address: string; /** * The port that Amazon Redshift Serverless listens on. */ port: number; /** * The VPC endpoint or the Redshift Serverless workgroup. See `VPC Endpoint` below. */ vpcEndpoints: outputs.redshiftserverless.GetWorkgroupEndpointVpcEndpoint[]; } interface GetWorkgroupEndpointVpcEndpoint { /** * The network interfaces of the endpoint.. See `Network Interface` below. */ networkInterfaces: outputs.redshiftserverless.GetWorkgroupEndpointVpcEndpointNetworkInterface[]; /** * The DNS address of the VPC endpoint. */ vpcEndpointId: string; /** * The port that Amazon Redshift Serverless listens on. */ vpcId: string; } interface GetWorkgroupEndpointVpcEndpointNetworkInterface { /** * The availability Zone. */ availabilityZone: string; /** * The unique identifier of the network interface. */ networkInterfaceId: string; /** * The IPv4 address of the network interface within the subnet. */ privateIpAddress: string; /** * The unique identifier of the subnet. */ subnetId: string; } interface WorkgroupConfigParameter { /** * The key of the parameter. The options are `autoMv`, `datestyle`, `enableCaseSensitiveIdentifier`, `enableUserActivityLogging`, `queryGroup`, `searchPath`, `requireSsl`, `useFipsSsl`, and [query monitoring metrics](https://docs.aws.amazon.com/redshift/latest/dg/cm-c-wlm-query-monitoring-rules.html#cm-c-wlm-query-monitoring-metrics-serverless) that let you define performance boundaries: `maxQueryCpuTime`, `maxQueryBlocksRead`, `maxScanRowCount`, `maxQueryExecutionTime`, `maxQueryQueueTime`, `maxQueryCpuUsagePercent`, `maxQueryTempBlocksToDisk`, `maxJoinRowCount` and `maxNestedLoopJoinRowCount`. */ parameterKey: string; /** * The value of the parameter to set. */ parameterValue: string; } interface WorkgroupEndpoint { /** * The DNS address of the VPC endpoint. */ address: string; /** * The port number on which the cluster accepts incoming connections. */ port: number; /** * The VPC endpoint or the Redshift Serverless workgroup. See `VPC Endpoint` below. */ vpcEndpoints: outputs.redshiftserverless.WorkgroupEndpointVpcEndpoint[]; } interface WorkgroupEndpointVpcEndpoint { /** * The network interfaces of the endpoint.. See `Network Interface` below. */ networkInterfaces: outputs.redshiftserverless.WorkgroupEndpointVpcEndpointNetworkInterface[]; /** * The DNS address of the VPC endpoint. */ vpcEndpointId: string; /** * The port that Amazon Redshift Serverless listens on. */ vpcId: string; } interface WorkgroupEndpointVpcEndpointNetworkInterface { /** * The availability Zone. */ availabilityZone: string; /** * The unique identifier of the network interface. */ networkInterfaceId: string; /** * The IPv4 address of the network interface within the subnet. */ privateIpAddress: string; /** * The unique identifier of the subnet. */ subnetId: string; } interface WorkgroupPricePerformanceTarget { /** * Whether to enable price-performance scaling. */ enabled: boolean; /** * The price-performance scaling level. Valid values are `1` (LOW_COST), `25` (ECONOMICAL), `50` (BALANCED), `75` (RESOURCEFUL), and `100` (HIGH_PERFORMANCE). */ level?: number; } } export declare namespace rekognition { interface CollectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface ProjectTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface StreamProcessorDataSharingPreference { /** * Whether you are sharing data with Rekognition to improve model performance. */ optIn: boolean; } interface StreamProcessorInput { /** * Kinesis input stream. See `kinesisVideoStream`. */ kinesisVideoStream: outputs.rekognition.StreamProcessorInputKinesisVideoStream; } interface StreamProcessorInputKinesisVideoStream { /** * ARN of the Kinesis video stream stream that streams the source video. */ arn: string; } interface StreamProcessorNotificationChannel { /** * Amazon Resource Number (ARN) of the Amazon Amazon Simple Notification Service topic to which Amazon Rekognition posts the completion status. */ snsTopicArn?: string; } interface StreamProcessorOutput { /** * Amazon Kinesis Data Streams stream to which the Amazon Rekognition stream processor streams the analysis results. See `kinesisDataStream`. */ kinesisDataStream?: outputs.rekognition.StreamProcessorOutputKinesisDataStream; /** * Amazon S3 bucket location to which Amazon Rekognition publishes the detailed inference results of a video analysis operation. See `s3Destination`. */ s3Destination?: outputs.rekognition.StreamProcessorOutputS3Destination; } interface StreamProcessorOutputKinesisDataStream { /** * ARN of the output Amazon Kinesis Data Streams stream. */ arn?: string; } interface StreamProcessorOutputS3Destination { /** * Name of the Amazon S3 bucket you want to associate with the streaming video project. */ bucket?: string; /** * Prefix value of the location within the bucket that you want the information to be published to. */ keyPrefix?: string; } interface StreamProcessorRegionsOfInterest { /** * Box representing a region of interest on screen. Only 1 per region is allowed. See `boundingBox`. */ boundingBox?: outputs.rekognition.StreamProcessorRegionsOfInterestBoundingBox; /** * Shape made up of up to 10 Point objects to define a region of interest. See `polygon`. */ polygons?: outputs.rekognition.StreamProcessorRegionsOfInterestPolygon[]; } interface StreamProcessorRegionsOfInterestBoundingBox { /** * Height of the bounding box as a ratio of the overall image height. */ height?: number; /** * Left coordinate of the bounding box as a ratio of overall image width. */ left?: number; /** * Top coordinate of the bounding box as a ratio of overall image height. */ top?: number; /** * Width of the bounding box as a ratio of the overall image width. */ width?: number; } interface StreamProcessorRegionsOfInterestPolygon { /** * Value of the X coordinate for a point on a Polygon. */ x?: number; /** * Value of the Y coordinate for a point on a Polygon. */ y?: number; } interface StreamProcessorSettings { /** * Label detection settings to use on a streaming video. See `connectedHome`. */ connectedHome?: outputs.rekognition.StreamProcessorSettingsConnectedHome; /** * Input face recognition parameters for an Amazon Rekognition stream processor. See `faceSearch`. */ faceSearch?: outputs.rekognition.StreamProcessorSettingsFaceSearch; } interface StreamProcessorSettingsConnectedHome { /** * What you want to detect in the video, such as people, packages, or pets. The current valid labels you can include in this list are: `PERSON`, `PET`, `PACKAGE`, and `ALL`. */ labels?: string[]; /** * Minimum confidence required to label an object in the video. */ minConfidence: number; } interface StreamProcessorSettingsFaceSearch { /** * ID of a collection that contains faces that you want to search for. */ collectionId: string; /** * Minimum face match confidence score that must be met to return a result for a recognized face. */ faceMatchThreshold: number; } interface StreamProcessorTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace resiliencehub { interface GetV2PolicyAvailabilitySlo { /** * Availability target as a percentage. */ target: number; } interface GetV2PolicyDataRecovery { /** * Maximum time between backups in minutes. */ timeBetweenBackupsInMinutes: number; } interface GetV2PolicyMultiAz { /** * Disaster recovery approach. */ disasterRecoveryApproach: string; /** * Recovery point objective in minutes. */ rpoInMinutes: number; /** * Recovery time objective in minutes. */ rtoInMinutes: number; } interface GetV2PolicyMultiRegion { /** * Disaster recovery approach. */ disasterRecoveryApproach: string; /** * Recovery point objective in minutes. */ rpoInMinutes: number; /** * Recovery time objective in minutes. */ rtoInMinutes: number; } interface GetV2ServiceAssociatedSystem { /** * ARN of the associated system. */ systemArn: string; /** * List of user journey identifiers that associate the system with the service. */ userJourneyIds: string[]; } interface GetV2ServicePermissionModel { /** * Cross-account IAM role. See `crossAccountRole` Block below. */ crossAccountRoles: outputs.resiliencehub.GetV2ServicePermissionModelCrossAccountRole[]; /** * Name of the IAM role that Resilience Hub assumes for resource discovery. */ invokerRoleName: string; } interface GetV2ServicePermissionModelCrossAccountRole { /** * ARN of the IAM Role for the profile. */ crossAccountRoleArn: string; /** * External ID used for assuming the cross-account role. */ externalId: string; } interface ResiliencyPolicyPolicy { /** * Specifies Availability Zone failure policy. See `policy.az` */ az?: outputs.resiliencehub.ResiliencyPolicyPolicyAz; /** * Specifies Infrastructure failure policy. See `policy.hardware` */ hardware?: outputs.resiliencehub.ResiliencyPolicyPolicyHardware; /** * Specifies Region failure policy. `policy.region` */ region?: outputs.resiliencehub.ResiliencyPolicyPolicyRegion; /** * Specifies Application failure policy. See `policy.software` * * The following arguments are optional: */ software?: outputs.resiliencehub.ResiliencyPolicyPolicySoftware; } interface ResiliencyPolicyPolicyAz { /** * Recovery Point Objective (RPO) as a Go duration. */ rpo: string; /** * Recovery Time Objective (RTO) as a Go duration. */ rto: string; } interface ResiliencyPolicyPolicyHardware { /** * Recovery Point Objective (RPO) as a Go duration. */ rpo: string; /** * Recovery Time Objective (RTO) as a Go duration. */ rto: string; } interface ResiliencyPolicyPolicyRegion { /** * Recovery Point Objective (RPO) as a Go duration. */ rpo?: string; /** * Recovery Time Objective (RTO) as a Go duration. */ rto?: string; } interface ResiliencyPolicyPolicySoftware { /** * Recovery Point Objective (RPO) as a Go duration. */ rpo: string; /** * Recovery Time Objective (RTO) as a Go duration. */ rto: string; } interface ResiliencyPolicyTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface V2InputSourceResourceConfiguration { /** * CloudFormation stack ARN. */ cfnStackArn?: string; /** * S3 URL. */ designFileS3Url?: string; /** * EKS configuration. See `eks` Block below. */ eks?: outputs.resiliencehub.V2InputSourceResourceConfigurationEks; /** * Resource tags used for discovery. See `resourceTag` Block below. */ resourceTags?: outputs.resiliencehub.V2InputSourceResourceConfigurationResourceTag[]; /** * S3 URL. */ tfStateFileUrl?: string; } interface V2InputSourceResourceConfigurationEks { /** * Cluster ARN. */ clusterArn: string; /** * List of Kubernetes namespaces within the EKS cluster. */ namespaces: string[]; } interface V2InputSourceResourceConfigurationResourceTag { /** * Tag key. */ key: string; /** * List of tag values. */ values: string[]; } interface V2PolicyAvailabilitySlo { /** * Availability target as a percentage (e.g., `99.9`). */ target: number; } interface V2PolicyDataRecovery { /** * Maximum time between backups in minutes. */ timeBetweenBackupsInMinutes: number; } interface V2PolicyMultiAz { /** * Multi-AZ disaster recovery approach. Valid values: `ACTIVE_ACTIVE`, `HOT_STANDBY`, `WARM_STANDBY`, `PILOT_LIGHT`, `BACKUP_AND_RESTORE`. */ disasterRecoveryApproach: string; /** * Recovery point objective in minutes. */ rpoInMinutes?: number; /** * Recovery time objective in minutes. */ rtoInMinutes?: number; } interface V2PolicyMultiRegion { /** * Multi-region disaster recovery approach. Valid values: `ACTIVE_ACTIVE`, `HOT_STANDBY`, `WARM_STANDBY`, `PILOT_LIGHT`, `BACKUP_AND_RESTORE`. */ disasterRecoveryApproach: string; /** * Recovery point objective in minutes. */ rpoInMinutes?: number; /** * Recovery time objective in minutes. */ rtoInMinutes?: number; } interface V2ServiceAssociatedSystem { /** * ARN of the system to associate with the service. */ systemArn: string; /** * List of user journey identifiers that associate the system with the service. */ userJourneyIds?: string[]; } interface V2ServicePermissionModel { /** * Cross-account IAM role. See `crossAccountRole` Block below. */ crossAccountRoles?: outputs.resiliencehub.V2ServicePermissionModelCrossAccountRole[]; /** * Name of the IAM role that Resilience Hub assumes for resource discovery. */ invokerRoleName: string; } interface V2ServicePermissionModelCrossAccountRole { /** * ARN of the IAM Role for the profile. */ crossAccountRoleArn: string; /** * External ID used for assuming the cross-account role. */ externalId?: string; } } export declare namespace resourceexplorer { interface IndexTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface SearchResource { /** * ARN of resource. */ arn: string; /** * The date and time that the information about this resource property was last updated. */ lastReportedAt: string; /** * Amazon Web Services account that owns the resource. */ owningAccountId: string; /** * Structure with additional type-specific details about the resource. See `properties` below. */ properties: outputs.resourceexplorer.SearchResourceProperty[]; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; /** * Type of the resource. */ resourceType: string; /** * Amazon Web Service that owns the resource and is responsible for creating and updating it. */ service: string; } interface SearchResourceCount { /** * Indicates whether the TotalResources value represents an exhaustive count of search results. If True, it indicates that the search was exhaustive. Every resource that matches the query was counted. If False, then the search reached the limit of 1,000 matching results, and stopped counting. */ complete: boolean; /** * Number of resources that match the search query. This value can't exceed 1,000. If there are more than 1,000 resources that match the query, then only 1,000 are counted and the Complete field is set to false. We recommend that you refine your query to return a smaller number of results. */ totalResources: number; } interface SearchResourceProperty { /** * Details about this property. The content of this field is a JSON object that varies based on the resource type. */ data: string; /** * The date and time that the information about this resource property was last updated. */ lastReportedAt: string; /** * Name of this property of the resource. */ name: string; } interface ViewFilters { /** * The string that contains the search keywords, prefixes, and operators to control the results that can be returned by a search operation. For more details, see [Search query syntax](https://docs.aws.amazon.com/resource-explorer/latest/userguide/using-search-query-syntax.html). */ filterString: string; } interface ViewIncludedProperty { /** * The name of the property that is included in this view. Valid values: `tags`. */ name: string; } } export declare namespace resourcegroups { interface GroupConfiguration { /** * A collection of parameters for this group configuration item. See below for details. */ parameters?: outputs.resourcegroups.GroupConfigurationParameter[]; /** * Specifies the type of group configuration item. */ type: string; } interface GroupConfigurationParameter { /** * The name of the group configuration parameter. */ name: string; /** * The value or values to be used for the specified parameter. */ values: string[]; } interface GroupResourceQuery { /** * The resource query as a JSON string. */ query: string; /** * The type of the resource query. Defaults to `TAG_FILTERS_1_0`. */ type?: string; } } export declare namespace resourcegroupstaggingapi { interface GetRequiredTagsRequiredTag { /** * CloudFormation resource types assigned the required tag keys. */ cloudFormationResourceTypes: string[]; /** * Tag keys marked as required in the `reportRequiredTagFor` block of the effective tag policy. */ reportingTagKeys: string[]; /** * Resource type for the required tag keys. */ resourceType: string; } interface GetResourcesResourceTagMappingList { /** * List of objects with information that shows whether a resource is compliant with the effective tag policy, including details on any noncompliant tag keys. */ complianceDetails: outputs.resourcegroupstaggingapi.GetResourcesResourceTagMappingListComplianceDetail[]; /** * ARN of the resource. */ resourceArn: string; /** * Map of tags assigned to the resource. */ tags: { [key: string]: string; }; } interface GetResourcesResourceTagMappingListComplianceDetail { /** * Whether the resource is compliant. * * ` keysWithNoncompliantValues ` - Set of tag keys with non-compliant tag values. * * ` nonCompliantKeys ` - Set of non-compliant tag keys. */ complianceStatus: boolean; keysWithNoncompliantValues: string[]; nonCompliantKeys: string[]; } interface GetResourcesTagFilter { /** * One part of a key-value pair that makes up a tag. */ key: string; /** * Optional part of a key-value pair that make up a tag. */ values?: string[]; } } export declare namespace rolesanywhere { interface TrustAnchorNotificationSetting { channel: string; configuredBy: string; /** * Whether or not the Trust Anchor should be enabled. */ enabled: boolean; event: string; threshold: number; } interface TrustAnchorSource { /** * The data denoting the source of trust, documented below */ sourceData: outputs.rolesanywhere.TrustAnchorSourceSourceData; /** * The type of the source of trust. Must be either `AWS_ACM_PCA` or `CERTIFICATE_BUNDLE`. */ sourceType: string; } interface TrustAnchorSourceSourceData { /** * The ARN of an ACM Private Certificate Authority. */ acmPcaArn?: string; x509CertificateData?: string; } } export declare namespace route53 { interface GetProfilesProfilesProfile { /** * ARN of the Profile. */ arn: string; /** * ID of the Profile. */ id: string; /** * Name of the Profile. */ name: string; /** * Share status of the Profile. Valid values [AWS docs](https://docs.aws.amazon.com/Route53/latest/APIReference/API_route53profiles_Profile.html) */ shareStatus: string; } interface GetQueryLogConfigFilter { /** * The name of the query logging configuration. */ name: string; values: string[]; } interface GetRecordsResourceRecordSet { /** * Information about the AWS resource traffic is routed to. */ aliasTarget: outputs.route53.GetRecordsResourceRecordSetAliasTarget; /** * Information about the CIDR location traffic is routed to. */ cidrRoutingConfig: outputs.route53.GetRecordsResourceRecordSetCidrRoutingConfig; /** * `PRIMARY` or `SECONDARY`. */ failover: string; /** * Information about how Amazon Route 53 responds to DNS queries based on the geographic origin of the query. */ geolocation: outputs.route53.GetRecordsResourceRecordSetGeolocation; /** * Information about how Amazon Route 53 responds to DNS queries based on the geographic origin of the query. */ geoproximityLocation: outputs.route53.GetRecordsResourceRecordSetGeoproximityLocation; /** * ID of any applicable health check. */ healthCheckId: string; /** * Traffic is routed approximately randomly to multiple resources. */ multiValueAnswer: boolean; /** * The name of the record. */ name: string; /** * The Amazon EC2 Region of the resource that this resource record set refers to. */ region: string; /** * The resource records. */ resourceRecords: outputs.route53.GetRecordsResourceRecordSetResourceRecord[]; /** * An identifier that differentiates among multiple resource record sets that have the same combination of name and type. */ setIdentifier: string; /** * The ID of any traffic policy instance that Route 53 created this resource record set for. */ trafficPolicyInstanceId: string; /** * The resource record cache time to live (TTL), in seconds. */ ttl: number; /** * The DNS record type. */ type: string; /** * Among resource record sets that have the same combination of DNS name and type, a value that determines the proportion of DNS queries that Amazon Route 53 responds to using the current resource record set. */ weight: number; } interface GetRecordsResourceRecordSetAliasTarget { /** * Target DNS name. */ dnsName: string; /** * Whether an alias resource record set inherits the health of the referenced AWS resource. */ evaluateTargetHealth: boolean; /** * Target hosted zone ID. */ hostedZoneId: string; } interface GetRecordsResourceRecordSetCidrRoutingConfig { /** * The CIDR collection ID. */ collectionId: string; /** * The CIDR collection location name. */ locationName: string; } interface GetRecordsResourceRecordSetGeolocation { /** * The two-letter code for the continent. */ continentCode: string; /** * The two-letter code for a country. */ countryCode: string; /** * The two-letter code for a state of the United States. */ subdivisionCode: string; } interface GetRecordsResourceRecordSetGeoproximityLocation { /** * The AWS Region the resource you are directing DNS traffic to, is in. */ awsRegion: string; /** * The bias increases or decreases the size of the geographic region from which Route 53 routes traffic to a resource. */ bias: number; /** * Contains the longitude and latitude for a geographic region. */ coordinates: outputs.route53.GetRecordsResourceRecordSetGeoproximityLocationCoordinates; /** * An AWS Local Zone Group. */ localZoneGroup: string; } interface GetRecordsResourceRecordSetGeoproximityLocationCoordinates { /** * Latitude. */ latitude: string; /** * Longitude. */ longitude: string; } interface GetRecordsResourceRecordSetResourceRecord { /** * The DNS record value. */ value: string; } interface GetResolverEndpointFilter { name: string; values: string[]; } interface GetResolverFirewallRulesFirewallRule { /** * The action that DNS Firewall should take on a DNS query when it matches one of the domains in the rule's domain list. */ action: string; /** * The DNS record's type. */ blockOverrideDnsType: string; /** * The custom DNS record to send back in response to the query. */ blockOverrideDomain: string; /** * The recommended amount of time, in seconds, for the DNS resolver or web browser to cache the provided override record. */ blockOverrideTtl: number; /** * The way that you want DNS Firewall to block the request. */ blockResponse: string; /** * The confidence threshold for DNS Firewall Advanced rules. */ confidenceThreshold: string; /** * The date and time that the rule was created, in Unix time format and Coordinated Universal Time (UTC). */ creationTime: string; /** * A unique string defined by you to identify the request. */ creatorRequestId: string; /** * The type of DNS Firewall Advanced rule. */ dnsThreatProtection: string; /** * The ID of the domain list that's used in the rule. */ firewallDomainListId: string; /** * How DNS Firewall evaluates DNS redirection in the DNS redirection chain. */ firewallDomainRedirectionAction: string; /** * The unique identifier of the firewall rule group that you want to retrieve the rules for. */ firewallRuleGroupId: string; /** * The ID of the DNS Firewall Advanced rule. */ firewallThreatProtectionId: string; /** * The date and time that the rule was last modified, in Unix time format and Coordinated Universal Time (UTC). */ modificationTime: string; /** * The name of the rule. */ name: string; /** * The setting that determines the processing order of the rules in a rule group. */ priority: number; /** * The DNS query type that the rule evaluates. */ qType: string; } interface GetResolverRuleTargetIp { /** * IPv4 address that you want to forward DNS queries to. */ ip: string; /** * IPv6 address that you want to forward DNS queries to. */ ipv6: string; /** * Port at the IP address that you want to forward DNS queries to. */ port: number; /** * Protocol for the target IP address. Valid values are `Do53` (DNS over port 53), `DoH` (DNS over HTTPS), and `DoH-FIPS` (DNS over HTTPS with FIPS). */ protocol: string; } interface GetTrafficPolicyDocumentEndpoint { /** * ID of an endpoint you want to assign. */ id: string; /** * To route traffic to an Amazon S3 bucket that is configured as a website endpoint, specify the region in which you created the bucket for `region`. */ region?: string; /** * Type of the endpoint. Valid values are `value`, `cloudfront`, `elastic-load-balancer`, `s3-website`, `application-load-balancer`, `network-load-balancer` and `elastic-beanstalk` */ type?: string; /** * Value of the `type`. */ value?: string; } interface GetTrafficPolicyDocumentRule { /** * Configuration block for when you add a geoproximity rule, you configure Amazon Route 53 to route traffic to your resources based on the geographic location of your resources. Only valid for `geoproximity` type. See below */ geoProximityLocations?: outputs.route53.GetTrafficPolicyDocumentRuleGeoProximityLocation[]; /** * ID of a rule you want to assign. */ id: string; /** * Configuration block for when you add a multivalue answer rule, you configure your traffic policy to route traffic approximately randomly to your healthy resources. Only valid for `multivalue` type. See below */ items?: outputs.route53.GetTrafficPolicyDocumentRuleItem[]; /** * Configuration block for when you add a geolocation rule, you configure your traffic policy to route your traffic based on the geographic location of your users. Only valid for `geo` type. See below */ locations?: outputs.route53.GetTrafficPolicyDocumentRuleLocation[]; /** * Configuration block for the settings for the rule or endpoint that you want to route traffic to whenever the corresponding resources are available. Only valid for `failover` type. See below */ primary?: outputs.route53.GetTrafficPolicyDocumentRulePrimary; regions?: outputs.route53.GetTrafficPolicyDocumentRuleRegion[]; /** * Configuration block for the rule or endpoint that you want to route traffic to whenever the primary resources are not available. Only valid for `failover` type. See below */ secondary?: outputs.route53.GetTrafficPolicyDocumentRuleSecondary; /** * Type of the rule. */ type?: string; } interface GetTrafficPolicyDocumentRuleGeoProximityLocation { /** * Specify a value for `bias` if you want to route more traffic to an endpoint from nearby endpoints (positive values) or route less traffic to an endpoint (negative values). */ bias?: string; /** * References to an endpoint. */ endpointReference?: string; /** * Indicates whether you want Amazon Route 53 to evaluate the health of the endpoint and route traffic only to healthy endpoints. */ evaluateTargetHealth?: boolean; /** * If you want to associate a health check with the endpoint or rule. */ healthCheck?: string; /** * Represents the location south (negative) or north (positive) of the equator. Valid values are -90 degrees to 90 degrees. */ latitude?: string; /** * Represents the location west (negative) or east (positive) of the prime meridian. Valid values are -180 degrees to 180 degrees. */ longitude?: string; /** * If your endpoint is an AWS resource, specify the AWS Region that you created the resource in. */ region?: string; /** * References to a rule. */ ruleReference?: string; } interface GetTrafficPolicyDocumentRuleItem { endpointReference?: string; healthCheck?: string; } interface GetTrafficPolicyDocumentRuleLocation { /** * Value of a continent. */ continent?: string; /** * Value of a country. */ country?: string; /** * References to an endpoint. */ endpointReference?: string; /** * Indicates whether you want Amazon Route 53 to evaluate the health of the endpoint and route traffic only to healthy endpoints. */ evaluateTargetHealth?: boolean; /** * If you want to associate a health check with the endpoint or rule. */ healthCheck?: string; /** * Indicates whether this set of values represents the default location. */ isDefault?: boolean; /** * References to a rule. */ ruleReference?: string; /** * Value of a subdivision. */ subdivision?: string; } interface GetTrafficPolicyDocumentRulePrimary { /** * References to an endpoint. */ endpointReference?: string; /** * Indicates whether you want Amazon Route 53 to evaluate the health of the endpoint and route traffic only to healthy endpoints. */ evaluateTargetHealth?: boolean; /** * If you want to associate a health check with the endpoint or rule. */ healthCheck?: string; /** * References to a rule. */ ruleReference?: string; } interface GetTrafficPolicyDocumentRuleRegion { /** * References to an endpoint. */ endpointReference?: string; /** * Indicates whether you want Amazon Route 53 to evaluate the health of the endpoint and route traffic only to healthy endpoints. */ evaluateTargetHealth?: boolean; /** * If you want to associate a health check with the endpoint or rule. */ healthCheck?: string; /** * Region code for the AWS Region that you created the resource in. */ region?: string; /** * References to a rule. */ ruleReference?: string; } interface GetTrafficPolicyDocumentRuleSecondary { endpointReference?: string; evaluateTargetHealth?: boolean; healthCheck?: string; ruleReference?: string; } interface ProfilesAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ProfilesProfileTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; } interface ProfilesResourceAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; } interface RecordAlias { /** * Set to `true` if you want Route 53 to determine whether to respond to DNS queries using this resource record set by checking the health of the resource record set. Some resources have special requirements, see [related part of documentation](https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resource-record-sets-values.html#rrsets-values-alias-evaluate-target-health). */ evaluateTargetHealth: boolean; /** * DNS domain name for a CloudFront distribution, S3 bucket, ELB, AWS Global Accelerator, or another resource record set in this hosted zone. */ name: string; /** * Hosted zone ID for a CloudFront distribution, S3 bucket, ELB, AWS Global Accelerator, or Route 53 hosted zone. See `resource_elb.zone_id` for example. */ zoneId: string; } interface RecordCidrRoutingPolicy { /** * The CIDR collection ID. See the `aws.route53.CidrCollection` resource for more details. */ collectionId: string; /** * The CIDR collection location name. See the `aws.route53.CidrLocation` resource for more details. A `locationName` with an asterisk `"*"` can be used to create a default CIDR record. `collectionId` is still required for default record. */ locationName: string; } interface RecordFailoverRoutingPolicy { /** * `PRIMARY` or `SECONDARY`. A `PRIMARY` record will be served if its healthcheck is passing, otherwise the `SECONDARY` will be served. See http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/dns-failover-configuring-options.html#dns-failover-failover-rrsets */ type: string; } interface RecordGeolocationRoutingPolicy { /** * A two-letter continent code. See http://docs.aws.amazon.com/Route53/latest/APIReference/API_GetGeoLocation.html for code details. Either `continent` or `country` must be specified. */ continent?: string; /** * A two-character country code or `*` to indicate a default resource record set. */ country?: string; /** * A subdivision code for a country. */ subdivision?: string; } interface RecordGeoproximityRoutingPolicy { /** * A AWS region where the resource is present. */ awsRegion?: string; /** * Route more traffic or less traffic to the resource by specifying a value ranges between -90 to 90. See https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy-geoproximity.html for bias details. */ bias?: number; /** * Specify `latitude` and `longitude` for routing traffic to non-AWS resources. */ coordinates?: outputs.route53.RecordGeoproximityRoutingPolicyCoordinate[]; /** * A AWS local zone group where the resource is present. See https://docs.aws.amazon.com/local-zones/latest/ug/available-local-zones.html for local zone group list. */ localZoneGroup?: string; } interface RecordGeoproximityRoutingPolicyCoordinate { latitude: string; longitude: string; } interface RecordLatencyRoutingPolicy { /** * An AWS region from which to measure latency. See http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy.html#routing-policy-latency */ region: string; } interface RecordWeightedRoutingPolicy { /** * A numeric value indicating the relative weight of the record. See http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy.html#routing-policy-weighted. */ weight: number; } interface RecordsExclusiveResourceRecordSet { /** * Alias target block. * See `aliasTarget` below. */ aliasTarget?: outputs.route53.RecordsExclusiveResourceRecordSetAliasTarget; cidrRoutingConfig?: outputs.route53.RecordsExclusiveResourceRecordSetCidrRoutingConfig; /** * Type of failover resource record. * Valid values are `PRIMARY` and `SECONDARY`. * See the [AWS documentation on DNS failover](https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/dns-failover.html) for additional details. */ failover?: string; /** * Geolocation block to control how Amazon Route 53 responds to DNS queries based on the geographic origin of the query. * See `geolocation` below. */ geolocation?: outputs.route53.RecordsExclusiveResourceRecordSetGeolocation; /** * Geoproximity location block. * See `geoproximityLocation` below. */ geoproximityLocation?: outputs.route53.RecordsExclusiveResourceRecordSetGeoproximityLocation; /** * Health check the record should be associated with. */ healthCheckId?: string; /** * Set to `true` to indicate this record is a multivalue answer record and traffic should be routed approximately randomly to multiple resources. */ multiValueAnswer?: boolean; /** * Name of the record. */ name: string; /** * AWS region of the resource this record set refers to. * Must be a valid AWS region name. * See the [AWS documentation](http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy.html#routing-policy-latency) on latency based routing for additional details. */ region?: string; /** * Information about the resource records to act upon. * See `resourceRecords` below. */ resourceRecords?: outputs.route53.RecordsExclusiveResourceRecordSetResourceRecord[]; /** * An identifier that differentiates among multiple resource record sets that have the same combination of name and type. * Required if using `cidrRoutingConfig`, `failover`, `geolocation`,`geoproximityLocation`, `multiValueAnswer`, `region`, or `weight`. */ setIdentifier?: string; /** * ID of the traffic policy instance that Route 53 created this resource record set for. * To delete the resource record set that is associated with a traffic policy instance, use the `DeleteTrafficPolicyInstance` API. * Route 53 will delete the resource record set automatically. * If the resource record set is deleted via `ChangeResourceRecordSets` (the API underpinning this Terraform resource), Route 53 doesn't automatically delete the traffic policy instance, and you'll continue to be charged for it. */ trafficPolicyInstanceId?: string; /** * Resource record cache time to live (TTL), in seconds. */ ttl?: number; /** * Record type. * Valid values are `A`, `AAAA`, `CAA`, `CNAME`, `DS`, `MX`, `NAPTR`, `NS`, `PTR`, `SOA`, `SPF`, `SRV`, `TXT`, `TLSA`, `SSHFP`, `SVCB`, and `HTTPS`. * * The following arguments are optional: * * > Exactly one of `resourceRecords` or `aliasTarget` must be specified. */ type?: string; /** * Among resource record sets that have the same combination of DNS name and type, a value that determines the proportion of DNS queries that Amazon Route 53 responds to using the current resource record set. */ weight?: number; } interface RecordsExclusiveResourceRecordSetAliasTarget { /** * DNS domain name for another resource record set in this hosted zone. */ dnsName: string; /** * Set to `true` if you want Route 53 to determine whether to respond to DNS queries using this resource record set by checking the health of the resource record set. Some resources have special requirements, see [the AWS documentation](https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resource-record-sets-values.html#rrsets-values-alias-evaluate-target-health) for additional details. */ evaluateTargetHealth: boolean; /** * Hosted zone ID for a CloudFront distribution, S3 bucket, ELB, AWS Global Accelerator, or Route 53 hosted zone. See `resource_elb.zone_id` for an example. */ hostedZoneId: string; } interface RecordsExclusiveResourceRecordSetCidrRoutingConfig { /** * CIDR collection ID. * See the `aws.route53.CidrCollection` resource for more details. */ collectionId: string; /** * CIDR collection location name. * See the `aws.route53.CidrLocation` resource for more details. * A `locationName` with an asterisk `"*"` can be used to create a default CIDR record. * `collectionId` is still required for a default record. */ locationName: string; } interface RecordsExclusiveResourceRecordSetGeolocation { /** * Two-letter continent code. * See the [AWS documentation](http://docs.aws.amazon.com/Route53/latest/APIReference/API_GetGeoLocation.html) for valid values. */ continentCode?: string; /** * Two-letter country code. * See the ISO standard linked from the [AWS documentation](http://docs.aws.amazon.com/Route53/latest/APIReference/API_GetGeoLocation.html) for valid values. */ countryCode?: string; /** * Subdivision code. */ subdivisionCode?: string; } interface RecordsExclusiveResourceRecordSetGeoproximityLocation { /** * AWS region of the resource where DNS traffic is directed to. */ awsRegion?: string; /** * Increases or decreases the size of the geographic region from which Route 53 routes traffic to a resource. * To expand the size of the geographic region from which Route 53 routes traffic to a resource, specify a positive integer from `1` to `99`. * To shrink the size of the geographic region from which Route 53 routes traffic to a resource, specify a negative bias of `-1` to `-99`. * See the [AWS documentation](https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy-geoproximity.html) for additional details. */ bias?: number; /** * Coordinates for a geoproximity resource record. * See `coordinates` below. */ coordinates?: outputs.route53.RecordsExclusiveResourceRecordSetGeoproximityLocationCoordinates; /** * AWS local zone group. * Identify the Local Zones Group for a specific Local Zone by using the [`describe-availability-zones` CLI command](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-availability-zones.html). */ localZoneGroup?: string; } interface RecordsExclusiveResourceRecordSetGeoproximityLocationCoordinates { /** * A coordinate of the north–south position of a geographic point on the surface of the Earth (`-90` - `90`). */ latitude: string; /** * A coordinate of the east–west position of a geographic point on the surface of the Earth (`-180` - `180`). */ longitude: string; } interface RecordsExclusiveResourceRecordSetResourceRecord { /** * DNS record value. */ value: string; } interface RecordsExclusiveTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ResolverEndpointIpAddress { /** * IPv4 address in the subnet that you want to use for DNS queries. */ ip: string; ipId: string; /** * IPv6 address in the subnet that you want to use for DNS queries. */ ipv6: string; /** * ID of the subnet that contains the IP address. */ subnetId: string; } interface ResolverRuleTargetIp { /** * One IPv4 address that you want to forward DNS queries to. */ ip?: string; /** * One IPv6 address that you want to forward DNS queries to. */ ipv6?: string; /** * Port at `ip` that you want to forward DNS queries to. Default value is `53`. */ port?: number; /** * Protocol for the resolver endpoint. Valid values can be found in the [AWS documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_route53resolver_TargetAddress.html). Default value is `Do53`. */ protocol?: string; } interface ZoneVpc { /** * ID of the VPC to associate. */ vpcId: string; /** * Region of the VPC to associate. Defaults to AWS provider region. */ vpcRegion: string; } } export declare namespace route53domains { interface DelegationSignerRecordSigningAttributes { /** * Algorithm which was used to generate the digest from the public key. */ algorithm: number; /** * Defines the type of key. It can be either a KSK (key-signing-key, value `257`) or ZSK (zone-signing-key, value `256`). */ flags: number; /** * The base64-encoded public key part of the key pair that is passed to the registry. */ publicKey: string; } interface DelegationSignerRecordTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface DomainAdminContact { /** * First line of the contact's address. */ addressLine1?: string; /** * Second line of contact's address, if any. */ addressLine2?: string; /** * The city of the contact's address. */ city?: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType?: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode?: string; /** * Email address of the contact. */ email?: string; /** * A list of name-value pairs for parameters required by certain top-level domains. */ extraParams?: outputs.route53domains.DomainAdminContactExtraParam[]; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax?: string; /** * First name of contact. */ firstName?: string; /** * Last name of contact. */ lastName?: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName?: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber?: string; /** * The state or province of the contact's city. */ state?: string; /** * The zip or postal code of the contact's address. */ zipCode?: string; } interface DomainAdminContactExtraParam { /** * The name of an additional parameter that is required by a top-level domain. */ name: string; /** * The value that corresponds with the name of an extra parameter. */ value: string; } interface DomainBillingContact { /** * First line of the contact's address. */ addressLine1: string; /** * Second line of contact's address, if any. */ addressLine2: string; /** * The city of the contact's address. */ city: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode: string; /** * Email address of the contact. */ email: string; /** * A list of name-value pairs for parameters required by certain top-level domains. */ extraParams: outputs.route53domains.DomainBillingContactExtraParam[]; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax: string; /** * First name of contact. */ firstName: string; /** * Last name of contact. */ lastName: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber: string; /** * The state or province of the contact's city. */ state: string; /** * The zip or postal code of the contact's address. */ zipCode: string; } interface DomainBillingContactExtraParam { /** * The name of an additional parameter that is required by a top-level domain. */ name: string; /** * The value that corresponds with the name of an extra parameter. */ value: string; } interface DomainNameServer { /** * Glue IP addresses of a name server. The list can contain only one IPv4 and one IPv6 address. */ glueIps: string[]; /** * The fully qualified host name of the name server. */ name: string; } interface DomainRegistrantContact { /** * First line of the contact's address. */ addressLine1?: string; /** * Second line of contact's address, if any. */ addressLine2?: string; /** * The city of the contact's address. */ city?: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType?: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode?: string; /** * Email address of the contact. */ email?: string; /** * A list of name-value pairs for parameters required by certain top-level domains. */ extraParams?: outputs.route53domains.DomainRegistrantContactExtraParam[]; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax?: string; /** * First name of contact. */ firstName?: string; /** * Last name of contact. */ lastName?: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName?: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber?: string; /** * The state or province of the contact's city. */ state?: string; /** * The zip or postal code of the contact's address. */ zipCode?: string; } interface DomainRegistrantContactExtraParam { /** * The name of an additional parameter that is required by a top-level domain. */ name: string; /** * The value that corresponds with the name of an extra parameter. */ value: string; } interface DomainTechContact { /** * First line of the contact's address. */ addressLine1?: string; /** * Second line of contact's address, if any. */ addressLine2?: string; /** * The city of the contact's address. */ city?: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType?: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode?: string; /** * Email address of the contact. */ email?: string; /** * A list of name-value pairs for parameters required by certain top-level domains. */ extraParams?: outputs.route53domains.DomainTechContactExtraParam[]; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax?: string; /** * First name of contact. */ firstName?: string; /** * Last name of contact. */ lastName?: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName?: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber?: string; /** * The state or province of the contact's city. */ state?: string; /** * The zip or postal code of the contact's address. */ zipCode?: string; } interface DomainTechContactExtraParam { /** * The name of an additional parameter that is required by a top-level domain. */ name: string; /** * The value that corresponds with the name of an extra parameter. */ value: string; } interface DomainTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface RegisteredDomainAdminContact { /** * First line of the contact's address. */ addressLine1: string; /** * Second line of contact's address, if any. */ addressLine2: string; /** * The city of the contact's address. */ city: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode: string; /** * Email address of the contact. */ email: string; /** * A key-value map of parameters required by certain top-level domains. */ extraParams: { [key: string]: string; }; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax: string; /** * First name of contact. */ firstName: string; /** * Last name of contact. */ lastName: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber: string; /** * The state or province of the contact's city. */ state: string; /** * The zip or postal code of the contact's address. */ zipCode: string; } interface RegisteredDomainBillingContact { /** * First line of the contact's address. */ addressLine1: string; /** * Second line of contact's address, if any. */ addressLine2: string; /** * The city of the contact's address. */ city: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode: string; /** * Email address of the contact. */ email: string; /** * A key-value map of parameters required by certain top-level domains. */ extraParams: { [key: string]: string; }; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax: string; /** * First name of contact. */ firstName: string; /** * Last name of contact. */ lastName: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber: string; /** * The state or province of the contact's city. */ state: string; /** * The zip or postal code of the contact's address. */ zipCode: string; } interface RegisteredDomainNameServer { /** * Glue IP addresses of a name server. The list can contain only one IPv4 and one IPv6 address. */ glueIps?: string[]; /** * The fully qualified host name of the name server. */ name: string; } interface RegisteredDomainRegistrantContact { /** * First line of the contact's address. */ addressLine1: string; /** * Second line of contact's address, if any. */ addressLine2: string; /** * The city of the contact's address. */ city: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode: string; /** * Email address of the contact. */ email: string; /** * A key-value map of parameters required by certain top-level domains. */ extraParams: { [key: string]: string; }; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax: string; /** * First name of contact. */ firstName: string; /** * Last name of contact. */ lastName: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber: string; /** * The state or province of the contact's city. */ state: string; /** * The zip or postal code of the contact's address. */ zipCode: string; } interface RegisteredDomainTechContact { /** * First line of the contact's address. */ addressLine1: string; /** * Second line of contact's address, if any. */ addressLine2: string; /** * The city of the contact's address. */ city: string; /** * Indicates whether the contact is a person, company, association, or public organization. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-ContactType) for valid values. */ contactType: string; /** * Code for the country of the contact's address. See the [AWS API documentation](https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_ContactDetail.html#Route53Domains-Type-domains_ContactDetail-CountryCode) for valid values. */ countryCode: string; /** * Email address of the contact. */ email: string; /** * A key-value map of parameters required by certain top-level domains. */ extraParams: { [key: string]: string; }; /** * Fax number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ fax: string; /** * First name of contact. */ firstName: string; /** * Last name of contact. */ lastName: string; /** * Name of the organization for contact types other than `PERSON`. */ organizationName: string; /** * The phone number of the contact. Phone number must be specified in the format "+[country dialing code].[number including any area code]". */ phoneNumber: string; /** * The state or province of the contact's city. */ state: string; /** * The zip or postal code of the contact's address. */ zipCode: string; } } export declare namespace route53recoverycontrol { interface ClusterClusterEndpoint { /** * Cluster endpoint. */ endpoint: string; /** * Region of the endpoint. */ region: string; } interface SafetyRuleRuleConfig { /** * Logical negation of the rule. */ inverted: boolean; /** * Number of controls that must be set when you specify an `ATLEAST` type rule. */ threshold: number; /** * Rule type. Valid values are `ATLEAST`, `AND`, and `OR`. */ type: string; } } export declare namespace route53recoveryreadiness { interface ResourceSetResource { componentId: string; /** * Component for DNS/Routing Control Readiness Checks. */ dnsTargetResource?: outputs.route53recoveryreadiness.ResourceSetResourceDnsTargetResource; /** * Recovery group ARN or cell ARN that contains this resource set. */ readinessScopes?: string[]; /** * ARN of the resource. */ resourceArn?: string; } interface ResourceSetResourceDnsTargetResource { /** * DNS Name that acts as the ingress point to a portion of application. */ domainName: string; /** * Hosted Zone ARN that contains the DNS record with the provided name of target resource. */ hostedZoneArn?: string; /** * Route53 record set id to uniquely identify a record given a `domainName` and a `recordType`. */ recordSetId?: string; /** * Type of DNS Record of target resource. */ recordType?: string; /** * Target resource the R53 record specified with the above params points to. */ targetResource?: outputs.route53recoveryreadiness.ResourceSetResourceDnsTargetResourceTargetResource; } interface ResourceSetResourceDnsTargetResourceTargetResource { /** * NLB resource a DNS Target Resource points to. Required if `r53Resource` is not set. */ nlbResource?: outputs.route53recoveryreadiness.ResourceSetResourceDnsTargetResourceTargetResourceNlbResource; /** * Route53 resource a DNS Target Resource record points to. */ r53Resource?: outputs.route53recoveryreadiness.ResourceSetResourceDnsTargetResourceTargetResourceR53Resource; } interface ResourceSetResourceDnsTargetResourceTargetResourceNlbResource { /** * NLB resource ARN. */ arn?: string; } interface ResourceSetResourceDnsTargetResourceTargetResourceR53Resource { /** * Domain name that is targeted. */ domainName?: string; /** * Resource record set ID that is targeted. */ recordSetId?: string; } } export declare namespace rum { interface AppMonitorAppMonitorConfiguration { /** * If you set this to `true`, RUM web client sets two cookies, a session cookie and a user cookie. The cookies allow the RUM web client to collect data relating to the number of users an application has and the behavior of the application across a sequence of events. Cookies are stored in the top-level domain of the current page. */ allowCookies?: boolean; /** * If you set this to `true`, RUM enables X-Ray tracing for the user sessions that RUM samples. RUM adds an X-Ray trace header to allowed HTTP requests. It also records an X-Ray segment for allowed HTTP requests. */ enableXray?: boolean; /** * A list of URLs in your website or application to exclude from RUM data collection. */ excludedPages?: string[]; /** * A list of pages in the CloudWatch RUM console that are to be displayed with a "favorite" icon. */ favoritePages?: string[]; /** * The ARN of the guest IAM role that is attached to the Amazon Cognito identity pool that is used to authorize the sending of data to RUM. */ guestRoleArn?: string; /** * The ID of the Amazon Cognito identity pool that is used to authorize the sending of data to RUM. */ identityPoolId?: string; /** * If this app monitor is to collect data from only certain pages in your application, this structure lists those pages. */ includedPages?: string[]; /** * Specifies the percentage of user sessions to use for RUM data collection. Choosing a higher percentage gives you more data but also incurs more costs. The number you specify is the percentage of user sessions that will be used. Default value is `0.1`. */ sessionSampleRate?: number; /** * An array that lists the types of telemetry data that this app monitor is to collect. Valid values are `errors`, `performance`, and `http`. */ telemetries?: string[]; } interface AppMonitorCustomEvents { /** * Specifies whether this app monitor allows the web client to define and send custom events. The default is for custom events to be `DISABLED`. Valid values are `DISABLED` and `ENABLED`. */ status?: string; } } export declare namespace s3 { interface AccessPointPublicAccessBlockConfiguration { /** * Whether Amazon S3 should block public ACLs for buckets in this account. Defaults to `true`. Enabling this setting does not affect existing policies or ACLs. When set to `true`, PUT Bucket acl and PUT Object acl calls fail if the specified ACL is public, PUT Object calls fail if the request includes a public ACL, and PUT Bucket calls fail if the request includes a public ACL. */ blockPublicAcls?: boolean; /** * Whether Amazon S3 should block public bucket policies for buckets in this account. Defaults to `true`. Enabling this setting does not affect existing bucket policies. When set to `true`, Amazon S3 rejects calls to PUT Bucket policy if the specified bucket policy allows public access. */ blockPublicPolicy?: boolean; /** * Whether Amazon S3 should ignore public ACLs for buckets in this account. Defaults to `true`. Enabling this setting does not affect the persistence of any existing ACLs and doesn't prevent new public ACLs from being set. When set to `true`, Amazon S3 ignores all public ACLs on buckets in this account and any objects that they contain. */ ignorePublicAcls?: boolean; /** * Whether Amazon S3 should restrict public bucket policies for buckets in this account. Defaults to `true`. Enabling this setting does not affect previously stored bucket policies, except that public and cross-account access within any public bucket policy, including non-public delegation to specific accounts, is blocked. When set to `true`, only the bucket owner and AWS Services can access buckets with public policies. */ restrictPublicBuckets?: boolean; } interface AccessPointVpcConfiguration { /** * VPC ID from which the access point allows connections. */ vpcId: string; } interface AnalyticsConfigurationFilter { /** * Object prefix for filtering. */ prefix?: string; /** * Set of object tags for filtering. */ tags?: { [key: string]: string; }; } interface AnalyticsConfigurationStorageClassAnalysis { /** * Data export configuration (documented below). */ dataExport: outputs.s3.AnalyticsConfigurationStorageClassAnalysisDataExport; } interface AnalyticsConfigurationStorageClassAnalysisDataExport { /** * Destination for the exported analytics data (documented below). */ destination: outputs.s3.AnalyticsConfigurationStorageClassAnalysisDataExportDestination; /** * Schema version of exported analytics data. Allowed values: `V_1`. Default value: `V_1`. */ outputSchemaVersion?: string; } interface AnalyticsConfigurationStorageClassAnalysisDataExportDestination { /** * Analytics data export currently only supports an S3 bucket destination (documented below). */ s3BucketDestination: outputs.s3.AnalyticsConfigurationStorageClassAnalysisDataExportDestinationS3BucketDestination; } interface AnalyticsConfigurationStorageClassAnalysisDataExportDestinationS3BucketDestination { /** * Account ID that owns the destination bucket. */ bucketAccountId?: string; /** * ARN of the destination bucket. */ bucketArn: string; /** * Output format of exported analytics data. Allowed values: `CSV`. Default value: `CSV`. */ format?: string; /** * Prefix to append to exported analytics data. */ prefix?: string; } interface BucketAbacAbacStatus { /** * ABAC status of the general purpose bucket. Valid values are `Enabled` and `Disabled`. By default, ABAC is disabled for all Amazon S3 general purpose buckets. */ status: string; } interface BucketAclAccessControlPolicy { /** * Set of `grant` configuration blocks. See below. */ grants?: outputs.s3.BucketAclAccessControlPolicyGrant[]; /** * Configuration block for the bucket owner's display name and ID. See below. */ owner: outputs.s3.BucketAclAccessControlPolicyOwner; } interface BucketAclAccessControlPolicyGrant { /** * Configuration block for the person being granted permissions. See below. */ grantee?: outputs.s3.BucketAclAccessControlPolicyGrantGrantee; /** * Logging permissions assigned to the grantee for the bucket. Valid values: `FULL_CONTROL`, `WRITE`, `WRITE_ACP`, `READ`, `READ_ACP`. See [What permissions can I grant?](https://docs.aws.amazon.com/AmazonS3/latest/userguide/acl-overview.html#permissions) for more details about what each permission means in the context of buckets. */ permission: string; } interface BucketAclAccessControlPolicyGrantGrantee { /** * Display name of the owner. * * @deprecated display_name is deprecated. This attribute is no longer returned by AWS and will be removed in a future major version. */ displayName: string; /** * Email address of the grantee. See [Regions and Endpoints](https://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region) for supported AWS regions where this argument can be specified. */ emailAddress?: string; /** * Canonical user ID of the grantee. */ id?: string; /** * Type of grantee. Valid values: `CanonicalUser`, `AmazonCustomerByEmail`, `Group`. */ type: string; /** * URI of the grantee group. */ uri?: string; } interface BucketAclAccessControlPolicyOwner { /** * Display name of the owner. * * @deprecated display_name is deprecated. This attribute is no longer returned by AWS and will be removed in a future major version. */ displayName: string; /** * ID of the owner. */ id: string; } interface BucketAclV2AccessControlPolicy { /** * Set of `grant` configuration blocks. See below. */ grants?: outputs.s3.BucketAclV2AccessControlPolicyGrant[]; /** * Configuration block for the bucket owner's display name and ID. See below. */ owner: outputs.s3.BucketAclV2AccessControlPolicyOwner; } interface BucketAclV2AccessControlPolicyGrant { /** * Configuration block for the person being granted permissions. See below. */ grantee?: outputs.s3.BucketAclV2AccessControlPolicyGrantGrantee; /** * Logging permissions assigned to the grantee for the bucket. Valid values: `FULL_CONTROL`, `WRITE`, `WRITE_ACP`, `READ`, `READ_ACP`. See [What permissions can I grant?](https://docs.aws.amazon.com/AmazonS3/latest/userguide/acl-overview.html#permissions) for more details about what each permission means in the context of buckets. */ permission: string; } interface BucketAclV2AccessControlPolicyGrantGrantee { /** * Display name of the owner. * * @deprecated display_name is deprecated. This attribute is no longer returned by AWS and will be removed in a future major version. */ displayName: string; /** * Email address of the grantee. See [Regions and Endpoints](https://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region) for supported AWS regions where this argument can be specified. */ emailAddress?: string; /** * Canonical user ID of the grantee. */ id?: string; /** * Type of grantee. Valid values: `CanonicalUser`, `AmazonCustomerByEmail`, `Group`. */ type: string; /** * URI of the grantee group. */ uri?: string; } interface BucketAclV2AccessControlPolicyOwner { /** * Display name of the owner. * * @deprecated display_name is deprecated. This attribute is no longer returned by AWS and will be removed in a future major version. */ displayName: string; /** * ID of the owner. */ id: string; } interface BucketCorsConfigurationCorsRule { /** * Set of Headers that are specified in the `Access-Control-Request-Headers` header. */ allowedHeaders?: string[]; /** * Set of HTTP methods that you allow the origin to execute. Valid values are `GET`, `PUT`, `HEAD`, `POST`, and `DELETE`. */ allowedMethods: string[]; /** * Set of origins you want customers to be able to access the bucket from. */ allowedOrigins: string[]; /** * Set of headers in the response that you want customers to be able to access from their applications (for example, from a JavaScript `XMLHttpRequest` object). */ exposeHeaders?: string[]; /** * Unique identifier for the rule. The value cannot be longer than 255 characters. */ id?: string; /** * Time in seconds that your browser is to cache the preflight response for the specified resource. */ maxAgeSeconds?: number; } interface BucketCorsConfigurationV2CorsRule { /** * Set of Headers that are specified in the `Access-Control-Request-Headers` header. */ allowedHeaders?: string[]; /** * Set of HTTP methods that you allow the origin to execute. Valid values are `GET`, `PUT`, `HEAD`, `POST`, and `DELETE`. */ allowedMethods: string[]; /** * Set of origins you want customers to be able to access the bucket from. */ allowedOrigins: string[]; /** * Set of headers in the response that you want customers to be able to access from their applications (for example, from a JavaScript `XMLHttpRequest` object). */ exposeHeaders?: string[]; /** * Unique identifier for the rule. The value cannot be longer than 255 characters. */ id?: string; /** * Time in seconds that your browser is to cache the preflight response for the specified resource. */ maxAgeSeconds?: number; } interface BucketCorsRule { /** * List of headers allowed. */ allowedHeaders?: string[]; /** * One or more HTTP methods that you allow the origin to execute. Can be `GET`, `PUT`, `POST`, `DELETE` or `HEAD`. */ allowedMethods: string[]; /** * One or more origins you want customers to be able to access the bucket from. */ allowedOrigins: string[]; /** * One or more headers in the response that you want customers to be able to access from their applications (for example, from a JavaScript `XMLHttpRequest` object). */ exposeHeaders?: string[]; /** * Time in seconds that browser can cache the response for a preflight request. */ maxAgeSeconds?: number; } interface BucketGrant { /** * Canonical user id to grant for. Used only when `type` is `CanonicalUser`. */ id?: string; /** * List of permissions to apply for grantee. Valid values are `READ`, `WRITE`, `READ_ACP`, `WRITE_ACP`, `FULL_CONTROL`. */ permissions: string[]; /** * Type of grantee to apply for. Valid values are `CanonicalUser` and `Group`. `AmazonCustomerByEmail` is not supported. */ type: string; /** * Uri address to grant for. Used only when `type` is `Group`. */ uri?: string; } interface BucketIntelligentTieringConfigurationFilter { /** * Object key name prefix that identifies the subset of objects to which the configuration applies. */ prefix?: string; /** * All of these tags must exist in the object's tag set in order for the configuration to apply. */ tags?: { [key: string]: string; }; } interface BucketIntelligentTieringConfigurationTiering { /** * S3 Intelligent-Tiering access tier. Valid values: `ARCHIVE_ACCESS`, `DEEP_ARCHIVE_ACCESS`. */ accessTier: string; /** * Number of consecutive days of no access after which an object will be eligible to be transitioned to the corresponding tier. */ days: number; } interface BucketLifecycleConfigurationRule { /** * Configuration block that specifies the days since the initiation of an incomplete multipart upload that Amazon S3 will wait before permanently removing all parts of the upload. See below. */ abortIncompleteMultipartUpload?: outputs.s3.BucketLifecycleConfigurationRuleAbortIncompleteMultipartUpload; /** * Configuration block that specifies the expiration for the lifecycle of the object in the form of date, days and, whether the object has a delete marker. See below. */ expiration?: outputs.s3.BucketLifecycleConfigurationRuleExpiration; /** * Configuration block used to identify objects that a Lifecycle Rule applies to. See below. */ filter?: outputs.s3.BucketLifecycleConfigurationRuleFilter; /** * Unique identifier for the rule. The value cannot be longer than 255 characters. */ id: string; /** * Configuration block that specifies when noncurrent object versions expire. See below. */ noncurrentVersionExpiration?: outputs.s3.BucketLifecycleConfigurationRuleNoncurrentVersionExpiration; /** * Set of configuration blocks that specify the transition rule for the lifecycle rule that describes when noncurrent objects transition to a specific storage class. See below. */ noncurrentVersionTransitions?: outputs.s3.BucketLifecycleConfigurationRuleNoncurrentVersionTransition[]; /** * Prefix identifying one or more objects to which the rule applies. Use `filter` instead, as this has been deprecated by Amazon S3. * * @deprecated Specify a prefix using 'filter' instead */ prefix: string; /** * Whether the rule is currently being applied. Valid values: `Enabled` or `Disabled`. */ status: string; /** * Set of configuration blocks that specify when an Amazon S3 object transitions to a specified storage class. See below. */ transitions?: outputs.s3.BucketLifecycleConfigurationRuleTransition[]; } interface BucketLifecycleConfigurationRuleAbortIncompleteMultipartUpload { /** * Number of days after which Amazon S3 aborts an incomplete multipart upload. */ daysAfterInitiation?: number; } interface BucketLifecycleConfigurationRuleExpiration { /** * Date the object is to be moved or deleted. The date value must be in [RFC3339 full-date format](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6) e.g. `2023-08-22`. */ date?: string; /** * Lifetime, in days, of the objects that are subject to the rule. The value must be a non-zero positive integer. */ days: number; /** * Whether Amazon S3 will remove a delete marker with no noncurrent versions. If set to `true`, the delete marker will be expired; if set to `false` the policy takes no action. */ expiredObjectDeleteMarker: boolean; } interface BucketLifecycleConfigurationRuleFilter { /** * Configuration block used to apply a logical `AND` to two or more predicates. See below. The Lifecycle Rule will apply to any object matching all the predicates configured inside the `and` block. */ and?: outputs.s3.BucketLifecycleConfigurationRuleFilterAnd; /** * Minimum object size (in bytes) to which the rule applies. */ objectSizeGreaterThan: number; /** * Maximum object size (in bytes) to which the rule applies. */ objectSizeLessThan: number; /** * Prefix identifying one or more objects to which the rule applies. Defaults to an empty string (`""`) if not specified. */ prefix: string; /** * Configuration block for specifying a tag key and value. See below. */ tag?: outputs.s3.BucketLifecycleConfigurationRuleFilterTag; } interface BucketLifecycleConfigurationRuleFilterAnd { /** * Minimum object size to which the rule applies. Value must be at least `0` if specified. Defaults to 128000 (128 KB) for all `storageClass` values unless `transitionDefaultMinimumObjectSize` specifies otherwise. */ objectSizeGreaterThan: number; /** * Maximum object size to which the rule applies. Value must be at least `1` if specified. */ objectSizeLessThan: number; /** * Prefix identifying one or more objects to which the rule applies. */ prefix: string; /** * Key-value map of resource tags. All of these tags must exist in the object's tag set in order for the rule to apply. If set, must contain at least one key-value pair. */ tags?: { [key: string]: string; }; } interface BucketLifecycleConfigurationRuleFilterTag { /** * Name of the object key. */ key: string; /** * Value of the tag. */ value: string; } interface BucketLifecycleConfigurationRuleNoncurrentVersionExpiration { /** * Number of noncurrent versions Amazon S3 will retain. Must be a non-zero positive integer. */ newerNoncurrentVersions?: number; /** * Number of days an object is noncurrent before Amazon S3 can perform the associated action. Must be a positive integer. */ noncurrentDays: number; } interface BucketLifecycleConfigurationRuleNoncurrentVersionTransition { /** * Number of noncurrent versions Amazon S3 will retain. Must be a non-zero positive integer. */ newerNoncurrentVersions?: number; /** * Number of days an object is noncurrent before Amazon S3 can perform the associated action. */ noncurrentDays: number; /** * Class of storage used to store the object. Valid Values: `GLACIER`, `STANDARD_IA`, `ONEZONE_IA`, `INTELLIGENT_TIERING`, `DEEP_ARCHIVE`, `GLACIER_IR`. */ storageClass: string; } interface BucketLifecycleConfigurationRuleTransition { /** * Date objects are transitioned to the specified storage class. The date value must be in [RFC3339 full-date format](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6) e.g. `2023-08-22`. */ date?: string; /** * Number of days after creation when objects are transitioned to the specified storage class. The value must be a positive integer. If both `days` and `date` are not specified, defaults to `0`. Valid values depend on `storageClass`, see [Transition objects using Amazon S3 Lifecycle](https://docs.aws.amazon.com/AmazonS3/latest/userguide/lifecycle-transition-general-considerations.html) for more details. */ days: number; /** * Class of storage used to store the object. Valid Values: `GLACIER`, `STANDARD_IA`, `ONEZONE_IA`, `INTELLIGENT_TIERING`, `DEEP_ARCHIVE`, `GLACIER_IR`. */ storageClass: string; } interface BucketLifecycleConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface BucketLifecycleConfigurationV2Rule { /** * Configuration block that specifies the days since the initiation of an incomplete multipart upload that Amazon S3 will wait before permanently removing all parts of the upload. See below. */ abortIncompleteMultipartUpload?: outputs.s3.BucketLifecycleConfigurationV2RuleAbortIncompleteMultipartUpload; /** * Configuration block that specifies the expiration for the lifecycle of the object in the form of date, days and, whether the object has a delete marker. See below. */ expiration?: outputs.s3.BucketLifecycleConfigurationV2RuleExpiration; /** * Configuration block used to identify objects that a Lifecycle Rule applies to. See below. */ filter?: outputs.s3.BucketLifecycleConfigurationV2RuleFilter; /** * Unique identifier for the rule. The value cannot be longer than 255 characters. */ id: string; /** * Configuration block that specifies when noncurrent object versions expire. See below. */ noncurrentVersionExpiration?: outputs.s3.BucketLifecycleConfigurationV2RuleNoncurrentVersionExpiration; /** * Set of configuration blocks that specify the transition rule for the lifecycle rule that describes when noncurrent objects transition to a specific storage class. See below. */ noncurrentVersionTransitions?: outputs.s3.BucketLifecycleConfigurationV2RuleNoncurrentVersionTransition[]; /** * Prefix identifying one or more objects to which the rule applies. Use `filter` instead, as this has been deprecated by Amazon S3. * * @deprecated Specify a prefix using 'filter' instead */ prefix: string; /** * Whether the rule is currently being applied. Valid values: `Enabled` or `Disabled`. */ status: string; /** * Set of configuration blocks that specify when an Amazon S3 object transitions to a specified storage class. See below. */ transitions?: outputs.s3.BucketLifecycleConfigurationV2RuleTransition[]; } interface BucketLifecycleConfigurationV2RuleAbortIncompleteMultipartUpload { /** * Number of days after which Amazon S3 aborts an incomplete multipart upload. */ daysAfterInitiation?: number; } interface BucketLifecycleConfigurationV2RuleExpiration { /** * Date the object is to be moved or deleted. The date value must be in [RFC3339 full-date format](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6) e.g. `2023-08-22`. */ date?: string; /** * Lifetime, in days, of the objects that are subject to the rule. The value must be a non-zero positive integer. */ days: number; /** * Whether Amazon S3 will remove a delete marker with no noncurrent versions. If set to `true`, the delete marker will be expired; if set to `false` the policy takes no action. */ expiredObjectDeleteMarker: boolean; } interface BucketLifecycleConfigurationV2RuleFilter { /** * Configuration block used to apply a logical `AND` to two or more predicates. See below. The Lifecycle Rule will apply to any object matching all the predicates configured inside the `and` block. */ and?: outputs.s3.BucketLifecycleConfigurationV2RuleFilterAnd; /** * Minimum object size (in bytes) to which the rule applies. */ objectSizeGreaterThan: number; /** * Maximum object size (in bytes) to which the rule applies. */ objectSizeLessThan: number; /** * Prefix identifying one or more objects to which the rule applies. Defaults to an empty string (`""`) if not specified. */ prefix: string; /** * Configuration block for specifying a tag key and value. See below. */ tag?: outputs.s3.BucketLifecycleConfigurationV2RuleFilterTag; } interface BucketLifecycleConfigurationV2RuleFilterAnd { /** * Minimum object size to which the rule applies. Value must be at least `0` if specified. Defaults to 128000 (128 KB) for all `storageClass` values unless `transitionDefaultMinimumObjectSize` specifies otherwise. */ objectSizeGreaterThan: number; /** * Maximum object size to which the rule applies. Value must be at least `1` if specified. */ objectSizeLessThan: number; /** * Prefix identifying one or more objects to which the rule applies. */ prefix: string; /** * Key-value map of resource tags. All of these tags must exist in the object's tag set in order for the rule to apply. If set, must contain at least one key-value pair. */ tags?: { [key: string]: string; }; } interface BucketLifecycleConfigurationV2RuleFilterTag { /** * Name of the object key. */ key: string; /** * Value of the tag. */ value: string; } interface BucketLifecycleConfigurationV2RuleNoncurrentVersionExpiration { /** * Number of noncurrent versions Amazon S3 will retain. Must be a non-zero positive integer. */ newerNoncurrentVersions?: number; /** * Number of days an object is noncurrent before Amazon S3 can perform the associated action. Must be a positive integer. */ noncurrentDays: number; } interface BucketLifecycleConfigurationV2RuleNoncurrentVersionTransition { /** * Number of noncurrent versions Amazon S3 will retain. Must be a non-zero positive integer. */ newerNoncurrentVersions?: number; /** * Number of days an object is noncurrent before Amazon S3 can perform the associated action. */ noncurrentDays: number; /** * Class of storage used to store the object. Valid Values: `GLACIER`, `STANDARD_IA`, `ONEZONE_IA`, `INTELLIGENT_TIERING`, `DEEP_ARCHIVE`, `GLACIER_IR`. */ storageClass: string; } interface BucketLifecycleConfigurationV2RuleTransition { /** * Date objects are transitioned to the specified storage class. The date value must be in [RFC3339 full-date format](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6) e.g. `2023-08-22`. */ date?: string; /** * Number of days after creation when objects are transitioned to the specified storage class. The value must be a positive integer. If both `days` and `date` are not specified, defaults to `0`. Valid values depend on `storageClass`, see [Transition objects using Amazon S3 Lifecycle](https://docs.aws.amazon.com/AmazonS3/latest/userguide/lifecycle-transition-general-considerations.html) for more details. */ days: number; /** * Class of storage used to store the object. Valid Values: `GLACIER`, `STANDARD_IA`, `ONEZONE_IA`, `INTELLIGENT_TIERING`, `DEEP_ARCHIVE`, `GLACIER_IR`. */ storageClass: string; } interface BucketLifecycleConfigurationV2Timeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface BucketLifecycleRule { /** * Number of days after initiating a multipart upload when the multipart upload must be completed. */ abortIncompleteMultipartUploadDays?: number; /** * Lifecycle rule status. */ enabled: boolean; /** * Configuration of the object expiration. See `expiration` Block below for details. */ expiration?: outputs.s3.BucketLifecycleRuleExpiration; /** * Unique identifier for the rule. Must be less than or equal to 255 characters in length. */ id: string; /** * When noncurrent object versions expire. See `noncurrentVersionExpiration` Block below for details. */ noncurrentVersionExpiration?: outputs.s3.BucketLifecycleRuleNoncurrentVersionExpiration; /** * When noncurrent object versions transition. See `noncurrentVersionTransition` Block below for details. */ noncurrentVersionTransitions?: outputs.s3.BucketLifecycleRuleNoncurrentVersionTransition[]; /** * Object key prefix identifying one or more objects to which the rule applies. */ prefix?: string; /** * Object tags key and value. */ tags?: { [key: string]: string; }; /** * Configuration of the object transition. See `transition` Block below for details. */ transitions?: outputs.s3.BucketLifecycleRuleTransition[]; } interface BucketLifecycleRuleExpiration { /** * Date after which you want the corresponding action to take effect. */ date?: string; /** * Number of days after object creation when the specific rule action takes effect. */ days?: number; /** * On a versioned bucket (versioning-enabled or versioning-suspended bucket), you can add this element in the lifecycle configuration to direct Amazon S3 to delete expired object delete markers. This cannot be specified with Days or Date in a Lifecycle Expiration Policy. */ expiredObjectDeleteMarker?: boolean; } interface BucketLifecycleRuleNoncurrentVersionExpiration { /** * Number of days noncurrent object versions expire. */ days?: number; } interface BucketLifecycleRuleNoncurrentVersionTransition { /** * Number of days noncurrent object versions transition. */ days?: number; /** * Amazon S3 [storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Transition.html#AmazonS3-Type-Transition-StorageClass) to which you want the object to transition. */ storageClass: string; } interface BucketLifecycleRuleTransition { /** * Date after which you want the corresponding action to take effect. */ date?: string; /** * Number of days after object creation when the specific rule action takes effect. */ days?: number; /** * Amazon S3 [storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Transition.html#AmazonS3-Type-Transition-StorageClass) to which you want the object to transition. */ storageClass: string; } interface BucketLogging { /** * Name of the bucket that will receive the log objects. */ targetBucket: string; /** * To specify a key prefix for log objects. */ targetPrefix?: string; } interface BucketLoggingTargetGrant { /** * Configuration block for the person being granted permissions. See below. */ grantee: outputs.s3.BucketLoggingTargetGrantGrantee; /** * Logging permissions assigned to the grantee for the bucket. Valid values: `FULL_CONTROL`, `READ`, `WRITE`. */ permission: string; } interface BucketLoggingTargetGrantGrantee { /** * @deprecated display_name is deprecated. This attribute is no longer returned by AWS and will be removed in a future major version. */ displayName: string; /** * Email address of the grantee. See [Regions and Endpoints](https://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region) for supported AWS regions where this argument can be specified. */ emailAddress?: string; /** * Canonical user ID of the grantee. */ id?: string; /** * Type of grantee. Valid values: `CanonicalUser`, `AmazonCustomerByEmail`, `Group`. */ type: string; /** * URI of the grantee group. */ uri?: string; } interface BucketLoggingTargetObjectKeyFormat { /** * Partitioned S3 key for log objects, in the form `[targetPrefix][SourceAccountId]/[SourceRegion]/[SourceBucket]/[YYYY]/[MM]/[DD]/[YYYY]-[MM]-[DD]-[hh]-[mm]-[ss]-[UniqueString]`. Conflicts with `simplePrefix`. See below. */ partitionedPrefix?: outputs.s3.BucketLoggingTargetObjectKeyFormatPartitionedPrefix; /** * Use the simple format for S3 keys for log objects, in the form `[targetPrefix][YYYY]-[MM]-[DD]-[hh]-[mm]-[ss]-[UniqueString]`. To use, set `simplePrefix {}`. Conflicts with `partitionedPrefix`. */ simplePrefix?: outputs.s3.BucketLoggingTargetObjectKeyFormatSimplePrefix; } interface BucketLoggingTargetObjectKeyFormatPartitionedPrefix { /** * Partition date source for the partitioned prefix. Valid values: `EventTime`, `DeliveryTime`. */ partitionDateSource: string; } interface BucketLoggingTargetObjectKeyFormatSimplePrefix { } interface BucketLoggingV2TargetGrant { /** * Configuration block for the person being granted permissions. See below. */ grantee: outputs.s3.BucketLoggingV2TargetGrantGrantee; /** * Logging permissions assigned to the grantee for the bucket. Valid values: `FULL_CONTROL`, `READ`, `WRITE`. */ permission: string; } interface BucketLoggingV2TargetGrantGrantee { /** * @deprecated display_name is deprecated. This attribute is no longer returned by AWS and will be removed in a future major version. */ displayName: string; /** * Email address of the grantee. See [Regions and Endpoints](https://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region) for supported AWS regions where this argument can be specified. */ emailAddress?: string; /** * Canonical user ID of the grantee. */ id?: string; /** * Type of grantee. Valid values: `CanonicalUser`, `AmazonCustomerByEmail`, `Group`. */ type: string; /** * URI of the grantee group. */ uri?: string; } interface BucketLoggingV2TargetObjectKeyFormat { /** * Partitioned S3 key for log objects, in the form `[targetPrefix][SourceAccountId]/[SourceRegion]/[SourceBucket]/[YYYY]/[MM]/[DD]/[YYYY]-[MM]-[DD]-[hh]-[mm]-[ss]-[UniqueString]`. Conflicts with `simplePrefix`. See below. */ partitionedPrefix?: outputs.s3.BucketLoggingV2TargetObjectKeyFormatPartitionedPrefix; /** * Use the simple format for S3 keys for log objects, in the form `[targetPrefix][YYYY]-[MM]-[DD]-[hh]-[mm]-[ss]-[UniqueString]`. To use, set `simplePrefix {}`. Conflicts with `partitionedPrefix`. */ simplePrefix?: outputs.s3.BucketLoggingV2TargetObjectKeyFormatSimplePrefix; } interface BucketLoggingV2TargetObjectKeyFormatPartitionedPrefix { /** * Partition date source for the partitioned prefix. Valid values: `EventTime`, `DeliveryTime`. */ partitionDateSource: string; } interface BucketLoggingV2TargetObjectKeyFormatSimplePrefix { } interface BucketMetadataConfigurationMetadataConfiguration { /** * Destination information for the S3 Metadata configuration. See `destination` Block for details. */ destinations: outputs.s3.BucketMetadataConfigurationMetadataConfigurationDestination[]; /** * Inventory table configuration. See `inventoryTableConfiguration` Block for details. */ inventoryTableConfiguration: outputs.s3.BucketMetadataConfigurationMetadataConfigurationInventoryTableConfiguration; /** * Journal table configuration. See `journalTableConfiguration` Block for details. */ journalTableConfiguration: outputs.s3.BucketMetadataConfigurationMetadataConfigurationJournalTableConfiguration; } interface BucketMetadataConfigurationMetadataConfigurationDestination { /** * ARN of the table bucket where the metadata configuration is stored. */ tableBucketArn: string; /** * Type of the table bucket where the metadata configuration is stored. */ tableBucketType: string; /** * Namespace in the table bucket where the metadata tables for the metadata configuration are stored. */ tableNamespace: string; } interface BucketMetadataConfigurationMetadataConfigurationInventoryTableConfiguration { /** * Configuration state of the inventory table, indicating whether the inventory table is enabled or disabled. Valid values: `ENABLED`, `DISABLED`. */ configurationState: string; /** * Encryption configuration for the inventory table. See `encryptionConfiguration` Block for details. */ encryptionConfiguration?: outputs.s3.BucketMetadataConfigurationMetadataConfigurationInventoryTableConfigurationEncryptionConfiguration; /** * Journal table ARN. */ tableArn: string; /** * Journal table name. */ tableName: string; } interface BucketMetadataConfigurationMetadataConfigurationInventoryTableConfigurationEncryptionConfiguration { /** * KMS key ARN when `sseAlgorithm` is `aws:kms`. */ kmsKeyArn?: string; /** * Encryption type for the metadata table. Valid values: `aws:kms`, `AES256`. */ sseAlgorithm: string; } interface BucketMetadataConfigurationMetadataConfigurationJournalTableConfiguration { /** * Encryption configuration for the journal table. See `encryptionConfiguration` Block for details. */ encryptionConfiguration?: outputs.s3.BucketMetadataConfigurationMetadataConfigurationJournalTableConfigurationEncryptionConfiguration; /** * Journal table record expiration settings. See `recordExpiration` Block for details. */ recordExpiration: outputs.s3.BucketMetadataConfigurationMetadataConfigurationJournalTableConfigurationRecordExpiration; /** * Journal table ARN. */ tableArn: string; /** * Journal table name. */ tableName: string; } interface BucketMetadataConfigurationMetadataConfigurationJournalTableConfigurationEncryptionConfiguration { /** * KMS key ARN when `sseAlgorithm` is `aws:kms`. */ kmsKeyArn?: string; /** * Encryption type for the metadata table. Valid values: `aws:kms`, `AES256`. */ sseAlgorithm: string; } interface BucketMetadataConfigurationMetadataConfigurationJournalTableConfigurationRecordExpiration { /** * Number of days to retain journal table records. */ days?: number; /** * Whether journal table record expiration is enabled or disabled. Valid values: `ENABLED`, `DISABLED`. */ expiration: string; } interface BucketMetadataConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface BucketMetricFilter { /** * S3 Access Point ARN for filtering (singular). */ accessPoint?: string; /** * Object prefix for filtering (singular). */ prefix?: string; /** * Object tags for filtering (up to 10). Unsupported for S3 directory buckets. */ tags?: { [key: string]: string; }; } interface BucketNotificationLambdaFunction { /** * [Event](http://docs.aws.amazon.com/AmazonS3/latest/dev/NotificationHowTo.html#notification-how-to-event-types-and-destinations) for which to send notifications. */ events: string[]; /** * Object key name prefix. */ filterPrefix?: string; /** * Object key name suffix. */ filterSuffix?: string; /** * Unique identifier for each of the notification configurations. */ id: string; /** * Lambda function ARN. */ lambdaFunctionArn?: string; } interface BucketNotificationQueue { /** * [Event](http://docs.aws.amazon.com/AmazonS3/latest/dev/NotificationHowTo.html#notification-how-to-event-types-and-destinations) for which to send notifications. */ events: string[]; /** * Object key name prefix. */ filterPrefix?: string; /** * Object key name suffix. */ filterSuffix?: string; /** * Unique identifier for each of the notification configurations. */ id: string; /** * SQS queue ARN. */ queueArn: string; } interface BucketNotificationTopic { /** * [Event](http://docs.aws.amazon.com/AmazonS3/latest/dev/NotificationHowTo.html#notification-how-to-event-types-and-destinations) for which to send notifications. */ events: string[]; /** * Object key name prefix. */ filterPrefix?: string; /** * Object key name suffix. */ filterSuffix?: string; /** * Unique identifier for each of the notification configurations. */ id: string; /** * SNS topic ARN. */ topicArn: string; } interface BucketObjectLockConfiguration { /** * Whether this bucket has an Object Lock configuration enabled. Valid value is `Enabled`. Use the top-level argument `objectLockEnabled` instead. * * @deprecated object_lock_enabled is deprecated. Use the top-level parameter objectLockEnabled instead. */ objectLockEnabled?: string; /** * Object Lock rule in place for this bucket. See `object_lock_configuration.rule` Block below for details. * * @deprecated rule is deprecated. Use the aws.s3.BucketObjectLockConfiguration resource instead. */ rule?: outputs.s3.BucketObjectLockConfigurationRule; } interface BucketObjectLockConfigurationRule { /** * Configuration block for specifying the default Object Lock retention settings for new objects placed in the specified bucket. See below. */ defaultRetention: outputs.s3.BucketObjectLockConfigurationRuleDefaultRetention; } interface BucketObjectLockConfigurationRuleDefaultRetention { /** * Number of days that you want to specify for the default retention period. */ days?: number; /** * Default Object Lock retention mode you want to apply to new objects placed in the specified bucket. Valid values: `COMPLIANCE`, `GOVERNANCE`. */ mode?: string; /** * Number of years that you want to specify for the default retention period. */ years?: number; } interface BucketObjectLockConfigurationV2Rule { /** * Configuration block for specifying the default Object Lock retention settings for new objects placed in the specified bucket. See below. */ defaultRetention: outputs.s3.BucketObjectLockConfigurationV2RuleDefaultRetention; } interface BucketObjectLockConfigurationV2RuleDefaultRetention { /** * Number of days that you want to specify for the default retention period. */ days?: number; /** * Default Object Lock retention mode you want to apply to new objects placed in the specified bucket. Valid values: `COMPLIANCE`, `GOVERNANCE`. */ mode?: string; /** * Number of years that you want to specify for the default retention period. */ years?: number; } interface BucketObjectv2OverrideProvider { /** * Override the provider `defaultTags` configuration block. See `defaultTags` Block below for more details. */ defaultTags?: outputs.s3.BucketObjectv2OverrideProviderDefaultTags; } interface BucketObjectv2OverrideProviderDefaultTags { /** * Map of tags to override the provider-level `defaultTags`. Must be an empty map to suppress all provider-level `defaultTags`. */ tags?: { [key: string]: string; }; } interface BucketOwnershipControlsRule { /** * Object ownership. Valid values: `BucketOwnerPreferred`, `ObjectWriter` or `BucketOwnerEnforced`. `BucketOwnerPreferred` means objects uploaded to the bucket change ownership to the bucket owner if the objects are uploaded with the `bucket-owner-full-control` canned ACL. `ObjectWriter` means the uploading account will own the object if the object is uploaded with the `bucket-owner-full-control` canned ACL. `BucketOwnerEnforced` means the bucket owner automatically owns and has full control over every object in the bucket, and ACLs no longer affect permissions to data in the S3 bucket. */ objectOwnership: string; } interface BucketReplicationConfigRule { /** * Whether delete markers are replicated. This argument is only valid with V2 replication configurations (i.e., when `filter` is used)documented below. */ deleteMarkerReplication?: outputs.s3.BucketReplicationConfigRuleDeleteMarkerReplication; /** * Destination for the rule. See below. */ destination: outputs.s3.BucketReplicationConfigRuleDestination; /** * Replicate existing objects in the source bucket according to the rule configurations. See below. */ existingObjectReplication?: outputs.s3.BucketReplicationConfigRuleExistingObjectReplication; /** * Filter that identifies subset of objects to which the replication rule applies. See below. If not specified, the `rule` will default to using `prefix`. */ filter?: outputs.s3.BucketReplicationConfigRuleFilter; /** * Unique identifier for the rule. Must be less than or equal to 255 characters in length. */ id: string; /** * Object key name prefix identifying one or more objects to which the rule applies. Must be less than or equal to 1024 characters in length. Defaults to an empty string (`""`) if `filter` is not specified. * * @deprecated prefix is deprecated. Use filter instead. */ prefix?: string; /** * Priority associated with the rule. Priority should only be set if `filter` is configured. If not provided, defaults to `0`. Priority must be unique between multiple rules. */ priority?: number; /** * Special object selection criteria. See below. */ sourceSelectionCriteria?: outputs.s3.BucketReplicationConfigRuleSourceSelectionCriteria; /** * Status of the rule. Either `"Enabled"` or `"Disabled"`. The rule is ignored if status is not "Enabled". */ status: string; } interface BucketReplicationConfigRuleDeleteMarkerReplication { /** * Whether delete markers should be replicated. Either `"Enabled"` or `"Disabled"`. */ status: string; } interface BucketReplicationConfigRuleDestination { /** * Configuration block that specifies the overrides to use for object owners on replication. See below. Specify this only in a cross-account scenario (where source and destination bucket owners are not the same), and you want to change replica ownership to the AWS account that owns the destination bucket. If this is not specified in the replication configuration, the replicas are owned by same AWS account that owns the source object. Must be used in conjunction with `account` owner override configuration. */ accessControlTranslation?: outputs.s3.BucketReplicationConfigRuleDestinationAccessControlTranslation; /** * Account ID to specify the replica ownership. Must be used in conjunction with `accessControlTranslation` override configuration. */ account?: string; /** * ARN of the bucket where you want Amazon S3 to store the results. */ bucket: string; /** * Configuration block that provides information about encryption. See below. If `sourceSelectionCriteria` is specified, you must specify this element. */ encryptionConfiguration?: outputs.s3.BucketReplicationConfigRuleDestinationEncryptionConfiguration; /** * Configuration block that specifies replication metrics-related settings enabling replication metrics and events. See below. */ metrics?: outputs.s3.BucketReplicationConfigRuleDestinationMetrics; /** * Configuration block that specifies S3 Replication Time Control (S3 RTC), including whether S3 RTC is enabled and the time when all objects and operations on objects must be replicated. See below. Replication Time Control must be used in conjunction with `metrics`. */ replicationTime?: outputs.s3.BucketReplicationConfigRuleDestinationReplicationTime; /** * [Storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Destination.html#AmazonS3-Type-Destination-StorageClass) used to store the object. By default, Amazon S3 uses the storage class of the source object to create the object replica. */ storageClass?: string; } interface BucketReplicationConfigRuleDestinationAccessControlTranslation { /** * Replica ownership. For default and valid values, see [PUT bucket replication](https://docs.aws.amazon.com/AmazonS3/latest/API/RESTBucketPUTreplication.html) in the Amazon S3 API Reference. Valid values: `Destination`. */ owner: string; } interface BucketReplicationConfigRuleDestinationEncryptionConfiguration { /** * ID (Key ARN or Alias ARN) of the customer managed AWS KMS key stored in KMS for the destination bucket. */ replicaKmsKeyId: string; } interface BucketReplicationConfigRuleDestinationMetrics { /** * Configuration block that specifies the time threshold for emitting the `s3:Replication:OperationMissedThreshold` event. See below. */ eventThreshold?: outputs.s3.BucketReplicationConfigRuleDestinationMetricsEventThreshold; /** * Status of the Destination Metrics. Either `"Enabled"` or `"Disabled"`. */ status: string; } interface BucketReplicationConfigRuleDestinationMetricsEventThreshold { /** * Time in minutes. Valid values: `15`. */ minutes: number; } interface BucketReplicationConfigRuleDestinationReplicationTime { /** * Status of the Replication Time Control. Either `"Enabled"` or `"Disabled"`. */ status: string; /** * Configuration block specifying the time by which replication should be complete for all objects and operations on objects. See below. */ time: outputs.s3.BucketReplicationConfigRuleDestinationReplicationTimeTime; } interface BucketReplicationConfigRuleDestinationReplicationTimeTime { /** * Time in minutes. Valid values: `15`. */ minutes: number; } interface BucketReplicationConfigRuleExistingObjectReplication { /** * Whether the existing objects should be replicated. Either `"Enabled"` or `"Disabled"`. */ status: string; } interface BucketReplicationConfigRuleFilter { /** * Configuration block for specifying rule filters. This element is required only if you specify more than one filter. See and below for more details. */ and?: outputs.s3.BucketReplicationConfigRuleFilterAnd; /** * Object key name prefix that identifies subset of objects to which the rule applies. Must be less than or equal to 1024 characters in length. */ prefix?: string; /** * Configuration block for specifying a tag key and value. See below. */ tag?: outputs.s3.BucketReplicationConfigRuleFilterTag; } interface BucketReplicationConfigRuleFilterAnd { /** * Object key name prefix that identifies subset of objects to which the rule applies. Must be less than or equal to 1024 characters in length. */ prefix?: string; /** * Map of tags (key and value pairs) that identifies a subset of objects to which the rule applies. The rule applies only to objects having all the tags in its tagset. */ tags?: { [key: string]: string; }; } interface BucketReplicationConfigRuleFilterTag { /** * Name of the object key. */ key: string; /** * Value of the tag. */ value: string; } interface BucketReplicationConfigRuleSourceSelectionCriteria { /** * Configuration block that you can specify for selections for modifications on replicas. Amazon S3 doesn't replicate replica modifications by default. In the latest version of replication configuration (when `filter` is specified), you can specify this element and set the status to `Enabled` to replicate modifications on replicas. */ replicaModifications?: outputs.s3.BucketReplicationConfigRuleSourceSelectionCriteriaReplicaModifications; /** * Configuration block for filter information for the selection of Amazon S3 objects encrypted with AWS KMS. If specified, `replicaKmsKeyId` in `destination` `encryptionConfiguration` must be specified as well. */ sseKmsEncryptedObjects?: outputs.s3.BucketReplicationConfigRuleSourceSelectionCriteriaSseKmsEncryptedObjects; } interface BucketReplicationConfigRuleSourceSelectionCriteriaReplicaModifications { /** * Whether the existing objects should be replicated. Either `"Enabled"` or `"Disabled"`. */ status: string; } interface BucketReplicationConfigRuleSourceSelectionCriteriaSseKmsEncryptedObjects { /** * Whether the existing objects should be replicated. Either `"Enabled"` or `"Disabled"`. */ status: string; } interface BucketReplicationConfiguration { /** * ARN of the IAM role for Amazon S3 to assume when replicating the objects. */ role: string; /** * Rules managing the replication. See `rules` Block below for details. */ rules: outputs.s3.BucketReplicationConfigurationRule[]; } interface BucketReplicationConfigurationRule { /** * Whether delete markers are replicated. The only valid value is `Enabled`. To disable, omit this argument. This argument is only valid with V2 replication configurations (i.e., when `filter` is used). */ deleteMarkerReplicationStatus?: string; /** * Destination for the rule. See `destination` Block below for details. */ destination: outputs.s3.BucketReplicationConfigurationRuleDestination; /** * Filter that identifies subset of objects to which the replication rule applies. See `filter` Block below for details. */ filter?: outputs.s3.BucketReplicationConfigurationRuleFilter; /** * Unique identifier for the rule. Must be less than or equal to 255 characters in length. */ id?: string; /** * Object keyname prefix identifying one or more objects to which the rule applies. Must be less than or equal to 1024 characters in length. */ prefix?: string; /** * Priority associated with the rule. Priority should only be set if `filter` is configured. If not provided, defaults to `0`. Priority must be unique between multiple rules. */ priority?: number; /** * Special object selection criteria. See `sourceSelectionCriteria` Block below for details. */ sourceSelectionCriteria?: outputs.s3.BucketReplicationConfigurationRuleSourceSelectionCriteria; /** * Status of the rule. Either `Enabled` or `Disabled`. The rule is ignored if status is not Enabled. */ status: string; } interface BucketReplicationConfigurationRuleDestination { /** * Overrides to use for object owners on replication. See `accessControlTranslation` Block below for details. Must be used in conjunction with `accountId` owner override configuration. */ accessControlTranslation?: outputs.s3.BucketReplicationConfigurationRuleDestinationAccessControlTranslation; /** * Account ID to use for overriding the object owner on replication. Must be used in conjunction with `accessControlTranslation` override configuration. */ accountId?: string; /** * ARN of the S3 bucket where you want Amazon S3 to store replicas of the object identified by the rule. */ bucket: string; /** * Enables replication metrics (required for S3 RTC). See `metrics` Block below for details. */ metrics?: outputs.s3.BucketReplicationConfigurationRuleDestinationMetrics; /** * Destination KMS encryption key ARN for SSE-KMS replication. Must be used in conjunction with `sseKmsEncryptedObjects` source selection criteria. */ replicaKmsKeyId?: string; /** * Enables S3 Replication Time Control (S3 RTC). See `replicationTime` Block below for details. */ replicationTime?: outputs.s3.BucketReplicationConfigurationRuleDestinationReplicationTime; /** * [Storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Destination.html#AmazonS3-Type-Destination-StorageClass) used to store the object. By default, Amazon S3 uses the storage class of the source object to create the object replica. */ storageClass?: string; } interface BucketReplicationConfigurationRuleDestinationAccessControlTranslation { /** * Replica ownership. For default and valid values, see [PUT bucket replication](https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketReplication.html) in the Amazon S3 API Reference. The only valid value is `Destination`. */ owner: string; } interface BucketReplicationConfigurationRuleDestinationMetrics { /** * Threshold within which objects are to be replicated. The only valid value is `15`. */ minutes?: number; /** * Status of replication metrics. Either `Enabled` or `Disabled`. */ status?: string; } interface BucketReplicationConfigurationRuleDestinationReplicationTime { /** * Threshold within which objects are to be replicated. The only valid value is `15`. */ minutes?: number; /** * Status of RTC. Either `Enabled` or `Disabled`. */ status?: string; } interface BucketReplicationConfigurationRuleFilter { /** * Object keyname prefix that identifies subset of objects to which the rule applies. Must be less than or equal to 1024 characters in length. */ prefix?: string; /** * Map of tags that identifies subset of objects to which the rule applies. The rule applies only to objects having all the tags in its tagset. */ tags?: { [key: string]: string; }; } interface BucketReplicationConfigurationRuleSourceSelectionCriteria { /** * Match SSE-KMS encrypted objects. See `sseKmsEncryptedObjects` Block below for details. If specified, `replicaKmsKeyId` in `destination` must be specified as well. */ sseKmsEncryptedObjects?: outputs.s3.BucketReplicationConfigurationRuleSourceSelectionCriteriaSseKmsEncryptedObjects; } interface BucketReplicationConfigurationRuleSourceSelectionCriteriaSseKmsEncryptedObjects { /** * Boolean which indicates if this criteria is enabled. */ enabled: boolean; } interface BucketServerSideEncryptionConfiguration { /** * Single object for server-side encryption by default configuration. See `server_side_encryption_configuration.rule` Block below for details. */ rule: outputs.s3.BucketServerSideEncryptionConfigurationRule; } interface BucketServerSideEncryptionConfigurationRule { /** * Single object for setting server-side encryption by default. See below. */ applyServerSideEncryptionByDefault?: outputs.s3.BucketServerSideEncryptionConfigurationRuleApplyServerSideEncryptionByDefault; /** * List of server-side encryption types to block for object uploads. Valid values are `SSE-C` (blocks uploads using server-side encryption with customer-provided keys) and `NONE` (unblocks all encryption types). Starting in March 2026, Amazon S3 will automatically block SSE-C uploads for all new buckets. */ blockedEncryptionTypes: string[]; /** * Whether or not to use [Amazon S3 Bucket Keys](https://docs.aws.amazon.com/AmazonS3/latest/dev/bucket-key.html) for SSE-KMS. */ bucketKeyEnabled: boolean; } interface BucketServerSideEncryptionConfigurationRuleApplyServerSideEncryptionByDefault { /** * AWS KMS master key ID used for the SSE-KMS encryption. This can only be used when you set the value of `sseAlgorithm` as `aws:kms`. The default `aws/s3` AWS KMS master key is used if this element is absent while the `sseAlgorithm` is `aws:kms`. */ kmsMasterKeyId: string; /** * Server-side encryption algorithm to use. Valid values are `AES256`, `aws:kms`, and `aws:kms:dsse` */ sseAlgorithm: string; } interface BucketServerSideEncryptionConfigurationV2Rule { /** * Single object for setting server-side encryption by default. See below. */ applyServerSideEncryptionByDefault?: outputs.s3.BucketServerSideEncryptionConfigurationV2RuleApplyServerSideEncryptionByDefault; /** * List of server-side encryption types to block for object uploads. Valid values are `SSE-C` (blocks uploads using server-side encryption with customer-provided keys) and `NONE` (unblocks all encryption types). Starting in March 2026, Amazon S3 will automatically block SSE-C uploads for all new buckets. */ blockedEncryptionTypes: string[]; /** * Whether or not to use [Amazon S3 Bucket Keys](https://docs.aws.amazon.com/AmazonS3/latest/dev/bucket-key.html) for SSE-KMS. */ bucketKeyEnabled: boolean; } interface BucketServerSideEncryptionConfigurationV2RuleApplyServerSideEncryptionByDefault { /** * AWS KMS master key ID used for the SSE-KMS encryption. This can only be used when you set the value of `sseAlgorithm` as `aws:kms`. The default `aws/s3` AWS KMS master key is used if this element is absent while the `sseAlgorithm` is `aws:kms`. */ kmsMasterKeyId: string; /** * Server-side encryption algorithm to use. Valid values are `AES256`, `aws:kms`, and `aws:kms:dsse` */ sseAlgorithm: string; } interface BucketV2CorsRule { /** * List of headers allowed. */ allowedHeaders?: string[]; /** * One or more HTTP methods that you allow the origin to execute. Can be `GET`, `PUT`, `POST`, `DELETE` or `HEAD`. */ allowedMethods: string[]; /** * One or more origins you want customers to be able to access the bucket from. */ allowedOrigins: string[]; /** * One or more headers in the response that you want customers to be able to access from their applications (for example, from a JavaScript `XMLHttpRequest` object). */ exposeHeaders?: string[]; /** * Time in seconds that browser can cache the response for a preflight request. */ maxAgeSeconds?: number; } interface BucketV2Grant { /** * Canonical user id to grant for. Used only when `type` is `CanonicalUser`. */ id?: string; /** * List of permissions to apply for grantee. Valid values are `READ`, `WRITE`, `READ_ACP`, `WRITE_ACP`, `FULL_CONTROL`. */ permissions: string[]; /** * Type of grantee to apply for. Valid values are `CanonicalUser` and `Group`. `AmazonCustomerByEmail` is not supported. */ type: string; /** * Uri address to grant for. Used only when `type` is `Group`. */ uri?: string; } interface BucketV2LifecycleRule { /** * Number of days after initiating a multipart upload when the multipart upload must be completed. */ abortIncompleteMultipartUploadDays?: number; /** * Lifecycle rule status. */ enabled: boolean; /** * Configuration of the object expiration. See `expiration` Block below for details. */ expirations?: outputs.s3.BucketV2LifecycleRuleExpiration[]; /** * Unique identifier for the rule. Must be less than or equal to 255 characters in length. */ id: string; /** * When noncurrent object versions expire. See `noncurrentVersionExpiration` Block below for details. */ noncurrentVersionExpirations?: outputs.s3.BucketV2LifecycleRuleNoncurrentVersionExpiration[]; /** * When noncurrent object versions transition. See `noncurrentVersionTransition` Block below for details. */ noncurrentVersionTransitions?: outputs.s3.BucketV2LifecycleRuleNoncurrentVersionTransition[]; /** * Object key prefix identifying one or more objects to which the rule applies. */ prefix?: string; /** * Object tags key and value. */ tags?: { [key: string]: string; }; /** * Configuration of the object transition. See `transition` Block below for details. */ transitions?: outputs.s3.BucketV2LifecycleRuleTransition[]; } interface BucketV2LifecycleRuleExpiration { /** * Date after which you want the corresponding action to take effect. */ date?: string; /** * Number of days after object creation when the specific rule action takes effect. */ days?: number; /** * On a versioned bucket (versioning-enabled or versioning-suspended bucket), you can add this element in the lifecycle configuration to direct Amazon S3 to delete expired object delete markers. This cannot be specified with Days or Date in a Lifecycle Expiration Policy. */ expiredObjectDeleteMarker?: boolean; } interface BucketV2LifecycleRuleNoncurrentVersionExpiration { /** * Number of days noncurrent object versions expire. */ days?: number; } interface BucketV2LifecycleRuleNoncurrentVersionTransition { /** * Number of days noncurrent object versions transition. */ days?: number; /** * Amazon S3 [storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Transition.html#AmazonS3-Type-Transition-StorageClass) to which you want the object to transition. */ storageClass: string; } interface BucketV2LifecycleRuleTransition { /** * Date after which you want the corresponding action to take effect. */ date?: string; /** * Number of days after object creation when the specific rule action takes effect. */ days?: number; /** * Amazon S3 [storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Transition.html#AmazonS3-Type-Transition-StorageClass) to which you want the object to transition. */ storageClass: string; } interface BucketV2Logging { /** * Name of the bucket that will receive the log objects. */ targetBucket: string; /** * To specify a key prefix for log objects. */ targetPrefix?: string; } interface BucketV2ObjectLockConfiguration { /** * Whether this bucket has an Object Lock configuration enabled. Valid value is `Enabled`. Use the top-level argument `objectLockEnabled` instead. * * @deprecated object_lock_enabled is deprecated. Use the top-level parameter objectLockEnabled instead. */ objectLockEnabled?: string; /** * Object Lock rule in place for this bucket. See `object_lock_configuration.rule` Block below for details. * * @deprecated rule is deprecated. Use the aws.s3.BucketObjectLockConfiguration resource instead. */ rules?: outputs.s3.BucketV2ObjectLockConfigurationRule[]; } interface BucketV2ObjectLockConfigurationRule { /** * Default retention period that you want to apply to new objects placed in this bucket. See `defaultRetention` Block below for details. */ defaultRetentions: outputs.s3.BucketV2ObjectLockConfigurationRuleDefaultRetention[]; } interface BucketV2ObjectLockConfigurationRuleDefaultRetention { /** * Number of days that you want to specify for the default retention period. */ days?: number; /** * Default Object Lock retention mode you want to apply to new objects placed in this bucket. Valid values are `GOVERNANCE` and `COMPLIANCE`. */ mode: string; /** * Number of years that you want to specify for the default retention period. */ years?: number; } interface BucketV2ReplicationConfiguration { /** * ARN of the IAM role for Amazon S3 to assume when replicating the objects. */ role: string; /** * Rules managing the replication. See `rules` Block below for details. */ rules: outputs.s3.BucketV2ReplicationConfigurationRule[]; } interface BucketV2ReplicationConfigurationRule { /** * Whether delete markers are replicated. The only valid value is `Enabled`. To disable, omit this argument. This argument is only valid with V2 replication configurations (i.e., when `filter` is used). */ deleteMarkerReplicationStatus?: string; /** * Destination for the rule. See `destination` Block below for details. */ destinations: outputs.s3.BucketV2ReplicationConfigurationRuleDestination[]; /** * Filter that identifies subset of objects to which the replication rule applies. See `filter` Block below for details. */ filters?: outputs.s3.BucketV2ReplicationConfigurationRuleFilter[]; /** * Unique identifier for the rule. Must be less than or equal to 255 characters in length. */ id?: string; /** * Object keyname prefix identifying one or more objects to which the rule applies. Must be less than or equal to 1024 characters in length. */ prefix?: string; /** * Priority associated with the rule. Priority should only be set if `filter` is configured. If not provided, defaults to `0`. Priority must be unique between multiple rules. */ priority?: number; /** * Special object selection criteria. See `sourceSelectionCriteria` Block below for details. */ sourceSelectionCriterias?: outputs.s3.BucketV2ReplicationConfigurationRuleSourceSelectionCriteria[]; /** * Status of the rule. Either `Enabled` or `Disabled`. The rule is ignored if status is not Enabled. */ status: string; } interface BucketV2ReplicationConfigurationRuleDestination { /** * Overrides to use for object owners on replication. See `accessControlTranslation` Block below for details. Must be used in conjunction with `accountId` owner override configuration. */ accessControlTranslations?: outputs.s3.BucketV2ReplicationConfigurationRuleDestinationAccessControlTranslation[]; /** * Account ID to use for overriding the object owner on replication. Must be used in conjunction with `accessControlTranslation` override configuration. */ accountId?: string; /** * ARN of the S3 bucket where you want Amazon S3 to store replicas of the object identified by the rule. */ bucket: string; /** * Enables replication metrics (required for S3 RTC). See `metrics` Block below for details. */ metrics?: outputs.s3.BucketV2ReplicationConfigurationRuleDestinationMetric[]; /** * Destination KMS encryption key ARN for SSE-KMS replication. Must be used in conjunction with `sseKmsEncryptedObjects` source selection criteria. */ replicaKmsKeyId?: string; /** * Enables S3 Replication Time Control (S3 RTC). See `replicationTime` Block below for details. */ replicationTimes?: outputs.s3.BucketV2ReplicationConfigurationRuleDestinationReplicationTime[]; /** * [Storage class](https://docs.aws.amazon.com/AmazonS3/latest/API/API_Destination.html#AmazonS3-Type-Destination-StorageClass) used to store the object. By default, Amazon S3 uses the storage class of the source object to create the object replica. */ storageClass?: string; } interface BucketV2ReplicationConfigurationRuleDestinationAccessControlTranslation { /** * Replica ownership. For default and valid values, see [PUT bucket replication](https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketReplication.html) in the Amazon S3 API Reference. The only valid value is `Destination`. */ owner: string; } interface BucketV2ReplicationConfigurationRuleDestinationMetric { /** * Threshold within which objects are to be replicated. The only valid value is `15`. */ minutes?: number; /** * Status of replication metrics. Either `Enabled` or `Disabled`. */ status?: string; } interface BucketV2ReplicationConfigurationRuleDestinationReplicationTime { /** * Threshold within which objects are to be replicated. The only valid value is `15`. */ minutes?: number; /** * Status of RTC. Either `Enabled` or `Disabled`. */ status?: string; } interface BucketV2ReplicationConfigurationRuleFilter { /** * Object keyname prefix that identifies subset of objects to which the rule applies. Must be less than or equal to 1024 characters in length. */ prefix?: string; /** * Map of tags that identifies subset of objects to which the rule applies. The rule applies only to objects having all the tags in its tagset. */ tags?: { [key: string]: string; }; } interface BucketV2ReplicationConfigurationRuleSourceSelectionCriteria { /** * Match SSE-KMS encrypted objects. See `sseKmsEncryptedObjects` Block below for details. If specified, `replicaKmsKeyId` in `destination` must be specified as well. */ sseKmsEncryptedObjects?: outputs.s3.BucketV2ReplicationConfigurationRuleSourceSelectionCriteriaSseKmsEncryptedObject[]; } interface BucketV2ReplicationConfigurationRuleSourceSelectionCriteriaSseKmsEncryptedObject { /** * Boolean which indicates if this criteria is enabled. */ enabled: boolean; } interface BucketV2ServerSideEncryptionConfiguration { /** * Single object for server-side encryption by default configuration. See `server_side_encryption_configuration.rule` Block below for details. */ rules: outputs.s3.BucketV2ServerSideEncryptionConfigurationRule[]; } interface BucketV2ServerSideEncryptionConfigurationRule { /** * Single object for setting server-side encryption by default. See `applyServerSideEncryptionByDefault` Block below for details. */ applyServerSideEncryptionByDefaults: outputs.s3.BucketV2ServerSideEncryptionConfigurationRuleApplyServerSideEncryptionByDefault[]; /** * Whether or not to use [Amazon S3 Bucket Keys](https://docs.aws.amazon.com/AmazonS3/latest/dev/bucket-key.html) for SSE-KMS. */ bucketKeyEnabled?: boolean; } interface BucketV2ServerSideEncryptionConfigurationRuleApplyServerSideEncryptionByDefault { /** * AWS KMS master key ID used for the SSE-KMS encryption. This can only be used when you set the value of `sseAlgorithm` as `aws:kms`. The default `aws/s3` AWS KMS master key is used if this element is absent while the `sseAlgorithm` is `aws:kms`. */ kmsMasterKeyId?: string; /** * Server-side encryption algorithm to use. Valid values are `AES256` and `aws:kms` */ sseAlgorithm: string; } interface BucketV2Versioning { /** * Enable versioning. Once you version-enable a bucket, it can never return to an unversioned state. You can, however, suspend versioning on that bucket. */ enabled?: boolean; /** * Enable MFA delete for either `Change the versioning state of your bucket` or `Permanently delete an object version`. Default is `false`. This cannot be used to toggle this setting but is available to allow managed buckets to reflect the state in AWS */ mfaDelete?: boolean; } interface BucketV2Website { /** * Absolute path to the document to return in case of a 4XX error. */ errorDocument?: string; /** * Amazon S3 returns this index document when requests are made to the root domain or any of the subfolders. */ indexDocument?: string; /** * Hostname to redirect all website requests for this bucket to. Hostname can optionally be prefixed with a protocol (`http://` or `https://`) to use when redirecting requests. The default is the protocol that is used in the original request. */ redirectAllRequestsTo?: string; /** * JSON array containing [routing rules](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-s3-websiteconfiguration-routingrules.html) describing redirect behavior and when redirects are applied. */ routingRules?: string; } interface BucketVersioning { /** * Enable versioning. Once you version-enable a bucket, it can never return to an unversioned state. You can, however, suspend versioning on that bucket. */ enabled?: boolean; /** * Enable MFA delete for either `Change the versioning state of your bucket` or `Permanently delete an object version`. Default is `false`. This cannot be used to toggle this setting but is available to allow managed buckets to reflect the state in AWS */ mfaDelete?: boolean; } interface BucketVersioningV2VersioningConfiguration { /** * Whether MFA delete is enabled in the bucket versioning configuration. Valid values: `Enabled` or `Disabled`. */ mfaDelete: string; /** * Versioning state of the bucket. Valid values: `Enabled`, `Suspended`, or `Disabled`. `Disabled` should only be used when creating or importing resources that correspond to unversioned S3 buckets. */ status: string; } interface BucketVersioningVersioningConfiguration { /** * Whether MFA delete is enabled in the bucket versioning configuration. Valid values: `Enabled` or `Disabled`. */ mfaDelete: string; /** * Versioning state of the bucket. Valid values: `Enabled`, `Suspended`, or `Disabled`. `Disabled` should only be used when creating or importing resources that correspond to unversioned S3 buckets. */ status: string; } interface BucketWebsite { /** * Absolute path to the document to return in case of a 4XX error. */ errorDocument?: string; /** * Amazon S3 returns this index document when requests are made to the root domain or any of the subfolders. */ indexDocument?: string; /** * Hostname to redirect all website requests for this bucket to. Hostname can optionally be prefixed with a protocol (`http://` or `https://`) to use when redirecting requests. The default is the protocol that is used in the original request. */ redirectAllRequestsTo?: string; /** * JSON array containing [routing rules](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-s3-websiteconfiguration-routingrules.html) describing redirect behavior and when redirects are applied. */ routingRules?: string; } interface BucketWebsiteConfigurationErrorDocument { /** * Object key name to use when a 4XX class error occurs. */ key: string; } interface BucketWebsiteConfigurationIndexDocument { /** * Suffix that is appended to a request that is for a directory on the website endpoint. The suffix must not be empty and must not include a slash character. For example, if the suffix is `index.html` and you make a request to `samplebucket/images/`, the data that is returned will be for the object with the key name `images/index.html`. */ suffix: string; } interface BucketWebsiteConfigurationRedirectAllRequestsTo { /** * Name of the host where requests are redirected. */ hostName: string; /** * Protocol to use when redirecting requests. The default is the protocol that is used in the original request. Valid values: `http`, `https`. */ protocol?: string; } interface BucketWebsiteConfigurationRoutingRule { /** * Configuration block for describing a condition that must be met for the specified redirect to apply. See below. */ condition?: outputs.s3.BucketWebsiteConfigurationRoutingRuleCondition; /** * Configuration block for redirect information. See below. */ redirect: outputs.s3.BucketWebsiteConfigurationRoutingRuleRedirect; } interface BucketWebsiteConfigurationRoutingRuleCondition { /** * HTTP error code when the redirect is applied. If specified with `keyPrefixEquals`, then both must be true for the redirect to be applied. */ httpErrorCodeReturnedEquals?: string; /** * Object key name prefix when the redirect is applied. If specified with `httpErrorCodeReturnedEquals`, then both must be true for the redirect to be applied. */ keyPrefixEquals?: string; } interface BucketWebsiteConfigurationRoutingRuleRedirect { /** * Host name to use in the redirect request. */ hostName?: string; /** * HTTP redirect code to use on the response. */ httpRedirectCode?: string; /** * Protocol to use when redirecting requests. The default is the protocol that is used in the original request. Valid values: `http`, `https`. */ protocol?: string; /** * Object key prefix to use in the redirect request. For example, to redirect requests for all pages with prefix `docs/` (objects in the `docs/` folder) to `documents/`, you can set a `condition` block with `keyPrefixEquals` set to `docs/` and in the `redirect` set `replaceKeyPrefixWith` to `/documents`. */ replaceKeyPrefixWith?: string; /** * Specific object key to use in the redirect request. For example, redirect request to `error.html`. */ replaceKeyWith?: string; } interface BucketWebsiteConfigurationV2ErrorDocument { /** * Object key name to use when a 4XX class error occurs. */ key: string; } interface BucketWebsiteConfigurationV2IndexDocument { /** * Suffix that is appended to a request that is for a directory on the website endpoint. The suffix must not be empty and must not include a slash character. For example, if the suffix is `index.html` and you make a request to `samplebucket/images/`, the data that is returned will be for the object with the key name `images/index.html`. */ suffix: string; } interface BucketWebsiteConfigurationV2RedirectAllRequestsTo { /** * Name of the host where requests are redirected. */ hostName: string; /** * Protocol to use when redirecting requests. The default is the protocol that is used in the original request. Valid values: `http`, `https`. */ protocol?: string; } interface BucketWebsiteConfigurationV2RoutingRule { /** * Configuration block for describing a condition that must be met for the specified redirect to apply. See below. */ condition?: outputs.s3.BucketWebsiteConfigurationV2RoutingRuleCondition; /** * Configuration block for redirect information. See below. */ redirect: outputs.s3.BucketWebsiteConfigurationV2RoutingRuleRedirect; } interface BucketWebsiteConfigurationV2RoutingRuleCondition { /** * HTTP error code when the redirect is applied. If specified with `keyPrefixEquals`, then both must be true for the redirect to be applied. */ httpErrorCodeReturnedEquals?: string; /** * Object key name prefix when the redirect is applied. If specified with `httpErrorCodeReturnedEquals`, then both must be true for the redirect to be applied. */ keyPrefixEquals?: string; } interface BucketWebsiteConfigurationV2RoutingRuleRedirect { /** * Host name to use in the redirect request. */ hostName?: string; /** * HTTP redirect code to use on the response. */ httpRedirectCode?: string; /** * Protocol to use when redirecting requests. The default is the protocol that is used in the original request. Valid values: `http`, `https`. */ protocol?: string; /** * Object key prefix to use in the redirect request. For example, to redirect requests for all pages with prefix `docs/` (objects in the `docs/` folder) to `documents/`, you can set a `condition` block with `keyPrefixEquals` set to `docs/` and in the `redirect` set `replaceKeyPrefixWith` to `/documents`. */ replaceKeyPrefixWith?: string; /** * Specific object key to use in the redirect request. For example, redirect request to `error.html`. */ replaceKeyWith?: string; } interface DirectoryBucketLocation { /** * [Availability Zone ID](https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-availability-zones.html) or Local Zone ID. */ name: string; /** * Location type. Valid values: `AvailabilityZone`, `LocalZone`. */ type: string; } interface FilesAccessPointPosixUser { /** * POSIX group ID. Changing this value forces replacement. */ gid: number; /** * Set of secondary POSIX group IDs. Changing this value forces replacement. */ secondaryGids?: number[]; /** * POSIX user ID. Changing this value forces replacement. */ uid: number; } interface FilesAccessPointRootDirectory { /** * Permissions to set when creating the root directory. See `creationPermissions` below. Changing this value forces replacement. */ creationPermissions?: outputs.s3.FilesAccessPointRootDirectoryCreationPermission[]; /** * Root directory path. Changing this value forces replacement. */ path?: string; } interface FilesAccessPointRootDirectoryCreationPermission { /** * Owner group ID. Changing this value forces replacement. */ ownerGid: number; /** * Owner user ID. Changing this value forces replacement. */ ownerUid: number; /** * POSIX permissions in octal notation. Changing this value forces replacement. */ permissions: string; } interface FilesAccessPointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface FilesFileSystemTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface FilesMountTargetTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface FilesSynchronizationConfigurationExpirationDataRule { /** * Number of days after last access before expiring data. */ daysAfterLastAccess: number; } interface FilesSynchronizationConfigurationImportDataRule { /** * S3 key prefix to apply this rule to. Use `""` for all objects. */ prefix: string; /** * Maximum object size in bytes to import. */ sizeLessThan: number; /** * Import trigger. Valid values: `ON_FILE_ACCESS`. */ trigger: string; } interface GetAccessPointPublicAccessBlockConfiguration { /** * Whether Amazon S3 blocks public ACLs for buckets in this account. */ blockPublicAcls: boolean; /** * Whether Amazon S3 blocks public bucket policies for buckets in this account. */ blockPublicPolicy: boolean; /** * Whether Amazon S3 ignores public ACLs for buckets in this account. */ ignorePublicAcls: boolean; /** * Whether Amazon S3 restricts public bucket policies for buckets in this account. */ restrictPublicBuckets: boolean; } interface GetAccessPointVpcConfiguration { /** * Access point will only allow connections from this VPC. */ vpcId: string; } interface GetBucketNotificationLambdaFunction { /** * [Events](https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html) for which Amazon S3 sends notifications. */ events: string[]; /** * Object key name prefix. */ filterPrefix: string; /** * Object key name suffix. */ filterSuffix: string; /** * Unique identifier for the notification configuration. */ id: string; /** * ARN of the Lambda function. */ lambdaFunctionArn: string; } interface GetBucketNotificationQueue { /** * [Events](https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html) for which Amazon S3 sends notifications. */ events: string[]; /** * Object key name prefix. */ filterPrefix: string; /** * Object key name suffix. */ filterSuffix: string; /** * Unique identifier for the notification configuration. */ id: string; /** * ARN of the SQS queue. */ queueArn: string; } interface GetBucketNotificationTopic { /** * [Events](https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html) for which Amazon S3 sends notifications. */ events: string[]; /** * Object key name prefix. */ filterPrefix: string; /** * Object key name suffix. */ filterSuffix: string; /** * Unique identifier for the notification configuration. */ id: string; /** * ARN of the SNS topic. */ topicArn: string; } interface GetBucketObjectLockConfigurationRule { /** * Default object lock retention settings for new objects placed in the bucket. See Default Retention below. */ defaultRetentions: outputs.s3.GetBucketObjectLockConfigurationRuleDefaultRetention[]; } interface GetBucketObjectLockConfigurationRuleDefaultRetention { /** * Default retention period in days. */ days: number; /** * Default object lock retention mode. Valid values are `GOVERNANCE` and `COMPLIANCE`. */ mode: string; /** * Default retention period in years. */ years: number; } interface GetBucketReplicationConfigurationRule { /** * Configuration block that specifies whether delete markers are replicated. See `deleteMarkerReplication` Block below. */ deleteMarkerReplications: outputs.s3.GetBucketReplicationConfigurationRuleDeleteMarkerReplication[]; /** * Configuration block that specifies the destination for the rule. See `destination` Block below. */ destinations: outputs.s3.GetBucketReplicationConfigurationRuleDestination[]; /** * Configuration block that specifies replication of existing objects. See `existingObjectReplication` Block below. */ existingObjectReplications: outputs.s3.GetBucketReplicationConfigurationRuleExistingObjectReplication[]; /** * Configuration block that identifies the subset of objects to which the rule applies. See `filter` Block below. */ filters: outputs.s3.GetBucketReplicationConfigurationRuleFilter[]; /** * Unique identifier for the rule. */ id: string; /** * Object key name prefix that identifies the subset of objects to which the rule applies. */ prefix: string; /** * Priority associated with the rule. */ priority: number; /** * Configuration block that specifies special object selection criteria. See `sourceSelectionCriteria` Block below. */ sourceSelectionCriterias: outputs.s3.GetBucketReplicationConfigurationRuleSourceSelectionCriteria[]; /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; } interface GetBucketReplicationConfigurationRuleDeleteMarkerReplication { /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; } interface GetBucketReplicationConfigurationRuleDestination { /** * Configuration block that specifies the overrides to use for object owners on replication. See `accessControlTranslation` Block below. */ accessControlTranslations: outputs.s3.GetBucketReplicationConfigurationRuleDestinationAccessControlTranslation[]; /** * Account ID used to specify the replica ownership. */ account: string; /** * Name of the bucket to get the replication configuration for. */ bucket: string; /** * Configuration block that provides information about encryption. See `encryptionConfiguration` Block below. */ encryptionConfigurations: outputs.s3.GetBucketReplicationConfigurationRuleDestinationEncryptionConfiguration[]; /** * Configuration block that specifies replication metrics-related settings. See `metrics` Block below. */ metrics: outputs.s3.GetBucketReplicationConfigurationRuleDestinationMetric[]; /** * Configuration block that specifies S3 Replication Time Control (S3 RTC). See `replicationTime` Block below. */ replicationTimes: outputs.s3.GetBucketReplicationConfigurationRuleDestinationReplicationTime[]; /** * Storage class used to store the object. */ storageClass: string; } interface GetBucketReplicationConfigurationRuleDestinationAccessControlTranslation { /** * Replica ownership. */ owner: string; } interface GetBucketReplicationConfigurationRuleDestinationEncryptionConfiguration { /** * ID (Key ARN or Alias ARN) of the customer managed AWS KMS key stored in KMS for the destination bucket. */ replicaKmsKeyId: string; } interface GetBucketReplicationConfigurationRuleDestinationMetric { /** * Configuration block that specifies the time threshold for emitting the `s3:Replication:OperationMissedThreshold` event. See `eventThreshold` Block below. */ eventThresholds: outputs.s3.GetBucketReplicationConfigurationRuleDestinationMetricEventThreshold[]; /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; } interface GetBucketReplicationConfigurationRuleDestinationMetricEventThreshold { /** * Time in minutes. */ minutes: number; } interface GetBucketReplicationConfigurationRuleDestinationReplicationTime { /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; /** * Configuration block that specifies the time by which replication should be complete for all objects and operations on objects. See `time` Block below. */ times: outputs.s3.GetBucketReplicationConfigurationRuleDestinationReplicationTimeTime[]; } interface GetBucketReplicationConfigurationRuleDestinationReplicationTimeTime { /** * Time in minutes. */ minutes: number; } interface GetBucketReplicationConfigurationRuleExistingObjectReplication { /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; } interface GetBucketReplicationConfigurationRuleFilter { /** * Configuration block for specifying rule filters. See `and` Block below. */ ands: outputs.s3.GetBucketReplicationConfigurationRuleFilterAnd[]; /** * Object key name prefix that identifies the subset of objects to which the rule applies. */ prefix: string; /** * List of tags that identify a subset of objects to which the rule applies. See `tag` Block below. */ tags: outputs.s3.GetBucketReplicationConfigurationRuleFilterTag[]; } interface GetBucketReplicationConfigurationRuleFilterAnd { /** * Object key name prefix that identifies the subset of objects to which the rule applies. */ prefix: string; /** * List of tags that identify a subset of objects to which the rule applies. See `tag` Block below. */ tags: outputs.s3.GetBucketReplicationConfigurationRuleFilterAndTag[]; } interface GetBucketReplicationConfigurationRuleFilterAndTag { /** * Name of the object key. */ key: string; /** * Value of the tag. */ value: string; } interface GetBucketReplicationConfigurationRuleFilterTag { /** * Name of the object key. */ key: string; /** * Value of the tag. */ value: string; } interface GetBucketReplicationConfigurationRuleSourceSelectionCriteria { /** * Configuration block for selections for modifications on replicas. See `replicaModifications` Block below. */ replicaModifications: outputs.s3.GetBucketReplicationConfigurationRuleSourceSelectionCriteriaReplicaModification[]; /** * Configuration block for filter information for the selection of Amazon S3 objects encrypted with AWS KMS. See `sseKmsEncryptedObjects` Block below. */ sseKmsEncryptedObjects: outputs.s3.GetBucketReplicationConfigurationRuleSourceSelectionCriteriaSseKmsEncryptedObject[]; } interface GetBucketReplicationConfigurationRuleSourceSelectionCriteriaReplicaModification { /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; } interface GetBucketReplicationConfigurationRuleSourceSelectionCriteriaSseKmsEncryptedObject { /** * Whether Amazon S3 replicates objects created with server-side encryption using an AWS KMS key stored in KMS. */ status: string; } interface GetBucketsBucket { /** * Bucket ARN. */ bucketArn: string; /** * Limits the response to buckets that are located in the specified AWS Region. The AWS Region must be expressed according to the AWS Region code. */ bucketRegion: string; /** * Bucket creation date. */ creationDate: string; /** * Bucket name. */ name: string; } interface GetFilesAccessPointPosixUser { /** * POSIX group ID. */ gid: number; /** * Set of secondary POSIX group IDs. */ secondaryGids: number[]; /** * POSIX user ID. */ uid: number; } interface GetFilesAccessPointRootDirectory { /** * Permissions set when the root directory was created. See `creationPermissions` below. */ creationPermissions?: outputs.s3.GetFilesAccessPointRootDirectoryCreationPermission[]; /** * Root directory path. */ path: string; } interface GetFilesAccessPointRootDirectoryCreationPermission { /** * Owner group ID. */ ownerGid: number; /** * Owner user ID. */ ownerUid: number; /** * POSIX permissions in octal notation. */ permissions: string; } interface GetFilesFileSystemsFileSystem { /** * ARN of the file system. */ arn: string; /** * S3 bucket ARN. */ bucket: string; /** * Creation time. */ creationTime: string; /** * Identifier of the file system. */ id: string; /** * KMS key ID for encryption. */ kmsKeyId: string; /** * File system name. */ name: string; /** * AWS account ID of the owner. */ ownerId: string; /** * IAM role ARN for S3 access. */ roleArn: string; /** * File system status. */ status: string; /** * Status message. */ statusMessage: string; } interface InventoryDestination { /** * S3 bucket configuration where inventory results are published. See `bucket` Block below. */ bucket: outputs.s3.InventoryDestinationBucket; } interface InventoryDestinationBucket { /** * ID of the account that owns the destination bucket. Recommended to be set to prevent problems if the destination bucket ownership changes. */ accountId?: string; /** * Amazon S3 bucket ARN of the destination. Only general purpose buckets are supported. */ bucketArn: string; /** * Type of server-side encryption to use to encrypt the inventory. See `encryption` Block below. */ encryption?: outputs.s3.InventoryDestinationBucketEncryption; /** * Output format of the inventory results. Valid values: `CSV`, [`ORC`](https://orc.apache.org/), [`Parquet`](https://parquet.apache.org/). * * The following arguments are optional: */ format: string; /** * Prefix that is prepended to all inventory results. */ prefix?: string; } interface InventoryDestinationBucketEncryption { /** * Server-side encryption with AWS KMS-managed keys to encrypt the inventory file. See `sseKms` Block below. */ sseKms?: outputs.s3.InventoryDestinationBucketEncryptionSseKms; /** * Server-side encryption with Amazon S3-managed keys (SSE-S3) to encrypt the inventory file. */ sseS3?: outputs.s3.InventoryDestinationBucketEncryptionSseS3; } interface InventoryDestinationBucketEncryptionSseKms { /** * ARN of the KMS customer master key (CMK) used to encrypt the inventory file. */ keyId: string; } interface InventoryDestinationBucketEncryptionSseS3 { } interface InventoryFilter { /** * Prefix that an object must have to be included in the inventory results. */ prefix?: string; } interface InventorySchedule { /** * How frequently inventory results are produced. Valid values: `Daily`, `Weekly`. */ frequency: string; } interface ObjectCopyGrant { /** * Email address of the grantee. Used only when `type` is `AmazonCustomerByEmail`. */ email?: string; /** * Canonical user ID of the grantee. Used only when `type` is `CanonicalUser`. */ id?: string; /** * List of permissions to grant to grantee. Valid values are `READ`, `READ_ACP`, `WRITE_ACP`, `FULL_CONTROL`. */ permissions: string[]; /** * Type of grantee. Valid values are `CanonicalUser`, `Group`, and `AmazonCustomerByEmail`. */ type: string; /** * URI of the grantee group. Used only when `type` is `Group`. */ uri?: string; } interface ObjectCopyOverrideProvider { /** * Configuration block to override the provider `defaultTags` configuration block. See `defaultTags` Block below. */ defaultTags?: outputs.s3.ObjectCopyOverrideProviderDefaultTags; } interface ObjectCopyOverrideProviderDefaultTags { /** * Map of tags to assign to the object. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: { [key: string]: string; }; } interface VectorsIndexEncryptionConfiguration { /** * KMS customer managed key ID to use for the encryption configuration. This parameter is allowed if and only if `sseType` is set to `aws:kms`. To specify the KMS key, you must use the format of the KMS key ARN. */ kmsKeyArn: string; /** * Type of encryption to use. Valid values: `AES256`, `aws:kms`. Defaults to `AES256`. */ sseType: string; } interface VectorsIndexMetadataConfiguration { /** * List of non-filterable metadata keys. */ nonFilterableMetadataKeys: string[]; } interface VectorsVectorBucketEncryptionConfiguration { /** * AWS KMS CMK ARN to use for the default encryption of the vector bucket. Allowed if and only if `sseType` is set to `aws:kms`. */ kmsKeyArn: string; /** * Server-side encryption type to use for the default encryption of the vector bucket. Valid values: `AES256`, `aws:kms`. */ sseType: string; } } export declare namespace s3control { interface AccessGrantAccessGrantsLocationConfiguration { /** * Sub-prefix. */ s3SubPrefix?: string; } interface AccessGrantGrantee { /** * Grantee identifier. */ granteeIdentifier: string; /** * Grantee types. Valid values: `DIRECTORY_USER`, `DIRECTORY_GROUP`, `IAM`. */ granteeType: string; } interface BucketLifecycleConfigurationRule { /** * Configuration block containing settings for abort incomplete multipart upload. See `abortIncompleteMultipartUpload` below. */ abortIncompleteMultipartUpload?: outputs.s3control.BucketLifecycleConfigurationRuleAbortIncompleteMultipartUpload; /** * Configuration block containing settings for expiration of objects. See `expiration` below. */ expiration?: outputs.s3control.BucketLifecycleConfigurationRuleExpiration; /** * Configuration block containing settings for filtering. See `filter` below. */ filter?: outputs.s3control.BucketLifecycleConfigurationRuleFilter; /** * Unique identifier for the rule. */ id: string; /** * Status of the rule. Valid values: `Enabled` and `Disabled`. Defaults to `Enabled`. */ status?: string; } interface BucketLifecycleConfigurationRuleAbortIncompleteMultipartUpload { /** * Number of days after which Amazon S3 aborts an incomplete multipart upload. */ daysAfterInitiation: number; } interface BucketLifecycleConfigurationRuleExpiration { /** * Date the object is to be deleted. Should be in `YYYY-MM-DD` date format, e.g., `2020-09-30`. */ date?: string; /** * Number of days before the object is to be deleted. */ days?: number; /** * Enable to remove a delete marker with no noncurrent versions. Cannot be specified with `date` or `days`. */ expiredObjectDeleteMarker?: boolean; } interface BucketLifecycleConfigurationRuleFilter { /** * Object prefix for rule filtering. */ prefix?: string; /** * Key-value map of object tags for rule filtering. */ tags?: { [key: string]: string; }; } interface DirectoryBucketAccessPointScopeScope { /** * You can specify a list of API operations as permissions for the access point. */ permissions?: string[]; /** * You can specify a list of prefixes, but the total length of characters of all prefixes must be less than 256 bytes. */ prefixes?: string[]; } interface GetAccessPointsAccessPoint { /** * Access point ARN. */ accessPointArn: string; /** * Access point alias. */ alias: string; /** * Name of the bucket associated with the access points. */ bucket: string; /** * AWS account ID associated with the S3 bucket associated with the access point. */ bucketAccountId: string; /** * Unique identifier for the access points data source. */ dataSourceId: string; /** * Type of the data source that the access points are attached to. To return all access points set this argument to `ALL`. */ dataSourceType: string; /** * Name of the access point. */ name: string; /** * Whether the access point allows access from the public Internet. */ networkOrigin: string; /** * VPC configuration for the access point. See `vpcConfiguration` below. */ vpcConfigurations: outputs.s3control.GetAccessPointsAccessPointVpcConfiguration[]; } interface GetAccessPointsAccessPointVpcConfiguration { /** * Access point will only allow connections from this VPC. */ vpcId: string; } interface GetMultiRegionAccessPointPublicAccessBlock { /** * Whether Amazon S3 should block public access control lists (ACLs). When set to `true`, PUT Bucket acl and PUT Object acl calls fail if the specified ACL is public, PUT Object calls fail if the request includes a public ACL, and PUT Bucket calls fail if the request includes a public ACL. */ blockPublicAcls: boolean; /** * Whether Amazon S3 should block public bucket policies for buckets in this account. When set to `true`, Amazon S3 rejects calls to PUT Bucket policy if the specified bucket policy allows public access. */ blockPublicPolicy: boolean; /** * Whether Amazon S3 should ignore public ACLs for buckets in this account. When set to `true`, Amazon S3 ignores all public ACLs on buckets in this account and any objects that they contain. */ ignorePublicAcls: boolean; /** * Whether Amazon S3 should restrict public bucket policies for buckets in this account. When set to `true`, only the bucket owner and AWS Services can access buckets with public policies. */ restrictPublicBuckets: boolean; } interface GetMultiRegionAccessPointRegion { /** * Name of the bucket. */ bucket: string; /** * AWS account ID that owns the bucket. */ bucketAccountId: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface GetMultiRegionAccessPointsAccessPoint { /** * Alias for the multi-region access point. */ alias: string; /** * Time the multi-region access point was created. */ createdAt: string; /** * Name of the multi-region access point. */ name: string; /** * Public access block configuration for this multi-region access point. See `publicAccessBlock` below. */ publicAccessBlocks: outputs.s3control.GetMultiRegionAccessPointsAccessPointPublicAccessBlock[]; /** * List of AWS Regions where the multi-region access point has data support. See `regions` below. */ regions: outputs.s3control.GetMultiRegionAccessPointsAccessPointRegion[]; /** * Current status of the multi-region access point. */ status: string; } interface GetMultiRegionAccessPointsAccessPointPublicAccessBlock { /** * Whether Amazon S3 should block public ACLs for buckets in this account. */ blockPublicAcls: boolean; /** * Whether Amazon S3 should block public bucket policies for buckets in this account. */ blockPublicPolicy: boolean; /** * Whether Amazon S3 should ignore public ACLs for buckets in this account. */ ignorePublicAcls: boolean; /** * Whether Amazon S3 should restrict public bucket policies for buckets in this account. */ restrictPublicBuckets: boolean; } interface GetMultiRegionAccessPointsAccessPointRegion { /** * Name of the associated bucket for the Region. */ bucket: string; /** * AWS account ID that owns the Amazon S3 bucket associated with this multi-region access point. */ bucketAccountId: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface MultiRegionAccessPointDetails { /** * Name of the Multi-Region Access Point. */ name: string; /** * Configuration block to manage the `PublicAccessBlock` configuration that you want to apply to this Multi-Region Access Point. You can enable the configuration options in any combination. See `publicAccessBlock` Block below. */ publicAccessBlock?: outputs.s3control.MultiRegionAccessPointDetailsPublicAccessBlock; /** * Region configuration block to specify the bucket associated with the Multi-Region Access Point. See `region` Block below. */ regions: outputs.s3control.MultiRegionAccessPointDetailsRegion[]; } interface MultiRegionAccessPointDetailsPublicAccessBlock { /** * Whether Amazon S3 should block public ACLs for buckets in this account. Defaults to `true`. Enabling this setting does not affect existing policies or ACLs. When set to `true`, PUT Bucket acl and PUT Object acl calls fail if the specified ACL is public, PUT Object calls fail if the request includes a public ACL, and PUT Bucket calls fail if the request includes a public ACL. */ blockPublicAcls?: boolean; /** * Whether Amazon S3 should block public bucket policies for buckets in this account. Defaults to `true`. Enabling this setting does not affect existing bucket policies. When set to `true`, Amazon S3 rejects calls to PUT Bucket policy if the specified bucket policy allows public access. */ blockPublicPolicy?: boolean; /** * Whether Amazon S3 should ignore public ACLs for buckets in this account. Defaults to `true`. Enabling this setting does not affect the persistence of any existing ACLs and doesn't prevent new public ACLs from being set. When set to `true`, Amazon S3 ignores all public ACLs on buckets in this account and any objects that they contain. */ ignorePublicAcls?: boolean; /** * Whether Amazon S3 should restrict public bucket policies for buckets in this account. Defaults to `true`. Enabling this setting does not affect previously stored bucket policies, except that public and cross-account access within any public bucket policy, including non-public delegation to specific accounts, is blocked. When set to `true`, only the bucket owner and AWS Services can access buckets with public policies. */ restrictPublicBuckets?: boolean; } interface MultiRegionAccessPointDetailsRegion { /** * Name of the associated bucket for the Region. */ bucket: string; /** * AWS account ID that owns the Amazon S3 bucket that's associated with this Multi-Region Access Point. */ bucketAccountId: string; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface MultiRegionAccessPointPolicyDetails { /** * Name of the Multi-Region Access Point. */ name: string; /** * Valid JSON document that specifies the policy that you want to associate with this Multi-Region Access Point. Once applied, the policy can be edited, but not deleted. For more information, see the documentation on [Multi-Region Access Point Permissions](https://docs.aws.amazon.com/AmazonS3/latest/userguide/MultiRegionAccessPointPermissions.html). * * > **NOTE:** When you update the `policy`, the update is first listed as the proposed policy. After the update is finished and all Regions have been updated, the proposed policy is listed as the established policy. If both policies have the same version number, the proposed policy is the established policy. */ policy: string; } interface MultiRegionAccessPointRoutesRoute { /** * Name of the Amazon S3 bucket. */ bucket: string; /** * AWS Region where the bucket is located. */ region: string; /** * Traffic routing configuration. A value of `0` indicates a passive status (traffic will not be routed to the Region), and a value of `100` indicates an active status (traffic will be routed to the Region). */ trafficDialPercentage: number; } interface ObjectLambdaAccessPointConfiguration { /** * Allowed features. Valid values: `GetObject-Range`, `GetObject-PartNumber`. */ allowedFeatures?: string[]; /** * Whether or not the CloudWatch metrics configuration is enabled. */ cloudWatchMetricsEnabled?: boolean; /** * Standard access point associated with the Object Lambda Access Point. */ supportingAccessPoint: string; /** * List of transformation configurations for the Object Lambda Access Point. See `transformationConfiguration` Block below for more details. */ transformationConfigurations: outputs.s3control.ObjectLambdaAccessPointConfigurationTransformationConfiguration[]; } interface ObjectLambdaAccessPointConfigurationTransformationConfiguration { /** * Actions of an Object Lambda Access Point configuration. Valid values: `GetObject`. */ actions: string[]; /** * Content transformation of an Object Lambda Access Point configuration. See `contentTransformation` Block below for more details. */ contentTransformation: outputs.s3control.ObjectLambdaAccessPointConfigurationTransformationConfigurationContentTransformation; } interface ObjectLambdaAccessPointConfigurationTransformationConfigurationContentTransformation { /** * Configuration for an AWS Lambda function. See `awsLambda` Block below for more details. */ awsLambda: outputs.s3control.ObjectLambdaAccessPointConfigurationTransformationConfigurationContentTransformationAwsLambda; } interface ObjectLambdaAccessPointConfigurationTransformationConfigurationContentTransformationAwsLambda { /** * ARN of the AWS Lambda function. */ functionArn: string; /** * Additional JSON that provides supplemental data to the Lambda function used to transform objects. */ functionPayload?: string; } interface StorageLensConfigurationStorageLensConfiguration { /** * Account-level configurations of the S3 Storage Lens configuration. See `accountLevel` below for more details. */ accountLevel: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevel; /** * Amazon Web Services organization for the S3 Storage Lens configuration. See `awsOrg` below for more details. */ awsOrg?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAwsOrg; /** * Properties of S3 Storage Lens metrics export including the destination, schema and format. See `dataExport` below for more details. */ dataExport?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExport; /** * Whether the S3 Storage Lens configuration is enabled. */ enabled: boolean; /** * What is excluded in this configuration. Conflicts with `include`. See `exclude` below for more details. */ exclude?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExclude; /** * Configuration for the S3 Storage Lens expanded prefix metrics report. Unlike the default Storage Lens metrics report, the enhanced prefix metrics report includes all S3 Storage Lens storage and activity data related to the full list of prefixes in your Storage Lens configuration. See `expandedPrefixesDataExport` below for more details. */ expandedPrefixesDataExport?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExport; /** * What is included in this configuration. Conflicts with `exclude`. See `include` below for more details. */ include?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationInclude; /** * Prefix delimiter used for object keys in this S3 Storage Lens configuration. */ prefixDelimiter?: string; } interface StorageLensConfigurationStorageLensConfigurationAccountLevel { /** * S3 Storage Lens activity metrics. See `activityMetrics` below for more details. */ activityMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelActivityMetrics; /** * Advanced cost-optimization metrics for S3 Storage Lens. See `advancedCostOptimizationMetrics` below for more details. */ advancedCostOptimizationMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelAdvancedCostOptimizationMetrics; /** * Advanced data-protection metrics for S3 Storage Lens. See `advancedDataProtectionMetrics` below for more details. */ advancedDataProtectionMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelAdvancedDataProtectionMetrics; /** * Advanced performance metrics for S3 Storage Lens. See `advancedPerformanceMetrics` below for more details. */ advancedPerformanceMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelAdvancedPerformanceMetrics; /** * S3 Storage Lens bucket-level configuration. See `bucketLevel` below for more details. */ bucketLevel: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevel; /** * Detailed status code metrics for S3 Storage Lens. See `detailedStatusCodeMetrics` below for more details. */ detailedStatusCodeMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelDetailedStatusCodeMetrics; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelActivityMetrics { /** * Whether the activity metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelAdvancedCostOptimizationMetrics { /** * Whether advanced cost-optimization metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelAdvancedDataProtectionMetrics { /** * Whether advanced data-protection metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelAdvancedPerformanceMetrics { /** * Whether advanced performance metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevel { /** * S3 Storage Lens activity metrics. See `activityMetrics` above for more details. */ activityMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelActivityMetrics; /** * Advanced cost-optimization metrics for S3 Storage Lens. See `advancedCostOptimizationMetrics` above for more details. */ advancedCostOptimizationMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelAdvancedCostOptimizationMetrics; /** * Advanced data-protection metrics for S3 Storage Lens. See `advancedDataProtectionMetrics` above for more details. */ advancedDataProtectionMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelAdvancedDataProtectionMetrics; /** * Advanced performance metrics for S3 Storage Lens. See `advancedPerformanceMetrics` above for more details. */ advancedPerformanceMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelAdvancedPerformanceMetrics; /** * Detailed status code metrics for S3 Storage Lens. See `detailedStatusCodeMetrics` above for more details. */ detailedStatusCodeMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelDetailedStatusCodeMetrics; /** * Prefix-level metrics for S3 Storage Lens. See `prefixLevel` below for more details. */ prefixLevel?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelPrefixLevel; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelActivityMetrics { /** * Whether the activity metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelAdvancedCostOptimizationMetrics { /** * Whether advanced cost-optimization metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelAdvancedDataProtectionMetrics { /** * Whether advanced data-protection metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelAdvancedPerformanceMetrics { /** * Whether advanced performance metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelDetailedStatusCodeMetrics { /** * Whether detailed status code metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelPrefixLevel { /** * Prefix-level storage metrics for S3 Storage Lens. See `storageMetrics` below for more details. */ storageMetrics: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelPrefixLevelStorageMetrics; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelPrefixLevelStorageMetrics { /** * Whether prefix-level storage metrics are enabled. */ enabled?: boolean; /** * Selection criteria. See `selectionCriteria` below for more details. */ selectionCriteria?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelPrefixLevelStorageMetricsSelectionCriteria; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelBucketLevelPrefixLevelStorageMetricsSelectionCriteria { /** * Delimiter of the selection criteria being used. */ delimiter?: string; /** * Max depth of the selection criteria. */ maxDepth?: number; /** * Minimum number of storage bytes percentage whose metrics will be selected. */ minStorageBytesPercentage?: number; } interface StorageLensConfigurationStorageLensConfigurationAccountLevelDetailedStatusCodeMetrics { /** * Whether detailed status code metrics are enabled. */ enabled?: boolean; } interface StorageLensConfigurationStorageLensConfigurationAwsOrg { /** * ARN of the Amazon Web Services organization. */ arn: string; } interface StorageLensConfigurationStorageLensConfigurationDataExport { /** * Amazon CloudWatch publishing for S3 Storage Lens metrics. See `cloudWatchMetrics` below for more details. */ cloudWatchMetrics?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportCloudWatchMetrics; /** * Bucket where the S3 Storage Lens metrics export will be located. See `s3BucketDestination` below for more details. */ s3BucketDestination?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestination; /** * S3 table bucket where the S3 Storage Lens metrics export will be located. See `storageLensTableDestination` below for more details. */ storageLensTableDestination?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestination; } interface StorageLensConfigurationStorageLensConfigurationDataExportCloudWatchMetrics { /** * Whether CloudWatch publishing for S3 Storage Lens metrics is enabled. */ enabled: boolean; } interface StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestination { /** * Account ID of the owner of the S3 Storage Lens metrics export bucket. */ accountId: string; /** * ARN of the bucket. */ arn: string; /** * Encryption of the metrics exports in this bucket. See `encryption` below for more details. */ encryption?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestinationEncryption; /** * Export format. Valid values: `CSV`, `Parquet`. */ format: string; /** * Schema version of the export file. Valid values: `V_1`. */ outputSchemaVersion: string; /** * Prefix of the destination bucket where the metrics export will be delivered. */ prefix?: string; } interface StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestinationEncryption { /** * SSE-KMS encryption. See `sseKms` below for more details. */ sseKms?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestinationEncryptionSseKms; /** * SSE-S3 encryption. An empty configuration block `{}` should be used. */ sseS3s?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestinationEncryptionSseS3[]; } interface StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestinationEncryptionSseKms { /** * KMS key ARN. */ keyId: string; } interface StorageLensConfigurationStorageLensConfigurationDataExportS3BucketDestinationEncryptionSseS3 { } interface StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestination { /** * Whether S3 Storage Lens export to S3 tables is enabled. */ enabled: boolean; /** * Encryption of the metrics exports in this S3 tables bucket. See `encryption` below for more details. */ encryption?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestinationEncryption; } interface StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestinationEncryption { /** * SSE-KMS encryption. See `sseKms` below for more details. */ sseKms?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestinationEncryptionSseKms; /** * SSE-S3 encryption. An empty configuration block `{}` should be used. */ sseS3s?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestinationEncryptionSseS3[]; } interface StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestinationEncryptionSseKms { /** * KMS key ARN. */ keyId: string; } interface StorageLensConfigurationStorageLensConfigurationDataExportStorageLensTableDestinationEncryptionSseS3 { } interface StorageLensConfigurationStorageLensConfigurationExclude { /** * List of S3 bucket ARNs. */ buckets?: string[]; /** * List of AWS Regions. */ regions?: string[]; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExport { /** * Bucket where the S3 Storage Lens expanded prefix metrics export will be located. See `s3BucketDestination` below for more details. */ s3BucketDestination?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestination; /** * S3 table bucket where the S3 Storage Lens expanded prefix metrics export will be located. See `storageLensTableDestination` below for more details. */ storageLensTableDestination?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestination; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestination { /** * Account ID of the owner of the S3 Storage Lens metrics export bucket. */ accountId: string; /** * ARN of the bucket. */ arn: string; /** * Encryption of the metrics exports in this bucket. See `encryption` below for more details. */ encryption?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestinationEncryption; /** * Export format. Valid values: `CSV`, `Parquet`. */ format: string; /** * Schema version of the export file. Valid values: `V_1`. */ outputSchemaVersion: string; /** * Prefix of the destination bucket where the metrics export will be delivered. */ prefix?: string; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestinationEncryption { /** * SSE-KMS encryption. See `sseKms` below for more details. */ sseKms?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestinationEncryptionSseKms; /** * SSE-S3 encryption. An empty configuration block `{}` should be used. */ sseS3s?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestinationEncryptionSseS3[]; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestinationEncryptionSseKms { /** * KMS key ARN. */ keyId: string; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportS3BucketDestinationEncryptionSseS3 { } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestination { /** * Whether S3 Storage Lens export to S3 tables is enabled. */ enabled: boolean; /** * Encryption of the metrics exports in this S3 tables bucket. See `encryption` below for more details. */ encryption?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestinationEncryption; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestinationEncryption { /** * SSE-KMS encryption. See `sseKms` below for more details. */ sseKms?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestinationEncryptionSseKms; /** * SSE-S3 encryption. An empty configuration block `{}` should be used. */ sseS3s?: outputs.s3control.StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestinationEncryptionSseS3[]; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestinationEncryptionSseKms { /** * KMS key ARN. */ keyId: string; } interface StorageLensConfigurationStorageLensConfigurationExpandedPrefixesDataExportStorageLensTableDestinationEncryptionSseS3 { } interface StorageLensConfigurationStorageLensConfigurationInclude { /** * List of S3 bucket ARNs. */ buckets?: string[]; /** * List of AWS Regions. */ regions?: string[]; } } export declare namespace s3outposts { interface EndpointNetworkInterface { /** * Identifier of the Elastic Network Interface (ENI). */ networkInterfaceId: string; } } export declare namespace s3tables { interface TableBucketEncryptionConfiguration { /** * ARN of a KMS Key to be used with `aws:kms` `sseAlgorithm` */ kmsKeyArn: string; /** * One of `aws:kms` or `AES256` */ sseAlgorithm: string; } interface TableBucketMaintenanceConfiguration { /** * Iceberg unreferenced file removal settings for the table bucket. See `icebergUnreferencedFileRemoval` below. */ icebergUnreferencedFileRemoval: outputs.s3tables.TableBucketMaintenanceConfigurationIcebergUnreferencedFileRemoval; } interface TableBucketMaintenanceConfigurationIcebergUnreferencedFileRemoval { /** * Settings object for unreferenced file removal. See `iceberg_unreferenced_file_removal.settings` below. */ settings: outputs.s3tables.TableBucketMaintenanceConfigurationIcebergUnreferencedFileRemovalSettings; /** * Whether the configuration is enabled. Valid values are `enabled` and `disabled`. */ status: string; } interface TableBucketMaintenanceConfigurationIcebergUnreferencedFileRemovalSettings { /** * Data objects marked for deletion are deleted after this many days. Must be at least `1`. */ nonCurrentDays: number; /** * Unreferenced data objects are marked for deletion after this many days. Must be at least `1`. */ unreferencedDays: number; } interface TableBucketReplicationRule { /** * Replication destination. See Destination below for more details. */ destinations: outputs.s3tables.TableBucketReplicationRuleDestination[]; } interface TableBucketReplicationRuleDestination { /** * ARN of destination table bucket to replicate source tables to. */ destinationTableBucketArn: string; } interface TableEncryptionConfiguration { /** * ARN of a KMS Key to be used with `aws:kms` `sseAlgorithm` */ kmsKeyArn: string; /** * One of `aws:kms` or `AES256` */ sseAlgorithm: string; } interface TableMaintenanceConfiguration { /** * Single Iceberg compaction settings object. See `icebergCompaction` below. */ icebergCompaction: outputs.s3tables.TableMaintenanceConfigurationIcebergCompaction; /** * Single Iceberg snapshot management settings object. See `icebergSnapshotManagement` below. */ icebergSnapshotManagement: outputs.s3tables.TableMaintenanceConfigurationIcebergSnapshotManagement; } interface TableMaintenanceConfigurationIcebergCompaction { /** * Settings object for compaction. See `iceberg_compaction.settings` below. */ settings: outputs.s3tables.TableMaintenanceConfigurationIcebergCompactionSettings; /** * Whether the configuration is enabled. Valid values are `enabled` and `disabled`. */ status: string; } interface TableMaintenanceConfigurationIcebergCompactionSettings { /** * Data objects smaller than this size may be combined with others to improve query performance. Must be between `64` and `512`. */ targetFileSizeMb: number; } interface TableMaintenanceConfigurationIcebergSnapshotManagement { /** * Settings object for snapshot management. See `iceberg_snapshot_management.settings` below. */ settings: outputs.s3tables.TableMaintenanceConfigurationIcebergSnapshotManagementSettings; /** * Whether the configuration is enabled. Valid values are `enabled` and `disabled`. */ status: string; } interface TableMaintenanceConfigurationIcebergSnapshotManagementSettings { /** * Snapshots older than this will be marked for deletion. Must be at least `1`. */ maxSnapshotAgeHours: number; /** * Minimum number of snapshots to keep. Must be at least `1`. */ minSnapshotsToKeep: number; } interface TableMetadata { /** * Details about the metadata for an Iceberg table. This block defines the schema structure for the Apache Iceberg table format. See `iceberg` below. */ iceberg: outputs.s3tables.TableMetadataIceberg; } interface TableMetadataIceberg { /** * Map of configuration properties for the Iceberg table, for example `write.distribution-mode` and `write.sort-order`. */ properties?: { [key: string]: string; }; /** * Schema configuration for the Iceberg table. See `schema` below. */ schema: outputs.s3tables.TableMetadataIcebergSchema; } interface TableMetadataIcebergSchema { /** * List of schema fields for the Iceberg table. Each field defines a column in the table schema. See `field` below. */ fields: outputs.s3tables.TableMetadataIcebergSchemaField[]; } interface TableMetadataIcebergSchemaField { /** * Name of the field. */ name: string; /** * Boolean value that specifies whether values are required for each row in this field. Defaults to `false`. */ required: boolean; /** * Field type. S3 Tables supports all Apache Iceberg primitive types including: `boolean`, `int`, `long`, `float`, `double`, `decimal(precision,scale)`, `date`, `time`, `timestamp`, `timestamptz`, `string`, `uuid`, `fixed(length)`, `binary`. */ type: string; } interface TableReplicationRule { /** * Replication destination. See Destination below for more details. */ destinations: outputs.s3tables.TableReplicationRuleDestination[]; } interface TableReplicationRuleDestination { /** * ARN of destination table bucket to replicate source tables to. */ destinationTableBucketArn: string; } } export declare namespace sagemaker { interface AlgorithmInferenceSpecification { /** * List of container definitions for inference. */ containers: outputs.sagemaker.AlgorithmInferenceSpecificationContainer[]; /** * Supported MIME types for inference requests. */ supportedContentTypes?: string[]; /** * Instance types supported for real-time inference. */ supportedRealtimeInferenceInstanceTypes?: string[]; /** * Supported MIME types for inference responses. */ supportedResponseMimeTypes?: string[]; /** * Instance types supported for batch transform. */ supportedTransformInstanceTypes?: string[]; } interface AlgorithmInferenceSpecificationContainer { /** * Additional model data to make available to the container. See Additional S3 Data Source. */ additionalS3DataSource?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerAdditionalS3DataSource; /** * Base model information for the container. See Base Model. */ baseModel?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerBaseModel; /** * DNS host name for the container. */ containerHostname?: string; /** * Environment variables to pass to the container. */ environment?: { [key: string]: string; }; /** * Machine learning framework in the container image. */ framework?: string; /** * Framework version in the container image. */ frameworkVersion?: string; /** * Container image URI. */ image?: string; /** * Digest of the container image. */ imageDigest: string; /** * Whether the container is used as a checkpoint container. */ isCheckpoint: boolean; /** * ETag for `modelDataUrl`. */ modelDataEtag?: string; /** * Source of model data for the container. See Model Data Source. */ modelDataSource?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerModelDataSource; /** * S3 or HTTPS URL of the model artifacts. */ modelDataUrl?: string; /** * Additional model input configuration. See Model Input. */ modelInput?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerModelInput; /** * Name of a pre-existing model nearest to the one being created. */ nearestModelName?: string; /** * AWS Marketplace product ID. */ productId?: string; } interface AlgorithmInferenceSpecificationContainerAdditionalS3DataSource { /** * Compression type for the data. Allowed values are: `None` and `Gzip`. */ compressionType?: string; /** * ETag of the S3 object. */ etag?: string; /** * Type of additional S3 data. */ s3DataType: string; /** * S3 or HTTPS URI for the additional data. */ s3Uri: string; } interface AlgorithmInferenceSpecificationContainerBaseModel { /** * Name of the SageMaker AI Hub content. */ hubContentName?: string; /** * Version of the SageMaker AI Hub content. */ hubContentVersion?: string; /** * Recipe name associated with the base model. */ recipeName?: string; } interface AlgorithmInferenceSpecificationContainerModelDataSource { /** * S3-backed model data source. See Model Data Source S3 Data Source. */ s3DataSource?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerModelDataSourceS3DataSource; } interface AlgorithmInferenceSpecificationContainerModelDataSourceS3DataSource { compressionType: string; etag?: string; hubAccessConfig?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerModelDataSourceS3DataSourceHubAccessConfig; /** * ETag of the manifest file. */ manifestEtag?: string; /** * S3 or HTTPS URI of the manifest file. */ manifestS3Uri?: string; modelAccessConfig?: outputs.sagemaker.AlgorithmInferenceSpecificationContainerModelDataSourceS3DataSourceModelAccessConfig; s3DataType: string; s3Uri: string; } interface AlgorithmInferenceSpecificationContainerModelDataSourceS3DataSourceHubAccessConfig { /** * ARN of the SageMaker AI Hub content. */ hubContentArn?: string; } interface AlgorithmInferenceSpecificationContainerModelDataSourceS3DataSourceModelAccessConfig { /** * Whether to accept the model end-user license agreement. */ acceptEula?: boolean; } interface AlgorithmInferenceSpecificationContainerModelInput { /** * Input configuration for the model. */ dataInputConfig?: string; } interface AlgorithmTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface AlgorithmTrainingSpecification { /** * Additional training data to make available to the algorithm. See Additional S3 Data Source. */ additionalS3DataSource?: outputs.sagemaker.AlgorithmTrainingSpecificationAdditionalS3DataSource; /** * List of metric definitions used to parse training logs. See Metric Definitions. */ metricDefinitions?: outputs.sagemaker.AlgorithmTrainingSpecificationMetricDefinition[]; /** * Hyperparameter definitions supported by the algorithm. See Supported Hyper Parameters. */ supportedHyperParameters?: outputs.sagemaker.AlgorithmTrainingSpecificationSupportedHyperParameter[]; /** * Instance types supported for training. */ supportedTrainingInstanceTypes: string[]; /** * Objective metrics supported for hyperparameter tuning jobs. See Supported Tuning Job Objective Metrics. */ supportedTuningJobObjectiveMetrics?: outputs.sagemaker.AlgorithmTrainingSpecificationSupportedTuningJobObjectiveMetric[]; /** * Whether the algorithm supports distributed training. */ supportsDistributedTraining: boolean; /** * List of channel definitions supported for training. See Training Channels. */ trainingChannels: outputs.sagemaker.AlgorithmTrainingSpecificationTrainingChannel[]; /** * Training image URI. */ trainingImage: string; /** * Digest of the training image. */ trainingImageDigest: string; } interface AlgorithmTrainingSpecificationAdditionalS3DataSource { /** * Compression type for the data. Allowed values are: `None` and `Gzip`. */ compressionType?: string; /** * ETag of the S3 object. */ etag?: string; /** * Type of additional S3 data. */ s3DataType: string; /** * S3 or HTTPS URI for the additional data. */ s3Uri: string; } interface AlgorithmTrainingSpecificationMetricDefinition { /** * Metric name. */ name: string; /** * Regular expression used to extract the metric from logs. */ regex: string; } interface AlgorithmTrainingSpecificationSupportedHyperParameter { /** * Default value for the hyperparameter. */ defaultValue?: string; /** * Description of the hyperparameter. */ description?: string; /** * Whether the hyperparameter is required. */ isRequired: boolean; /** * Whether the hyperparameter can be tuned. */ isTunable: boolean; /** * Hyperparameter name. */ name: string; /** * Allowed value range for the hyperparameter. See Parameter Range. */ range?: outputs.sagemaker.AlgorithmTrainingSpecificationSupportedHyperParameterRange; /** * Hyperparameter type. Allowed values are: `Integer`, `Continuous`, `Categorical`, and `FreeText`. */ type: string; } interface AlgorithmTrainingSpecificationSupportedHyperParameterRange { /** * Categorical range definition. See Categorical Parameter Range Specification. */ categoricalParameterRangeSpecification?: outputs.sagemaker.AlgorithmTrainingSpecificationSupportedHyperParameterRangeCategoricalParameterRangeSpecification; /** * Continuous range definition. See Continuous Parameter Range Specification. */ continuousParameterRangeSpecification?: outputs.sagemaker.AlgorithmTrainingSpecificationSupportedHyperParameterRangeContinuousParameterRangeSpecification; /** * Integer range definition. See Integer Parameter Range Specification. */ integerParameterRangeSpecification?: outputs.sagemaker.AlgorithmTrainingSpecificationSupportedHyperParameterRangeIntegerParameterRangeSpecification; } interface AlgorithmTrainingSpecificationSupportedHyperParameterRangeCategoricalParameterRangeSpecification { /** * Allowed categorical values. */ values: string[]; } interface AlgorithmTrainingSpecificationSupportedHyperParameterRangeContinuousParameterRangeSpecification { /** * Maximum allowed value. */ maxValue: string; /** * Minimum allowed value. */ minValue: string; } interface AlgorithmTrainingSpecificationSupportedHyperParameterRangeIntegerParameterRangeSpecification { /** * Maximum allowed value. */ maxValue: string; /** * Minimum allowed value. */ minValue: string; } interface AlgorithmTrainingSpecificationSupportedTuningJobObjectiveMetric { /** * Metric name. */ metricName: string; /** * Objective type. Allowed values are: `Minimize` and `Maximize`. */ type: string; } interface AlgorithmTrainingSpecificationTrainingChannel { /** * Description of the channel. */ description?: string; /** * Whether the channel is required. */ isRequired: boolean; /** * Channel name. */ name: string; /** * Supported compression types. Allowed values are: `None` and `Gzip`. */ supportedCompressionTypes?: string[]; /** * Supported input content types. */ supportedContentTypes: string[]; /** * Supported training input modes. */ supportedInputModes: string[]; } interface AlgorithmValidationSpecification { /** * Validation profiles for the algorithm. See Validation Profiles. */ validationProfiles: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfiles; /** * IAM role ARN used for validation. */ validationRole: string; } interface AlgorithmValidationSpecificationValidationProfiles { /** * Profile name. */ profileName: string; /** * Training job definition used during validation. See Training Job Definition. */ trainingJobDefinition: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinition; /** * Transform job definition used during validation. See Transform Job Definition. */ transformJobDefinition?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTransformJobDefinition; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinition { /** * Hyperparameters to pass to the training job. */ hyperParameters?: { [key: string]: string; }; /** * Input channel configuration for the validation training job. See Input Data Config. */ inputDataConfigs: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfig[]; /** * Output configuration for the validation training job. See Output Data Config. */ outputDataConfig: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionOutputDataConfig; /** * Resource configuration for the validation training job. See Resource Config. */ resourceConfig: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfig; /** * Stopping condition for the validation training job. See Stopping Condition. */ stoppingCondition: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionStoppingCondition; /** * Input mode for the validation training job. Allowed values are: `Pipe`, `File`, and `FastFile`. */ trainingInputMode: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfig { /** * Name of the channel. */ channelName: string; /** * Compression type of the input data. Allowed values are: `None` and `Gzip`. */ compressionType?: string; /** * MIME type of the input data. */ contentType?: string; /** * Source of the input data. See Data Source. */ dataSource: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSource; /** * Training input mode for the channel. Allowed values are: `Pipe`, `File`, and `FastFile`. */ inputMode: string; /** * Record wrapper type. Allowed values are: `None` and `RecordIO`. */ recordWrapperType?: string; /** * Shuffle configuration for the channel. See Shuffle Config. */ shuffleConfig?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigShuffleConfig; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSource { /** * File system-backed data source. See File System Data Source. */ fileSystemDataSource?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceFileSystemDataSource; /** * S3-backed training data source. See Training S3 Data Source. */ s3DataSource?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceS3DataSource; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceFileSystemDataSource { /** * Path to the directory in the mounted file system. */ directoryPath: string; /** * File system access mode. */ fileSystemAccessMode: string; /** * ID of the file system. */ fileSystemId: string; /** * File system type. */ fileSystemType: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceS3DataSource { /** * List of JSON attribute names to select from the input data. */ attributeNames?: string[]; hubAccessConfig?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceHubAccessConfig; /** * Instance group names associated with the data source. */ instanceGroupNames?: string[]; modelAccessConfig?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceModelAccessConfig; /** * Distribution type for S3 data. Allowed values are: `FullyReplicated` and `ShardedByS3Key`. */ s3DataDistributionType?: string; s3DataType: string; s3Uri: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceHubAccessConfig { /** * ARN of the SageMaker AI Hub content. */ hubContentArn?: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceModelAccessConfig { /** * Whether to accept the model end-user license agreement. */ acceptEula?: boolean; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionInputDataConfigShuffleConfig { /** * Shuffle seed. */ seed: number; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionOutputDataConfig { /** * Compression type for the output data. Allowed values are: `None` and `GZIP`. */ compressionType: string; /** * KMS key ID used to encrypt output data. */ kmsKeyId?: string; /** * S3 or HTTPS URI where output data is stored. */ s3OutputPath: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfig { /** * Number of training instances. */ instanceCount?: number; /** * Instance group definitions for the training job. See Instance Groups. */ instanceGroups?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfigInstanceGroup[]; /** * Placement configuration for the training job. See Instance Placement Config. */ instancePlacementConfig?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfigInstancePlacementConfig; /** * Training instance type. */ instanceType?: string; /** * Warm pool keep-alive period in seconds. */ keepAlivePeriodInSeconds: number; /** * ARN of the SageMaker AI training plan. */ trainingPlanArn?: string; /** * KMS key ID used to encrypt the training volume. */ volumeKmsKeyId?: string; /** * Size of the training volume in GiB. */ volumeSizeInGb?: number; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfigInstanceGroup { /** * Number of instances in the group. */ instanceCount: number; /** * Name of the instance group. */ instanceGroupName: string; /** * Instance type for the group. */ instanceType: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfigInstancePlacementConfig { /** * Whether multiple jobs can share the placement configuration. */ enableMultipleJobs?: boolean; /** * Placement specifications for ultra servers. See Placement Specifications. */ placementSpecifications?: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfigInstancePlacementConfigPlacementSpecification[]; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionResourceConfigInstancePlacementConfigPlacementSpecification { /** * Number of instances for the placement specification. */ instanceCount: number; /** * Ultra server ID. */ ultraServerId?: string; } interface AlgorithmValidationSpecificationValidationProfilesTrainingJobDefinitionStoppingCondition { /** * Maximum time, in seconds, a job can remain pending. */ maxPendingTimeInSeconds: number; /** * Maximum runtime, in seconds, for the training job. */ maxRuntimeInSeconds?: number; /** * Maximum wait time, in seconds, including spot interruptions. */ maxWaitTimeInSeconds: number; } interface AlgorithmValidationSpecificationValidationProfilesTransformJobDefinition { /** * Batch strategy for the transform job. Allowed values are: `MultiRecord` and `SingleRecord`. */ batchStrategy?: string; /** * Environment variables to pass to the transform container. */ environment?: { [key: string]: string; }; /** * Maximum number of parallel transform requests. */ maxConcurrentTransforms?: number; /** * Maximum payload size, in MiB, for transform requests. */ maxPayloadInMb?: number; /** * Input configuration for the transform job. See Transform Input. */ transformInput: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformInput; /** * Output configuration for the transform job. See Transform Output. */ transformOutput: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformOutput; /** * Compute resources for the transform job. See Transform Resources. */ transformResources: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformResources; } interface AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformInput { /** * Compression type of the input data. Allowed values are: `None` and `Gzip`. */ compressionType?: string; /** * MIME type of the input data. */ contentType?: string; /** * Data source for the transform job. See Transform Job Data Source. */ dataSource: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformInputDataSource; /** * Method used to split the transform input. Allowed values are: `None`, `Line`, `RecordIO`, and `TFRecord`. */ splitType?: string; } interface AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformInputDataSource { /** * S3-backed training data source. See Training S3 Data Source. */ s3DataSource: outputs.sagemaker.AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformInputDataSourceS3DataSource; } interface AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformInputDataSourceS3DataSource { s3DataType: string; s3Uri: string; } interface AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformOutput { /** * MIME type of the transform output. */ accept?: string; /** * Method used to assemble the transform output. Allowed values are: `None` and `Line`. */ assembleWith?: string; /** * KMS key ID used to encrypt transform output. */ kmsKeyId?: string; /** * S3 or HTTPS URI where transform output is stored. */ s3OutputPath: string; } interface AlgorithmValidationSpecificationValidationProfilesTransformJobDefinitionTransformResources { /** * Number of transform instances. */ instanceCount: number; /** * Transform instance type. */ instanceType: string; /** * Transform AMI version. */ transformAmiVersion?: string; /** * KMS key ID used to encrypt the transform volume. */ volumeKmsKeyId?: string; } interface AppImageConfigCodeEditorAppImageConfig { /** * The configuration used to run the application image container. See Container Config details below. */ containerConfig?: outputs.sagemaker.AppImageConfigCodeEditorAppImageConfigContainerConfig; /** * The URL where the Git repository is located. See File System Config details below. */ fileSystemConfig?: outputs.sagemaker.AppImageConfigCodeEditorAppImageConfigFileSystemConfig; } interface AppImageConfigCodeEditorAppImageConfigContainerConfig { /** * The arguments for the container when you're running the application. */ containerArguments?: string[]; /** * The entrypoint used to run the application in the container. */ containerEntrypoints?: string[]; /** * The environment variables to set in the container. */ containerEnvironmentVariables?: { [key: string]: string; }; } interface AppImageConfigCodeEditorAppImageConfigFileSystemConfig { /** * The default POSIX group ID (GID). If not specified, defaults to `100`. Valid values are `0` and `100`. */ defaultGid?: number; /** * The default POSIX user ID (UID). If not specified, defaults to `1000`. Valid values are `0` and `1000`. */ defaultUid?: number; /** * The path within the image to mount the user's EFS home directory. The directory should be empty. If not specified, defaults to `/home/sagemaker-user`. * * > **Note:** When specifying `defaultGid` and `defaultUid`, Valid value pairs are [`0`, `0`] and [`100`, `1000`]. */ mountPath?: string; } interface AppImageConfigJupyterLabImageConfig { /** * The configuration used to run the application image container. See Container Config details below. */ containerConfig?: outputs.sagemaker.AppImageConfigJupyterLabImageConfigContainerConfig; /** * The URL where the Git repository is located. See File System Config details below. */ fileSystemConfig?: outputs.sagemaker.AppImageConfigJupyterLabImageConfigFileSystemConfig; } interface AppImageConfigJupyterLabImageConfigContainerConfig { /** * The arguments for the container when you're running the application. */ containerArguments?: string[]; /** * The entrypoint used to run the application in the container. */ containerEntrypoints?: string[]; /** * The environment variables to set in the container. */ containerEnvironmentVariables?: { [key: string]: string; }; } interface AppImageConfigJupyterLabImageConfigFileSystemConfig { /** * The default POSIX group ID (GID). If not specified, defaults to `100`. Valid values are `0` and `100`. */ defaultGid?: number; /** * The default POSIX user ID (UID). If not specified, defaults to `1000`. Valid values are `0` and `1000`. */ defaultUid?: number; /** * The path within the image to mount the user's EFS home directory. The directory should be empty. If not specified, defaults to `/home/sagemaker-user`. * * > **Note:** When specifying `defaultGid` and `defaultUid`, Valid value pairs are [`0`, `0`] and [`100`, `1000`]. */ mountPath?: string; } interface AppImageConfigKernelGatewayImageConfig { /** * The URL where the Git repository is located. See File System Config details below. */ fileSystemConfig?: outputs.sagemaker.AppImageConfigKernelGatewayImageConfigFileSystemConfig; /** * The default branch for the Git repository. See Kernel Spec details below. */ kernelSpecs: outputs.sagemaker.AppImageConfigKernelGatewayImageConfigKernelSpec[]; } interface AppImageConfigKernelGatewayImageConfigFileSystemConfig { /** * The default POSIX group ID (GID). If not specified, defaults to `100`. Valid values are `0` and `100`. */ defaultGid?: number; /** * The default POSIX user ID (UID). If not specified, defaults to `1000`. Valid values are `0` and `1000`. */ defaultUid?: number; /** * The path within the image to mount the user's EFS home directory. The directory should be empty. If not specified, defaults to `/home/sagemaker-user`. * * > **Note:** When specifying `defaultGid` and `defaultUid`, Valid value pairs are [`0`, `0`] and [`100`, `1000`]. */ mountPath?: string; } interface AppImageConfigKernelGatewayImageConfigKernelSpec { /** * The display name of the kernel. */ displayName?: string; /** * The name of the kernel. */ name: string; } interface AppResourceSpec { /** * The instance type that the image version runs on. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface CodeRepositoryGitConfig { /** * The default branch for the Git repository. */ branch?: string; /** * The URL where the Git repository is located. */ repositoryUrl: string; /** * ARN of the AWS Secrets Manager secret that contains the credentials used to access the git repository. The secret must have a staging label of AWSCURRENT and must be in the following format: `{"username": UserName, "password": Password}` */ secretArn?: string; } interface DataQualityJobDefinitionDataQualityAppSpecification { /** * Sets the environment variables in the container that the monitoring job runs. A list of key value pairs. */ environment?: { [key: string]: string; }; /** * The container image that the data quality monitoring job runs. */ imageUri: string; /** * An Amazon S3 URI to a script that is called after analysis has been performed. Applicable only for the built-in (first party) containers. */ postAnalyticsProcessorSourceUri?: string; /** * An Amazon S3 URI to a script that is called per row prior to running analysis. It can base64 decode the payload and convert it into a flatted json so that the built-in container can use the converted data. Applicable only for the built-in (first party) containers. */ recordPreprocessorSourceUri?: string; } interface DataQualityJobDefinitionDataQualityBaselineConfig { /** * The constraints resource for a monitoring job. Fields are documented below. */ constraintsResource?: outputs.sagemaker.DataQualityJobDefinitionDataQualityBaselineConfigConstraintsResource; /** * The statistics resource for a monitoring job. Fields are documented below. */ statisticsResource?: outputs.sagemaker.DataQualityJobDefinitionDataQualityBaselineConfigStatisticsResource; } interface DataQualityJobDefinitionDataQualityBaselineConfigConstraintsResource { /** * The Amazon S3 URI for the constraints resource. */ s3Uri?: string; } interface DataQualityJobDefinitionDataQualityBaselineConfigStatisticsResource { /** * The Amazon S3 URI for the statistics resource. */ s3Uri?: string; } interface DataQualityJobDefinitionDataQualityJobInput { /** * Input object for the batch transform job. Fields are documented below. */ batchTransformInput?: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobInputBatchTransformInput; /** * Input object for the endpoint. Fields are documented below. */ endpointInput?: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobInputEndpointInput; } interface DataQualityJobDefinitionDataQualityJobInputBatchTransformInput { /** * The Amazon S3 location being used to capture the data. */ dataCapturedDestinationS3Uri: string; /** * The dataset format for your batch transform job. Fields are documented below. */ datasetFormat: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobInputBatchTransformInputDatasetFormat; /** * Path to the filesystem where the batch transform data is available to the container. Defaults to `/opt/ml/processing/input`. */ localPath?: string; /** * Whether input data distributed in Amazon S3 is fully replicated or sharded by an S3 key. Defaults to `FullyReplicated`. Valid values are `FullyReplicated` or `ShardedByS3Key` */ s3DataDistributionType: string; /** * Whether the `Pipe` or `File` is used as the input mode for transferring data for the monitoring job. `Pipe` mode is recommended for large datasets. `File` mode is useful for small files that fit in memory. Defaults to `File`. Valid values are `Pipe` or `File` */ s3InputMode: string; } interface DataQualityJobDefinitionDataQualityJobInputBatchTransformInputDatasetFormat { /** * The CSV dataset used in the monitoring job. Fields are documented below. */ csv?: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobInputBatchTransformInputDatasetFormatCsv; /** * The JSON dataset used in the monitoring job. Fields are documented below. */ json?: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobInputBatchTransformInputDatasetFormatJson; } interface DataQualityJobDefinitionDataQualityJobInputBatchTransformInputDatasetFormatCsv { /** * Indicates if the CSV data has a header. */ header?: boolean; } interface DataQualityJobDefinitionDataQualityJobInputBatchTransformInputDatasetFormatJson { /** * Indicates if the file should be read as a json object per line. */ line?: boolean; } interface DataQualityJobDefinitionDataQualityJobInputEndpointInput { /** * An endpoint in customer's account which has `dataCaptureConfig` enabled. */ endpointName: string; /** * Path to the filesystem where the endpoint data is available to the container. Defaults to `/opt/ml/processing/input`. */ localPath?: string; /** * Whether input data distributed in Amazon S3 is fully replicated or sharded by an S3 key. Defaults to `FullyReplicated`. Valid values are `FullyReplicated` or `ShardedByS3Key` */ s3DataDistributionType: string; /** * Whether the `Pipe` or `File` is used as the input mode for transferring data for the monitoring job. `Pipe` mode is recommended for large datasets. `File` mode is useful for small files that fit in memory. Defaults to `File`. Valid values are `Pipe` or `File` */ s3InputMode: string; } interface DataQualityJobDefinitionDataQualityJobOutputConfig { /** * KMS key that Amazon SageMaker AI uses to encrypt the model artifacts at rest using Amazon S3 server-side encryption. */ kmsKeyId?: string; /** * Monitoring outputs for monitoring jobs. This is where the output of the periodic monitoring jobs is uploaded. Fields are documented below. */ monitoringOutputs: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobOutputConfigMonitoringOutputs; } interface DataQualityJobDefinitionDataQualityJobOutputConfigMonitoringOutputs { /** * The Amazon S3 storage location where the results of a monitoring job are saved. Fields are documented below. */ s3Output: outputs.sagemaker.DataQualityJobDefinitionDataQualityJobOutputConfigMonitoringOutputsS3Output; } interface DataQualityJobDefinitionDataQualityJobOutputConfigMonitoringOutputsS3Output { /** * The local path to the Amazon S3 storage location where Amazon SageMaker AI saves the results of a monitoring job. LocalPath is an absolute path for the output data. Defaults to `/opt/ml/processing/output`. */ localPath?: string; /** * Whether to upload the results of the monitoring job continuously or after the job completes. Valid values are `Continuous` or `EndOfJob` */ s3UploadMode: string; /** * A URI that identifies the Amazon S3 storage location where Amazon SageMaker AI saves the results of a monitoring job. */ s3Uri: string; } interface DataQualityJobDefinitionJobResources { /** * The configuration for the cluster resources used to run the processing job. Fields are documented below. */ clusterConfig: outputs.sagemaker.DataQualityJobDefinitionJobResourcesClusterConfig; } interface DataQualityJobDefinitionJobResourcesClusterConfig { /** * The number of ML compute instances to use in the model monitoring job. For distributed processing jobs, specify a value greater than 1. */ instanceCount: number; /** * The ML compute instance type for the processing job. */ instanceType: string; /** * KMS key that Amazon SageMaker AI uses to encrypt data on the storage volume attached to the ML compute instance(s) that run the model monitoring job. */ volumeKmsKeyId?: string; /** * The size of the ML storage volume, in gigabytes, that you want to provision. You must specify sufficient ML storage for your scenario. */ volumeSizeInGb: number; } interface DataQualityJobDefinitionNetworkConfig { /** * Whether to encrypt all communications between the instances used for the monitoring jobs. Choose `true` to encrypt communications. Encryption provides greater security for distributed jobs, but the processing might take longer. */ enableInterContainerTrafficEncryption?: boolean; /** * Whether to allow inbound and outbound network calls to and from the containers used for the monitoring job. */ enableNetworkIsolation?: boolean; /** * Specifies a VPC that your training jobs and hosted models have access to. Control access to and from your training and model containers by configuring the VPC. Fields are documented below. */ vpcConfig?: outputs.sagemaker.DataQualityJobDefinitionNetworkConfigVpcConfig; } interface DataQualityJobDefinitionNetworkConfigVpcConfig { /** * The VPC security group IDs, in the form sg-xxxxxxxx. Specify the security groups for the VPC that is specified in the `subnets` field. */ securityGroupIds: string[]; /** * The ID of the subnets in the VPC to which you want to connect your training job or model. */ subnets: string[]; } interface DataQualityJobDefinitionStoppingCondition { /** * The maximum runtime allowed in seconds. */ maxRuntimeInSeconds: number; } interface DeviceDevice { /** * A description for the device. */ description?: string; /** * The name of the device. */ deviceName: string; /** * Amazon Web Services Internet of Things (IoT) object name. */ iotThingName?: string; } interface DeviceFleetOutputConfig { /** * KMS key that Amazon SageMaker AI uses to encrypt data on the storage volume after compilation job. If you don't provide a KMS key ID, Amazon SageMaker AI uses the default KMS key for Amazon S3 for your role's account. */ kmsKeyId?: string; /** * The Amazon Simple Storage (S3) bucker URI. */ s3OutputLocation: string; } interface DomainDefaultSpaceSettings { /** * The settings for assigning a custom file system to a user profile. Permitted users can access this file system in Amazon SageMaker AI Studio. See `customFileSystemConfig` Block below. */ customFileSystemConfigs?: outputs.sagemaker.DomainDefaultSpaceSettingsCustomFileSystemConfig[]; /** * Details about the POSIX identity that is used for file system operations. See `customPosixUserConfig` Block below. */ customPosixUserConfig?: outputs.sagemaker.DomainDefaultSpaceSettingsCustomPosixUserConfig; /** * The execution role for the space. */ executionRole: string; /** * The settings for the JupyterLab application. See `jupyterLabAppSettings` Block below. */ jupyterLabAppSettings?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettings; /** * The Jupyter server's app settings. See `jupyterServerAppSettings` Block below. */ jupyterServerAppSettings?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterServerAppSettings; /** * The kernel gateway app settings. See `kernelGatewayAppSettings` Block below. */ kernelGatewayAppSettings?: outputs.sagemaker.DomainDefaultSpaceSettingsKernelGatewayAppSettings; /** * Security groups for the VPC that the space uses for communication. */ securityGroups?: string[]; /** * The storage settings for a private space. See `spaceStorageSettings` Block below. */ spaceStorageSettings: outputs.sagemaker.DomainDefaultSpaceSettingsSpaceStorageSettings; } interface DomainDefaultSpaceSettingsCustomFileSystemConfig { /** * The default EBS storage settings for a private space. See `efsFileSystemConfig` Block below. */ efsFileSystemConfig?: outputs.sagemaker.DomainDefaultSpaceSettingsCustomFileSystemConfigEfsFileSystemConfig; } interface DomainDefaultSpaceSettingsCustomFileSystemConfigEfsFileSystemConfig { /** * The ID of your Amazon EFS file system. */ fileSystemId: string; /** * The path to the file system directory that is accessible in Amazon SageMaker AI Studio. Permitted users can access only this directory and below. */ fileSystemPath: string; } interface DomainDefaultSpaceSettingsCustomPosixUserConfig { /** * The POSIX group ID. */ gid: number; /** * The POSIX user ID. */ uid: number; } interface DomainDefaultSpaceSettingsJupyterLabAppSettings { /** * Indicates whether idle shutdown is activated for JupyterLab applications. see `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettingsAppLifecycleManagement; /** * The lifecycle configuration that runs before the default lifecycle configuration. It can override changes made in the default lifecycle configuration. */ builtInLifecycleConfigArn?: string; /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. see `codeRepository` Block below. */ codeRepositories?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettingsCodeRepository[]; /** * A list of custom SageMaker AI images that are configured to run as a JupyterLab app. see `customImage` Block below. */ customImages?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettingsDefaultResourceSpec; /** * The configuration parameters that specify the IAM roles assumed by the execution role of SageMaker AI (assumable roles) and the cluster instances or job execution environments (execution roles or runtime roles) to manage and access resources required for running Amazon EMR clusters or Amazon EMR Serverless applications. see `emrSettings` Block below. */ emrSettings?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettingsEmrSettings; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultSpaceSettingsJupyterLabAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. see `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings; } interface DomainDefaultSpaceSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; /** * Indicates whether idle shutdown is activated for the application type. Valid values are `ENABLED` and `DISABLED`. */ lifecycleManagement?: string; /** * The maximum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ maxIdleTimeoutInMinutes?: number; /** * The minimum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ minIdleTimeoutInMinutes?: number; } interface DomainDefaultSpaceSettingsJupyterLabAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface DomainDefaultSpaceSettingsJupyterLabAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface DomainDefaultSpaceSettingsJupyterLabAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultSpaceSettingsJupyterLabAppSettingsEmrSettings { /** * Array of ARNs of the IAM roles that the execution role of SageMaker AI can assume for performing operations or tasks related to Amazon EMR clusters or Amazon EMR Serverless applications. These roles define the permissions and access policies required when performing Amazon EMR-related operations, such as listing, connecting to, or terminating Amazon EMR clusters or Amazon EMR Serverless applications. They are typically used in cross-account access scenarios, where the Amazon EMR resources (clusters or serverless applications) are located in a different AWS account than the SageMaker AI domain. */ assumableRoleArns?: string[]; /** * Array of ARNs of the IAM roles used by the Amazon EMR cluster instances or job execution environments to access other AWS services and resources needed during the runtime of your Amazon EMR or Amazon EMR Serverless workloads, such as Amazon S3 for data access, Amazon CloudWatch for logging, or other AWS services based on the particular workload requirements. */ executionRoleArns?: string[]; } interface DomainDefaultSpaceSettingsJupyterServerAppSettings { /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. see `codeRepository` Block below. */ codeRepositories?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterServerAppSettingsCodeRepository[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultSpaceSettingsJupyterServerAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultSpaceSettingsJupyterServerAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface DomainDefaultSpaceSettingsJupyterServerAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultSpaceSettingsKernelGatewayAppSettings { /** * A list of custom SageMaker AI images that are configured to run as a KernelGateway app. see `customImage` Block below. */ customImages?: outputs.sagemaker.DomainDefaultSpaceSettingsKernelGatewayAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultSpaceSettingsKernelGatewayAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultSpaceSettingsKernelGatewayAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface DomainDefaultSpaceSettingsKernelGatewayAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultSpaceSettingsSpaceStorageSettings { /** * The default EBS storage settings for a private space. See `defaultEbsStorageSettings` Block below. */ defaultEbsStorageSettings?: outputs.sagemaker.DomainDefaultSpaceSettingsSpaceStorageSettingsDefaultEbsStorageSettings; } interface DomainDefaultSpaceSettingsSpaceStorageSettingsDefaultEbsStorageSettings { /** * The default size of the EBS storage volume for a private space. */ defaultEbsVolumeSizeInGb: number; /** * The maximum size of the EBS storage volume for a private space. */ maximumEbsVolumeSizeInGb: number; } interface DomainDefaultUserSettings { /** * Indicates whether auto-mounting of an EFS volume is supported for the user profile. The `DefaultAsDomain` value is only supported for user profiles. Do not use the `DefaultAsDomain` value when setting this parameter for a domain. Valid values are: `Enabled`, `Disabled`, and `DefaultAsDomain`. */ autoMountHomeEfs: string; /** * The Canvas app settings. See `canvasAppSettings` Block below. */ canvasAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettings; /** * The Code Editor application settings. See `codeEditorAppSettings` Block below. */ codeEditorAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsCodeEditorAppSettings; /** * The settings for assigning a custom file system to a user profile. Permitted users can access this file system in Amazon SageMaker AI Studio. See `customFileSystemConfig` Block below. */ customFileSystemConfigs?: outputs.sagemaker.DomainDefaultUserSettingsCustomFileSystemConfig[]; /** * Details about the POSIX identity that is used for file system operations. See `customPosixUserConfig` Block below. */ customPosixUserConfig?: outputs.sagemaker.DomainDefaultUserSettingsCustomPosixUserConfig; /** * The default experience that the user is directed to when accessing the domain. The supported values are: `studio::`: Indicates that Studio is the default experience. This value can only be passed if StudioWebPortal is set to ENABLED. `app:JupyterServer:`: Indicates that Studio Classic is the default experience. */ defaultLandingUri: string; /** * The execution role ARN for the user. */ executionRole: string; /** * The settings for the JupyterLab application. See `jupyterLabAppSettings` Block below. */ jupyterLabAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettings; /** * The Jupyter server's app settings. See `jupyterServerAppSettings` Block below. */ jupyterServerAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsJupyterServerAppSettings; /** * The kernel gateway app settings. See `kernelGatewayAppSettings` Block below. */ kernelGatewayAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsKernelGatewayAppSettings; /** * The RSession app settings. See `rSessionAppSettings` Block below. */ rSessionAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsRSessionAppSettings; /** * A collection of settings that configure user interaction with the RStudioServerPro app. See `rStudioServerProAppSettings` Block below. */ rStudioServerProAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsRStudioServerProAppSettings; /** * A list of security group IDs that will be attached to the user. */ securityGroups?: string[]; /** * The sharing settings. See `sharingSettings` Block below. */ sharingSettings?: outputs.sagemaker.DomainDefaultUserSettingsSharingSettings; /** * The storage settings for a private space. See `spaceStorageSettings` Block below. */ spaceStorageSettings: outputs.sagemaker.DomainDefaultUserSettingsSpaceStorageSettings; /** * Whether the user can access Studio. If this value is set to `DISABLED`, the user cannot access Studio, even if that is the default experience for the domain. Valid values are `ENABLED` and `DISABLED`. */ studioWebPortal: string; /** * The Studio Web Portal settings. See `studioWebPortalSettings` Block below. */ studioWebPortalSettings?: outputs.sagemaker.DomainDefaultUserSettingsStudioWebPortalSettings; /** * The TensorBoard app settings. See `tensorBoardAppSettings` Block below. */ tensorBoardAppSettings?: outputs.sagemaker.DomainDefaultUserSettingsTensorBoardAppSettings; } interface DomainDefaultUserSettingsCanvasAppSettings { /** * The model deployment settings for the SageMaker AI Canvas application. See `directDeploySettings` Block below. */ directDeploySettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsDirectDeploySettings; /** * The settings for running Amazon EMR Serverless jobs in SageMaker AI Canvas. See `emrServerlessSettings` Block below. */ emrServerlessSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsEmrServerlessSettings; generativeAiSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsGenerativeAiSettings; /** * The settings for connecting to an external data source with OAuth. See `identityProviderOauthSettings` Block below. */ identityProviderOauthSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsIdentityProviderOauthSetting[]; /** * The settings for document querying. See `kendraSettings` Block below. */ kendraSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsKendraSettings; /** * The model registry settings for the SageMaker AI Canvas application. See `modelRegisterSettings` Block below. */ modelRegisterSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsModelRegisterSettings; /** * Time series forecast settings for the Canvas app. See `timeSeriesForecastingSettings` Block below. */ timeSeriesForecastingSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsTimeSeriesForecastingSettings; /** * The workspace settings for the SageMaker AI Canvas application. See `workspaceSettings` Block below. */ workspaceSettings?: outputs.sagemaker.DomainDefaultUserSettingsCanvasAppSettingsWorkspaceSettings; } interface DomainDefaultUserSettingsCanvasAppSettingsDirectDeploySettings { /** * Describes whether model deployment permissions are enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsEmrServerlessSettings { /** * ARN of the AWS IAM role that is assumed for running Amazon EMR Serverless jobs in SageMaker AI Canvas. This role should have the necessary permissions to read and write data attached and a trust relationship with EMR Serverless. */ executionRoleArn?: string; /** * Describes whether Amazon EMR Serverless job capabilities are enabled or disabled in the SageMaker AI Canvas application. Valid values are: `ENABLED` and `DISABLED`. */ status?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsGenerativeAiSettings { amazonBedrockRoleArn?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsIdentityProviderOauthSetting { /** * The name of the data source that you're connecting to. Canvas currently supports OAuth for Snowflake and Salesforce Data Cloud. Valid values are `SalesforceGenie` and `Snowflake`. */ dataSourceName?: string; /** * The ARN of an Amazon Web Services Secrets Manager secret that stores the credentials from your identity provider, such as the client ID and secret, authorization URL, and token URL. */ secretArn: string; /** * Describes whether OAuth for a data source is enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsKendraSettings { /** * Describes whether the document querying feature is enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsModelRegisterSettings { /** * ARN of the SageMaker AI model registry account. Required only to register model versions created by a different SageMaker AI Canvas AWS account than the AWS account in which SageMaker AI model registry is set up. */ crossAccountModelRegisterRoleArn?: string; /** * Describes whether the integration to the model registry is enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsTimeSeriesForecastingSettings { /** * The IAM role that Canvas passes to Amazon Forecast for time series forecasting. By default, Canvas uses the execution role specified in the UserProfile that launches the Canvas app. If an execution role is not specified in the UserProfile, Canvas uses the execution role specified in the Domain that owns the UserProfile. To allow time series forecasting, this IAM role should have the [AmazonSageMakerCanvasForecastAccess](https://docs.aws.amazon.com/sagemaker/latest/dg/security-iam-awsmanpol-canvas.html#security-iam-awsmanpol-AmazonSageMakerCanvasForecastAccess) policy attached and forecast.amazonaws.com added in the trust relationship as a service principal. */ amazonForecastRoleArn?: string; /** * Describes whether time series forecasting is enabled or disabled in the Canvas app. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface DomainDefaultUserSettingsCanvasAppSettingsWorkspaceSettings { /** * The Amazon S3 bucket used to store artifacts generated by Canvas. Updating the Amazon S3 location impacts existing configuration settings, and Canvas users no longer have access to their artifacts. Canvas users must log out and log back in to apply the new location. */ s3ArtifactPath?: string; /** * KMS encryption key ID that is used to encrypt artifacts generated by Canvas in the Amazon S3 bucket. */ s3KmsKeyId?: string; } interface DomainDefaultUserSettingsCodeEditorAppSettings { /** * Indicates whether idle shutdown is activated for JupyterLab applications. see `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.DomainDefaultUserSettingsCodeEditorAppSettingsAppLifecycleManagement; /** * The lifecycle configuration that runs before the default lifecycle configuration. It can override changes made in the default lifecycle configuration. */ builtInLifecycleConfigArn?: string; /** * A list of custom SageMaker AI images that are configured to run as a CodeEditor app. see `customImage` Block below. */ customImages?: outputs.sagemaker.DomainDefaultUserSettingsCodeEditorAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultUserSettingsCodeEditorAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultUserSettingsCodeEditorAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. see `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.DomainDefaultUserSettingsCodeEditorAppSettingsAppLifecycleManagementIdleSettings; } interface DomainDefaultUserSettingsCodeEditorAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; /** * Indicates whether idle shutdown is activated for the application type. Valid values are `ENABLED` and `DISABLED`. */ lifecycleManagement?: string; /** * The maximum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ maxIdleTimeoutInMinutes?: number; /** * The minimum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ minIdleTimeoutInMinutes?: number; } interface DomainDefaultUserSettingsCodeEditorAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface DomainDefaultUserSettingsCodeEditorAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultUserSettingsCustomFileSystemConfig { /** * The default EBS storage settings for a private space. See `efsFileSystemConfig` Block below. */ efsFileSystemConfig?: outputs.sagemaker.DomainDefaultUserSettingsCustomFileSystemConfigEfsFileSystemConfig; } interface DomainDefaultUserSettingsCustomFileSystemConfigEfsFileSystemConfig { /** * The ID of your Amazon EFS file system. */ fileSystemId: string; /** * The path to the file system directory that is accessible in Amazon SageMaker AI Studio. Permitted users can access only this directory and below. */ fileSystemPath: string; } interface DomainDefaultUserSettingsCustomPosixUserConfig { /** * The POSIX group ID. */ gid: number; /** * The POSIX user ID. */ uid: number; } interface DomainDefaultUserSettingsJupyterLabAppSettings { /** * Indicates whether idle shutdown is activated for JupyterLab applications. see `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettingsAppLifecycleManagement; /** * The lifecycle configuration that runs before the default lifecycle configuration. It can override changes made in the default lifecycle configuration. */ builtInLifecycleConfigArn?: string; /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. see `codeRepository` Block below. */ codeRepositories?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettingsCodeRepository[]; /** * A list of custom SageMaker AI images that are configured to run as a JupyterLab app. see `customImage` Block below. */ customImages?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettingsDefaultResourceSpec; /** * The configuration parameters that specify the IAM roles assumed by the execution role of SageMaker AI (assumable roles) and the cluster instances or job execution environments (execution roles or runtime roles) to manage and access resources required for running Amazon EMR clusters or Amazon EMR Serverless applications. see `emrSettings` Block below. */ emrSettings?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettingsEmrSettings; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultUserSettingsJupyterLabAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. see `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.DomainDefaultUserSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings; } interface DomainDefaultUserSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; /** * Indicates whether idle shutdown is activated for the application type. Valid values are `ENABLED` and `DISABLED`. */ lifecycleManagement?: string; /** * The maximum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ maxIdleTimeoutInMinutes?: number; /** * The minimum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ minIdleTimeoutInMinutes?: number; } interface DomainDefaultUserSettingsJupyterLabAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface DomainDefaultUserSettingsJupyterLabAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface DomainDefaultUserSettingsJupyterLabAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultUserSettingsJupyterLabAppSettingsEmrSettings { /** * Array of ARNs of the IAM roles that the execution role of SageMaker AI can assume for performing operations or tasks related to Amazon EMR clusters or Amazon EMR Serverless applications. These roles define the permissions and access policies required when performing Amazon EMR-related operations, such as listing, connecting to, or terminating Amazon EMR clusters or Amazon EMR Serverless applications. They are typically used in cross-account access scenarios, where the Amazon EMR resources (clusters or serverless applications) are located in a different AWS account than the SageMaker AI domain. */ assumableRoleArns?: string[]; /** * Array of ARNs of the IAM roles used by the Amazon EMR cluster instances or job execution environments to access other AWS services and resources needed during the runtime of your Amazon EMR or Amazon EMR Serverless workloads, such as Amazon S3 for data access, Amazon CloudWatch for logging, or other AWS services based on the particular workload requirements. */ executionRoleArns?: string[]; } interface DomainDefaultUserSettingsJupyterServerAppSettings { /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. see `codeRepository` Block below. */ codeRepositories?: outputs.sagemaker.DomainDefaultUserSettingsJupyterServerAppSettingsCodeRepository[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultUserSettingsJupyterServerAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultUserSettingsJupyterServerAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface DomainDefaultUserSettingsJupyterServerAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultUserSettingsKernelGatewayAppSettings { /** * A list of custom SageMaker AI images that are configured to run as a KernelGateway app. see `customImage` Block below. */ customImages?: outputs.sagemaker.DomainDefaultUserSettingsKernelGatewayAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultUserSettingsKernelGatewayAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface DomainDefaultUserSettingsKernelGatewayAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface DomainDefaultUserSettingsKernelGatewayAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultUserSettingsRSessionAppSettings { /** * A list of custom SageMaker AI images that are configured to run as a RSession app. see `customImage` Block below. */ customImages?: outputs.sagemaker.DomainDefaultUserSettingsRSessionAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block above. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultUserSettingsRSessionAppSettingsDefaultResourceSpec; } interface DomainDefaultUserSettingsRSessionAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface DomainDefaultUserSettingsRSessionAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDefaultUserSettingsRStudioServerProAppSettings { /** * Indicates whether the current user has access to the RStudioServerPro app. Valid values are `ENABLED` and `DISABLED`. */ accessStatus?: string; /** * The level of permissions that the user has within the RStudioServerPro app. This value defaults to `R_STUDIO_USER`. The `R_STUDIO_ADMIN` value allows the user access to the RStudio Administrative Dashboard. Valid values are `R_STUDIO_USER` and `R_STUDIO_ADMIN`. */ userGroup?: string; } interface DomainDefaultUserSettingsSharingSettings { /** * Whether to include the notebook cell output when sharing the notebook. The default is `Disabled`. Valid values are `Allowed` and `Disabled`. */ notebookOutputOption?: string; /** * When `notebookOutputOption` is Allowed, the KMS encryption key ID used to encrypt the notebook cell output in the Amazon S3 bucket. */ s3KmsKeyId?: string; /** * When `notebookOutputOption` is Allowed, the Amazon S3 bucket used to save the notebook cell output. */ s3OutputPath?: string; } interface DomainDefaultUserSettingsSpaceStorageSettings { /** * The default EBS storage settings for a private space. See `defaultEbsStorageSettings` Block below. */ defaultEbsStorageSettings?: outputs.sagemaker.DomainDefaultUserSettingsSpaceStorageSettingsDefaultEbsStorageSettings; } interface DomainDefaultUserSettingsSpaceStorageSettingsDefaultEbsStorageSettings { /** * The default size of the EBS storage volume for a private space. */ defaultEbsVolumeSizeInGb: number; /** * The maximum size of the EBS storage volume for a private space. */ maximumEbsVolumeSizeInGb: number; } interface DomainDefaultUserSettingsStudioWebPortalSettings { /** * The Applications supported in Studio that are hidden from the Studio left navigation pane. */ hiddenAppTypes?: string[]; /** * The instance types you are hiding from the Studio user interface. */ hiddenInstanceTypes?: string[]; /** * The machine learning tools that are hidden from the Studio left navigation pane. */ hiddenMlTools?: string[]; } interface DomainDefaultUserSettingsTensorBoardAppSettings { /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block below. */ defaultResourceSpec?: outputs.sagemaker.DomainDefaultUserSettingsTensorBoardAppSettingsDefaultResourceSpec; } interface DomainDefaultUserSettingsTensorBoardAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDomainSettings { /** * A collection of settings that configure the domain’s Docker interaction. see `dockerSettings` Block below. */ dockerSettings?: outputs.sagemaker.DomainDomainSettingsDockerSettings; /** * The configuration for attaching a SageMaker AI user profile name to the execution role as a sts:SourceIdentity key [AWS Docs](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_monitor.html). Valid values are `USER_PROFILE_NAME` and `DISABLED`. */ executionRoleIdentityConfig?: string; /** * A collection of settings that configure the RStudioServerPro Domain-level app. see `rStudioServerProDomainSettings` Block below. */ rStudioServerProDomainSettings?: outputs.sagemaker.DomainDomainSettingsRStudioServerProDomainSettings; /** * Security groups for the VPC that the Domain uses for communication between Domain-level apps and user apps. */ securityGroupIds?: string[]; /** * Configuration for trusted identity propagation. See the `trustedIdentityPropagationSettings` Block below. */ trustedIdentityPropagationSettings?: outputs.sagemaker.DomainDomainSettingsTrustedIdentityPropagationSettings; } interface DomainDomainSettingsDockerSettings { /** * Indicates whether the domain can access Docker. Valid values are `ENABLED` and `DISABLED`. */ enableDockerAccess?: string; /** * The list of Amazon Web Services accounts that are trusted when the domain is created in VPC-only mode. */ vpcOnlyTrustedAccounts?: string[]; } interface DomainDomainSettingsRStudioServerProDomainSettings { /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see `defaultResourceSpec` Block above. */ defaultResourceSpec?: outputs.sagemaker.DomainDomainSettingsRStudioServerProDomainSettingsDefaultResourceSpec; /** * The ARN of the execution role for the RStudioServerPro Domain-level app. */ domainExecutionRoleArn: string; /** * A URL pointing to an RStudio Connect server. */ rStudioConnectUrl?: string; /** * A URL pointing to an RStudio Package Manager server. */ rStudioPackageManagerUrl?: string; } interface DomainDomainSettingsRStudioServerProDomainSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface DomainDomainSettingsTrustedIdentityPropagationSettings { /** * Whether to enable Trusted Identity Propagation (TIP) for the domain. Valid values are `ENABLED` and `DISABLED`. When enabled, user identities from IAM Identity Center are propagated through the domain to TIP enabled AWS services. Can only be `ENABLED` when `authMode` is `SSO`. */ status: string; } interface DomainRetentionPolicy { /** * The retention policy for data stored on an Amazon Elastic File System (EFS) volume. Valid values are `Retain` or `Delete`. Default value is `Retain`. */ homeEfsFileSystem?: string; } interface EndpointConfigurationAsyncInferenceConfig { /** * Configures the behavior of the client used by SageMaker AI to interact with the model container during asynchronous inference. */ clientConfig?: outputs.sagemaker.EndpointConfigurationAsyncInferenceConfigClientConfig; /** * Configuration for asynchronous inference invocation outputs. */ outputConfig: outputs.sagemaker.EndpointConfigurationAsyncInferenceConfigOutputConfig; } interface EndpointConfigurationAsyncInferenceConfigClientConfig { /** * Maximum number of concurrent requests sent by the SageMaker AI client to the model container. If no value is provided, SageMaker AI will choose an optimal value for you. */ maxConcurrentInvocationsPerInstance?: number; } interface EndpointConfigurationAsyncInferenceConfigOutputConfig { /** * KMS key that SageMaker AI uses to encrypt the asynchronous inference output in S3. */ kmsKeyId?: string; /** * Configuration for notifications of inference results for asynchronous inference. */ notificationConfig?: outputs.sagemaker.EndpointConfigurationAsyncInferenceConfigOutputConfigNotificationConfig; /** * S3 location to upload failure inference responses to. */ s3FailurePath?: string; /** * S3 location to upload inference responses to. */ s3OutputPath: string; } interface EndpointConfigurationAsyncInferenceConfigOutputConfigNotificationConfig { /** * SNS topic to post a notification to when inference fails. If no topic is provided, no notification is sent on failure. */ errorTopic?: string; /** * SNS topics where you want the inference response to be included. Valid values are `SUCCESS_NOTIFICATION_TOPIC` and `ERROR_NOTIFICATION_TOPIC`. */ includeInferenceResponseIns?: string[]; /** * SNS topic to post a notification to when inference completes successfully. If no topic is provided, no notification is sent on success. */ successTopic?: string; } interface EndpointConfigurationDataCaptureConfig { /** * Content type headers to capture. See `captureContentTypeHeader` below. */ captureContentTypeHeader?: outputs.sagemaker.EndpointConfigurationDataCaptureConfigCaptureContentTypeHeader; /** * What data to capture. Fields are documented below. */ captureOptions: outputs.sagemaker.EndpointConfigurationDataCaptureConfigCaptureOption[]; /** * URL for S3 location where the captured data is stored. */ destinationS3Uri: string; /** * Flag to enable data capture. Defaults to `false`. */ enableCapture?: boolean; /** * Portion of data to capture. Should be between 0 and 100. */ initialSamplingPercentage: number; /** * ARN of a KMS key that SageMaker AI uses to encrypt the captured data on S3. */ kmsKeyId?: string; } interface EndpointConfigurationDataCaptureConfigCaptureContentTypeHeader { /** * CSV content type headers to capture. One of `csvContentTypes` or `jsonContentTypes` is required. */ csvContentTypes?: string[]; /** * The JSON content type headers to capture. One of `jsonContentTypes` or `csvContentTypes` is required. */ jsonContentTypes?: string[]; } interface EndpointConfigurationDataCaptureConfigCaptureOption { /** * Data to be captured. Should be one of `Input`, `Output` or `InputAndOutput`. */ captureMode: string; } interface EndpointConfigurationProductionVariant { /** * Size of the Elastic Inference (EI) instance to use for the production variant. */ acceleratorType?: string; /** * Settings for the capacity reservation for the compute instances that SageMaker AI reserves for an endpoint. See capacityReservationConfig below. */ capacityReservationConfig?: outputs.sagemaker.EndpointConfigurationProductionVariantCapacityReservationConfig; /** * Timeout value, in seconds, for your inference container to pass health check by SageMaker AI Hosting. For more information about health check, see [How Your Container Should Respond to Health Check (Ping) Requests](https://docs.aws.amazon.com/sagemaker/latest/dg/your-algorithms-inference-code.html#your-algorithms-inference-algo-ping-requests). Valid values between `60` and `3600`. */ containerStartupHealthCheckTimeoutInSeconds?: number; /** * Core dump configuration from the model container when the process crashes. Fields are documented below. */ coreDumpConfig?: outputs.sagemaker.EndpointConfigurationProductionVariantCoreDumpConfig; /** * Whether to turn on native AWS SSM access for a production variant behind an endpoint. By default, SSM access is disabled for all production variants behind endpoints. Ignored if `modelName` is not set (Inference Components endpoint). */ enableSsmAccess?: boolean; /** * Option from a collection of preconfigured AMI images. Each image is configured by AWS with a set of software and driver versions. AWS optimizes these configurations for different machine learning workloads. */ inferenceAmiVersion?: string; /** * Initial number of instances used for auto-scaling. */ initialInstanceCount?: number; /** * Initial traffic distribution among all of the models that you specify in the endpoint configuration. If unspecified, defaults to `1.0`. Ignored if `modelName` is not set (Inference Components endpoint). */ initialVariantWeight?: number; /** * Type of instance to start. */ instanceType?: string; /** * Control the range in the number of instances that the endpoint provisions as it scales up or down to accommodate traffic. */ managedInstanceScaling?: outputs.sagemaker.EndpointConfigurationProductionVariantManagedInstanceScaling; /** * Timeout value, in seconds, to download and extract the model that you want to host from S3 to the individual inference instance associated with this production variant. Valid values between `60` and `3600`. */ modelDataDownloadTimeoutInSeconds?: number; /** * Name of the model to use. Required unless using Inference Components (in which case `executionRoleArn` must be specified at the endpoint configuration level). */ modelName?: string; /** * How the endpoint routes incoming traffic. See routingConfig below. */ routingConfigs?: outputs.sagemaker.EndpointConfigurationProductionVariantRoutingConfig[]; /** * How an endpoint performs asynchronous inference. */ serverlessConfig?: outputs.sagemaker.EndpointConfigurationProductionVariantServerlessConfig; /** * Name of the variant. If omitted, the provider will assign a random, unique name. */ variantName: string; /** * Size, in GB, of the ML storage volume attached to individual inference instance associated with the production variant. Valid values between `1` and `512`. */ volumeSizeInGb: number; } interface EndpointConfigurationProductionVariantCapacityReservationConfig { /** * Capacity reservation preference. Valid value is `capacity-reservations-only`. When set to `capacity-reservations-only`, SageMaker AI launches instances only into an ML capacity reservation; if no capacity is available, the instances fail to launch. */ capacityReservationPreference?: string; /** * ARN that uniquely identifies the ML capacity reservation that SageMaker AI applies when it deploys the endpoint. */ mlReservationArn?: string; } interface EndpointConfigurationProductionVariantCoreDumpConfig { /** * S3 bucket to send the core dump to. */ destinationS3Uri: string; /** * KMS key that SageMaker AI uses to encrypt the core dump data at rest using S3 server-side encryption. */ kmsKeyId?: string; } interface EndpointConfigurationProductionVariantManagedInstanceScaling { /** * Maximum number of instances that the endpoint can provision when it scales up to accommodate an increase in traffic. */ maxInstanceCount?: number; /** * Minimum number of instances that the endpoint must retain when it scales down to accommodate a decrease in traffic. */ minInstanceCount?: number; /** * Whether managed instance scaling is enabled. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface EndpointConfigurationProductionVariantRoutingConfig { /** * How the endpoint routes incoming traffic. Valid values are `LEAST_OUTSTANDING_REQUESTS` and `RANDOM`. `LEAST_OUTSTANDING_REQUESTS` routes requests to the specific instances that have more capacity to process them. `RANDOM` routes each request to a randomly chosen instance. */ routingStrategy: string; } interface EndpointConfigurationProductionVariantServerlessConfig { /** * Maximum number of concurrent invocations your serverless endpoint can process. Valid values are between `1` and `200`. */ maxConcurrency: number; /** * Memory size of your serverless endpoint. Valid values are in 1 GB increments: `1024` MB, `2048` MB, `3072` MB, `4096` MB, `5120` MB, or `6144` MB. */ memorySizeInMb: number; /** * Amount of provisioned concurrency to allocate for the serverless endpoint. Should be less than or equal to `maxConcurrency`. Valid values are between `1` and `200`. */ provisionedConcurrency?: number; } interface EndpointConfigurationShadowProductionVariant { /** * Size of the Elastic Inference (EI) instance to use for the production variant. */ acceleratorType?: string; /** * Settings for the capacity reservation for the compute instances that SageMaker AI reserves for an endpoint. See capacityReservationConfig below. */ capacityReservationConfig?: outputs.sagemaker.EndpointConfigurationShadowProductionVariantCapacityReservationConfig; /** * Timeout value, in seconds, for your inference container to pass health check by SageMaker AI Hosting. For more information about health check, see [How Your Container Should Respond to Health Check (Ping) Requests](https://docs.aws.amazon.com/sagemaker/latest/dg/your-algorithms-inference-code.html#your-algorithms-inference-algo-ping-requests). Valid values between `60` and `3600`. */ containerStartupHealthCheckTimeoutInSeconds?: number; /** * Core dump configuration from the model container when the process crashes. Fields are documented below. */ coreDumpConfig?: outputs.sagemaker.EndpointConfigurationShadowProductionVariantCoreDumpConfig; /** * Whether to turn on native AWS SSM access for a production variant behind an endpoint. By default, SSM access is disabled for all production variants behind endpoints. Ignored if `modelName` is not set (Inference Components endpoint). */ enableSsmAccess?: boolean; /** * Option from a collection of preconfigured AMI images. Each image is configured by AWS with a set of software and driver versions. AWS optimizes these configurations for different machine learning workloads. */ inferenceAmiVersion?: string; /** * Initial number of instances used for auto-scaling. */ initialInstanceCount?: number; /** * Initial traffic distribution among all of the models that you specify in the endpoint configuration. If unspecified, defaults to `1.0`. Ignored if `modelName` is not set (Inference Components endpoint). */ initialVariantWeight?: number; /** * Type of instance to start. */ instanceType?: string; /** * Control the range in the number of instances that the endpoint provisions as it scales up or down to accommodate traffic. */ managedInstanceScaling?: outputs.sagemaker.EndpointConfigurationShadowProductionVariantManagedInstanceScaling; /** * Timeout value, in seconds, to download and extract the model that you want to host from S3 to the individual inference instance associated with this production variant. Valid values between `60` and `3600`. */ modelDataDownloadTimeoutInSeconds?: number; /** * Name of the model to use. Required unless using Inference Components (in which case `executionRoleArn` must be specified at the endpoint configuration level). */ modelName?: string; /** * How the endpoint routes incoming traffic. See routingConfig below. */ routingConfigs?: outputs.sagemaker.EndpointConfigurationShadowProductionVariantRoutingConfig[]; /** * How an endpoint performs asynchronous inference. */ serverlessConfig?: outputs.sagemaker.EndpointConfigurationShadowProductionVariantServerlessConfig; /** * Name of the variant. If omitted, the provider will assign a random, unique name. */ variantName: string; /** * Size, in GB, of the ML storage volume attached to individual inference instance associated with the production variant. Valid values between `1` and `512`. */ volumeSizeInGb?: number; } interface EndpointConfigurationShadowProductionVariantCapacityReservationConfig { /** * Capacity reservation preference. Valid value is `capacity-reservations-only`. When set to `capacity-reservations-only`, SageMaker AI launches instances only into an ML capacity reservation; if no capacity is available, the instances fail to launch. */ capacityReservationPreference?: string; /** * ARN that uniquely identifies the ML capacity reservation that SageMaker AI applies when it deploys the endpoint. */ mlReservationArn?: string; } interface EndpointConfigurationShadowProductionVariantCoreDumpConfig { /** * S3 bucket to send the core dump to. */ destinationS3Uri: string; /** * KMS key that SageMaker AI uses to encrypt the core dump data at rest using S3 server-side encryption. */ kmsKeyId: string; } interface EndpointConfigurationShadowProductionVariantManagedInstanceScaling { /** * Maximum number of instances that the endpoint can provision when it scales up to accommodate an increase in traffic. */ maxInstanceCount?: number; /** * Minimum number of instances that the endpoint must retain when it scales down to accommodate a decrease in traffic. */ minInstanceCount?: number; /** * Whether managed instance scaling is enabled. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface EndpointConfigurationShadowProductionVariantRoutingConfig { /** * How the endpoint routes incoming traffic. Valid values are `LEAST_OUTSTANDING_REQUESTS` and `RANDOM`. `LEAST_OUTSTANDING_REQUESTS` routes requests to the specific instances that have more capacity to process them. `RANDOM` routes each request to a randomly chosen instance. */ routingStrategy: string; } interface EndpointConfigurationShadowProductionVariantServerlessConfig { /** * Maximum number of concurrent invocations your serverless endpoint can process. Valid values are between `1` and `200`. */ maxConcurrency: number; /** * Memory size of your serverless endpoint. Valid values are in 1 GB increments: `1024` MB, `2048` MB, `3072` MB, `4096` MB, `5120` MB, or `6144` MB. */ memorySizeInMb: number; /** * Amount of provisioned concurrency to allocate for the serverless endpoint. Should be less than or equal to `maxConcurrency`. Valid values are between `1` and `200`. */ provisionedConcurrency?: number; } interface EndpointDeploymentConfig { /** * Automatic rollback configuration for handling endpoint deployment failures and recovery. See Auto Rollback Configuration. */ autoRollbackConfiguration?: outputs.sagemaker.EndpointDeploymentConfigAutoRollbackConfiguration; /** * Update policy for a blue/green deployment. If this update policy is specified, SageMaker AI creates a new fleet during the deployment while maintaining the old fleet. SageMaker AI flips traffic to the new fleet according to the specified traffic routing configuration. Only one update policy should be used in the deployment configuration. If no update policy is specified, SageMaker AI uses a blue/green deployment strategy with all at once traffic shifting by default. See Blue Green Update Config. */ blueGreenUpdatePolicy?: outputs.sagemaker.EndpointDeploymentConfigBlueGreenUpdatePolicy; /** * Specifies a rolling deployment strategy for updating a SageMaker AI endpoint. See Rolling Update Policy. */ rollingUpdatePolicy?: outputs.sagemaker.EndpointDeploymentConfigRollingUpdatePolicy; } interface EndpointDeploymentConfigAutoRollbackConfiguration { /** * List of CloudWatch alarms in your account that are configured to monitor metrics on an endpoint. If any alarms are tripped during a deployment, SageMaker AI rolls back the deployment. See Alarms. */ alarms?: outputs.sagemaker.EndpointDeploymentConfigAutoRollbackConfigurationAlarm[]; } interface EndpointDeploymentConfigAutoRollbackConfigurationAlarm { /** * The name of a CloudWatch alarm in your account. */ alarmName: string; } interface EndpointDeploymentConfigBlueGreenUpdatePolicy { maximumExecutionTimeoutInSeconds?: number; /** * Additional waiting time in seconds after the completion of an endpoint deployment before terminating the old endpoint fleet. Default is `0`. Valid values are between `0` and `3600`. */ terminationWaitInSeconds?: number; /** * Defines the traffic routing strategy to shift traffic from the old fleet to the new fleet during an endpoint deployment. See Traffic Routing Configuration. */ trafficRoutingConfiguration: outputs.sagemaker.EndpointDeploymentConfigBlueGreenUpdatePolicyTrafficRoutingConfiguration; } interface EndpointDeploymentConfigBlueGreenUpdatePolicyTrafficRoutingConfiguration { /** * Batch size for the first step to turn on traffic on the new endpoint fleet. Value must be less than or equal to 50% of the variant's total instance count. See Canary Size. */ canarySize?: outputs.sagemaker.EndpointDeploymentConfigBlueGreenUpdatePolicyTrafficRoutingConfigurationCanarySize; /** * Batch size for each step to turn on traffic on the new endpoint fleet. Value must be 10-50% of the variant's total instance count. See Linear Step Size. */ linearStepSize?: outputs.sagemaker.EndpointDeploymentConfigBlueGreenUpdatePolicyTrafficRoutingConfigurationLinearStepSize; /** * Traffic routing strategy type. Valid values are: `ALL_AT_ONCE`, `CANARY`, and `LINEAR`. */ type: string; /** * The waiting time (in seconds) between incremental steps to turn on traffic on the new endpoint fleet. Valid values are between `0` and `3600`. */ waitIntervalInSeconds: number; } interface EndpointDeploymentConfigBlueGreenUpdatePolicyTrafficRoutingConfigurationCanarySize { /** * Specifies the endpoint capacity type. Valid values are: `INSTANCE_COUNT`, or `CAPACITY_PERCENT`. */ type: string; /** * Defines the capacity size, either as a number of instances or a capacity percentage. */ value: number; } interface EndpointDeploymentConfigBlueGreenUpdatePolicyTrafficRoutingConfigurationLinearStepSize { /** * Specifies the endpoint capacity type. Valid values are: `INSTANCE_COUNT`, or `CAPACITY_PERCENT`. */ type: string; /** * Defines the capacity size, either as a number of instances or a capacity percentage. */ value: number; } interface EndpointDeploymentConfigRollingUpdatePolicy { /** * Batch size for each rolling step to provision capacity and turn on traffic on the new endpoint fleet, and terminate capacity on the old endpoint fleet. Value must be between 5% to 50% of the variant's total instance count. See Maximum Batch Size. */ maximumBatchSize: outputs.sagemaker.EndpointDeploymentConfigRollingUpdatePolicyMaximumBatchSize; /** * The time limit for the total deployment. Exceeding this limit causes a timeout. Valid values are between `600` and `14400`. */ maximumExecutionTimeoutInSeconds?: number; /** * Batch size for rollback to the old endpoint fleet. Each rolling step to provision capacity and turn on traffic on the old endpoint fleet, and terminate capacity on the new endpoint fleet. If this field is absent, the default value will be set to 100% of total capacity which means to bring up the whole capacity of the old fleet at once during rollback. See Rollback Maximum Batch Size. */ rollbackMaximumBatchSize?: outputs.sagemaker.EndpointDeploymentConfigRollingUpdatePolicyRollbackMaximumBatchSize; /** * The length of the baking period, during which SageMaker AI monitors alarms for each batch on the new fleet. Valid values are between `0` and `3600`. */ waitIntervalInSeconds: number; } interface EndpointDeploymentConfigRollingUpdatePolicyMaximumBatchSize { /** * Specifies the endpoint capacity type. Valid values are: `INSTANCE_COUNT`, or `CAPACITY_PERCENT`. */ type: string; /** * Defines the capacity size, either as a number of instances or a capacity percentage. */ value: number; } interface EndpointDeploymentConfigRollingUpdatePolicyRollbackMaximumBatchSize { /** * Specifies the endpoint capacity type. Valid values are: `INSTANCE_COUNT`, or `CAPACITY_PERCENT`. */ type: string; /** * Defines the capacity size, either as a number of instances or a capacity percentage. */ value: number; } interface FeatureGroupFeatureDefinition { collectionConfig?: outputs.sagemaker.FeatureGroupFeatureDefinitionCollectionConfig; collectionType?: string; /** * The name of a feature. `featureName` cannot be any of the following: `isDeleted`, `writeTime`, `apiInvocationTime`. */ featureName?: string; /** * The value type of a feature. Valid values are `Integral`, `Fractional`, or `String`. */ featureType?: string; } interface FeatureGroupFeatureDefinitionCollectionConfig { vectorConfig?: outputs.sagemaker.FeatureGroupFeatureDefinitionCollectionConfigVectorConfig; } interface FeatureGroupFeatureDefinitionCollectionConfigVectorConfig { dimension?: number; } interface FeatureGroupOfflineStoreConfig { /** * The meta data of the Glue table that is autogenerated when an OfflineStore is created. See Data Catalog Config Below. */ dataCatalogConfig: outputs.sagemaker.FeatureGroupOfflineStoreConfigDataCatalogConfig; /** * Set to `true` to turn Online Store On. */ disableGlueTableCreation?: boolean; /** * The Amazon Simple Storage (Amazon S3) location of OfflineStore. See S3 Storage Config Below. */ s3StorageConfig: outputs.sagemaker.FeatureGroupOfflineStoreConfigS3StorageConfig; /** * Format for the offline store table. Supported formats are `Glue` (Default) and Apache `Iceberg` (https://iceberg.apache.org/). */ tableFormat?: string; } interface FeatureGroupOfflineStoreConfigDataCatalogConfig { /** * The name of the Glue table catalog. */ catalog: string; /** * The name of the Glue table database. */ database: string; /** * The name of the Glue table. */ tableName: string; } interface FeatureGroupOfflineStoreConfigS3StorageConfig { /** * KMS key ID of the key used to encrypt any objects written into the OfflineStore S3 location. */ kmsKeyId?: string; /** * The S3 path where offline records are written. */ resolvedOutputS3Uri: string; /** * The S3 URI, or location in Amazon S3, of OfflineStore. */ s3Uri: string; } interface FeatureGroupOnlineStoreConfig { /** * Set to `true` to disable the automatic creation of an AWS Glue table when configuring an OfflineStore. */ enableOnlineStore?: boolean; /** * Security config for at-rest encryption of your OnlineStore. See Security Config Below. */ securityConfig?: outputs.sagemaker.FeatureGroupOnlineStoreConfigSecurityConfig; /** * Option for different tiers of low latency storage for real-time data retrieval. Valid values are `Standard`, or `InMemory`. */ storageType?: string; /** * Time to live duration, where the record is hard deleted after the expiration time is reached; ExpiresAt = EventTime + TtlDuration.. See TTl Duration Below. */ ttlDuration?: outputs.sagemaker.FeatureGroupOnlineStoreConfigTtlDuration; } interface FeatureGroupOnlineStoreConfigSecurityConfig { /** * ID of the KMS key that SageMaker AI Feature Store uses to encrypt the Amazon S3 objects at rest using Amazon S3 server-side encryption. */ kmsKeyId?: string; } interface FeatureGroupOnlineStoreConfigTtlDuration { /** * TtlDuration time unit. Valid values are `Seconds`, `Minutes`, `Hours`, `Days`, or `Weeks`. */ unit?: string; /** * TtlDuration time value. */ value?: number; } interface FeatureGroupThroughputConfig { provisionedReadCapacityUnits?: number; provisionedWriteCapacityUnits?: number; throughputMode: string; } interface FlowDefinitionHumanLoopActivationConfig { /** * defines under what conditions SageMaker AI creates a human loop. See Human Loop Activation Conditions Config details below. */ humanLoopActivationConditionsConfig?: outputs.sagemaker.FlowDefinitionHumanLoopActivationConfigHumanLoopActivationConditionsConfig; } interface FlowDefinitionHumanLoopActivationConfigHumanLoopActivationConditionsConfig { /** * A JSON expressing use-case specific conditions declaratively. If any condition is matched, atomic tasks are created against the configured work team. For more information about how to structure the JSON, see [JSON Schema for Human Loop Activation Conditions in Amazon Augmented AI](https://docs.aws.amazon.com/sagemaker/latest/dg/a2i-human-fallback-conditions-json-schema.html). */ humanLoopActivationConditions: string; } interface FlowDefinitionHumanLoopConfig { /** * ARN of the human task user interface. */ humanTaskUiArn: string; /** * Defines the amount of money paid to an Amazon Mechanical Turk worker for each task performed. See Public Workforce Task Price details below. */ publicWorkforceTaskPrice?: outputs.sagemaker.FlowDefinitionHumanLoopConfigPublicWorkforceTaskPrice; /** * The length of time that a task remains available for review by human workers. Valid value range between `1` and `864000`. */ taskAvailabilityLifetimeInSeconds?: number; /** * The number of distinct workers who will perform the same task on each object. Valid value range between `1` and `3`. */ taskCount: number; /** * A description for the human worker task. */ taskDescription: string; /** * An array of keywords used to describe the task so that workers can discover the task. */ taskKeywords?: string[]; /** * The amount of time that a worker has to complete a task. The default value is `3600` seconds. */ taskTimeLimitInSeconds?: number; /** * A title for the human worker task. */ taskTitle: string; /** * ARN of the human task user interface. ARN of a team of workers. For Public workforces see [AWS Docs](https://docs.aws.amazon.com/sagemaker/latest/dg/sms-workforce-management-public.html). */ workteamArn: string; } interface FlowDefinitionHumanLoopConfigPublicWorkforceTaskPrice { /** * Defines the amount of money paid to an Amazon Mechanical Turk worker in United States dollars. See Amount In Usd details below. */ amountInUsd?: outputs.sagemaker.FlowDefinitionHumanLoopConfigPublicWorkforceTaskPriceAmountInUsd; } interface FlowDefinitionHumanLoopConfigPublicWorkforceTaskPriceAmountInUsd { /** * The fractional portion, in cents, of the amount. Valid value range between `0` and `99`. */ cents?: number; /** * The whole number of dollars in the amount. Valid value range between `0` and `2`. */ dollars?: number; /** * Fractions of a cent, in tenths. Valid value range between `0` and `9`. */ tenthFractionsOfACent?: number; } interface FlowDefinitionHumanLoopRequestSource { /** * Specifies whether Amazon Rekognition or Amazon Textract are used as the integration source. Valid values are: `AWS/Rekognition/DetectModerationLabels/Image/V3` and `AWS/Textract/AnalyzeDocument/Forms/V1`. */ awsManagedHumanLoopRequestSource: string; } interface FlowDefinitionOutputConfig { /** * KMS key ARN for server-side encryption. */ kmsKeyId?: string; /** * The Amazon S3 path where the object containing human output will be made available. */ s3OutputPath: string; } interface HubContentReferenceTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface HubS3StorageConfig { /** * The Amazon S3 bucket prefix for hosting hub content.interface. */ s3OutputPath?: string; } interface HumanTaskUIUiTemplate { /** * The content of the Liquid template for the worker user interface. */ content?: string; /** * The SHA-256 digest of the contents of the template. */ contentSha256: string; /** * The URL for the user interface template. */ url: string; } interface HyperParameterTuningJobAutotune { /** * Autotune mode. Valid value is `Enabled`. */ mode: string; } interface HyperParameterTuningJobConfig { /** * Objective metric used by tuning. See `objective`. */ objective?: outputs.sagemaker.HyperParameterTuningJobConfigObjective; /** * Hyperparameter search ranges. See `parameterRanges`. */ parameterRanges?: outputs.sagemaker.HyperParameterTuningJobConfigParameterRanges; /** * Random seed for tuning. */ randomSeed?: number; /** * Training job limits for tuning. See `resourceLimits`. */ resourceLimits: outputs.sagemaker.HyperParameterTuningJobConfigResourceLimits; /** * Search strategy for tuning. */ strategy: string; /** * Extra strategy options. See `strategyConfig`. */ strategyConfig?: outputs.sagemaker.HyperParameterTuningJobConfigStrategyConfig; /** * Early stopping behavior for training jobs. */ trainingJobEarlyStoppingType: string; /** * Conditions to complete tuning. See `tuningJobCompletionCriteria`. */ tuningJobCompletionCriteria?: outputs.sagemaker.HyperParameterTuningJobConfigTuningJobCompletionCriteria; } interface HyperParameterTuningJobConfigObjective { /** * Metric name that tuning tries to optimize. */ metricName: string; /** * Optimization direction. Valid values include `Minimize` and `Maximize`. */ type: string; } interface HyperParameterTuningJobConfigParameterRanges { /** * Parameter list for automatic range selection. */ autoParameters?: outputs.sagemaker.HyperParameterTuningJobConfigParameterRangesAutoParameter[]; /** * Categorical parameter ranges. */ categoricalParameterRanges?: outputs.sagemaker.HyperParameterTuningJobConfigParameterRangesCategoricalParameterRange[]; /** * Continuous parameter ranges. */ continuousParameterRanges?: outputs.sagemaker.HyperParameterTuningJobConfigParameterRangesContinuousParameterRange[]; /** * Integer parameter ranges. */ integerParameterRanges?: outputs.sagemaker.HyperParameterTuningJobConfigParameterRangesIntegerParameterRange[]; } interface HyperParameterTuningJobConfigParameterRangesAutoParameter { /** * Parameter name. */ name: string; /** * Value hint for the parameter. */ valueHint: string; } interface HyperParameterTuningJobConfigParameterRangesCategoricalParameterRange { /** * Parameter name. */ name: string; /** * Set of allowed values. */ values: string[]; } interface HyperParameterTuningJobConfigParameterRangesContinuousParameterRange { /** * Maximum value. */ maxValue: string; /** * Minimum value. */ minValue: string; /** * Parameter name. */ name: string; /** * Scaling rule for the range. */ scalingType: string; } interface HyperParameterTuningJobConfigParameterRangesIntegerParameterRange { /** * Maximum value. */ maxValue: string; /** * Minimum value. */ minValue: string; /** * Parameter name. */ name: string; /** * Scaling rule for the range. */ scalingType: string; } interface HyperParameterTuningJobConfigResourceLimits { /** * Maximum total training jobs. */ maxNumberOfTrainingJobs: number; /** * Maximum parallel training jobs. */ maxParallelTrainingJobs: number; /** * Maximum total runtime in seconds. */ maxRuntimeInSeconds: number; } interface HyperParameterTuningJobConfigStrategyConfig { /** * Hyperband strategy settings. See `hyperbandStrategyConfig`. */ hyperbandStrategyConfig?: outputs.sagemaker.HyperParameterTuningJobConfigStrategyConfigHyperbandStrategyConfig; } interface HyperParameterTuningJobConfigStrategyConfigHyperbandStrategyConfig { /** * Upper bound for resource allocation. */ maxResource?: number; /** * Lower bound for resource allocation. */ minResource?: number; } interface HyperParameterTuningJobConfigTuningJobCompletionCriteria { /** * Stop condition for non-improving jobs. See `bestObjectiveNotImproving`. */ bestObjectiveNotImproving?: outputs.sagemaker.HyperParameterTuningJobConfigTuningJobCompletionCriteriaBestObjectiveNotImproving; /** * Stop condition based on convergence. See `convergenceDetected`. */ convergenceDetected?: outputs.sagemaker.HyperParameterTuningJobConfigTuningJobCompletionCriteriaConvergenceDetected; /** * Target metric value that can stop tuning. */ targetObjectiveMetricValue?: number; } interface HyperParameterTuningJobConfigTuningJobCompletionCriteriaBestObjectiveNotImproving { /** * Maximum training jobs without improvement before completion. */ maxNumberOfTrainingJobsNotImproving: number; } interface HyperParameterTuningJobConfigTuningJobCompletionCriteriaConvergenceDetected { /** * Whether to complete tuning when convergence is detected. */ completeOnConvergence?: string; } interface HyperParameterTuningJobTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface HyperParameterTuningJobTrainingJobDefinition { /** * Algorithm settings. See `algorithmSpecification`. */ algorithmSpecification: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionAlgorithmSpecification; /** * Checkpoint output location. See `checkpointConfig`. */ checkpointConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionCheckpointConfig; /** * Name for this definition. */ definitionName?: string; /** * Whether to encrypt traffic between containers. */ enableInterContainerTrafficEncryption: boolean; /** * Whether to use managed spot training. */ enableManagedSpotTraining: boolean; /** * Whether to isolate network access for containers. */ enableNetworkIsolation: boolean; /** * Map of environment variables. */ environment?: { [key: string]: string; }; /** * Hyperparameter ranges for this definition. See `parameterRanges`. */ hyperParameterRanges?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterRanges; /** * Tuning resource settings. See `hyperParameterTuningResourceConfig`. */ hyperParameterTuningResourceConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterTuningResourceConfig; /** * Input data channels. See `inputDataConfig`. */ inputDataConfigs?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfig[]; /** * Output data settings. See `outputDataConfig`. */ outputDataConfig: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionOutputDataConfig; /** * Training resources. See `resourceConfig`. */ resourceConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionResourceConfig; /** * Retry settings. See `retryStrategy`. */ retryStrategies: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionRetryStrategy[]; /** * IAM role ARN used by SageMaker AI. */ roleArn: string; /** * Map of fixed hyperparameters. */ staticHyperParameters: { [key: string]: string; }; /** * Stopping settings. See `stoppingCondition`. */ stoppingCondition: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionStoppingCondition; /** * Objective for this training definition. See `tuningObjective`. */ tuningObjective?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionTuningObjective; /** * VPC settings. See `vpcConfig`. */ vpcConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionVpcConfig; } interface HyperParameterTuningJobTrainingJobDefinitionAlgorithmSpecification { /** * SageMaker algorithm ARN. */ algorithmName: string; /** * Metric extraction rules. */ metricDefinitions?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionAlgorithmSpecificationMetricDefinition[]; /** * Container image used for training. */ trainingImage: string; /** * Training input mode. * * Provide exactly one of `algorithmName` or `trainingImage`. */ trainingInputMode: string; } interface HyperParameterTuningJobTrainingJobDefinitionAlgorithmSpecificationMetricDefinition { /** * Metric name. */ name: string; /** * Pattern used to extract metric values. */ regex: string; } interface HyperParameterTuningJobTrainingJobDefinitionCheckpointConfig { /** * Local path for checkpoints. */ localPath?: string; /** * S3 or HTTPS destination for checkpoints. */ s3Uri: string; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterRanges { /** * Parameter list for automatic range selection. */ autoParameters?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesAutoParameter[]; /** * Categorical parameter ranges. */ categoricalParameterRanges?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesCategoricalParameterRange[]; /** * Continuous parameter ranges. */ continuousParameterRanges?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesContinuousParameterRange[]; /** * Integer parameter ranges. */ integerParameterRanges?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesIntegerParameterRange[]; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesAutoParameter { /** * Parameter name. */ name: string; /** * Value hint for the parameter. */ valueHint: string; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesCategoricalParameterRange { /** * Parameter name. */ name: string; /** * Set of allowed values. */ values: string[]; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesContinuousParameterRange { /** * Maximum value. */ maxValue: string; /** * Minimum value. */ minValue: string; /** * Parameter name. */ name: string; /** * Scaling rule for the range. */ scalingType: string; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterRangesIntegerParameterRange { /** * Maximum value. */ maxValue: string; /** * Minimum value. */ minValue: string; /** * Parameter name. */ name: string; /** * Scaling rule for the range. */ scalingType: string; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterTuningResourceConfig { /** * Allocation strategy for tuning resources. */ allocationStrategy?: string; /** * Per-instance-type resource settings. See `instanceConfigs`. */ instanceConfigs?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionHyperParameterTuningResourceConfigInstanceConfig[]; /** * Number of training instances. */ instanceCount?: number; /** * Training instance type. */ instanceType?: string; /** * KMS key ID for volume encryption. */ volumeKmsKeyId?: string; /** * Volume size in GB. * * Do not set `instanceCount`, `instanceType`, or `volumeSizeInGb` when `instanceConfigs` is set. */ volumeSizeInGb?: number; } interface HyperParameterTuningJobTrainingJobDefinitionHyperParameterTuningResourceConfigInstanceConfig { /** * Number of instances. */ instanceCount?: number; /** * Instance type. */ instanceType?: string; /** * Volume size in GB. */ volumeSizeInGb?: number; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfig { /** * Input channel name. */ channelName: string; /** * Compression type. */ compressionType?: string; /** * Content type string. */ contentType?: string; /** * Data source settings. See `dataSource`. */ dataSource: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSource; /** * Input mode. */ inputMode?: string; /** * Record wrapper format. */ recordWrapperType?: string; /** * Shuffling settings. See `shuffleConfig`. */ shuffleConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfigShuffleConfig; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSource { /** * File system source settings. See `fileSystemDataSource`. */ fileSystemDataSource?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceFileSystemDataSource; /** * S3 source settings. See `s3DataSource`. */ s3DataSource?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceS3DataSource; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceFileSystemDataSource { /** * Directory path in the file system. */ directoryPath: string; /** * Access mode for the file system. */ fileSystemAccessMode: string; /** * File system ID. */ fileSystemId: string; /** * File system type. */ fileSystemType: string; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceS3DataSource { /** * Attribute names for Pipe mode. */ attributeNames?: string[]; /** * Hub access settings. See `hubAccessConfig`. */ hubAccessConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceHubAccessConfig; /** * Instance group names used with this channel. */ instanceGroupNames?: string[]; /** * Model access settings. See `modelAccessConfig`. */ modelAccessConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceModelAccessConfig; /** * Distribution mode for S3 data. */ s3DataDistributionType?: string; /** * S3 data type. */ s3DataType: string; /** * S3 or HTTPS source URI. */ s3Uri: string; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceHubAccessConfig { /** * Hub content ARN. */ hubContentArn: string; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfigDataSourceS3DataSourceModelAccessConfig { /** * Whether to accept model EULA. Value must be `true`. */ acceptEula: boolean; } interface HyperParameterTuningJobTrainingJobDefinitionInputDataConfigShuffleConfig { /** * Shuffle seed. */ seed: number; } interface HyperParameterTuningJobTrainingJobDefinitionOutputDataConfig { /** * Compression type for output. */ compressionType?: string; /** * KMS key ID for output encryption. */ kmsKeyId?: string; /** * S3 or HTTPS output path. */ s3OutputPath: string; } interface HyperParameterTuningJobTrainingJobDefinitionResourceConfig { /** * Number of instances. */ instanceCount?: number; /** * Instance group settings. See `instanceGroups`. */ instanceGroups?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionResourceConfigInstanceGroup[]; /** * Placement settings. See `instancePlacementConfig`. */ instancePlacementConfig?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionResourceConfigInstancePlacementConfig; /** * Instance type. */ instanceType?: string; /** * Warm pool keep-alive period in seconds. */ keepAlivePeriodInSeconds?: number; /** * Training plan ARN. */ trainingPlanArn?: string; /** * KMS key ID for volume encryption. */ volumeKmsKeyId?: string; /** * Volume size in GB. */ volumeSizeInGb?: number; } interface HyperParameterTuningJobTrainingJobDefinitionResourceConfigInstanceGroup { /** * Number of instances in the group. */ instanceCount: number; /** * Name of the group. */ instanceGroupName: string; /** * Instance type. */ instanceType: string; } interface HyperParameterTuningJobTrainingJobDefinitionResourceConfigInstancePlacementConfig { /** * Whether to run multiple jobs on shared infrastructure. */ enableMultipleJobs?: boolean; /** * Placement details. See `placementSpecifications`. */ placementSpecifications?: outputs.sagemaker.HyperParameterTuningJobTrainingJobDefinitionResourceConfigInstancePlacementConfigPlacementSpecification[]; } interface HyperParameterTuningJobTrainingJobDefinitionResourceConfigInstancePlacementConfigPlacementSpecification { /** * Number of instances in this placement item. */ instanceCount: number; /** * UltraServer ID. */ ultraServerId?: string; } interface HyperParameterTuningJobTrainingJobDefinitionRetryStrategy { /** * Maximum retry attempts. */ maximumRetryAttempts: number; } interface HyperParameterTuningJobTrainingJobDefinitionStoppingCondition { /** * Maximum pending time in seconds. */ maxPendingTimeInSeconds?: number; /** * Maximum runtime in seconds. */ maxRuntimeInSeconds?: number; /** * Maximum wait time in seconds. */ maxWaitTimeInSeconds?: number; } interface HyperParameterTuningJobTrainingJobDefinitionTuningObjective { /** * Metric name for objective. */ metricName: string; /** * Optimization direction. Valid values include `Minimize` and `Maximize`. */ type: string; } interface HyperParameterTuningJobTrainingJobDefinitionVpcConfig { /** * Security group IDs. */ securityGroupIds: string[]; /** * Subnet IDs. */ subnets: string[]; } interface HyperParameterTuningJobWarmStartConfig { /** * Parent tuning jobs for warm start. */ parentHyperParameterTuningJobs?: outputs.sagemaker.HyperParameterTuningJobWarmStartConfigParentHyperParameterTuningJob[]; /** * Warm start mode. */ warmStartType?: string; } interface HyperParameterTuningJobWarmStartConfigParentHyperParameterTuningJob { /** * Parent tuning job name. */ name: string; } interface LabelingJobHumanTaskConfig { /** * How labels are consolidated across human workers. Fields are documented below. */ annotationConsolidationConfig?: outputs.sagemaker.LabelingJobHumanTaskConfigAnnotationConsolidationConfig; /** * Maximum number of data objects that can be labeled by human workers at the same time. */ maxConcurrentTaskCount: number; /** * Number of human workers that will label an object. */ numberOfHumanWorkersPerDataObject: number; /** * ARN of a Lambda function that is run before a data object is sent to a human worker. */ preHumanTaskLambdaArn?: string; /** * Price to pay for each task performed by an Amazon Mechanical Turk worker. Fields are documented below. */ publicWorkforceTaskPrice?: outputs.sagemaker.LabelingJobHumanTaskConfigPublicWorkforceTaskPrice; /** * length of time that a task remains available for labeling by human workers. */ taskAvailabilityLifetimeInSeconds: number; /** * Description of the task. */ taskDescription: string; /** * Keywords used to describe the task. */ taskKeywords?: string[]; /** * Amount of time that a worker has to complete a task. */ taskTimeLimitInSeconds: number; /** * Title for the task. */ taskTitle: string; /** * Information about the user interface that workers use to complete the labeling task. Fields are documented below. */ uiConfig: outputs.sagemaker.LabelingJobHumanTaskConfigUiConfig; /** * ARN of the work team assigned to complete the tasks. */ workteamArn: string; } interface LabelingJobHumanTaskConfigAnnotationConsolidationConfig { /** * ARN of a Lambda function that implements the logic for annotation consolidation and to process output data. */ annotationConsolidationLambdaArn: string; } interface LabelingJobHumanTaskConfigPublicWorkforceTaskPrice { /** * Amount of money paid to an Amazon Mechanical Turk worker in United States dollars. Fields are documented below. */ amountInUsd?: outputs.sagemaker.LabelingJobHumanTaskConfigPublicWorkforceTaskPriceAmountInUsd; } interface LabelingJobHumanTaskConfigPublicWorkforceTaskPriceAmountInUsd { /** * Fractional portion, in cents, of the amount. */ cents?: number; /** * Whole number of dollars in the amount. */ dollars?: number; /** * Fractions of a cent, in tenths. */ tenthFractionsOfACent?: number; } interface LabelingJobHumanTaskConfigUiConfig { /** * ARN of the worker task template used to render the worker UI and tools for labeling job tasks. */ humanTaskUiArn?: string; /** * S3 bucket location of the UI template, or worker task template. */ uiTemplateS3Uri?: string; } interface LabelingJobInputConfig { /** * Attributes of the data. Fields are documented below. */ dataAttributes?: outputs.sagemaker.LabelingJobInputConfigDataAttributes; /** * Location of the input data.. Fields are documented below. */ dataSource: outputs.sagemaker.LabelingJobInputConfigDataSource; } interface LabelingJobInputConfigDataAttributes { /** * Declares that your content is free of personally identifiable information or adult content. Valid values: `FreeOfPersonallyIdentifiableInformation`, `FreeOfAdultContent`. */ contentClassifiers?: string[]; } interface LabelingJobInputConfigDataSource { /** * S3 location of the input data objects.. Fields are documented below. */ s3DataSource?: outputs.sagemaker.LabelingJobInputConfigDataSourceS3DataSource; /** * SNS data source used for streaming labeling jobs. Fields are documented below. */ snsDataSource?: outputs.sagemaker.LabelingJobInputConfigDataSourceSnsDataSource; } interface LabelingJobInputConfigDataSourceS3DataSource { /** * S3 location of the manifest file that describes the input data objects. */ manifestS3Uri: string; } interface LabelingJobInputConfigDataSourceSnsDataSource { /** * SNS input topic ARN. */ snsTopicArn: string; } interface LabelingJobLabelCounter { /** * Total number of objects that could not be labeled due to an error. */ failedNonRetryableError: number; /** * Total number of objects labeled by a human worker. */ humanLabeled: number; /** * Total number of objects labeled by automated data labeling. */ machineLabeled: number; /** * Total number of objects labeled. */ totalLabeled: number; /** * Total number of objects not yet labeled. */ unlabeled: number; } interface LabelingJobLabelingJobAlgorithmsConfig { /** * ARN of the final model used for auto-labeling. */ initialActiveLearningModelArn?: string; /** * ARN of the algorithm used for auto-labeling. */ labelingJobAlgorithmSpecificationArn: string; /** * Configuration information for the labeling job. Fields are documented below. */ labelingJobResourceConfig?: outputs.sagemaker.LabelingJobLabelingJobAlgorithmsConfigLabelingJobResourceConfig; } interface LabelingJobLabelingJobAlgorithmsConfigLabelingJobResourceConfig { /** * ID of the key that Amazon SageMaker uses to encrypt data on the storage volume attached to the ML compute instance(s) that run the training and inference jobs used for automated data labeling. */ volumeKmsKeyId?: string; /** * VPC that SageMaker jobs, hosted models, and compute resources have access to. Fields are documented below. */ vpcConfig?: outputs.sagemaker.LabelingJobLabelingJobAlgorithmsConfigLabelingJobResourceConfigVpcConfig; } interface LabelingJobLabelingJobAlgorithmsConfigLabelingJobResourceConfigVpcConfig { /** * VPC security group IDs. */ securityGroupIds: string[]; /** * IDs of the subnets in the VPC to which to connect the training job. Fields are documented below. */ subnets: string[]; } interface LabelingJobOutputConfig { /** * ID of the key used to encrypt the output data. */ kmsKeyId: string; /** * S3 location to write output data. */ s3OutputPath: string; /** * SNS output topic ARN. */ snsTopicArn?: string; } interface LabelingJobStoppingCondition { /** * Maximum number of objects that can be labeled by human workers. */ maxHumanLabeledObjectCount: number; /** * Maximum number of input data objects that should be labeled. */ maxPercentageOfInputDatasetLabeled: number; } interface MlflowAppTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ModelCardExportJobExportArtifact { /** * Amazon S3 URI of the exported model artifacts. */ s3ExportArtifacts: string; } interface ModelCardExportJobOutputConfig { /** * Amazon S3 output path. */ s3OutputPath: string; } interface ModelCardExportJobTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface ModelCardSecurityConfig { /** * KMS key ARN. */ kmsKeyId: string; } interface ModelCardTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface ModelContainer { /** * Additional data sources that are available to the model in addition to those specified in `modelDataSource`. See Additional Model Data Source. */ additionalModelDataSources: outputs.sagemaker.ModelContainerAdditionalModelDataSource[]; /** * DNS host name for the container. */ containerHostname?: string; /** * Environment variables for the Docker container. */ environment?: { [key: string]: string; }; /** * Registry path where the inference code image is stored in Amazon ECR. */ image?: string; /** * Whether the model container is in Amazon ECR or a private Docker registry accessible from your VPC. For more information see [Using a Private Docker Registry for Real-Time Inference Containers](https://docs.aws.amazon.com/sagemaker/latest/dg/your-algorithms-containers-inference-private.html). see Image Config. */ imageConfig?: outputs.sagemaker.ModelContainerImageConfig; /** * Inference specification name in the model package version. */ inferenceSpecificationName?: string; /** * Container hosts value. Allowed values are: `SingleModel` and `MultiModel`. The default value is `SingleModel`. */ mode?: string; /** * Location of model data to deploy. Use this for uncompressed model deployment. For information about how to deploy an uncompressed model, see [Deploying uncompressed models](https://docs.aws.amazon.com/sagemaker/latest/dg/large-model-inference-uncompressed.html) in the _AWS SageMaker AI Developer Guide_. */ modelDataSource: outputs.sagemaker.ModelContainerModelDataSource; /** * URL for the S3 location where model artifacts are stored. */ modelDataUrl?: string; /** * ARN of the model package to use to create the model. * A list of key value pairs. */ modelPackageName?: string; /** * Specifies additional configuration for multi-model endpoints. see Multi Model Config. */ multiModelConfig?: outputs.sagemaker.ModelContainerMultiModelConfig; } interface ModelContainerAdditionalModelDataSource { /** * Custom name for the additional model data source object. It will be stored in `/opt/ml/additional-model-data-sources//`. */ channelName: string; /** * S3 location of model data to deploy. See S3 Data Source. */ s3DataSources: outputs.sagemaker.ModelContainerAdditionalModelDataSourceS3DataSource[]; } interface ModelContainerAdditionalModelDataSourceS3DataSource { /** * How the model data is prepared. Allowed values are: `None` and `Gzip`. */ compressionType: string; /** * Specifies the access configuration file for the ML model. You can explicitly accept the model end-user license agreement (EULA) within the `modelAccessConfig` configuration block. See Model Access Config. */ modelAccessConfig?: outputs.sagemaker.ModelContainerAdditionalModelDataSourceS3DataSourceModelAccessConfig; /** * Type of model data to deploy. Allowed values are: `S3Object` and `S3Prefix`. */ s3DataType: string; /** * The S3 path of model data to deploy. */ s3Uri: string; } interface ModelContainerAdditionalModelDataSourceS3DataSourceModelAccessConfig { /** * Specifies agreement to the model end-user license agreement (EULA). The value must be set to `true` in order to accept the EULA that this model requires. You are responsible for reviewing and complying with any applicable license terms and making sure they are acceptable for your use case before downloading or using a model. */ acceptEula: boolean; } interface ModelContainerImageConfig { /** * Whether the model container is in Amazon ECR or a private Docker registry accessible from your VPC. Allowed values are: `Platform` and `Vpc`. */ repositoryAccessMode: string; /** * Specifies an authentication configuration for the private docker registry where your model image is hosted. Specify a value for this property only if you specified Vpc as the value for the RepositoryAccessMode field, and the private Docker registry where the model image is hosted requires authentication. see Repository Auth Config. */ repositoryAuthConfig?: outputs.sagemaker.ModelContainerImageConfigRepositoryAuthConfig; } interface ModelContainerImageConfigRepositoryAuthConfig { /** * ARN of an AWS Lambda function that provides credentials to authenticate to the private Docker registry where your model image is hosted. For information about how to create an AWS Lambda function, see [Create a Lambda function with the console](https://docs.aws.amazon.com/lambda/latest/dg/getting-started-create-function.html) in the _AWS Lambda Developer Guide_. */ repositoryCredentialsProviderArn: string; } interface ModelContainerModelDataSource { /** * S3 location of model data to deploy. See S3 Data Source. */ s3DataSources: outputs.sagemaker.ModelContainerModelDataSourceS3DataSource[]; } interface ModelContainerModelDataSourceS3DataSource { /** * How the model data is prepared. Allowed values are: `None` and `Gzip`. */ compressionType: string; /** * Specifies the access configuration file for the ML model. You can explicitly accept the model end-user license agreement (EULA) within the `modelAccessConfig` configuration block. See Model Access Config. */ modelAccessConfig?: outputs.sagemaker.ModelContainerModelDataSourceS3DataSourceModelAccessConfig; /** * Type of model data to deploy. Allowed values are: `S3Object` and `S3Prefix`. */ s3DataType: string; /** * The S3 path of model data to deploy. */ s3Uri: string; } interface ModelContainerModelDataSourceS3DataSourceModelAccessConfig { /** * Specifies agreement to the model end-user license agreement (EULA). The value must be set to `true` in order to accept the EULA that this model requires. You are responsible for reviewing and complying with any applicable license terms and making sure they are acceptable for your use case before downloading or using a model. */ acceptEula: boolean; } interface ModelContainerMultiModelConfig { /** * Whether to cache models for a multi-model endpoint. By default, multi-model endpoints cache models so that a model does not have to be loaded into memory each time it is invoked. Some use cases do not benefit from model caching. For example, if an endpoint hosts a large number of models that are each invoked infrequently, the endpoint might perform better if you disable model caching. To disable model caching, set the value of this parameter to `Disabled`. Allowed values are: `Enabled` and `Disabled`. */ modelCacheSetting?: string; } interface ModelInferenceExecutionConfig { /** * How containers in a multi-container are run. Allowed values are: `Serial` and `Direct`. */ mode: string; } interface ModelPrimaryContainer { /** * Additional data sources that are available to the model in addition to those specified in `modelDataSource`. See Additional Model Data Source. */ additionalModelDataSources: outputs.sagemaker.ModelPrimaryContainerAdditionalModelDataSource[]; /** * DNS host name for the container. */ containerHostname?: string; /** * Environment variables for the Docker container. */ environment?: { [key: string]: string; }; /** * Registry path where the inference code image is stored in Amazon ECR. */ image?: string; /** * Whether the model container is in Amazon ECR or a private Docker registry accessible from your VPC. For more information see [Using a Private Docker Registry for Real-Time Inference Containers](https://docs.aws.amazon.com/sagemaker/latest/dg/your-algorithms-containers-inference-private.html). see Image Config. */ imageConfig?: outputs.sagemaker.ModelPrimaryContainerImageConfig; /** * Inference specification name in the model package version. */ inferenceSpecificationName?: string; mode?: string; /** * Location of model data to deploy. Use this for uncompressed model deployment. For information about how to deploy an uncompressed model, see [Deploying uncompressed models](https://docs.aws.amazon.com/sagemaker/latest/dg/large-model-inference-uncompressed.html) in the _AWS SageMaker AI Developer Guide_. */ modelDataSource: outputs.sagemaker.ModelPrimaryContainerModelDataSource; /** * URL for the S3 location where model artifacts are stored. */ modelDataUrl?: string; /** * ARN of the model package to use to create the model. * A list of key value pairs. */ modelPackageName?: string; /** * Specifies additional configuration for multi-model endpoints. see Multi Model Config. */ multiModelConfig?: outputs.sagemaker.ModelPrimaryContainerMultiModelConfig; } interface ModelPrimaryContainerAdditionalModelDataSource { /** * Custom name for the additional model data source object. It will be stored in `/opt/ml/additional-model-data-sources//`. */ channelName: string; /** * S3 location of model data to deploy. See S3 Data Source. */ s3DataSources: outputs.sagemaker.ModelPrimaryContainerAdditionalModelDataSourceS3DataSource[]; } interface ModelPrimaryContainerAdditionalModelDataSourceS3DataSource { /** * How the model data is prepared. Allowed values are: `None` and `Gzip`. */ compressionType: string; /** * Specifies the access configuration file for the ML model. You can explicitly accept the model end-user license agreement (EULA) within the `modelAccessConfig` configuration block. See Model Access Config. */ modelAccessConfig?: outputs.sagemaker.ModelPrimaryContainerAdditionalModelDataSourceS3DataSourceModelAccessConfig; /** * Type of model data to deploy. Allowed values are: `S3Object` and `S3Prefix`. */ s3DataType: string; /** * The S3 path of model data to deploy. */ s3Uri: string; } interface ModelPrimaryContainerAdditionalModelDataSourceS3DataSourceModelAccessConfig { /** * Specifies agreement to the model end-user license agreement (EULA). The value must be set to `true` in order to accept the EULA that this model requires. You are responsible for reviewing and complying with any applicable license terms and making sure they are acceptable for your use case before downloading or using a model. */ acceptEula: boolean; } interface ModelPrimaryContainerImageConfig { /** * Whether the model container is in Amazon ECR or a private Docker registry accessible from your VPC. Allowed values are: `Platform` and `Vpc`. */ repositoryAccessMode: string; /** * Specifies an authentication configuration for the private docker registry where your model image is hosted. Specify a value for this property only if you specified Vpc as the value for the RepositoryAccessMode field, and the private Docker registry where the model image is hosted requires authentication. see Repository Auth Config. */ repositoryAuthConfig?: outputs.sagemaker.ModelPrimaryContainerImageConfigRepositoryAuthConfig; } interface ModelPrimaryContainerImageConfigRepositoryAuthConfig { /** * ARN of an AWS Lambda function that provides credentials to authenticate to the private Docker registry where your model image is hosted. For information about how to create an AWS Lambda function, see [Create a Lambda function with the console](https://docs.aws.amazon.com/lambda/latest/dg/getting-started-create-function.html) in the _AWS Lambda Developer Guide_. */ repositoryCredentialsProviderArn: string; } interface ModelPrimaryContainerModelDataSource { /** * S3 location of model data to deploy. See S3 Data Source. */ s3DataSources: outputs.sagemaker.ModelPrimaryContainerModelDataSourceS3DataSource[]; } interface ModelPrimaryContainerModelDataSourceS3DataSource { /** * How the model data is prepared. Allowed values are: `None` and `Gzip`. */ compressionType: string; /** * Specifies the access configuration file for the ML model. You can explicitly accept the model end-user license agreement (EULA) within the `modelAccessConfig` configuration block. See Model Access Config. */ modelAccessConfig?: outputs.sagemaker.ModelPrimaryContainerModelDataSourceS3DataSourceModelAccessConfig; /** * Type of model data to deploy. Allowed values are: `S3Object` and `S3Prefix`. */ s3DataType: string; /** * The S3 path of model data to deploy. */ s3Uri: string; } interface ModelPrimaryContainerModelDataSourceS3DataSourceModelAccessConfig { /** * Specifies agreement to the model end-user license agreement (EULA). The value must be set to `true` in order to accept the EULA that this model requires. You are responsible for reviewing and complying with any applicable license terms and making sure they are acceptable for your use case before downloading or using a model. */ acceptEula: boolean; } interface ModelPrimaryContainerMultiModelConfig { /** * Whether to cache models for a multi-model endpoint. By default, multi-model endpoints cache models so that a model does not have to be loaded into memory each time it is invoked. Some use cases do not benefit from model caching. For example, if an endpoint hosts a large number of models that are each invoked infrequently, the endpoint might perform better if you disable model caching. To disable model caching, set the value of this parameter to `Disabled`. Allowed values are: `Enabled` and `Disabled`. */ modelCacheSetting?: string; } interface ModelVpcConfig { /** * List of security group IDs you want to be applied to your training job or model. Specify the security groups for the VPC that is specified in the Subnets field. */ securityGroupIds: string[]; /** * List of subnet IDs in the VPC to which you want to connect your training job or model. */ subnets: string[]; } interface MonitoringScheduleMonitoringScheduleConfig { /** * Defines the monitoring job. Fields are documented below. */ monitoringJobDefinition?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinition; /** * The name of the monitoring job definition to schedule. */ monitoringJobDefinitionName?: string; /** * The type of the monitoring job definition to schedule. Valid values are `DataQuality`, `ModelQuality`, `ModelBias` or `ModelExplainability` */ monitoringType: string; /** * Configures the monitoring schedule. Fields are documented below. */ scheduleConfig: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigScheduleConfig; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinition { /** * Baseline configuration used to validate that the data conforms to the specified constraints and statistics. Fields are documented below. */ baseline?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionBaseline; /** * Map of environment variables in the Docker container. */ environment?: { [key: string]: string; }; /** * Configures the monitoring job to run a specified Docker container image. Fields are documented below. */ monitoringAppSpecification: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringAppSpecification; /** * Inputs for the monitoring job. Fields are documented below. */ monitoringInputs: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputs; /** * Outputs from the monitoring job to be uploaded to Amazon S3. Fields are documented below. */ monitoringOutputConfig: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringOutputConfig; /** * Identifies the resources, ML compute instances, and ML storage volumes to deploy for a monitoring job. Fields are documented below. */ monitoringResources: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringResources; /** * Networking options for the monitoring job. Fields are documented below. */ networkConfig?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionNetworkConfig; /** * ARN of an IAM role that Amazon SageMaker AI can assume to perform tasks on your behalf. */ roleArn: string; /** * How long the monitoring job is allowed to run. Fields are documented below. */ stoppingConditions: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionStoppingCondition[]; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionBaseline { baseliningJobName?: string; constraintsResource?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionBaselineConstraintsResource; statisticsResource?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionBaselineStatisticsResource; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionBaselineConstraintsResource { /** * URI that identifies the Amazon S3 storage location where Amazon SageMaker AI saves the results of a monitoring job. */ s3Uri?: string; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionBaselineStatisticsResource { /** * URI that identifies the Amazon S3 storage location where Amazon SageMaker AI saves the results of a monitoring job. */ s3Uri?: string; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringAppSpecification { /** * List of arguments for the container used to run the monitoring job. */ containerArguments?: string[]; /** * Entrypoint for the container used to run the monitoring job. */ containerEntrypoints?: string[]; /** * Container image to be run by the monitoring job. */ imageUri: string; /** * Script that is called after analysis has been performed. */ postAnalyticsProcessorSourceUri?: string; /** * Script that is called per row prior to running analysis. */ recordPreprocessorSourceUri?: string; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputs { /** * Input object for the batch transform job. Fields are documented below. */ batchTransformInput?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInput; /** * Endpoint for a monitoring job. Fields are documented below. */ endpointInput?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsEndpointInput; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInput { /** * Amazon S3 location being used to capture the data. */ dataCapturedDestinationS3Uri: string; /** * Dataset format for the batch transform job. Fields are documented below. */ datasetFormat: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInputDatasetFormat; /** * Monitoring jobs subtract this time from the end time. */ endTimeOffset?: string; /** * Attributes of the input data to exclude from the analysis. */ excludeFeaturesAttribute?: string; /** * Attributes of the input data that are the input features. */ featuresAttribute?: string; /** * Attribute of the input data that represents the ground truth label. */ inferenceAttribute?: string; /** * Path to the filesystem where the batch transform data is available to the container. */ localPath: string; /** * In a classification problem, the attribute that represents the class probability. */ probabilityAttribute?: string; /** * Threshold for the class probability to be evaluated as a positive result. */ probabilityThresholdAttribute?: number; /** * Whether input data distributed in Amazon S3 is fully replicated or sharded by an S3 key. Valid values: `FullyReplicated`, `ShardedByS3Key`. */ s3DataDistributionType: string; /** * Input mode for transferring data for the monitoring job. Valid values: `Pipe`, `File`. */ s3InputMode: string; /** * Monitoring jobs subtract this time from the start time. */ startTimeOffset?: string; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInputDatasetFormat { /** * CSV dataset used in the monitoring job. Fields are documented below. */ csv?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInputDatasetFormatCsv; /** * JSON dataset used in the monitoring job. Fields are documented below. */ json?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInputDatasetFormatJson; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInputDatasetFormatCsv { /** * Indicates if the CSV data has a header. */ header?: boolean; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsBatchTransformInputDatasetFormatJson { /** * Indicates if the file should be read as a JSON object per line. */ line?: boolean; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringInputsEndpointInput { /** * Monitoring jobs subtract this time from the end time. */ endTimeOffset?: string; /** * Endpoint in customer's account which has enabled `DataCaptureConfig`. */ endpointName: string; /** * Attributes of the input data to exclude from the analysis. */ excludeFeaturesAttribute?: string; /** * Attributes of the input data that are the input features. */ featuresAttribute?: string; /** * Attribute of the input data that represents the ground truth label. */ inferenceAttribute?: string; /** * Path to the filesystem where the endpoint data is available to the container. */ localPath: string; /** * In a classification problem, the attribute that represents the class probability. */ probabilityAttribute?: string; /** * Threshold for the class probability to be evaluated as a positive result. */ probabilityThresholdAttribute?: number; /** * Whether input data distributed in Amazon S3 is fully replicated or sharded by an S3 key. Valid values: `FullyReplicated`, `ShardedByS3Key`. */ s3DataDistributionType: string; /** * Input mode for transferring data for the monitoring job. Valid values: `Pipe`, `File`. */ s3InputMode: string; /** * Monitoring jobs subtract this time from the start time. */ startTimeOffset?: string; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringOutputConfig { /** * AWS KMS key that Amazon SageMaker AI uses to encrypt the model artifacts at rest using Amazon S3 server-side encryption. */ kmsKeyId?: string; /** * Monitoring outputs for monitoring jobs. Fields are documented below. */ monitoringOutputs: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringOutputConfigMonitoringOutputs; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringOutputConfigMonitoringOutputs { /** * Amazon S3 storage location where the results of a monitoring job are saved. Fields are documented below. */ s3Output: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringOutputConfigMonitoringOutputsS3Output; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringOutputConfigMonitoringOutputsS3Output { /** * Local path to the Amazon S3 storage location where Amazon SageMaker AI saves the results of a monitoring job. */ localPath: string; /** * Whether to upload the results of the monitoring job continuously or after the job completes. Valid values: `Continuous`, `EndOfJob`. */ s3UploadMode: string; /** * URI that identifies the Amazon S3 storage location where Amazon SageMaker AI saves the results of a monitoring job. */ s3Uri: string; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringResources { /** * Configuration for the cluster resources used to run the processing job. Fields are documented below. */ clusterConfig: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringResourcesClusterConfig; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionMonitoringResourcesClusterConfig { /** * Number of ML compute instances to use in the model monitoring job. */ instanceCount: number; /** * ML compute instance type for the processing job. */ instanceType: string; /** * AWS KMS key that Amazon SageMaker AI uses to encrypt data on the storage volume attached to the ML compute instance(s) that run the model monitoring job. */ volumeKmsKeyId?: string; /** * size of the ML storage volume, in gigabytes, to provision. */ volumeSizeInGb: number; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionNetworkConfig { /** * Whether to encrypt all communications between distributed processing jobs. */ enableInterContainerTrafficEncryption?: boolean; /** * Whether to allow inbound and outbound network calls to and from the containers used for the processing job. */ enableNetworkIsolation?: boolean; /** * VPC that SageMaker jobs, hosted models, and compute resources have access to. Fields are documented below. */ vpcConfig?: outputs.sagemaker.MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionNetworkConfigVpcConfig; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionNetworkConfigVpcConfig { /** * VPC security group IDs. */ securityGroupIds: string[]; /** * Subnet IDs. */ subnets: string[]; } interface MonitoringScheduleMonitoringScheduleConfigMonitoringJobDefinitionStoppingCondition { /** * Maximum runtime allowed in seconds. */ maxRuntimeInSeconds: number; } interface MonitoringScheduleMonitoringScheduleConfigScheduleConfig { /** * A cron expression that describes details about the monitoring schedule. For example, and hourly schedule would be `cron(0 * ? * * *)`. */ scheduleExpression: string; } interface NotebookInstanceInstanceMetadataServiceConfiguration { /** * Indicates the minimum IMDS version that the notebook instance supports. When passed "1" is passed. This means that both IMDSv1 and IMDSv2 are supported. Valid values are `1` and `2`. */ minimumInstanceMetadataServiceVersion: string; } interface PipelineParallelismConfiguration { /** * The max number of steps that can be executed in parallel. */ maxParallelExecutionSteps: number; } interface PipelinePipelineDefinitionS3Location { /** * Name of the S3 bucket. */ bucket: string; /** * The object key (or key name) uniquely identifies the object in an S3 bucket. */ objectKey: string; /** * Version Id of the pipeline definition file. If not specified, Amazon SageMaker AI will retrieve the latest version. */ versionId?: string; } interface ProjectServiceCatalogProvisioningDetails { /** * The path identifier of the product. This value is optional if the product has a default path, and required if the product has more than one path. */ pathId?: string; /** * The ID of the product to provision. */ productId: string; /** * The ID of the provisioning artifact. */ provisioningArtifactId: string; /** * A list of key value pairs that you specify when you provision a product. See Provisioning Parameter below. */ provisioningParameters?: outputs.sagemaker.ProjectServiceCatalogProvisioningDetailsProvisioningParameter[]; } interface ProjectServiceCatalogProvisioningDetailsProvisioningParameter { /** * The key that identifies a provisioning parameter. */ key: string; /** * The value of the provisioning parameter. */ value?: string; } interface SpaceOwnershipSettings { /** * The user profile who is the owner of the private space. */ ownerUserProfileName: string; } interface SpaceSpaceSettings { /** * The type of app created within the space. */ appType?: string; /** * The Code Editor application settings. See `codeEditorAppSettings` Block below. */ codeEditorAppSettings?: outputs.sagemaker.SpaceSpaceSettingsCodeEditorAppSettings; /** * A file system, created by you, that you assign to a space for an Amazon SageMaker AI Domain. See `customFileSystem` Block below. */ customFileSystems?: outputs.sagemaker.SpaceSpaceSettingsCustomFileSystem[]; /** * The settings for the JupyterLab application. See `jupyterLabAppSettings` Block below. */ jupyterLabAppSettings?: outputs.sagemaker.SpaceSpaceSettingsJupyterLabAppSettings; /** * The Jupyter server's app settings. See `jupyterServerAppSettings` Block below. */ jupyterServerAppSettings?: outputs.sagemaker.SpaceSpaceSettingsJupyterServerAppSettings; /** * The kernel gateway app settings. See `kernelGatewayAppSettings` Block below. */ kernelGatewayAppSettings?: outputs.sagemaker.SpaceSpaceSettingsKernelGatewayAppSettings; /** * The storage settings. See `spaceStorageSettings` Block below. */ spaceStorageSettings: outputs.sagemaker.SpaceSpaceSettingsSpaceStorageSettings; } interface SpaceSpaceSettingsCodeEditorAppSettings { /** * Settings that are used to configure and manage the lifecycle of JupyterLab applications in a space. See `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.SpaceSpaceSettingsCodeEditorAppSettingsAppLifecycleManagement; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. See `defaultResourceSpec` Block below. */ defaultResourceSpec: outputs.sagemaker.SpaceSpaceSettingsCodeEditorAppSettingsDefaultResourceSpec; } interface SpaceSpaceSettingsCodeEditorAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. See `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.SpaceSpaceSettingsCodeEditorAppSettingsAppLifecycleManagementIdleSettings; } interface SpaceSpaceSettingsCodeEditorAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; } interface SpaceSpaceSettingsCodeEditorAppSettingsDefaultResourceSpec { /** * The instance type. */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * ARN of the SageMaker AI image created on the instance. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface SpaceSpaceSettingsCustomFileSystem { /** * A custom file system in Amazon EFS. See `efsFileSystem` Block below. */ efsFileSystem: outputs.sagemaker.SpaceSpaceSettingsCustomFileSystemEfsFileSystem; } interface SpaceSpaceSettingsCustomFileSystemEfsFileSystem { /** * The ID of your Amazon EFS file system. */ fileSystemId: string; } interface SpaceSpaceSettingsJupyterLabAppSettings { /** * Settings that are used to configure and manage the lifecycle of JupyterLab applications in a space. See `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.SpaceSpaceSettingsJupyterLabAppSettingsAppLifecycleManagement; /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterLab application. See `codeRepository` Block below. */ codeRepositories?: outputs.sagemaker.SpaceSpaceSettingsJupyterLabAppSettingsCodeRepository[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. See `defaultResourceSpec` Block below. */ defaultResourceSpec: outputs.sagemaker.SpaceSpaceSettingsJupyterLabAppSettingsDefaultResourceSpec; } interface SpaceSpaceSettingsJupyterLabAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. See `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.SpaceSpaceSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings; } interface SpaceSpaceSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; } interface SpaceSpaceSettingsJupyterLabAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface SpaceSpaceSettingsJupyterLabAppSettingsDefaultResourceSpec { /** * The instance type. */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * ARN of the SageMaker AI image created on the instance. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface SpaceSpaceSettingsJupyterServerAppSettings { /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. See `codeRepository` Block below. */ codeRepositories?: outputs.sagemaker.SpaceSpaceSettingsJupyterServerAppSettingsCodeRepository[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. See `defaultResourceSpec` Block below. */ defaultResourceSpec: outputs.sagemaker.SpaceSpaceSettingsJupyterServerAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface SpaceSpaceSettingsJupyterServerAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface SpaceSpaceSettingsJupyterServerAppSettingsDefaultResourceSpec { /** * The instance type. */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * ARN of the SageMaker AI image created on the instance. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface SpaceSpaceSettingsKernelGatewayAppSettings { /** * A list of custom SageMaker AI images that are configured to run as a KernelGateway app. See `customImage` Block below. */ customImages?: outputs.sagemaker.SpaceSpaceSettingsKernelGatewayAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. See `defaultResourceSpec` Block below. */ defaultResourceSpec: outputs.sagemaker.SpaceSpaceSettingsKernelGatewayAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface SpaceSpaceSettingsKernelGatewayAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface SpaceSpaceSettingsKernelGatewayAppSettingsDefaultResourceSpec { /** * The instance type. */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * ARN of the SageMaker AI image created on the instance. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface SpaceSpaceSettingsSpaceStorageSettings { /** * A collection of EBS storage settings for a space. See `ebsStorageSettings` Block below. */ ebsStorageSettings: outputs.sagemaker.SpaceSpaceSettingsSpaceStorageSettingsEbsStorageSettings; } interface SpaceSpaceSettingsSpaceStorageSettingsEbsStorageSettings { /** * The size of an EBS storage volume for a space. */ ebsVolumeSizeInGb: number; } interface SpaceSpaceSharingSettings { /** * Specifies the sharing type of the space. Valid values are `Private` and `Shared`. */ sharingType: string; } interface TrainingJobAlgorithmSpecification { /** * Name or ARN of the algorithm resource to use for the training job. */ algorithmName?: string; /** * List of arguments for the container entrypoint. Maximum of 100 entries. */ containerArguments?: string[]; /** * List of entrypoint commands for the container. Maximum of 100 entries. */ containerEntrypoints?: string[]; /** * Whether to enable SageMaker AI metrics time series collection. */ enableSagemakerMetricsTimeSeries: boolean; /** * List of metric definitions for the training job. Maximum of 40. Use this to extract custom metrics from your own training container logs. SageMaker can still publish built-in metrics for built-in algorithms and supported prebuilt images when this block is omitted. See `metricDefinitions` below. */ metricDefinitions?: outputs.sagemaker.TrainingJobAlgorithmSpecificationMetricDefinition[]; /** * Registry path of the Docker image that contains the training algorithm. */ trainingImage?: string; /** * Training image configuration. See `trainingImageConfig` below. */ trainingImageConfig?: outputs.sagemaker.TrainingJobAlgorithmSpecificationTrainingImageConfig; /** * Input mode for the training data. Valid values: `File`, `Pipe`, `FastFile`. */ trainingInputMode?: string; } interface TrainingJobAlgorithmSpecificationMetricDefinition { /** * Name of the metric. */ name: string; /** * Regular expression that searches the output of the training job and captures the value of the metric. */ regex: string; } interface TrainingJobAlgorithmSpecificationTrainingImageConfig { /** * Access mode for the training image repository. */ trainingRepositoryAccessMode?: string; /** * Authentication configuration for the training image repository. See `trainingRepositoryAuthConfig` below. */ trainingRepositoryAuthConfig?: outputs.sagemaker.TrainingJobAlgorithmSpecificationTrainingImageConfigTrainingRepositoryAuthConfig; } interface TrainingJobAlgorithmSpecificationTrainingImageConfigTrainingRepositoryAuthConfig { /** * ARN of the Lambda function that provides credentials to authenticate to the private Docker registry. */ trainingRepositoryCredentialsProviderArn?: string; } interface TrainingJobCheckpointConfig { /** * Local path where checkpoints are written. */ localPath?: string; /** * S3 URI where checkpoints are stored. */ s3Uri: string; } interface TrainingJobDebugHookConfig { /** * List of tensor collections to configure for the debug hook. Maximum of 20. See `collectionConfigurations` below. */ collectionConfigurations?: outputs.sagemaker.TrainingJobDebugHookConfigCollectionConfiguration[]; /** * Map of parameters for the debug hook. Maximum of 20 entries. */ hookParameters?: { [key: string]: string; }; /** * Local path where debug output is written. */ localPath?: string; /** * S3 URI where debug output is stored. */ s3OutputPath: string; } interface TrainingJobDebugHookConfigCollectionConfiguration { /** * Name of the tensor collection. */ collectionName?: string; /** * Map of parameters for the tensor collection. */ collectionParameters?: { [key: string]: string; }; } interface TrainingJobDebugRuleConfiguration { /** * Instance type to deploy for the debug rule evaluation. Valid values are SageMaker AI processing instance types. */ instanceType?: string; /** * Local path where debug rule output is written. */ localPath?: string; /** * Name of the rule configuration. Must be between 1 and 256 characters. */ ruleConfigurationName: string; /** * Docker image URI for the rule evaluator. */ ruleEvaluatorImage: string; /** * Map of parameters for the rule configuration. Maximum of 100 entries. */ ruleParameters?: { [key: string]: string; }; /** * S3 URI where rule output is stored. */ s3OutputPath?: string; /** * Size of the storage volume for the rule evaluator, in GB. */ volumeSizeInGb: number; } interface TrainingJobExperimentConfig { /** * Name of the SageMaker AI Experiment to associate with. */ experimentName?: string; /** * Name of the Experiment Run to associate with. */ runName?: string; /** * Display name for the trial component. */ trialComponentDisplayName?: string; /** * Name of the SageMaker AI Trial to associate with. */ trialName?: string; } interface TrainingJobInfraCheckConfig { /** * Whether to enable infrastructure health checks before training. */ enableInfraCheck?: boolean; } interface TrainingJobInputDataConfig { /** * Name of the channel. Must be between 1 and 64 characters. */ channelName: string; /** * Compression type for the input data. Valid values: `None`, `Gzip`. */ compressionType: string; /** * MIME type of the input data. */ contentType: string; /** * Location of the channel data. See `dataSource` below. */ dataSource?: outputs.sagemaker.TrainingJobInputDataConfigDataSource; /** * Input mode for the channel data. Valid values: `File`, `Pipe`, `FastFile`. */ inputMode: string; /** * Record wrapper type. Valid values: `None`, `RecordIO`. */ recordWrapperType: string; /** * Configuration for shuffling data in the channel. See `shuffleConfig` below. */ shuffleConfig?: outputs.sagemaker.TrainingJobInputDataConfigShuffleConfig; } interface TrainingJobInputDataConfigDataSource { /** * File system data source. See `fileSystemDataSource` below. */ fileSystemDataSource?: outputs.sagemaker.TrainingJobInputDataConfigDataSourceFileSystemDataSource; /** * S3 data source. See `s3DataSource` below. */ s3DataSource?: outputs.sagemaker.TrainingJobInputDataConfigDataSourceS3DataSource; } interface TrainingJobInputDataConfigDataSourceFileSystemDataSource { /** * Full path to the directory on the file system. */ directoryPath: string; /** * Access mode for the file system. Valid values: `ro`, `rw`. */ fileSystemAccessMode: string; /** * File system ID. */ fileSystemId: string; /** * File system type. Valid values: `EFS`, `FSxLustre`. */ fileSystemType: string; } interface TrainingJobInputDataConfigDataSourceS3DataSource { /** * List of attribute names to include in the training dataset. Maximum of 16. */ attributeNames?: string[]; /** * SageMaker AI Hub access configuration. See `hubAccessConfig` below. */ hubAccessConfig?: outputs.sagemaker.TrainingJobInputDataConfigDataSourceS3DataSourceHubAccessConfig; /** * List of instance group names for the training data distribution. Maximum of 5. */ instanceGroupNames?: string[]; /** * Model access configuration. See `modelAccessConfig` below. */ modelAccessConfig?: outputs.sagemaker.TrainingJobInputDataConfigDataSourceS3DataSourceModelAccessConfig; /** * Distribution type for S3 data. Valid values: `FullyReplicated`, `ShardedByS3Key`. */ s3DataDistributionType?: string; /** * S3 data type. Valid values: `ManifestFile`, `S3Prefix`, `AugmentedManifestFile`. */ s3DataType: string; /** * S3 URI of the data. */ s3Uri: string; } interface TrainingJobInputDataConfigDataSourceS3DataSourceHubAccessConfig { /** * ARN of the hub content. */ hubContentArn: string; } interface TrainingJobInputDataConfigDataSourceS3DataSourceModelAccessConfig { /** * Whether to accept the model EULA. */ acceptEula: boolean; } interface TrainingJobInputDataConfigShuffleConfig { /** * Seed value used to shuffle the training data. */ seed?: number; } interface TrainingJobMlflowConfig { /** * Name of the MLflow experiment. */ mlflowExperimentName?: string; /** * ARN of the MLflow tracking server. */ mlflowResourceArn: string; /** * Name of the MLflow run. */ mlflowRunName?: string; } interface TrainingJobModelPackageConfig { /** * ARN of the model package group. */ modelPackageGroupArn: string; /** * ARN of the source model package. */ sourceModelPackageArn?: string; } interface TrainingJobOutputDataConfig { /** * Output compression type. Valid values: `GZIP`, `NONE`. */ compressionType: string; /** * KMS key ID used to encrypt the output data. */ kmsKeyId: string; /** * S3 URI where output data is stored. */ s3OutputPath: string; } interface TrainingJobProfilerConfig { /** * Whether to disable the profiler. */ disableProfiler?: boolean; /** * Time interval in milliseconds for capturing system metrics. Valid values: `100`, `200`, `500`, `1000`, `5000`, `60000`. */ profilingIntervalInMilliseconds?: number; /** * Map of profiling parameters. Maximum of 20 entries. */ profilingParameters?: { [key: string]: string; }; /** * S3 URI where profiler output is stored. */ s3OutputPath?: string; } interface TrainingJobProfilerRuleConfiguration { /** * Instance type to deploy for the profiler rule evaluation. Valid values are SageMaker AI processing instance types. */ instanceType?: string; /** * Local path where profiler rule output is written. */ localPath?: string; /** * Name of the profiler rule configuration. Must be between 1 and 256 characters. */ ruleConfigurationName: string; /** * Docker image URI for the profiler rule evaluator. */ ruleEvaluatorImage: string; /** * Map of parameters for the profiler rule. Maximum of 100 entries. */ ruleParameters?: { [key: string]: string; }; /** * S3 URI where profiler rule output is stored. */ s3OutputPath?: string; /** * Size of the storage volume for the profiler rule evaluator, in GB. */ volumeSizeInGb: number; } interface TrainingJobRemoteDebugConfig { /** * Whether to enable remote debugging for the training job. */ enableRemoteDebug?: boolean; } interface TrainingJobResourceConfig { /** * Number of ML compute instances to use. Conflicts with `instanceGroups`. */ instanceCount: number; /** * List of instance groups for heterogeneous cluster training. Maximum of 5. Conflicts with `instanceCount`, `instanceType`, and `keepAlivePeriodInSeconds`. See `instanceGroups` below. */ instanceGroups?: outputs.sagemaker.TrainingJobResourceConfigInstanceGroup[]; /** * Instance placement configuration. See `instancePlacementConfig` below. */ instancePlacementConfig?: outputs.sagemaker.TrainingJobResourceConfigInstancePlacementConfig; /** * ML compute instance type. Conflicts with `instanceGroups`. */ instanceType: string; /** * Time in seconds to keep instances alive after training completes, for warm pool reuse. Valid values: 0–3600. Conflicts with `instanceGroups`. */ keepAlivePeriodInSeconds: number; /** * ARN of the training plan to use. */ trainingPlanArn?: string; /** * KMS key ID used to encrypt data on the storage volume. */ volumeKmsKeyId?: string; /** * Size of the storage volume attached to each instance, in GB. */ volumeSizeInGb: number; } interface TrainingJobResourceConfigInstanceGroup { /** * Number of instances in the group. */ instanceCount?: number; /** * Name of the instance group. */ instanceGroupName?: string; /** * ML compute instance type for the group. */ instanceType?: string; } interface TrainingJobResourceConfigInstancePlacementConfig { /** * Whether to enable multiple jobs on the same instance. */ enableMultipleJobs?: boolean; /** * Placement specifications for instance placement. See `placementSpecifications` below. */ placementSpecifications?: outputs.sagemaker.TrainingJobResourceConfigInstancePlacementConfigPlacementSpecification[]; } interface TrainingJobResourceConfigInstancePlacementConfigPlacementSpecification { /** * Number of instances in the placement. */ instanceCount?: number; /** * Ultra server ID for the placement. */ ultraServerId?: string; } interface TrainingJobRetryStrategy { /** * Maximum number of retry attempts. Valid values: 1–30. */ maximumRetryAttempts: number; } interface TrainingJobServerlessJobConfig { /** * Whether to accept the model EULA. */ acceptEula?: boolean; /** * ARN of the base foundation model from the SageMaker AI Public Hub. */ baseModelArn: string; /** * Customization technique to apply. Valid values: `FINE_TUNING`, `DOMAIN_ADAPTION`. */ customizationTechnique?: string; /** * Evaluation type. Valid values: `AUTOMATIC`, `HUMAN`, `NONE`. */ evaluationType?: string; /** * ARN of the evaluator. */ evaluatorArn?: string; /** * Serverless job type. Valid values: `FINE_TUNING`, `EVALUATION`, `DISTILLATION`. */ jobType: string; /** * Parameter-Efficient Fine-Tuning (PEFT) method. Valid values: `LORA`. */ peft?: string; } interface TrainingJobSessionChainingConfig { /** * Whether to enable session tag chaining for the training job. */ enableSessionTagChaining?: boolean; } interface TrainingJobStoppingCondition { /** * Maximum time in seconds a training job can be pending before it is stopped. Valid values: 7200–2419200. */ maxPendingTimeInSeconds: number; /** * Maximum time in seconds the training job can run before it is stopped. */ maxRuntimeInSeconds: number; /** * Maximum time in seconds to wait for a managed spot training job to complete. */ maxWaitTimeInSeconds: number; } interface TrainingJobTensorBoardOutputConfig { /** * Local path where TensorBoard output is written. */ localPath?: string; /** * S3 URI where TensorBoard output is stored. */ s3OutputPath: string; } interface TrainingJobTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface TrainingJobVpcConfig { /** * List of VPC security group IDs. Maximum of 5. */ securityGroupIds: string[]; /** * List of subnet IDs. Maximum of 16. */ subnets: string[]; } interface UserProfileUserSettings { /** * Indicates whether auto-mounting of an EFS volume is supported for the user profile. The `DefaultAsDomain` value is only supported for user profiles. Do not use the `DefaultAsDomain` value when setting this parameter for a domain. Valid values are: `Enabled`, `Disabled`, and `DefaultAsDomain`. */ autoMountHomeEfs: string; /** * The Canvas app settings. See Canvas App Settings below. */ canvasAppSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettings; /** * The Code Editor application settings. See Code Editor App Settings below. */ codeEditorAppSettings?: outputs.sagemaker.UserProfileUserSettingsCodeEditorAppSettings; /** * The settings for assigning a custom file system to a user profile. Permitted users can access this file system in Amazon SageMaker AI Studio. See Custom File System Config below. */ customFileSystemConfigs?: outputs.sagemaker.UserProfileUserSettingsCustomFileSystemConfig[]; /** * Details about the POSIX identity that is used for file system operations. See Custom Posix User Config below. */ customPosixUserConfig?: outputs.sagemaker.UserProfileUserSettingsCustomPosixUserConfig; /** * The default experience that the user is directed to when accessing the domain. The supported values are: `studio::`: Indicates that Studio is the default experience. This value can only be passed if StudioWebPortal is set to ENABLED. `app:JupyterServer:`: Indicates that Studio Classic is the default experience. */ defaultLandingUri?: string; /** * The execution role ARN for the user. */ executionRole: string; /** * The settings for the JupyterLab application. See Jupyter Lab App Settings below. */ jupyterLabAppSettings?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettings; /** * The Jupyter server's app settings. See Jupyter Server App Settings below. */ jupyterServerAppSettings?: outputs.sagemaker.UserProfileUserSettingsJupyterServerAppSettings; /** * The kernel gateway app settings. See Kernel Gateway App Settings below. */ kernelGatewayAppSettings?: outputs.sagemaker.UserProfileUserSettingsKernelGatewayAppSettings; /** * The RSession app settings. See RSession App Settings below. */ rSessionAppSettings?: outputs.sagemaker.UserProfileUserSettingsRSessionAppSettings; /** * A collection of settings that configure user interaction with the RStudioServerPro app. See RStudioServerProAppSettings below. */ rStudioServerProAppSettings?: outputs.sagemaker.UserProfileUserSettingsRStudioServerProAppSettings; /** * A list of security group IDs that will be attached to the user. */ securityGroups?: string[]; /** * The sharing settings. See Sharing Settings below. */ sharingSettings?: outputs.sagemaker.UserProfileUserSettingsSharingSettings; /** * The storage settings for a private space. See Space Storage Settings below. */ spaceStorageSettings: outputs.sagemaker.UserProfileUserSettingsSpaceStorageSettings; /** * Whether the user can access Studio. If this value is set to `DISABLED`, the user cannot access Studio, even if that is the default experience for the domain. Valid values are `ENABLED` and `DISABLED`. */ studioWebPortal: string; /** * The Studio Web Portal settings. See `studioWebPortalSettings` Block below. */ studioWebPortalSettings?: outputs.sagemaker.UserProfileUserSettingsStudioWebPortalSettings; /** * The TensorBoard app settings. See TensorBoard App Settings below. */ tensorBoardAppSettings?: outputs.sagemaker.UserProfileUserSettingsTensorBoardAppSettings; } interface UserProfileUserSettingsCanvasAppSettings { /** * The model deployment settings for the SageMaker AI Canvas application. See Direct Deploy Settings below. */ directDeploySettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsDirectDeploySettings; /** * The settings for running Amazon EMR Serverless jobs in SageMaker AI Canvas. See `emrServerlessSettings` Block below. */ emrServerlessSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsEmrServerlessSettings; generativeAiSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsGenerativeAiSettings; /** * The settings for connecting to an external data source with OAuth. See Identity Provider OAuth Settings below. */ identityProviderOauthSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsIdentityProviderOauthSetting[]; /** * The settings for document querying. See Kendra Settings below. */ kendraSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsKendraSettings; /** * The model registry settings for the SageMaker AI Canvas application. See Model Register Settings below. */ modelRegisterSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsModelRegisterSettings; /** * Time series forecast settings for the Canvas app. See Time Series Forecasting Settings below. */ timeSeriesForecastingSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsTimeSeriesForecastingSettings; /** * The workspace settings for the SageMaker AI Canvas application. See Workspace Settings below. */ workspaceSettings?: outputs.sagemaker.UserProfileUserSettingsCanvasAppSettingsWorkspaceSettings; } interface UserProfileUserSettingsCanvasAppSettingsDirectDeploySettings { /** * Describes whether model deployment permissions are enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface UserProfileUserSettingsCanvasAppSettingsEmrServerlessSettings { /** * ARN of the AWS IAM role that is assumed for running Amazon EMR Serverless jobs in SageMaker AI Canvas. This role should have the necessary permissions to read and write data attached and a trust relationship with EMR Serverless. */ executionRoleArn?: string; /** * Describes whether Amazon EMR Serverless job capabilities are enabled or disabled in the SageMaker AI Canvas application. Valid values are: `ENABLED` and `DISABLED`. */ status?: string; } interface UserProfileUserSettingsCanvasAppSettingsGenerativeAiSettings { amazonBedrockRoleArn?: string; } interface UserProfileUserSettingsCanvasAppSettingsIdentityProviderOauthSetting { /** * The name of the data source that you're connecting to. Canvas currently supports OAuth for Snowflake and Salesforce Data Cloud. Valid values are `SalesforceGenie` and `Snowflake`. */ dataSourceName?: string; /** * The ARN of an Amazon Web Services Secrets Manager secret that stores the credentials from your identity provider, such as the client ID and secret, authorization URL, and token URL. */ secretArn: string; /** * Describes whether OAuth for a data source is enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface UserProfileUserSettingsCanvasAppSettingsKendraSettings { /** * Describes whether the document querying feature is enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface UserProfileUserSettingsCanvasAppSettingsModelRegisterSettings { /** * ARN of the SageMaker AI model registry account. Required only to register model versions created by a different SageMaker AI Canvas AWS account than the AWS account in which SageMaker AI model registry is set up. */ crossAccountModelRegisterRoleArn?: string; /** * Describes whether the integration to the model registry is enabled or disabled in the Canvas application. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface UserProfileUserSettingsCanvasAppSettingsTimeSeriesForecastingSettings { /** * The IAM role that Canvas passes to Amazon Forecast for time series forecasting. By default, Canvas uses the execution role specified in the UserProfile that launches the Canvas app. If an execution role is not specified in the UserProfile, Canvas uses the execution role specified in the Domain that owns the UserProfile. To allow time series forecasting, this IAM role should have the [AmazonSageMakerCanvasForecastAccess](https://docs.aws.amazon.com/sagemaker/latest/dg/security-iam-awsmanpol-canvas.html#security-iam-awsmanpol-AmazonSageMakerCanvasForecastAccess) policy attached and forecast.amazonaws.com added in the trust relationship as a service principal. */ amazonForecastRoleArn?: string; /** * Describes whether time series forecasting is enabled or disabled in the Canvas app. Valid values are `ENABLED` and `DISABLED`. */ status?: string; } interface UserProfileUserSettingsCanvasAppSettingsWorkspaceSettings { /** * The Amazon S3 bucket used to store artifacts generated by Canvas. Updating the Amazon S3 location impacts existing configuration settings, and Canvas users no longer have access to their artifacts. Canvas users must log out and log back in to apply the new location. */ s3ArtifactPath?: string; /** * KMS encryption key ID that is used to encrypt artifacts generated by Canvas in the Amazon S3 bucket. */ s3KmsKeyId?: string; } interface UserProfileUserSettingsCodeEditorAppSettings { /** * Indicates whether idle shutdown is activated for JupyterLab applications. see `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.UserProfileUserSettingsCodeEditorAppSettingsAppLifecycleManagement; /** * The lifecycle configuration that runs before the default lifecycle configuration. It can override changes made in the default lifecycle configuration. */ builtInLifecycleConfigArn?: string; /** * A list of custom SageMaker AI images that are configured to run as a CodeEditor app. see Custom Image below. */ customImages?: outputs.sagemaker.UserProfileUserSettingsCodeEditorAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see Default Resource Spec below. */ defaultResourceSpec?: outputs.sagemaker.UserProfileUserSettingsCodeEditorAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface UserProfileUserSettingsCodeEditorAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. see `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.UserProfileUserSettingsCodeEditorAppSettingsAppLifecycleManagementIdleSettings; } interface UserProfileUserSettingsCodeEditorAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; /** * Indicates whether idle shutdown is activated for the application type. Valid values are `ENABLED` and `DISABLED`. */ lifecycleManagement?: string; /** * The maximum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ maxIdleTimeoutInMinutes?: number; /** * The minimum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ minIdleTimeoutInMinutes?: number; } interface UserProfileUserSettingsCodeEditorAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface UserProfileUserSettingsCodeEditorAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface UserProfileUserSettingsCustomFileSystemConfig { /** * The default EBS storage settings for a private space. See EFS File System Config below. */ efsFileSystemConfigs?: outputs.sagemaker.UserProfileUserSettingsCustomFileSystemConfigEfsFileSystemConfig[]; } interface UserProfileUserSettingsCustomFileSystemConfigEfsFileSystemConfig { /** * The ID of your Amazon EFS file system. */ fileSystemId: string; /** * The path to the file system directory that is accessible in Amazon SageMaker AI Studio. Permitted users can access only this directory and below. */ fileSystemPath?: string; } interface UserProfileUserSettingsCustomPosixUserConfig { /** * The POSIX group ID. */ gid: number; /** * The POSIX user ID. */ uid: number; } interface UserProfileUserSettingsJupyterLabAppSettings { /** * Indicates whether idle shutdown is activated for JupyterLab applications. see `appLifecycleManagement` Block below. */ appLifecycleManagement?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettingsAppLifecycleManagement; /** * The lifecycle configuration that runs before the default lifecycle configuration. It can override changes made in the default lifecycle configuration. */ builtInLifecycleConfigArn?: string; /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. see Code Repository below. */ codeRepositories?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettingsCodeRepository[]; customImages?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see Default Resource Spec below. */ defaultResourceSpec?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettingsDefaultResourceSpec; /** * The configuration parameters that specify the IAM roles assumed by the execution role of SageMaker AI (assumable roles) and the cluster instances or job execution environments (execution roles or runtime roles) to manage and access resources required for running Amazon EMR clusters or Amazon EMR Serverless applications. see `emrSettings` Block below. */ emrSettings?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettingsEmrSettings; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface UserProfileUserSettingsJupyterLabAppSettingsAppLifecycleManagement { /** * Settings related to idle shutdown of Studio applications. see `idleSettings` Block below. */ idleSettings?: outputs.sagemaker.UserProfileUserSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings; } interface UserProfileUserSettingsJupyterLabAppSettingsAppLifecycleManagementIdleSettings { /** * The time that SageMaker AI waits after the application becomes idle before shutting it down. Valid values are between `60` and `525600`. */ idleTimeoutInMinutes?: number; /** * Indicates whether idle shutdown is activated for the application type. Valid values are `ENABLED` and `DISABLED`. */ lifecycleManagement?: string; /** * The maximum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ maxIdleTimeoutInMinutes?: number; /** * The minimum value in minutes that custom idle shutdown can be set to by the user. Valid values are between `60` and `525600`. */ minIdleTimeoutInMinutes?: number; } interface UserProfileUserSettingsJupyterLabAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface UserProfileUserSettingsJupyterLabAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface UserProfileUserSettingsJupyterLabAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface UserProfileUserSettingsJupyterLabAppSettingsEmrSettings { /** * Array of ARNs of the IAM roles that the execution role of SageMaker AI can assume for performing operations or tasks related to Amazon EMR clusters or Amazon EMR Serverless applications. These roles define the permissions and access policies required when performing Amazon EMR-related operations, such as listing, connecting to, or terminating Amazon EMR clusters or Amazon EMR Serverless applications. They are typically used in cross-account access scenarios, where the Amazon EMR resources (clusters or serverless applications) are located in a different AWS account than the SageMaker AI domain. */ assumableRoleArns?: string[]; /** * Array of ARNs of the IAM roles used by the Amazon EMR cluster instances or job execution environments to access other AWS services and resources needed during the runtime of your Amazon EMR or Amazon EMR Serverless workloads, such as Amazon S3 for data access, Amazon CloudWatch for logging, or other AWS services based on the particular workload requirements. */ executionRoleArns?: string[]; } interface UserProfileUserSettingsJupyterServerAppSettings { /** * A list of Git repositories that SageMaker AI automatically displays to users for cloning in the JupyterServer application. see Code Repository below. */ codeRepositories?: outputs.sagemaker.UserProfileUserSettingsJupyterServerAppSettingsCodeRepository[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see Default Resource Spec below. */ defaultResourceSpec?: outputs.sagemaker.UserProfileUserSettingsJupyterServerAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface UserProfileUserSettingsJupyterServerAppSettingsCodeRepository { /** * The URL of the Git repository. */ repositoryUrl: string; } interface UserProfileUserSettingsJupyterServerAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface UserProfileUserSettingsKernelGatewayAppSettings { /** * A list of custom SageMaker AI images that are configured to run as a KernelGateway app. see Custom Image below. */ customImages?: outputs.sagemaker.UserProfileUserSettingsKernelGatewayAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see Default Resource Spec below. */ defaultResourceSpec?: outputs.sagemaker.UserProfileUserSettingsKernelGatewayAppSettingsDefaultResourceSpec; /** * ARN of the Lifecycle Configurations. */ lifecycleConfigArns?: string[]; } interface UserProfileUserSettingsKernelGatewayAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface UserProfileUserSettingsKernelGatewayAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface UserProfileUserSettingsRSessionAppSettings { /** * A list of custom SageMaker AI images that are configured to run as a KernelGateway app. see Custom Image below. */ customImages?: outputs.sagemaker.UserProfileUserSettingsRSessionAppSettingsCustomImage[]; /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see Default Resource Spec below. */ defaultResourceSpec?: outputs.sagemaker.UserProfileUserSettingsRSessionAppSettingsDefaultResourceSpec; } interface UserProfileUserSettingsRSessionAppSettingsCustomImage { /** * The name of the App Image Config. */ appImageConfigName: string; /** * The name of the Custom Image. */ imageName: string; /** * The version number of the Custom Image. */ imageVersionNumber?: number; } interface UserProfileUserSettingsRSessionAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface UserProfileUserSettingsRStudioServerProAppSettings { /** * Indicates whether the current user has access to the RStudioServerPro app. Valid values are `ENABLED` and `DISABLED`. */ accessStatus?: string; /** * The level of permissions that the user has within the RStudioServerPro app. This value defaults to `R_STUDIO_USER`. The `R_STUDIO_ADMIN` value allows the user access to the RStudio Administrative Dashboard. Valid values are `R_STUDIO_USER` and `R_STUDIO_ADMIN`. */ userGroup?: string; } interface UserProfileUserSettingsSharingSettings { /** * Whether to include the notebook cell output when sharing the notebook. The default is `Disabled`. Valid values are `Allowed` and `Disabled`. */ notebookOutputOption?: string; /** * When `notebookOutputOption` is Allowed, the KMS encryption key ID used to encrypt the notebook cell output in the Amazon S3 bucket. */ s3KmsKeyId?: string; /** * When `notebookOutputOption` is Allowed, the Amazon S3 bucket used to save the notebook cell output. */ s3OutputPath?: string; } interface UserProfileUserSettingsSpaceStorageSettings { /** * The default EBS storage settings for a private space. See Default EBS Storage Settings below. */ defaultEbsStorageSettings?: outputs.sagemaker.UserProfileUserSettingsSpaceStorageSettingsDefaultEbsStorageSettings; } interface UserProfileUserSettingsSpaceStorageSettingsDefaultEbsStorageSettings { /** * The default size of the EBS storage volume for a private space. */ defaultEbsVolumeSizeInGb: number; /** * The maximum size of the EBS storage volume for a private space. */ maximumEbsVolumeSizeInGb: number; } interface UserProfileUserSettingsStudioWebPortalSettings { /** * The Applications supported in Studio that are hidden from the Studio left navigation pane. */ hiddenAppTypes?: string[]; /** * The instance types you are hiding from the Studio user interface. */ hiddenInstanceTypes?: string[]; /** * The machine learning tools that are hidden from the Studio left navigation pane. */ hiddenMlTools?: string[]; } interface UserProfileUserSettingsTensorBoardAppSettings { /** * Default instance type and the ARN of the SageMaker AI image created on the instance. see Default Resource Spec below. */ defaultResourceSpec?: outputs.sagemaker.UserProfileUserSettingsTensorBoardAppSettingsDefaultResourceSpec; } interface UserProfileUserSettingsTensorBoardAppSettingsDefaultResourceSpec { /** * The instance type that the image version runs on.. For valid values see [SageMaker AI Instance Types](https://docs.aws.amazon.com/sagemaker/latest/dg/notebooks-available-instance-types.html). */ instanceType?: string; /** * ARN of the Lifecycle Configuration attached to the Resource. */ lifecycleConfigArn?: string; /** * The ARN of the SageMaker AI image that the image version belongs to. */ sagemakerImageArn?: string; /** * The SageMaker AI Image Version Alias. */ sagemakerImageVersionAlias?: string; /** * The ARN of the image version created on the instance. */ sagemakerImageVersionArn?: string; } interface WorkforceCognitoConfig { /** * The client ID for your Amazon Cognito user pool. */ clientId: string; /** * ID for your Amazon Cognito user pool. */ userPool: string; } interface WorkforceOidcConfig { /** * A string to string map of identifiers specific to the custom identity provider (IdP) being used. */ authenticationRequestExtraParams?: { [key: string]: string; }; /** * The OIDC IdP authorization endpoint used to configure your private workforce. */ authorizationEndpoint: string; /** * The OIDC IdP client ID used to configure your private workforce. */ clientId: string; /** * The OIDC IdP client secret used to configure your private workforce. */ clientSecret: string; /** * The OIDC IdP issuer used to configure your private workforce. */ issuer: string; /** * The OIDC IdP JSON Web Key Set (Jwks) URI used to configure your private workforce. */ jwksUri: string; /** * The OIDC IdP logout endpoint used to configure your private workforce. */ logoutEndpoint: string; /** * An array of string identifiers used to refer to the specific pieces of user data or claims that the client application wants to access. */ scope?: string; /** * The OIDC IdP token endpoint used to configure your private workforce. */ tokenEndpoint: string; /** * The OIDC IdP user information endpoint used to configure your private workforce. */ userInfoEndpoint: string; } interface WorkforceSourceIpConfig { /** * A list of up to 10 CIDR values. */ cidrs: string[]; } interface WorkforceWorkforceVpcConfig { /** * The VPC security group IDs. The security groups must be for the same VPC as specified in the subnet. */ securityGroupIds?: string[]; /** * The ID of the subnets in the VPC that you want to connect. */ subnets?: string[]; /** * The IDs for the VPC service endpoints of your VPC workforce. */ vpcEndpointId: string; /** * The ID of the VPC that the workforce uses for communication. */ vpcId?: string; } interface WorkteamMemberDefinition { /** * The Amazon Cognito user group that is part of the work team. See Cognito Member Definition details below. */ cognitoMemberDefinition?: outputs.sagemaker.WorkteamMemberDefinitionCognitoMemberDefinition; /** * A list user groups that exist in your OIDC Identity Provider (IdP). One to ten groups can be used to create a single private work team. See Cognito Member Definition details below. */ oidcMemberDefinition?: outputs.sagemaker.WorkteamMemberDefinitionOidcMemberDefinition; } interface WorkteamMemberDefinitionCognitoMemberDefinition { /** * An identifier for an application client. You must create the app client ID using Amazon Cognito. */ clientId: string; /** * An identifier for a user group. */ userGroup: string; /** * An identifier for a user pool. The user pool must be in the same region as the service that you are calling. */ userPool: string; } interface WorkteamMemberDefinitionOidcMemberDefinition { /** * A list of comma separated strings that identifies user groups in your OIDC IdP. Each user group is made up of a group of private workers. */ groups: string[]; } interface WorkteamNotificationConfiguration { /** * The ARN for the SNS topic to which notifications should be published. */ notificationTopicArn?: string; } interface WorkteamWorkerAccessConfiguration { /** * Defines any Amazon S3 resource constraints. see S3 Presign details below. */ s3Presign: outputs.sagemaker.WorkteamWorkerAccessConfigurationS3Presign; } interface WorkteamWorkerAccessConfigurationS3Presign { /** * Use this parameter to specify the allowed request source. Possible sources are either SourceIp or VpcSourceIp. see IAM Policy Constraints details below. */ iamPolicyConstraints: outputs.sagemaker.WorkteamWorkerAccessConfigurationS3PresignIamPolicyConstraints; } interface WorkteamWorkerAccessConfigurationS3PresignIamPolicyConstraints { /** * When SourceIp is Enabled the worker's IP address when a task is rendered in the worker portal is added to the IAM policy as a Condition used to generate the Amazon S3 presigned URL. This IP address is checked by Amazon S3 and must match in order for the Amazon S3 resource to be rendered in the worker portal. Valid values are `Enabled` or `Disabled` */ sourceIp: string; /** * When VpcSourceIp is Enabled the worker's IP address when a task is rendered in private worker portal inside the VPC is added to the IAM policy as a Condition used to generate the Amazon S3 presigned URL. To render the task successfully Amazon S3 checks that the presigned URL is being accessed over an Amazon S3 VPC Endpoint, and that the worker's IP address matches the IP address in the IAM policy. To learn more about configuring private worker portal, see [Use Amazon VPC mode from a private worker portal](https://docs.aws.amazon.com/sagemaker/latest/dg/samurai-vpc-worker-portal.html). Valid values are `Enabled` or `Disabled` */ vpcSourceIp: string; } } export declare namespace savingsplans { interface GetOfferingsFilter { /** * Filter name. */ name: string; /** * List of filter values. */ values: string[]; } interface GetOfferingsOffering { /** * Currency. */ currency: string; /** * Description. */ description: string; /** * Duration, in seconds. */ durationSeconds: number; /** * Offering ID. */ offeringId: string; /** * Operation. */ operation: string; /** * Payment option. */ paymentOption: string; /** * Plan type. */ planType: string; /** * List of product types. */ productTypes: string[]; /** * List of properties. See `properties` Attribute Reference. */ properties: outputs.savingsplans.GetOfferingsOfferingProperty[]; /** * Service code. */ serviceCode: string; /** * Usage type. */ usageType: string; } interface GetOfferingsOfferingProperty { /** * Property name. */ name: string; /** * Property value. */ value: string; } interface SavingsPlanTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace scheduler { interface ScheduleFlexibleTimeWindow { /** * Maximum time window during which a schedule can be invoked. Ranges from `1` to `1440` minutes. */ maximumWindowInMinutes?: number; /** * Determines whether the schedule is invoked within a flexible time window. One of: `OFF`, `FLEXIBLE`. */ mode: string; } interface ScheduleTarget { /** * ARN of the target of this schedule, such as a SQS queue or ECS cluster. For universal targets, this is a [Service ARN specific to the target service](https://docs.aws.amazon.com/scheduler/latest/UserGuide/managing-targets-universal.html#supported-universal-targets). */ arn: string; /** * Information about an Amazon SQS queue that EventBridge Scheduler uses as a dead-letter queue for your schedule. If specified, EventBridge Scheduler delivers failed events that could not be successfully delivered to a target to the queue. Detailed below. */ deadLetterConfig?: outputs.scheduler.ScheduleTargetDeadLetterConfig; /** * Templated target type for the Amazon ECS [`RunTask`](https://docs.aws.amazon.com/AmazonECS/latest/APIReference/API_RunTask.html) API operation. Detailed below. */ ecsParameters?: outputs.scheduler.ScheduleTargetEcsParameters; /** * Templated target type for the EventBridge [`PutEvents`](https://docs.aws.amazon.com/eventbridge/latest/APIReference/API_PutEvents.html) API operation. Detailed below. */ eventbridgeParameters?: outputs.scheduler.ScheduleTargetEventbridgeParameters; /** * Text, or well-formed JSON, passed to the target. Read more in [Universal target](https://docs.aws.amazon.com/scheduler/latest/UserGuide/managing-targets-universal.html). */ input?: string; /** * Templated target type for the Amazon Kinesis [`PutRecord`](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_PutRecord.html) API operation. Detailed below. */ kinesisParameters?: outputs.scheduler.ScheduleTargetKinesisParameters; /** * Information about the retry policy settings. Detailed below. */ retryPolicy?: outputs.scheduler.ScheduleTargetRetryPolicy; /** * ARN of the IAM role that EventBridge Scheduler will use for this target when the schedule is invoked. Read more in [Set up the execution role](https://docs.aws.amazon.com/scheduler/latest/UserGuide/setting-up.html#setting-up-execution-role). * * The following arguments are optional: */ roleArn: string; /** * Templated target type for the Amazon SageMaker AI [`StartPipelineExecution`](https://docs.aws.amazon.com/sagemaker/latest/APIReference/API_StartPipelineExecution.html) API operation. Detailed below. */ sagemakerPipelineParameters?: outputs.scheduler.ScheduleTargetSagemakerPipelineParameters; /** * The templated target type for the Amazon SQS [`SendMessage`](https://docs.aws.amazon.com/AWSSimpleQueueService/latest/APIReference/API_SendMessage.html) API operation. Detailed below. */ sqsParameters?: outputs.scheduler.ScheduleTargetSqsParameters; } interface ScheduleTargetDeadLetterConfig { /** * ARN of the SQS queue specified as the destination for the dead-letter queue. */ arn: string; } interface ScheduleTargetEcsParameters { /** * Up to `6` capacity provider strategies to use for the task. Detailed below. */ capacityProviderStrategies?: outputs.scheduler.ScheduleTargetEcsParametersCapacityProviderStrategy[]; /** * Specifies whether to enable Amazon ECS managed tags for the task. For more information, see [Tagging Your Amazon ECS Resources](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-using-tags.html) in the Amazon ECS Developer Guide. */ enableEcsManagedTags?: boolean; /** * Specifies whether to enable the execute command functionality for the containers in this task. */ enableExecuteCommand?: boolean; /** * Specifies an ECS task group for the task. At most 255 characters. */ group?: string; /** * Specifies the launch type on which your task is running. The launch type that you specify here must match one of the launch type (compatibilities) of the target task. One of: `EC2`, `FARGATE`, `EXTERNAL`. */ launchType?: string; /** * Configures the networking associated with the task. Detailed below. */ networkConfiguration?: outputs.scheduler.ScheduleTargetEcsParametersNetworkConfiguration; /** * A set of up to 10 placement constraints to use for the task. Detailed below. */ placementConstraints?: outputs.scheduler.ScheduleTargetEcsParametersPlacementConstraint[]; /** * A set of up to 5 placement strategies. Detailed below. */ placementStrategies?: outputs.scheduler.ScheduleTargetEcsParametersPlacementStrategy[]; /** * Specifies the platform version for the task. Specify only the numeric portion of the platform version, such as `1.1.0`. */ platformVersion?: string; /** * Specifies whether to propagate the tags from the task definition to the task. One of: `TASK_DEFINITION`. */ propagateTags?: string; /** * Reference ID to use for the task. */ referenceId?: string; /** * The metadata that you apply to the task. Each tag consists of a key and an optional value. For more information, see [`RunTask`](https://docs.aws.amazon.com/AmazonECS/latest/APIReference/API_RunTask.html) in the Amazon ECS API Reference. */ tags?: { [key: string]: string; }; /** * The number of tasks to create. Ranges from `1` (default) to `10`. */ taskCount?: number; /** * ARN of the task definition to use. * * The following arguments are optional: */ taskDefinitionArn: string; } interface ScheduleTargetEcsParametersCapacityProviderStrategy { /** * How many tasks, at a minimum, to run on the specified capacity provider. Only one capacity provider in a capacity provider strategy can have a base defined. Ranges from `0` (default) to `100000`. */ base?: number; /** * Short name of the capacity provider. */ capacityProvider: string; /** * Designates the relative percentage of the total number of tasks launched that should use the specified capacity provider. The weight value is taken into consideration after the base value, if defined, is satisfied. Ranges from from `0` to `1000`. */ weight?: number; } interface ScheduleTargetEcsParametersNetworkConfiguration { /** * Specifies whether the task's elastic network interface receives a public IP address. This attribute is a boolean type, where `true` maps to `ENABLED` and `false` to `DISABLED`. You can specify `true` only when the `launchType` is set to `FARGATE`. */ assignPublicIp?: boolean; /** * Set of 1 to 5 Security Group ID-s to be associated with the task. These security groups must all be in the same VPC. */ securityGroups?: string[]; /** * Set of 1 to 16 subnets to be associated with the task. These subnets must all be in the same VPC. */ subnets: string[]; } interface ScheduleTargetEcsParametersPlacementConstraint { /** * A cluster query language expression to apply to the constraint. You cannot specify an expression if the constraint type is `distinctInstance`. For more information, see [Cluster query language](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/cluster-query-language.html) in the Amazon ECS Developer Guide. */ expression?: string; /** * The type of constraint. One of: `distinctInstance`, `memberOf`. */ type: string; } interface ScheduleTargetEcsParametersPlacementStrategy { /** * The field to apply the placement strategy against. */ field?: string; /** * The type of placement strategy. One of: `random`, `spread`, `binpack`. */ type: string; } interface ScheduleTargetEventbridgeParameters { /** * Free-form string used to decide what fields to expect in the event detail. Up to 128 characters. */ detailType: string; /** * Source of the event. */ source: string; } interface ScheduleTargetKinesisParameters { /** * Specifies the shard to which EventBridge Scheduler sends the event. Up to 256 characters. */ partitionKey: string; } interface ScheduleTargetRetryPolicy { /** * Maximum amount of time, in seconds, to continue to make retry attempts. Ranges from `60` to `86400` (default). */ maximumEventAgeInSeconds?: number; /** * Maximum number of retry attempts to make before the request fails. Ranges from `0` to `185` (default). */ maximumRetryAttempts?: number; } interface ScheduleTargetSagemakerPipelineParameters { /** * Set of up to 200 parameter names and values to use when executing the SageMaker AI Model Building Pipeline. Detailed below. */ pipelineParameters?: outputs.scheduler.ScheduleTargetSagemakerPipelineParametersPipelineParameter[]; } interface ScheduleTargetSagemakerPipelineParametersPipelineParameter { /** * Name of parameter to start execution of a SageMaker AI Model Building Pipeline. */ name: string; /** * Value of parameter to start execution of a SageMaker AI Model Building Pipeline. */ value: string; } interface ScheduleTargetSqsParameters { /** * FIFO message group ID to use as the target. */ messageGroupId?: string; } } export declare namespace secretsmanager { interface GetSecretRotationExternalSecretRotationMetadata { /** * Metadata key name. */ key: string; /** * Metadata value for the specified key. */ value: string; } interface GetSecretRotationRotationRule { /** * Number of days between automatic scheduled rotations of the secret. */ automaticallyAfterDays: number; /** * Length of the rotation window in hours. */ duration: string; /** * `cron()` or `rate()` expression that defines the schedule for rotating the secret. */ scheduleExpression: string; } interface GetSecretVersionsVersion { /** * Date and time this version of the secret was created. */ createdTime: string; /** * Date that this version of the secret was last accessed. */ lastAccessedDate: string; /** * Unique version identifier of this version of the secret. */ versionId: string; /** * List of staging labels attached to the version. */ versionStages: string[]; } interface GetSecretsFilter { /** * Name of the filter field. Valid values can be found in the [Secrets Manager ListSecrets API Reference](https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_ListSecrets.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface SecretReplica { /** * ARN, Key ID, or Alias of the AWS KMS key within the region secret is replicated to. If one is not specified, then Secrets Manager defaults to using the AWS account's default KMS key (`aws/secretsmanager`) in the region or creates one for use if non-existent. */ kmsKeyId: string; /** * Date that you last accessed the secret in the Region. */ lastAccessedDate: string; /** * Region for replicating the secret. */ region: string; /** * Status can be `InProgress`, `Failed`, or `InSync`. */ status: string; /** * Message such as `Replication succeeded` or `Secret with this name already exists in this region`. */ statusMessage: string; } interface SecretRotationExternalSecretRotationMetadata { /** * Metadata key name. Partner-specific keys are required for each external secret type. See [partner documentation](https://docs.aws.amazon.com/secretsmanager/latest/userguide/mes-partners.html) for required keys. */ key: string; /** * Metadata value for the specified key. */ value: string; } interface SecretRotationRotationRules { /** * Number of days between automatic scheduled rotations of the secret. Either `automaticallyAfterDays` or `scheduleExpression` must be specified. */ automaticallyAfterDays?: number; /** * The length of the rotation window in hours. For example, `3h` for a three hour window. */ duration?: string; /** * `cron()` or `rate()` expression that defines the schedule for rotating your secret. Either `automaticallyAfterDays` or `scheduleExpression` must be specified. */ scheduleExpression?: string; } } export declare namespace securityhub { interface AutomationRuleAction { /** * A block that specifies that the automation rule action is an update to a finding field. Documented below. */ findingFieldsUpdate?: outputs.securityhub.AutomationRuleActionFindingFieldsUpdate; /** * Specifies that the rule action should update the `Types` finding field. The `Types` finding field classifies findings in the format of namespace/category/classifier. */ type?: string; } interface AutomationRuleActionFindingFieldsUpdate { /** * The rule action updates the `Confidence` field of a finding. */ confidence?: number; /** * The rule action updates the `Criticality` field of a finding. */ criticality?: number; /** * A resource block that updates the note. Documented below. */ note?: outputs.securityhub.AutomationRuleActionFindingFieldsUpdateNote; /** * A resource block that the rule action updates the `RelatedFindings` field of a finding. Documented below. */ relatedFindings?: outputs.securityhub.AutomationRuleActionFindingFieldsUpdateRelatedFinding[]; /** * A resource block that updates to the severity information for a finding. Documented below. */ severity?: outputs.securityhub.AutomationRuleActionFindingFieldsUpdateSeverity; /** * The rule action updates the `Types` field of a finding. */ types?: string[]; /** * The rule action updates the `UserDefinedFields` field of a finding. */ userDefinedFields?: { [key: string]: string; }; /** * The rule action updates the `VerificationState` field of a finding. The allowed values are the following `UNKNOWN`, `TRUE_POSITIVE`, `FALSE_POSITIVE` and `BENIGN_POSITIVE`. */ verificationState?: string; /** * A resource block that is used to update information about the investigation into the finding. Documented below. */ workflow?: outputs.securityhub.AutomationRuleActionFindingFieldsUpdateWorkflow; } interface AutomationRuleActionFindingFieldsUpdateNote { /** * The updated note text. */ text: string; /** * The principal that updated the note. */ updatedBy: string; } interface AutomationRuleActionFindingFieldsUpdateRelatedFinding { /** * The product-generated identifier for a related finding. */ id: string; /** * The ARN of the product that generated a related finding. */ productArn: string; } interface AutomationRuleActionFindingFieldsUpdateSeverity { /** * The severity value of the finding. The allowed values are the following `INFORMATIONAL`, `LOW`, `MEDIUM`, `HIGH` and `CRITICAL`. */ label: string; /** * The native severity as defined by the AWS service or integrated partner product that generated the finding. */ product?: number; } interface AutomationRuleActionFindingFieldsUpdateWorkflow { /** * The status of the investigation into the finding. The allowed values are the following `NEW`, `NOTIFIED`, `RESOLVED` and `SUPPRESSED`. */ status?: string; } interface AutomationRuleCriteria { /** * The AWS account ID in which a finding was generated. Documented below. */ awsAccountIds?: outputs.securityhub.AutomationRuleCriteriaAwsAccountId[]; /** * The name of the AWS account in which a finding was generated. Documented below. */ awsAccountNames?: outputs.securityhub.AutomationRuleCriteriaAwsAccountName[]; /** * The name of the company for the product that generated the finding. For control-based findings, the company is AWS. Documented below. */ companyNames?: outputs.securityhub.AutomationRuleCriteriaCompanyName[]; /** * The unique identifier of a standard in which a control is enabled. Documented below. */ complianceAssociatedStandardsIds?: outputs.securityhub.AutomationRuleCriteriaComplianceAssociatedStandardsId[]; /** * The security control ID for which a finding was generated. Security control IDs are the same across standards. Documented below. */ complianceSecurityControlIds?: outputs.securityhub.AutomationRuleCriteriaComplianceSecurityControlId[]; /** * The result of a security check. This field is only used for findings generated from controls. Documented below. */ complianceStatuses?: outputs.securityhub.AutomationRuleCriteriaComplianceStatus[]; /** * The likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. `Confidence` is scored on a 0–100 basis using a ratio scale. A value of `0` means 0 percent confidence, and a value of `100` means 100 percent confidence. Documented below. */ confidences?: outputs.securityhub.AutomationRuleCriteriaConfidence[]; /** * A timestamp that indicates when this finding record was created. Documented below. */ createdAts?: outputs.securityhub.AutomationRuleCriteriaCreatedAt[]; /** * The level of importance that is assigned to the resources that are associated with a finding. Documented below. */ criticalities?: outputs.securityhub.AutomationRuleCriteriaCriticality[]; /** * A finding's description. Documented below. */ descriptions?: outputs.securityhub.AutomationRuleCriteriaDescription[]; /** * A timestamp that indicates when the potential security issue captured by a finding was first observed by the security findings product. Documented below. */ firstObservedAts?: outputs.securityhub.AutomationRuleCriteriaFirstObservedAt[]; /** * The identifier for the solution-specific component that generated a finding. Documented below. */ generatorIds?: outputs.securityhub.AutomationRuleCriteriaGeneratorId[]; /** * The product-specific identifier for a finding. Documented below. */ ids?: outputs.securityhub.AutomationRuleCriteriaId[]; /** * A timestamp that indicates when the potential security issue captured by a finding was most recently observed by the security findings product. Documented below. */ lastObservedAts?: outputs.securityhub.AutomationRuleCriteriaLastObservedAt[]; /** * The text of a user-defined note that's added to a finding. Documented below. */ noteTexts?: outputs.securityhub.AutomationRuleCriteriaNoteText[]; /** * The timestamp of when the note was updated. Documented below. */ noteUpdatedAts?: outputs.securityhub.AutomationRuleCriteriaNoteUpdatedAt[]; /** * The principal that created a note. Documented below. */ noteUpdatedBies?: outputs.securityhub.AutomationRuleCriteriaNoteUpdatedBy[]; /** * ARN for a third-party product that generated a finding in Security Hub. Documented below. */ productArns?: outputs.securityhub.AutomationRuleCriteriaProductArn[]; /** * Provides the name of the product that generated the finding. For control-based findings, the product name is Security Hub. Documented below. */ productNames?: outputs.securityhub.AutomationRuleCriteriaProductName[]; /** * Provides the current state of a finding. Documented below. */ recordStates?: outputs.securityhub.AutomationRuleCriteriaRecordState[]; /** * The product-generated identifier for a related finding. Documented below. */ relatedFindingsIds?: outputs.securityhub.AutomationRuleCriteriaRelatedFindingsId[]; /** * The ARN for the product that generated a related finding. Documented below. */ relatedFindingsProductArns?: outputs.securityhub.AutomationRuleCriteriaRelatedFindingsProductArn[]; /** * ARN of the application that is related to a finding. Documented below. */ resourceApplicationArns?: outputs.securityhub.AutomationRuleCriteriaResourceApplicationArn[]; /** * The name of the application that is related to a finding. Documented below. */ resourceApplicationNames?: outputs.securityhub.AutomationRuleCriteriaResourceApplicationName[]; /** * Custom fields and values about the resource that a finding pertains to. Documented below. */ resourceDetailsOthers?: outputs.securityhub.AutomationRuleCriteriaResourceDetailsOther[]; /** * Identifier for the given resource type. For AWS resources that are identified by ARNs, this is the ARN. For AWS resources that lack ARNs, this is the identifier as defined by the AWS service that created the resource. For non-AWS resources, this is a unique identifier that is associated with the resource. Documented below. */ resourceIds?: outputs.securityhub.AutomationRuleCriteriaResourceId[]; /** * The partition in which the resource that the finding pertains to is located. A partition is a group of AWS Regions. Each AWS account is scoped to one partition. Documented below. */ resourcePartitions?: outputs.securityhub.AutomationRuleCriteriaResourcePartition[]; /** * The AWS Region where the resource that a finding pertains to is located. Documented below. */ resourceRegions?: outputs.securityhub.AutomationRuleCriteriaResourceRegion[]; /** * A list of AWS tags associated with a resource at the time the finding was processed. Documented below. */ resourceTags?: outputs.securityhub.AutomationRuleCriteriaResourceTag[]; /** * The type of resource that the finding pertains to. Documented below. */ resourceTypes?: outputs.securityhub.AutomationRuleCriteriaResourceType[]; /** * The severity value of the finding. Documented below. */ severityLabels?: outputs.securityhub.AutomationRuleCriteriaSeverityLabel[]; /** * Provides a URL that links to a page about the current finding in the finding product. Documented below. */ sourceUrls?: outputs.securityhub.AutomationRuleCriteriaSourceUrl[]; /** * A finding's title. Documented below. */ titles?: outputs.securityhub.AutomationRuleCriteriaTitle[]; /** * One or more finding types in the format of namespace/category/classifier that classify a finding. Documented below. */ types?: outputs.securityhub.AutomationRuleCriteriaType[]; /** * A timestamp that indicates when the finding record was most recently updated. Documented below. */ updatedAts?: outputs.securityhub.AutomationRuleCriteriaUpdatedAt[]; /** * A list of user-defined name and value string pairs added to a finding. Documented below. */ userDefinedFields?: outputs.securityhub.AutomationRuleCriteriaUserDefinedField[]; /** * Provides the veracity of a finding. Documented below. */ verificationStates?: outputs.securityhub.AutomationRuleCriteriaVerificationState[]; /** * Provides information about the status of the investigation into a finding. Documented below. */ workflowStatuses?: outputs.securityhub.AutomationRuleCriteriaWorkflowStatus[]; } interface AutomationRuleCriteriaAwsAccountId { comparison: string; value: string; } interface AutomationRuleCriteriaAwsAccountName { comparison: string; value: string; } interface AutomationRuleCriteriaCompanyName { comparison: string; value: string; } interface AutomationRuleCriteriaComplianceAssociatedStandardsId { comparison: string; value: string; } interface AutomationRuleCriteriaComplianceSecurityControlId { comparison: string; value: string; } interface AutomationRuleCriteriaComplianceStatus { comparison: string; value: string; } interface AutomationRuleCriteriaConfidence { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: number; gt?: number; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: number; lt?: number; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: number; } interface AutomationRuleCriteriaCreatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.AutomationRuleCriteriaCreatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface AutomationRuleCriteriaCreatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface AutomationRuleCriteriaCriticality { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: number; gt?: number; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: number; lt?: number; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: number; } interface AutomationRuleCriteriaDescription { comparison: string; value: string; } interface AutomationRuleCriteriaFirstObservedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.AutomationRuleCriteriaFirstObservedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface AutomationRuleCriteriaFirstObservedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface AutomationRuleCriteriaGeneratorId { comparison: string; value: string; } interface AutomationRuleCriteriaId { comparison: string; value: string; } interface AutomationRuleCriteriaLastObservedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.AutomationRuleCriteriaLastObservedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface AutomationRuleCriteriaLastObservedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface AutomationRuleCriteriaNoteText { comparison: string; value: string; } interface AutomationRuleCriteriaNoteUpdatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.AutomationRuleCriteriaNoteUpdatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface AutomationRuleCriteriaNoteUpdatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface AutomationRuleCriteriaNoteUpdatedBy { comparison: string; value: string; } interface AutomationRuleCriteriaProductArn { comparison: string; value: string; } interface AutomationRuleCriteriaProductName { comparison: string; value: string; } interface AutomationRuleCriteriaRecordState { comparison: string; value: string; } interface AutomationRuleCriteriaRelatedFindingsId { comparison: string; value: string; } interface AutomationRuleCriteriaRelatedFindingsProductArn { comparison: string; value: string; } interface AutomationRuleCriteriaResourceApplicationArn { comparison: string; value: string; } interface AutomationRuleCriteriaResourceApplicationName { comparison: string; value: string; } interface AutomationRuleCriteriaResourceDetailsOther { comparison: string; /** * The key of the map filter. */ key: string; value: string; } interface AutomationRuleCriteriaResourceId { comparison: string; value: string; } interface AutomationRuleCriteriaResourcePartition { comparison: string; value: string; } interface AutomationRuleCriteriaResourceRegion { comparison: string; value: string; } interface AutomationRuleCriteriaResourceTag { comparison: string; /** * The key of the map filter. */ key: string; value: string; } interface AutomationRuleCriteriaResourceType { comparison: string; value: string; } interface AutomationRuleCriteriaSeverityLabel { comparison: string; value: string; } interface AutomationRuleCriteriaSourceUrl { comparison: string; value: string; } interface AutomationRuleCriteriaTitle { comparison: string; value: string; } interface AutomationRuleCriteriaType { comparison: string; value: string; } interface AutomationRuleCriteriaUpdatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.AutomationRuleCriteriaUpdatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface AutomationRuleCriteriaUpdatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface AutomationRuleCriteriaUserDefinedField { comparison: string; /** * The key of the map filter. */ key: string; value: string; } interface AutomationRuleCriteriaVerificationState { comparison: string; value: string; } interface AutomationRuleCriteriaWorkflowStatus { comparison: string; value: string; } interface AutomationRuleV2Action { /** * Settings for external integration actions. See `externalIntegrationConfiguration` below. */ externalIntegrationConfiguration?: outputs.securityhub.AutomationRuleV2ActionExternalIntegrationConfiguration; /** * Settings for updating finding fields. See `findingFieldsUpdate` below. */ findingFieldsUpdate?: outputs.securityhub.AutomationRuleV2ActionFindingFieldsUpdate; /** * The action type. Valid values: `FINDING_FIELDS_UPDATE`, `EXTERNAL_INTEGRATION`. */ type: string; } interface AutomationRuleV2ActionExternalIntegrationConfiguration { /** * The ARN of the connector. */ connectorArn: string; } interface AutomationRuleV2ActionFindingFieldsUpdate { /** * A comment for the finding. */ comment?: string; /** * The severity ID to assign. */ severityId?: number; /** * The status ID to assign. */ statusId?: number; } interface AutomationRuleV2Criteria { /** * JSON-encoded OCSF finding criteria for the rule. See the [AWS API Reference](https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_OcsfFindingFilters.html) for details. */ ocsfFindingCriteriaJson: string; } interface ConfigurationPolicyConfigurationPolicy { /** * A list that defines which security standards are enabled in the configuration policy. It must be defined if `serviceEnabled` is set to true. */ enabledStandardArns?: string[]; /** * Defines which security controls are enabled in the configuration policy and any customizations to parameters affecting them. It must be defined if `serviceEnabled` is set to true. See below. */ securityControlsConfiguration?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfiguration; /** * Indicates whether Security Hub is enabled in the policy. */ serviceEnabled: boolean; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfiguration { /** * A list of security controls that are disabled in the configuration policy Security Hub enables all other controls (including newly released controls) other than the listed controls. Conflicts with `enabledControlIdentifiers`. */ disabledControlIdentifiers?: string[]; /** * A list of security controls that are enabled in the configuration policy. Security Hub disables all other controls (including newly released controls) other than the listed controls. Conflicts with `disabledControlIdentifiers`. */ enabledControlIdentifiers?: string[]; /** * A list of control parameter customizations that are included in a configuration policy. Include multiple blocks to define multiple control custom parameters. See below. */ securityControlCustomParameters?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameter[]; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameter { /** * An object that specifies parameter values for a control in a configuration policy. See below. */ parameters: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameter[]; /** * The ID of the security control. For more information see the [Security Hub controls reference] documentation. */ securityControlId: string; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameter { /** * The bool `value` for a Boolean-typed Security Hub Control Parameter. */ bool?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterBool; /** * The float `value` for a Double-typed Security Hub Control Parameter. */ double?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterDouble; /** * The string `value` for a Enum-typed Security Hub Control Parameter. */ enum?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterEnum; /** * The string list `value` for a EnumList-typed Security Hub Control Parameter. */ enumList?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterEnumList; /** * The int `value` for a Int-typed Security Hub Control Parameter. */ int?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterInt; /** * The int list `value` for a IntList-typed Security Hub Control Parameter. */ intList?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterIntList; /** * The name of the control parameter. For more information see the [Security Hub controls reference] documentation. */ name: string; /** * The string `value` for a String-typed Security Hub Control Parameter. */ string?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterString; /** * The string list `value` for a StringList-typed Security Hub Control Parameter. */ stringList?: outputs.securityhub.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterStringList; /** * Identifies whether a control parameter uses a custom user-defined value or subscribes to the default Security Hub behavior. Valid values: `DEFAULT`, `CUSTOM`. */ valueType: string; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterBool { value: boolean; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterDouble { value: number; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterEnum { value: string; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterEnumList { values: string[]; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterInt { value: number; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterIntList { values: number[]; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterString { value: string; } interface ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterStringList { values: string[]; } interface ConnectorV2ConnectorProvider { /** * Details about a Jira Cloud integration. See `jiraCloud` below. */ jiraCloud?: outputs.securityhub.ConnectorV2ConnectorProviderJiraCloud; /** * Details about a ServiceNow ITSM integration. See `serviceNow` below. */ serviceNow?: outputs.securityhub.ConnectorV2ConnectorProviderServiceNow; } interface ConnectorV2ConnectorProviderJiraCloud { /** * Status of the authorization between Jira Cloud and the service. */ authStatus: string; /** * URL to provide to customers for OAuth auth code flow. */ authUrl: string; /** * Cloud ID of the Jira Cloud. */ cloudId: string; /** * URL domain of the Jira Cloud instance. */ domain: string; /** * Jira Cloud project key. */ projectKey: string; } interface ConnectorV2ConnectorProviderServiceNow { /** * Status of the authorization between ServiceNow and the service. */ authStatus: string; /** * Instance name of ServiceNow ITSM. */ instanceName: string; /** * ARN of the AWS Secrets Manager secret that contains the ServiceNow credentials. */ secretArn: string; } interface ConnectorV2Health { /** * Status of the connector. */ connectorStatus: string; /** * Timestamp for the time the health status was checked. */ lastCheckedAt: string; /** * Message for the reason of `connectorStatus` change. */ message: string; } interface GetEnabledStandardsStandardsSubscription { /** * ARN of the standard. */ standardsArn: string; /** * Whether you can retrieve information about and configure individual controls that apply to the standard. Valid values: `READY_FOR_UPDATES`, `NOT_READY_FOR_UPDATES`. */ standardsControlsUpdatable: string; /** * Key-value map of input for the standard. */ standardsInputs: { [key: string]: string; }; /** * Status of your subscription to the standard. Valid values: `PENDING`, `READY`, `FAILED`, `DELETING`, `INCOMPLETE`. */ standardsStatus: string; /** * Reason for the current status. See below for details. */ standardsStatusReasons: outputs.securityhub.GetEnabledStandardsStandardsSubscriptionStandardsStatusReason[]; /** * ARN of the resource that represents your subscription to the standard. */ standardsSubscriptionArn: string; } interface GetEnabledStandardsStandardsSubscriptionStandardsStatusReason { /** * Reason code that represents the reason for the current status of a standard subscription. Valid values: `NO_AVAILABLE_CONFIGURATION_RECORDER`, `MAXIMUM_NUMBER_OF_CONFIG_RULES_EXCEEDED`, `INTERNAL_ERROR`. */ statusReasonCode: string; } interface GetSecurityControlsSecurityControlDefinition { /** * Whether the security control is available in the current AWS Region. Valid values: `AVAILABLE`, `UNAVAILABLE`. */ currentRegionAvailability: string; /** * Security control properties that you can customize. */ customizableProperties: string[]; /** * Description of the security control across standards. */ description: string; /** * Link to Security Hub CSPM documentation that explains how to remediate a failed finding for the security control. */ remediationUrl: string; /** * Unique identifier of the security control across standards. */ securityControlId: string; /** * Severity of the security control. Valid values: `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`. */ severityRating: string; /** * Title of the security control. */ title: string; } interface GetStandardsControlAssociationsStandardsControlAssociation { /** * Enablement status of a control in a specific standard. */ associationStatus: string; /** * List of underlying requirements in the compliance framework related to the standard. */ relatedRequirements: string[]; /** * ARN of the security control. */ securityControlArn: string; /** * The identifier of the control (identified with `SecurityControlId`, `SecurityControlArn`, or a mix of both parameters). */ securityControlId: string; /** * ARN of the standard. */ standardsArn: string; /** * Description of the standard. */ standardsControlDescription: string; /** * Title of the standard. */ standardsControlTitle: string; /** * Last time that a control's enablement status in a specified standard was updated. */ updatedAt: string; /** * Reason for updating a control's enablement status in a specified standard. */ updatedReason: string; } interface InsightFilters { /** * AWS account ID that a finding is generated in. See String_Filter below for more details. */ awsAccountIds?: outputs.securityhub.InsightFiltersAwsAccountId[]; /** * The name of the AWS account in which a finding is generated. See String_Filter below for more details. */ awsAccountNames?: outputs.securityhub.InsightFiltersAwsAccountName[]; /** * The name of the findings provider (company) that owns the solution (product) that generates findings. See String_Filter below for more details. */ companyNames?: outputs.securityhub.InsightFiltersCompanyName[]; /** * The unique identifier of a standard in which a control is enabled. See String_Filter below for more details. */ complianceAssociatedStandardsIds?: outputs.securityhub.InsightFiltersComplianceAssociatedStandardsId[]; /** * The unique identifier of a control across standards. See String_Filter below for more details. */ complianceSecurityControlIds?: outputs.securityhub.InsightFiltersComplianceSecurityControlId[]; /** * The unique identifier of a control across standards. See String_Filter below for more details. */ complianceSecurityControlParametersNames?: outputs.securityhub.InsightFiltersComplianceSecurityControlParametersName[]; /** * The current value of a security control parameter. See String_Filter below for more details. */ complianceSecurityControlParametersValues?: outputs.securityhub.InsightFiltersComplianceSecurityControlParametersValue[]; /** * Exclusive to findings that are generated as the result of a check run against a specific rule in a supported standard, such as CIS AWS Foundations. Contains security standard-related finding details. See String Filter below for more details. */ complianceStatuses?: outputs.securityhub.InsightFiltersComplianceStatus[]; /** * A finding's confidence. Confidence is defined as the likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence is scored on a 0-100 basis using a ratio scale, where 0 means zero percent confidence and 100 means 100 percent confidence. See Number Filter below for more details. */ confidences?: outputs.securityhub.InsightFiltersConfidence[]; /** * An ISO8601-formatted timestamp that indicates when the security-findings provider captured the potential security issue that a finding captured. See Date Filter below for more details. */ createdAts?: outputs.securityhub.InsightFiltersCreatedAt[]; /** * The level of importance assigned to the resources associated with the finding. A score of 0 means that the underlying resources have no criticality, and a score of 100 is reserved for the most critical resources. See Number Filter below for more details. */ criticalities?: outputs.securityhub.InsightFiltersCriticality[]; /** * A finding's description. See String Filter below for more details. */ descriptions?: outputs.securityhub.InsightFiltersDescription[]; /** * The finding provider value for the finding confidence. Confidence is defined as the likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence is scored on a 0-100 basis using a ratio scale, where 0 means zero percent confidence and 100 means 100 percent confidence. See Number Filter below for more details. */ findingProviderFieldsConfidences?: outputs.securityhub.InsightFiltersFindingProviderFieldsConfidence[]; /** * The finding provider value for the level of importance assigned to the resources associated with the findings. A score of 0 means that the underlying resources have no criticality, and a score of 100 is reserved for the most critical resources. See Number Filter below for more details. */ findingProviderFieldsCriticalities?: outputs.securityhub.InsightFiltersFindingProviderFieldsCriticality[]; /** * The finding identifier of a related finding that is identified by the finding provider. See String Filter below for more details. */ findingProviderFieldsRelatedFindingsIds?: outputs.securityhub.InsightFiltersFindingProviderFieldsRelatedFindingsId[]; /** * The ARN of the solution that generated a related finding that is identified by the finding provider. See String Filter below for more details. */ findingProviderFieldsRelatedFindingsProductArns?: outputs.securityhub.InsightFiltersFindingProviderFieldsRelatedFindingsProductArn[]; /** * The finding provider value for the severity label. See String Filter below for more details. */ findingProviderFieldsSeverityLabels?: outputs.securityhub.InsightFiltersFindingProviderFieldsSeverityLabel[]; /** * The finding provider's original value for the severity. See String Filter below for more details. */ findingProviderFieldsSeverityOriginals?: outputs.securityhub.InsightFiltersFindingProviderFieldsSeverityOriginal[]; /** * One or more finding types that the finding provider assigned to the finding. Uses the format of `namespace/category/classifier` that classify a finding. Valid namespace values include: `Software and Configuration Checks`, `TTPs`, `Effects`, `Unusual Behaviors`, and `Sensitive Data Identifications`. See String Filter below for more details. */ findingProviderFieldsTypes?: outputs.securityhub.InsightFiltersFindingProviderFieldsType[]; /** * An ISO8601-formatted timestamp that indicates when the security-findings provider first observed the potential security issue that a finding captured. See Date Filter below for more details. */ firstObservedAts?: outputs.securityhub.InsightFiltersFirstObservedAt[]; /** * The identifier for the solution-specific component (a discrete unit of logic) that generated a finding. See String Filter below for more details. */ generatorIds?: outputs.securityhub.InsightFiltersGeneratorId[]; /** * The security findings provider-specific identifier for a finding. See String Filter below for more details. */ ids?: outputs.securityhub.InsightFiltersId[]; /** * A keyword for a finding. See Keyword Filter below for more details. */ keywords?: outputs.securityhub.InsightFiltersKeyword[]; /** * An ISO8601-formatted timestamp that indicates when the security-findings provider most recently observed the potential security issue that a finding captured. See Date Filter below for more details. */ lastObservedAts?: outputs.securityhub.InsightFiltersLastObservedAt[]; /** * The name of the malware that was observed. See String Filter below for more details. */ malwareNames?: outputs.securityhub.InsightFiltersMalwareName[]; /** * The filesystem path of the malware that was observed. See String Filter below for more details. */ malwarePaths?: outputs.securityhub.InsightFiltersMalwarePath[]; /** * The state of the malware that was observed. See String Filter below for more details. */ malwareStates?: outputs.securityhub.InsightFiltersMalwareState[]; /** * The type of the malware that was observed. See String Filter below for more details. */ malwareTypes?: outputs.securityhub.InsightFiltersMalwareType[]; /** * The destination domain of network-related information about a finding. See String Filter below for more details. */ networkDestinationDomains?: outputs.securityhub.InsightFiltersNetworkDestinationDomain[]; /** * The destination IPv4 address of network-related information about a finding. See Ip Filter below for more details. */ networkDestinationIpv4s?: outputs.securityhub.InsightFiltersNetworkDestinationIpv4[]; /** * The destination IPv6 address of network-related information about a finding. See Ip Filter below for more details. */ networkDestinationIpv6s?: outputs.securityhub.InsightFiltersNetworkDestinationIpv6[]; /** * The destination port of network-related information about a finding. See Number Filter below for more details. */ networkDestinationPorts?: outputs.securityhub.InsightFiltersNetworkDestinationPort[]; /** * Indicates the direction of network traffic associated with a finding. See String Filter below for more details. */ networkDirections?: outputs.securityhub.InsightFiltersNetworkDirection[]; /** * The protocol of network-related information about a finding. See String Filter below for more details. */ networkProtocols?: outputs.securityhub.InsightFiltersNetworkProtocol[]; /** * The source domain of network-related information about a finding. See String Filter below for more details. */ networkSourceDomains?: outputs.securityhub.InsightFiltersNetworkSourceDomain[]; /** * The source IPv4 address of network-related information about a finding. See Ip Filter below for more details. */ networkSourceIpv4s?: outputs.securityhub.InsightFiltersNetworkSourceIpv4[]; /** * The source IPv6 address of network-related information about a finding. See Ip Filter below for more details. */ networkSourceIpv6s?: outputs.securityhub.InsightFiltersNetworkSourceIpv6[]; /** * The source media access control (MAC) address of network-related information about a finding. See String Filter below for more details. */ networkSourceMacs?: outputs.securityhub.InsightFiltersNetworkSourceMac[]; /** * The source port of network-related information about a finding. See Number Filter below for more details. */ networkSourcePorts?: outputs.securityhub.InsightFiltersNetworkSourcePort[]; /** * The text of a note. See String Filter below for more details. */ noteTexts?: outputs.securityhub.InsightFiltersNoteText[]; /** * The timestamp of when the note was updated. See Date Filter below for more details. */ noteUpdatedAts?: outputs.securityhub.InsightFiltersNoteUpdatedAt[]; /** * The principal that created a note. See String Filter below for more details. */ noteUpdatedBies?: outputs.securityhub.InsightFiltersNoteUpdatedBy[]; /** * The date/time that the process was launched. See Date Filter below for more details. */ processLaunchedAts?: outputs.securityhub.InsightFiltersProcessLaunchedAt[]; /** * The name of the process. See String Filter below for more details. */ processNames?: outputs.securityhub.InsightFiltersProcessName[]; /** * The parent process ID. See Number Filter below for more details. */ processParentPids?: outputs.securityhub.InsightFiltersProcessParentPid[]; /** * The path to the process executable. See String Filter below for more details. */ processPaths?: outputs.securityhub.InsightFiltersProcessPath[]; /** * The process ID. See Number Filter below for more details. */ processPids?: outputs.securityhub.InsightFiltersProcessPid[]; /** * The date/time that the process was terminated. See Date Filter below for more details. */ processTerminatedAts?: outputs.securityhub.InsightFiltersProcessTerminatedAt[]; /** * The ARN generated by Security Hub that uniquely identifies a third-party company (security findings provider) after this provider's product (solution that generates findings) is registered with Security Hub. See String Filter below for more details. */ productArns?: outputs.securityhub.InsightFiltersProductArn[]; /** * A data type where security-findings providers can include additional solution-specific details that aren't part of the defined `AwsSecurityFinding` format. See Map Filter below for more details. */ productFields?: outputs.securityhub.InsightFiltersProductField[]; /** * The name of the solution (product) that generates findings. See String Filter below for more details. */ productNames?: outputs.securityhub.InsightFiltersProductName[]; /** * The recommendation of what to do about the issue described in a finding. See String Filter below for more details. */ recommendationTexts?: outputs.securityhub.InsightFiltersRecommendationText[]; /** * The updated record state for the finding. See String Filter below for more details. */ recordStates?: outputs.securityhub.InsightFiltersRecordState[]; /** * The solution-generated identifier for a related finding. See String Filter below for more details. */ relatedFindingsIds?: outputs.securityhub.InsightFiltersRelatedFindingsId[]; /** * The ARN of the solution that generated a related finding. See String Filter below for more details. */ relatedFindingsProductArns?: outputs.securityhub.InsightFiltersRelatedFindingsProductArn[]; /** * The IAM profile ARN of the instance. See String Filter below for more details. */ resourceAwsEc2InstanceIamInstanceProfileArns?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceIamInstanceProfileArn[]; /** * AMI ID of the instance. See String Filter below for more details. */ resourceAwsEc2InstanceImageIds?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceImageId[]; /** * The IPv4 addresses associated with the instance. See Ip Filter below for more details. */ resourceAwsEc2InstanceIpv4Addresses?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceIpv4Address[]; /** * The IPv6 addresses associated with the instance. See Ip Filter below for more details. */ resourceAwsEc2InstanceIpv6Addresses?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceIpv6Address[]; /** * The key name associated with the instance. See String Filter below for more details. */ resourceAwsEc2InstanceKeyNames?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceKeyName[]; /** * The date and time the instance was launched. See Date Filter below for more details. */ resourceAwsEc2InstanceLaunchedAts?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceLaunchedAt[]; /** * The identifier of the subnet that the instance was launched in. See String Filter below for more details. */ resourceAwsEc2InstanceSubnetIds?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceSubnetId[]; /** * The instance type of the instance. See String Filter below for more details. */ resourceAwsEc2InstanceTypes?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceType[]; /** * The identifier of the VPC that the instance was launched in. See String Filter below for more details. */ resourceAwsEc2InstanceVpcIds?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceVpcId[]; /** * The creation date/time of the IAM access key related to a finding. See Date Filter below for more details. */ resourceAwsIamAccessKeyCreatedAts?: outputs.securityhub.InsightFiltersResourceAwsIamAccessKeyCreatedAt[]; /** * The status of the IAM access key related to a finding. See String Filter below for more details. */ resourceAwsIamAccessKeyStatuses?: outputs.securityhub.InsightFiltersResourceAwsIamAccessKeyStatus[]; /** * The user associated with the IAM access key related to a finding. See String Filter below for more details. */ resourceAwsIamAccessKeyUserNames?: outputs.securityhub.InsightFiltersResourceAwsIamAccessKeyUserName[]; /** * The canonical user ID of the owner of the S3 bucket. See String Filter below for more details. */ resourceAwsS3BucketOwnerIds?: outputs.securityhub.InsightFiltersResourceAwsS3BucketOwnerId[]; /** * The display name of the owner of the S3 bucket. See String Filter below for more details. */ resourceAwsS3BucketOwnerNames?: outputs.securityhub.InsightFiltersResourceAwsS3BucketOwnerName[]; /** * The identifier of the image related to a finding. See String Filter below for more details. */ resourceContainerImageIds?: outputs.securityhub.InsightFiltersResourceContainerImageId[]; /** * The name of the image related to a finding. See String Filter below for more details. */ resourceContainerImageNames?: outputs.securityhub.InsightFiltersResourceContainerImageName[]; /** * The date/time that the container was started. See Date Filter below for more details. */ resourceContainerLaunchedAts?: outputs.securityhub.InsightFiltersResourceContainerLaunchedAt[]; /** * The name of the container related to a finding. See String Filter below for more details. */ resourceContainerNames?: outputs.securityhub.InsightFiltersResourceContainerName[]; /** * The details of a resource that doesn't have a specific subfield for the resource type defined. See Map Filter below for more details. */ resourceDetailsOthers?: outputs.securityhub.InsightFiltersResourceDetailsOther[]; /** * The canonical identifier for the given resource type. See String Filter below for more details. */ resourceIds?: outputs.securityhub.InsightFiltersResourceId[]; /** * The canonical AWS partition name that the Region is assigned to. See String Filter below for more details. */ resourcePartitions?: outputs.securityhub.InsightFiltersResourcePartition[]; /** * The canonical AWS external Region name where this resource is located. See String Filter below for more details. */ resourceRegions?: outputs.securityhub.InsightFiltersResourceRegion[]; /** * A list of AWS tags associated with a resource at the time the finding was processed. See Map Filter below for more details. */ resourceTags?: outputs.securityhub.InsightFiltersResourceTag[]; /** * Specifies the type of the resource that details are provided for. See String Filter below for more details. */ resourceTypes?: outputs.securityhub.InsightFiltersResourceType[]; /** * The label of a finding's severity. See String Filter below for more details. */ severityLabels?: outputs.securityhub.InsightFiltersSeverityLabel[]; /** * A URL that links to a page about the current finding in the security-findings provider's solution. See String Filter below for more details. */ sourceUrls?: outputs.securityhub.InsightFiltersSourceUrl[]; /** * The category of a threat intelligence indicator. See String Filter below for more details. */ threatIntelIndicatorCategories?: outputs.securityhub.InsightFiltersThreatIntelIndicatorCategory[]; /** * The date/time of the last observation of a threat intelligence indicator. See Date Filter below for more details. */ threatIntelIndicatorLastObservedAts?: outputs.securityhub.InsightFiltersThreatIntelIndicatorLastObservedAt[]; /** * The URL for more details from the source of the threat intelligence. See String Filter below for more details. */ threatIntelIndicatorSourceUrls?: outputs.securityhub.InsightFiltersThreatIntelIndicatorSourceUrl[]; /** * The source of the threat intelligence. See String Filter below for more details. */ threatIntelIndicatorSources?: outputs.securityhub.InsightFiltersThreatIntelIndicatorSource[]; /** * The type of a threat intelligence indicator. See String Filter below for more details. */ threatIntelIndicatorTypes?: outputs.securityhub.InsightFiltersThreatIntelIndicatorType[]; /** * The value of a threat intelligence indicator. See String Filter below for more details. */ threatIntelIndicatorValues?: outputs.securityhub.InsightFiltersThreatIntelIndicatorValue[]; /** * A finding's title. See String Filter below for more details. */ titles?: outputs.securityhub.InsightFiltersTitle[]; /** * A finding type in the format of `namespace/category/classifier` that classifies a finding. See String Filter below for more details. */ types?: outputs.securityhub.InsightFiltersType[]; /** * An ISO8601-formatted timestamp that indicates when the security-findings provider last updated the finding record. See Date Filter below for more details. */ updatedAts?: outputs.securityhub.InsightFiltersUpdatedAt[]; /** * A list of name/value string pairs associated with the finding. These are custom, user-defined fields added to a finding. See Map Filter below for more details. */ userDefinedValues?: outputs.securityhub.InsightFiltersUserDefinedValue[]; /** * The veracity of a finding. See String Filter below for more details. */ verificationStates?: outputs.securityhub.InsightFiltersVerificationState[]; /** * The status of the investigation into a finding. See Workflow Status Filter below for more details. */ workflowStatuses?: outputs.securityhub.InsightFiltersWorkflowStatus[]; } interface InsightFiltersAwsAccountId { comparison: string; value: string; } interface InsightFiltersAwsAccountName { comparison: string; value: string; } interface InsightFiltersCompanyName { comparison: string; value: string; } interface InsightFiltersComplianceAssociatedStandardsId { comparison: string; value: string; } interface InsightFiltersComplianceSecurityControlId { comparison: string; value: string; } interface InsightFiltersComplianceSecurityControlParametersName { comparison: string; value: string; } interface InsightFiltersComplianceSecurityControlParametersValue { comparison: string; value: string; } interface InsightFiltersComplianceStatus { comparison: string; value: string; } interface InsightFiltersConfidence { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersCreatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersCreatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersCreatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersCriticality { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersDescription { comparison: string; value: string; } interface InsightFiltersFindingProviderFieldsConfidence { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersFindingProviderFieldsCriticality { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersFindingProviderFieldsRelatedFindingsId { comparison: string; value: string; } interface InsightFiltersFindingProviderFieldsRelatedFindingsProductArn { comparison: string; value: string; } interface InsightFiltersFindingProviderFieldsSeverityLabel { comparison: string; value: string; } interface InsightFiltersFindingProviderFieldsSeverityOriginal { comparison: string; value: string; } interface InsightFiltersFindingProviderFieldsType { comparison: string; value: string; } interface InsightFiltersFirstObservedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersFirstObservedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersFirstObservedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersGeneratorId { comparison: string; value: string; } interface InsightFiltersId { comparison: string; value: string; } interface InsightFiltersKeyword { /** * A value for the keyword. */ value: string; } interface InsightFiltersLastObservedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersLastObservedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersLastObservedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersMalwareName { comparison: string; value: string; } interface InsightFiltersMalwarePath { comparison: string; value: string; } interface InsightFiltersMalwareState { comparison: string; value: string; } interface InsightFiltersMalwareType { comparison: string; value: string; } interface InsightFiltersNetworkDestinationDomain { comparison: string; value: string; } interface InsightFiltersNetworkDestinationIpv4 { /** * A finding's CIDR value. */ cidr: string; } interface InsightFiltersNetworkDestinationIpv6 { /** * A finding's CIDR value. */ cidr: string; } interface InsightFiltersNetworkDestinationPort { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersNetworkDirection { comparison: string; value: string; } interface InsightFiltersNetworkProtocol { comparison: string; value: string; } interface InsightFiltersNetworkSourceDomain { comparison: string; value: string; } interface InsightFiltersNetworkSourceIpv4 { /** * A finding's CIDR value. */ cidr: string; } interface InsightFiltersNetworkSourceIpv6 { /** * A finding's CIDR value. */ cidr: string; } interface InsightFiltersNetworkSourceMac { comparison: string; value: string; } interface InsightFiltersNetworkSourcePort { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersNoteText { comparison: string; value: string; } interface InsightFiltersNoteUpdatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersNoteUpdatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersNoteUpdatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersNoteUpdatedBy { comparison: string; value: string; } interface InsightFiltersProcessLaunchedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersProcessLaunchedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersProcessLaunchedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersProcessName { comparison: string; value: string; } interface InsightFiltersProcessParentPid { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersProcessPath { comparison: string; value: string; } interface InsightFiltersProcessPid { /** * The equal-to condition to be applied to a single field when querying for findings, provided as a String. */ eq?: string; /** * The greater-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ gte?: string; /** * The less-than-equal condition to be applied to a single field when querying for findings, provided as a String. */ lte?: string; } interface InsightFiltersProcessTerminatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersProcessTerminatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersProcessTerminatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersProductArn { comparison: string; value: string; } interface InsightFiltersProductField { comparison: string; /** * The key of the map filter. For example, for `ResourceTags`, `Key` identifies the name of the tag. For `UserDefinedFields`, `Key` is the name of the field. */ key: string; value: string; } interface InsightFiltersProductName { comparison: string; value: string; } interface InsightFiltersRecommendationText { comparison: string; value: string; } interface InsightFiltersRecordState { comparison: string; value: string; } interface InsightFiltersRelatedFindingsId { comparison: string; value: string; } interface InsightFiltersRelatedFindingsProductArn { comparison: string; value: string; } interface InsightFiltersResourceAwsEc2InstanceIamInstanceProfileArn { comparison: string; value: string; } interface InsightFiltersResourceAwsEc2InstanceImageId { comparison: string; value: string; } interface InsightFiltersResourceAwsEc2InstanceIpv4Address { /** * A finding's CIDR value. */ cidr: string; } interface InsightFiltersResourceAwsEc2InstanceIpv6Address { /** * A finding's CIDR value. */ cidr: string; } interface InsightFiltersResourceAwsEc2InstanceKeyName { comparison: string; value: string; } interface InsightFiltersResourceAwsEc2InstanceLaunchedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersResourceAwsEc2InstanceLaunchedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersResourceAwsEc2InstanceLaunchedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersResourceAwsEc2InstanceSubnetId { comparison: string; value: string; } interface InsightFiltersResourceAwsEc2InstanceType { comparison: string; value: string; } interface InsightFiltersResourceAwsEc2InstanceVpcId { comparison: string; value: string; } interface InsightFiltersResourceAwsIamAccessKeyCreatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersResourceAwsIamAccessKeyCreatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersResourceAwsIamAccessKeyCreatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersResourceAwsIamAccessKeyStatus { comparison: string; value: string; } interface InsightFiltersResourceAwsIamAccessKeyUserName { comparison: string; value: string; } interface InsightFiltersResourceAwsS3BucketOwnerId { comparison: string; value: string; } interface InsightFiltersResourceAwsS3BucketOwnerName { comparison: string; value: string; } interface InsightFiltersResourceContainerImageId { comparison: string; value: string; } interface InsightFiltersResourceContainerImageName { comparison: string; value: string; } interface InsightFiltersResourceContainerLaunchedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersResourceContainerLaunchedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersResourceContainerLaunchedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersResourceContainerName { comparison: string; value: string; } interface InsightFiltersResourceDetailsOther { comparison: string; /** * The key of the map filter. For example, for `ResourceTags`, `Key` identifies the name of the tag. For `UserDefinedFields`, `Key` is the name of the field. */ key: string; value: string; } interface InsightFiltersResourceId { comparison: string; value: string; } interface InsightFiltersResourcePartition { comparison: string; value: string; } interface InsightFiltersResourceRegion { comparison: string; value: string; } interface InsightFiltersResourceTag { comparison: string; /** * The key of the map filter. For example, for `ResourceTags`, `Key` identifies the name of the tag. For `UserDefinedFields`, `Key` is the name of the field. */ key: string; value: string; } interface InsightFiltersResourceType { comparison: string; value: string; } interface InsightFiltersSeverityLabel { comparison: string; value: string; } interface InsightFiltersSourceUrl { comparison: string; value: string; } interface InsightFiltersThreatIntelIndicatorCategory { comparison: string; value: string; } interface InsightFiltersThreatIntelIndicatorLastObservedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersThreatIntelIndicatorLastObservedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersThreatIntelIndicatorLastObservedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersThreatIntelIndicatorSource { comparison: string; value: string; } interface InsightFiltersThreatIntelIndicatorSourceUrl { comparison: string; value: string; } interface InsightFiltersThreatIntelIndicatorType { comparison: string; value: string; } interface InsightFiltersThreatIntelIndicatorValue { comparison: string; value: string; } interface InsightFiltersTitle { comparison: string; value: string; } interface InsightFiltersType { comparison: string; value: string; } interface InsightFiltersUpdatedAt { /** * A configuration block of the date range for the date filter. See dateRange below for more details. */ dateRange?: outputs.securityhub.InsightFiltersUpdatedAtDateRange; /** * An end date for the date filter. Required with `start` if `dateRange` is not specified. */ end?: string; /** * A start date for the date filter. Required with `end` if `dateRange` is not specified. */ start?: string; } interface InsightFiltersUpdatedAtDateRange { /** * A date range unit for the date filter. Valid values: `DAYS`. */ unit: string; /** * A date range value for the date filter, provided as an Integer. */ value: number; } interface InsightFiltersUserDefinedValue { comparison: string; /** * The key of the map filter. For example, for `ResourceTags`, `Key` identifies the name of the tag. For `UserDefinedFields`, `Key` is the name of the field. */ key: string; value: string; } interface InsightFiltersVerificationState { comparison: string; value: string; } interface InsightFiltersWorkflowStatus { comparison: string; value: string; } interface OrganizationConfigurationOrganizationConfiguration { /** * Indicates whether the organization uses local or central configuration. If using central configuration, `autoEnable` must be set to `false` and `autoEnableStandards` set to `NONE`. More information can be found in the [documentation for central configuration](https://docs.aws.amazon.com/securityhub/latest/userguide/central-configuration-intro.html). Valid values: `LOCAL`, `CENTRAL`. */ configurationType: string; } } export declare namespace securitylake { interface AwsLogSourceSource { /** * Specify the AWS account information where you want to enable Security Lake. * If not specified, uses all accounts included in the Security Lake. */ accounts: string[]; /** * Specify the Regions where you want to enable Security Lake. */ regions: string[]; /** * The name for a AWS source. This must be a Regionally unique value. Valid values: `ROUTE53`, `VPC_FLOW`, `SH_FINDINGS`, `CLOUD_TRAIL_MGMT`, `LAMBDA_EXECUTION`, `S3_DATA`, `EKS_AUDIT`, `WAF`. */ sourceName: string; /** * The version for a AWS source. * If not specified, the version will be the default. * This must be a Regionally unique value. */ sourceVersion: string; } interface CustomLogSourceAttribute { /** * The ARN of the AWS Glue crawler. */ crawlerArn: string; /** * The ARN of the AWS Glue database where results are written. */ databaseArn: string; /** * The ARN of the AWS Glue table. */ tableArn: string; } interface CustomLogSourceConfiguration { /** * The configuration for the Glue Crawler for the third-party custom source. */ crawlerConfiguration: outputs.securitylake.CustomLogSourceConfigurationCrawlerConfiguration; /** * The identity of the log provider for the third-party custom source. */ providerIdentity: outputs.securitylake.CustomLogSourceConfigurationProviderIdentity; } interface CustomLogSourceConfigurationCrawlerConfiguration { /** * The ARN of the AWS Identity and Access Management (IAM) role to be used by the AWS Glue crawler. */ roleArn: string; } interface CustomLogSourceConfigurationProviderIdentity { /** * The external ID used to estalish trust relationship with the AWS identity. */ externalId: string; /** * The AWS identity principal. */ principal: string; } interface CustomLogSourceProviderDetail { /** * The location of the partition in the Amazon S3 bucket for Security Lake. */ location: string; /** * The ARN of the IAM role to be used by the entity putting logs into your custom source partition. */ roleArn: string; } interface DataLakeConfiguration { /** * Provides encryption details of Amazon Security Lake object. */ encryptionConfigurations: outputs.securitylake.DataLakeConfigurationEncryptionConfiguration[]; /** * Provides lifecycle details of Amazon Security Lake object. */ lifecycleConfiguration?: outputs.securitylake.DataLakeConfigurationLifecycleConfiguration; /** * The AWS Regions where Security Lake is automatically enabled. */ region: string; /** * Provides replication details of Amazon Security Lake object. */ replicationConfiguration?: outputs.securitylake.DataLakeConfigurationReplicationConfiguration; } interface DataLakeConfigurationEncryptionConfiguration { /** * The id of KMS encryption key used by Amazon Security Lake to encrypt the Security Lake object. */ kmsKeyId: string; } interface DataLakeConfigurationLifecycleConfiguration { /** * Provides data expiration details of Amazon Security Lake object. */ expiration?: outputs.securitylake.DataLakeConfigurationLifecycleConfigurationExpiration; /** * Provides data storage transition details of Amazon Security Lake object. */ transitions?: outputs.securitylake.DataLakeConfigurationLifecycleConfigurationTransition[]; } interface DataLakeConfigurationLifecycleConfigurationExpiration { /** * Number of days before data transition to a different S3 Storage Class in the Amazon Security Lake object. */ days?: number; } interface DataLakeConfigurationLifecycleConfigurationTransition { /** * Number of days before data transition to a different S3 Storage Class in the Amazon Security Lake object. */ days?: number; /** * The range of storage classes that you can choose from based on the data access, resiliency, and cost requirements of your workloads. */ storageClass?: string; } interface DataLakeConfigurationReplicationConfiguration { /** * Replication enables automatic, asynchronous copying of objects across Amazon S3 buckets. Amazon S3 buckets that are configured for object replication can be owned by the same AWS account or by different accounts. You can replicate objects to a single destination bucket or to multiple destination buckets. The destination buckets can be in different AWS Regions or within the same Region as the source bucket. */ regions?: string[]; /** * Replication settings for the Amazon S3 buckets. This parameter uses the AWS Identity and Access Management (IAM) role you created that is managed by Security Lake, to ensure the replication setting is correct. */ roleArn?: string; } interface DataLakeTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface SubscriberNotificationConfiguration { /** * The configurations for HTTPS subscriber notification. */ httpsNotificationConfiguration?: outputs.securitylake.SubscriberNotificationConfigurationHttpsNotificationConfiguration; /** * The configurations for SQS subscriber notification. * There are no parameters within `sqsNotificationConfiguration`. */ sqsNotificationConfiguration?: outputs.securitylake.SubscriberNotificationConfigurationSqsNotificationConfiguration; } interface SubscriberNotificationConfigurationHttpsNotificationConfiguration { /** * The API key name for the notification subscription. */ authorizationApiKeyName?: string; /** * The API key value for the notification subscription. */ authorizationApiKeyValue?: string; /** * The subscription endpoint in Security Lake. * If you prefer notification with an HTTPS endpoint, populate this field. */ endpoint: string; /** * The HTTP method used for the notification subscription. * Valid values are `POST` and `PUT`. */ httpMethod?: string; /** * ARN of the EventBridge API destinations IAM role that you created. * For more information about ARNs and how to use them in policies, see Managing data access and AWS Managed Policies in the Amazon Security Lake User Guide. */ targetRoleArn: string; } interface SubscriberNotificationConfigurationSqsNotificationConfiguration { } interface SubscriberSource { /** * Amazon Security Lake supports log and event collection for natively supported AWS services. See `awsLogSourceResource` Block below. */ awsLogSourceResource?: outputs.securitylake.SubscriberSourceAwsLogSourceResource; /** * Amazon Security Lake supports custom source types. See `customLogSourceResource` Block below. */ customLogSourceResource?: outputs.securitylake.SubscriberSourceCustomLogSourceResource; } interface SubscriberSourceAwsLogSourceResource { /** * The name for a AWS source. This must be a Regionally unique value. Valid values: `ROUTE53`, `VPC_FLOW`, `SH_FINDINGS`, `CLOUD_TRAIL_MGMT`, `LAMBDA_EXECUTION`, `S3_DATA`, `EKS_AUDIT` and `WAF`. */ sourceName: string; /** * The version for a AWS source. This must be a Regionally unique value. */ sourceVersion: string; } interface SubscriberSourceCustomLogSourceResource { /** * The attributes of the third-party custom source. See `attributes` Block below. */ attributes: outputs.securitylake.SubscriberSourceCustomLogSourceResourceAttribute[]; /** * The details of the log provider for the third-party custom source. See `provider` Block below. */ providers: outputs.securitylake.SubscriberSourceCustomLogSourceResourceProvider[]; /** * The name for a third-party custom source. This must be a Regionally unique value. */ sourceName: string; /** * The version for a third-party custom source. This must be a Regionally unique value. */ sourceVersion: string; } interface SubscriberSourceCustomLogSourceResourceAttribute { /** * The ARN of the AWS Glue crawler. */ crawlerArn: string; /** * The ARN of the AWS Glue database where results are written. */ databaseArn: string; /** * The ARN of the AWS Glue table. */ tableArn: string; } interface SubscriberSourceCustomLogSourceResourceProvider { /** * The location of the partition in the Amazon S3 bucket for Security Lake. */ location: string; /** * The ARN of the IAM role to be used by the entity putting logs into your custom source partition. */ roleArn: string; } interface SubscriberSubscriberIdentity { /** * The external ID used to establish trust relationship with the AWS identity. */ externalId: string; /** * The AWS identity principal. */ principal: string; } interface SubscriberTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace servicecatalog { interface GetLaunchPathsSummary { /** * Block for constraints on the portfolio-product relationship. See details below. */ constraintSummaries: outputs.servicecatalog.GetLaunchPathsSummaryConstraintSummary[]; /** * Name of the portfolio to which the path was assigned. */ name: string; /** * Identifier of the product path. */ pathId: string; /** * Tags associated with this product path. */ tags: { [key: string]: string; }; } interface GetLaunchPathsSummaryConstraintSummary { /** * Description of the constraint. */ description: string; /** * Type of constraint. Valid values are `LAUNCH`, `NOTIFICATION`, `STACKSET`, and `TEMPLATE`. */ type: string; } interface GetPortfolioConstraintsDetail { /** * Identifier of the constraint. */ constraintId: string; /** * Description of the constraint. */ description: string; owner: string; /** * Portfolio identifier. * * The following arguments are optional: */ portfolioId: string; /** * Product identifier. */ productId: string; /** * Type of constraint. Valid values are `LAUNCH`, `NOTIFICATION`, `STACKSET`, and `TEMPLATE`. */ type: string; } interface GetProvisioningArtifactsProvisioningArtifactDetail { /** * Indicates whether the product version is active. */ active: boolean; /** * The UTC time stamp of the creation time. */ createdTime: string; /** * The description of the provisioning artifact. */ description: string; /** * Information set by the administrator to provide guidance to end users about which provisioning artifacts to use. */ guidance: string; /** * The identifier of the provisioning artifact. */ id: string; /** * The name of the provisioning artifact. */ name: string; /** * The type of provisioning artifact. */ type: string; } interface ProductProvisioningArtifactParameters { /** * Description of the provisioning artifact (i.e., version), including how it differs from the previous provisioning artifact. */ description?: string; /** * Whether AWS Service Catalog stops validating the specified provisioning artifact template even if it is invalid. */ disableTemplateValidation?: boolean; /** * Name of the provisioning artifact (for example, `v1`, `v2beta`). No spaces are allowed. */ name?: string; /** * Template source as the physical ID of the resource that contains the template. Currently only supports CloudFormation stack ARN. Specify the physical ID as `arn:[partition]:cloudformation:[region]:[account ID]:stack/[stack name]/[resource ID]`. */ templatePhysicalId?: string; /** * Template source as URL of the CloudFormation template in Amazon S3. */ templateUrl?: string; /** * Type of provisioning artifact. See [AWS Docs](https://docs.aws.amazon.com/servicecatalog/latest/dg/API_ProvisioningArtifactProperties.html) for valid list of values. */ type?: string; } interface ProvisionedProductOutput { /** * The description of the output. */ description: string; /** * The output key. */ key: string; /** * The output value. */ value: string; } interface ProvisionedProductProvisioningParameter { /** * Parameter key. */ key: string; /** * Whether to ignore `value` and keep the previous parameter value. Ignored when initially provisioning a product. */ usePreviousValue?: boolean; /** * Parameter value. */ value?: string; } interface ProvisionedProductStackSetProvisioningPreferences { /** * One or more AWS accounts that will have access to the provisioned product. The AWS accounts specified should be within the list of accounts in the STACKSET constraint. To get the list of accounts in the STACKSET constraint, use the `awsServicecatalogProvisioningParameters` data source. If no values are specified, the default value is all accounts from the STACKSET constraint. */ accounts?: string[]; /** * Number of accounts, per region, for which this operation can fail before AWS Service Catalog stops the operation in that region. If the operation is stopped in a region, AWS Service Catalog doesn't attempt the operation in any subsequent regions. You must specify either `failureToleranceCount` or `failureTolerancePercentage`, but not both. The default value is 0 if no value is specified. */ failureToleranceCount?: number; /** * Percentage of accounts, per region, for which this stack operation can fail before AWS Service Catalog stops the operation in that region. If the operation is stopped in a region, AWS Service Catalog doesn't attempt the operation in any subsequent regions. When calculating the number of accounts based on the specified percentage, AWS Service Catalog rounds down to the next whole number. You must specify either `failureToleranceCount` or `failureTolerancePercentage`, but not both. */ failureTolerancePercentage?: number; /** * Maximum number of accounts in which to perform this operation at one time. This is dependent on the value of `failureToleranceCount`. `maxConcurrencyCount` is at most one more than the `failureToleranceCount`. Note that this setting lets you specify the maximum for operations. For large deployments, under certain circumstances the actual number of accounts acted upon concurrently may be lower due to service throttling. You must specify either `maxConcurrencyCount` or `maxConcurrencyPercentage`, but not both. */ maxConcurrencyCount?: number; /** * Maximum percentage of accounts in which to perform this operation at one time. When calculating the number of accounts based on the specified percentage, AWS Service Catalog rounds down to the next whole number. This is true except in cases where rounding down would result is zero. In this case, AWS Service Catalog sets the number as 1 instead. Note that this setting lets you specify the maximum for operations. For large deployments, under certain circumstances the actual number of accounts acted upon concurrently may be lower due to service throttling. You must specify either `maxConcurrencyCount` or `maxConcurrencyPercentage`, but not both. */ maxConcurrencyPercentage?: number; /** * One or more AWS Regions where the provisioned product will be available. The specified regions should be within the list of regions from the STACKSET constraint. To get the list of regions in the STACKSET constraint, use the `awsServicecatalogProvisioningParameters` data source. If no values are specified, the default value is all regions from the STACKSET constraint. */ regions?: string[]; } interface ServiceActionDefinition { /** * ARN of the role that performs the self-service actions on your behalf. For example, `arn:aws:iam::12345678910:role/ActionRole`. To reuse the provisioned product launch role, set to `LAUNCH_ROLE`. */ assumeRole?: string; /** * Name of the SSM document. For example, `AWS-RestartEC2Instance`. If you are using a shared SSM document, you must provide the ARN instead of the name. */ name: string; /** * List of parameters in JSON format. For example: `[{\"Name\":\"InstanceId\",\"Type\":\"TARGET\"}]` or `[{\"Name\":\"InstanceId\",\"Type\":\"TEXT_VALUE\"}]`. */ parameters?: string; /** * Service action definition type. Valid value is `SSM_AUTOMATION`. Default is `SSM_AUTOMATION`. */ type?: string; /** * SSM document version. For example, `1`. */ version: string; } } export declare namespace servicediscovery { interface GetServiceDnsConfig { /** * An array that contains one DnsRecord object for each resource record set. See `dnsRecords` Block for details. */ dnsRecords: outputs.servicediscovery.GetServiceDnsConfigDnsRecord[]; /** * ID of the namespace that the service belongs to. */ namespaceId: string; /** * Routing policy that you want to apply to all records that Route 53 creates when you register an instance and specify the service. Valid Values: MULTIVALUE, WEIGHTED */ routingPolicy: string; } interface GetServiceDnsConfigDnsRecord { /** * Amount of time, in seconds, that you want DNS resolvers to cache the settings for this resource record set. */ ttl: number; /** * The type of health check that you want to create, which indicates how Route 53 determines whether an endpoint is healthy. Valid Values: HTTP, HTTPS, TCP */ type: string; } interface GetServiceHealthCheckConfig { /** * The number of 30-second intervals that you want service discovery to wait before it changes the health status of a service instance. Maximum value of 10. */ failureThreshold: number; /** * Path that you want Route 53 to request when performing health checks. Route 53 automatically adds the DNS name for the service. If you don't specify a value, the default value is /. */ resourcePath: string; /** * The type of health check that you want to create, which indicates how Route 53 determines whether an endpoint is healthy. Valid Values: HTTP, HTTPS, TCP */ type: string; } interface GetServiceHealthCheckCustomConfig { /** * The number of 30-second intervals that you want service discovery to wait before it changes the health status of a service instance. Maximum value of 10. */ failureThreshold: number; } interface ServiceDnsConfig { /** * An array that contains one DnsRecord object for each resource record set. See `dnsRecords` Block for details. */ dnsRecords: outputs.servicediscovery.ServiceDnsConfigDnsRecord[]; /** * The ID of the namespace to use for DNS configuration. */ namespaceId: string; /** * The routing policy that you want to apply to all records that Route 53 creates when you register an instance and specify the service. Valid Values: MULTIVALUE, WEIGHTED */ routingPolicy?: string; } interface ServiceDnsConfigDnsRecord { /** * The amount of time, in seconds, that you want DNS resolvers to cache the settings for this resource record set. */ ttl: number; /** * The type of the resource, which indicates the value that Amazon Route 53 returns in response to DNS queries. Valid Values: A, AAAA, SRV, CNAME */ type: string; } interface ServiceHealthCheckConfig { /** * The number of consecutive health checks. Maximum value of 10. */ failureThreshold?: number; /** * The path that you want Route 53 to request when performing health checks. Route 53 automatically adds the DNS name for the service. If you don't specify a value, the default value is /. */ resourcePath?: string; /** * The type of health check that you want to create, which indicates how Route 53 determines whether an endpoint is healthy. Valid Values: HTTP, HTTPS, TCP */ type?: string; } interface ServiceHealthCheckCustomConfig { /** * The number of 30-second intervals that you want service discovery to wait before it changes the health status of a service instance. Value is always set to 1. * * @deprecated failure_threshold is deprecated. The argument is no longer supported by AWS and the value is always set to 1. The attribute will be removed in a future major version. */ failureThreshold?: number; } } export declare namespace servicequotas { interface GetServiceQuotaUsageMetric { /** * The metric dimensions. */ metricDimensions: outputs.servicequotas.GetServiceQuotaUsageMetricMetricDimension[]; /** * The name of the metric. */ metricName: string; /** * The namespace of the metric. */ metricNamespace: string; /** * The metric statistic that AWS recommend you use when determining quota usage. */ metricStatisticRecommendation: string; } interface GetServiceQuotaUsageMetricMetricDimension { class: string; resource: string; service: string; type: string; } interface GetTemplatesTemplate { /** * Indicates whether the quota is global. */ globalQuota: boolean; /** * Quota identifier. */ quotaCode: string; /** * Quota name. */ quotaName: string; /** * AWS Region to which the quota increases apply. Use `aws.getRegion` instead. */ region: string; /** * Service identifier. */ serviceCode: string; /** * Service name. */ serviceName: string; /** * Unit of measurement. */ unit: string; /** * The new, increased value for the quota. */ value: number; } interface ServiceQuotaUsageMetric { /** * The metric dimensions. */ metricDimensions: outputs.servicequotas.ServiceQuotaUsageMetricMetricDimension[]; /** * The name of the metric. */ metricName: string; /** * The namespace of the metric. */ metricNamespace: string; /** * The metric statistic that AWS recommend you use when determining quota usage. */ metricStatisticRecommendation: string; } interface ServiceQuotaUsageMetricMetricDimension { class: string; resource: string; service: string; type: string; } } export declare namespace ses { interface ConfigurationSetDeliveryOptions { /** * Whether messages that use the configuration set are required to use TLS. If the value is `Require`, messages are only delivered if a TLS connection can be established. If the value is `Optional`, messages can be delivered in plain text if a TLS connection can't be established. Valid values: `Require` or `Optional`. Defaults to `Optional`. */ tlsPolicy?: string; } interface ConfigurationSetTrackingOptions { /** * Custom subdomain that is used to redirect email recipients to the Amazon SES event tracking domain. */ customRedirectDomain?: string; } interface EventDestinationCloudwatchDestination { /** * Default value for the event */ defaultValue: string; /** * Name for the dimension */ dimensionName: string; /** * Source for the value. May be any of `"messageTag"`, `"emailHeader"` or `"linkTag"`. */ valueSource: string; } interface EventDestinationKinesisDestination { /** * ARN of the role that has permissions to access the Kinesis Stream */ roleArn: string; /** * ARN of the Kinesis Stream */ streamArn: string; } interface EventDestinationSnsDestination { /** * ARN of the SNS topic */ topicArn: string; } interface ReceiptRuleAddHeaderAction { /** * Name of the header to add. */ headerName: string; /** * Value of the header to add. */ headerValue: string; /** * Position of the action in the receipt rule. */ position: number; } interface ReceiptRuleBounceAction { /** * Message to send. */ message: string; /** * Position of the action in the receipt rule. */ position: number; /** * Email address of the sender. */ sender: string; /** * RFC 5321 SMTP reply code. */ smtpReplyCode: string; /** * RFC 3463 SMTP enhanced status code. */ statusCode?: string; /** * ARN of an SNS topic to notify. */ topicArn?: string; } interface ReceiptRuleLambdaAction { /** * ARN of the Lambda function to invoke. */ functionArn: string; /** * `Event` or `RequestResponse`. */ invocationType?: string; /** * Position of the action in the receipt rule. */ position: number; /** * ARN of an SNS topic to notify. */ topicArn?: string; } interface ReceiptRuleS3Action { /** * Name of the S3 bucket. */ bucketName: string; /** * ARN of the IAM role to be used by Amazon Simple Email Service while writing to the Amazon S3 bucket, optionally encrypting your mail via the provided customer managed key, and publishing to the Amazon SNS topic. */ iamRoleArn?: string; /** * ARN of the KMS key. */ kmsKeyArn?: string; /** * Key prefix of the S3 bucket. */ objectKeyPrefix?: string; /** * Position of the action in the receipt rule. */ position: number; /** * ARN of an SNS topic to notify. */ topicArn?: string; } interface ReceiptRuleSnsAction { /** * Encoding to use for the email within the Amazon SNS notification. Default value is `UTF-8`. */ encoding?: string; /** * Position of the action in the receipt rule. */ position: number; /** * ARN of an SNS topic to notify. */ topicArn: string; } interface ReceiptRuleStopAction { /** * Position of the action in the receipt rule. */ position: number; /** * Scope to apply. The only acceptable value is `RuleSet`. */ scope: string; /** * ARN of an SNS topic to notify. */ topicArn?: string; } interface ReceiptRuleWorkmailAction { /** * ARN of the WorkMail organization. */ organizationArn: string; /** * Position of the action in the receipt rule. */ position: number; /** * ARN of an SNS topic to notify. */ topicArn?: string; } } export declare namespace sesv2 { interface AccountVdmAttributesDashboardAttributes { /** * Status of your VDM engagement metrics collection. Valid values: `ENABLED`, `DISABLED`. */ engagementMetrics?: string; } interface AccountVdmAttributesGuardianAttributes { /** * Status of your VDM optimized shared delivery. Valid values: `ENABLED`, `DISABLED`. */ optimizedSharedDelivery?: string; } interface ConfigurationSetDeliveryOptions { /** * Maximum amount of time, in seconds, that Amazon SES API v2 will attempt delivery of email. If specified, the value must be greater than or equal to 300 seconds (5 minutes) and less than or equal to 50400 seconds (840 minutes). */ maxDeliverySeconds?: number; /** * Name of the dedicated IP pool to associate with the configuration set. */ sendingPoolName?: string; /** * Whether messages that use the configuration set are required to use TLS. Valid values: `REQUIRE`, `OPTIONAL`. */ tlsPolicy?: string; } interface ConfigurationSetEventDestinationEventDestination { /** * Object that defines an Amazon CloudWatch destination for email events. See `cloudWatchDestination` Block for details. */ cloudWatchDestination?: outputs.sesv2.ConfigurationSetEventDestinationEventDestinationCloudWatchDestination; /** * When the event destination is enabled, the specified event types are sent to the destinations. Default: `false`. */ enabled?: boolean; /** * Object that defines an Amazon EventBridge destination for email events. You can use Amazon EventBridge to send notifications when certain email events occur. See `eventBridgeDestination` Block for details. */ eventBridgeDestination?: outputs.sesv2.ConfigurationSetEventDestinationEventDestinationEventBridgeDestination; /** * Object that defines an Amazon Kinesis Data Firehose destination for email events. See `kinesisFirehoseDestination` Block for details. */ kinesisFirehoseDestination?: outputs.sesv2.ConfigurationSetEventDestinationEventDestinationKinesisFirehoseDestination; /** * An array that specifies which events the Amazon SES API v2 should send to the destinations. Valid values: `SEND`, `REJECT`, `BOUNCE`, `COMPLAINT`, `DELIVERY`, `OPEN`, `CLICK`, `RENDERING_FAILURE`, `DELIVERY_DELAY`, `SUBSCRIPTION`. */ matchingEventTypes: string[]; /** * Object that defines an AWS End User Messaging project destination for email events. See `pinpointDestination` Block for details. */ pinpointDestination?: outputs.sesv2.ConfigurationSetEventDestinationEventDestinationPinpointDestination; /** * Object that defines an Amazon SNS destination for email events. See `snsDestination` Block for details. */ snsDestination?: outputs.sesv2.ConfigurationSetEventDestinationEventDestinationSnsDestination; } interface ConfigurationSetEventDestinationEventDestinationCloudWatchDestination { /** * Array of objects that define the dimensions to use when you send email events to Amazon CloudWatch. See `dimensionConfiguration` Block for details. */ dimensionConfigurations: outputs.sesv2.ConfigurationSetEventDestinationEventDestinationCloudWatchDestinationDimensionConfiguration[]; } interface ConfigurationSetEventDestinationEventDestinationCloudWatchDestinationDimensionConfiguration { /** * Default value of the dimension that is published to Amazon CloudWatch if you don't provide the value of the dimension when you send an email. */ defaultDimensionValue: string; /** * Name of an Amazon CloudWatch dimension associated with an email sending metric. */ dimensionName: string; /** * Location where the Amazon SES API v2 finds the value of a dimension to publish to Amazon CloudWatch. Valid values: `MESSAGE_TAG`, `EMAIL_HEADER`, `LINK_TAG`. */ dimensionValueSource: string; } interface ConfigurationSetEventDestinationEventDestinationEventBridgeDestination { /** * ARN of the Amazon EventBridge bus to publish email events to. Only the default bus is supported. */ eventBusArn: string; } interface ConfigurationSetEventDestinationEventDestinationKinesisFirehoseDestination { /** * ARN of the Amazon Kinesis Data Firehose stream that the Amazon SES API v2 sends email events to. */ deliveryStreamArn: string; /** * ARN of the IAM role that the Amazon SES API v2 uses to send email events to the Amazon Kinesis Data Firehose stream. */ iamRoleArn: string; } interface ConfigurationSetEventDestinationEventDestinationPinpointDestination { /** * ARN of the AWS End User Messaging project to send email events to. */ applicationArn: string; } interface ConfigurationSetEventDestinationEventDestinationSnsDestination { /** * ARN of the Amazon SNS topic to publish email events to. */ topicArn: string; } interface ConfigurationSetReputationOptions { /** * Date and time (in Unix time) when the reputation metrics were last given a fresh start. When your account is given a fresh start, your reputation metrics are calculated starting from the date of the fresh start. */ lastFreshStart: string; /** * If `true`, tracking of reputation metrics is enabled for the configuration set. If `false`, tracking of reputation metrics is disabled for the configuration set. */ reputationMetricsEnabled: boolean; } interface ConfigurationSetSendingOptions { /** * If `true`, email sending is enabled for the configuration set. If `false`, email sending is disabled for the configuration set. */ sendingEnabled: boolean; } interface ConfigurationSetSuppressionOptions { /** * List that contains the reasons that email addresses are automatically added to the suppression list for your account. Valid values: `BOUNCE`, `COMPLAINT`. */ suppressedReasons?: string[]; } interface ConfigurationSetTrackingOptions { /** * Domain to use for tracking open and click events. */ customRedirectDomain: string; /** * HTTPS policy to use for tracking open and click events. Valid values are `REQUIRE`, `REQUIRE_OPEN_ONLY` or `OPTIONAL`. */ httpsPolicy?: string; } interface ConfigurationSetVdmOptions { /** * Additional settings for your VDM configuration as applicable to the Dashboard. See `dashboardOptions` Block for details. */ dashboardOptions?: outputs.sesv2.ConfigurationSetVdmOptionsDashboardOptions; /** * Additional settings for your VDM configuration as applicable to the Guardian. See `guardianOptions` Block for details. */ guardianOptions?: outputs.sesv2.ConfigurationSetVdmOptionsGuardianOptions; } interface ConfigurationSetVdmOptionsDashboardOptions { /** * Status of your VDM engagement metrics collection. Valid values: `ENABLED`, `DISABLED`. */ engagementMetrics?: string; } interface ConfigurationSetVdmOptionsGuardianOptions { /** * Status of your VDM optimized shared delivery. Valid values: `ENABLED`, `DISABLED`. */ optimizedSharedDelivery?: string; } interface ContactListTopic { /** * Default subscription status to be applied to a contact if the contact has not noted their preference for subscribing to a topic. */ defaultSubscriptionStatus: string; /** * Description of what the topic is about, which the contact will see. */ description?: string; /** * Name of the topic the contact will see. */ displayName: string; /** * Name of the topic. * * The following arguments are optional: */ topicName: string; } interface EmailIdentityDkimSigningAttributes { /** * [Easy DKIM] Key length of the DKIM key pair in use. */ currentSigningKeyLength: string; /** * [Bring Your Own DKIM] Private key used to generate a DKIM signature. The private key must use 1024 or 2048-bit RSA encryption, and must be encoded using base64 encoding. * * > **NOTE:** You have to delete the first and last lines ('-----BEGIN PRIVATE KEY-----' and '-----END PRIVATE KEY-----', respectively) of the generated private key. Additionally, you have to remove the line breaks in the generated private key. The resulting value is a string of characters with no spaces or line breaks. */ domainSigningPrivateKey?: string; /** * [Bring Your Own DKIM] String used to identify a public key in the DNS configuration for a domain. */ domainSigningSelector?: string; /** * [Easy DKIM] Last time a key pair was generated for this identity. */ lastKeyGenerationTimestamp: string; /** * [Easy DKIM] Key length of the future DKIM key pair to be generated. This can be changed at most once per day. Valid values: `RSA_1024_BIT`, `RSA_2048_BIT`. */ nextSigningKeyLength: string; /** * How DKIM was configured for the identity. `AWS_SES` indicates that DKIM was configured for the identity by using Easy DKIM. `EXTERNAL` indicates that DKIM was configured for the identity by using Bring Your Own DKIM (BYODKIM). */ signingAttributesOrigin: string; /** * Whether Amazon SES has successfully located the DKIM records in the DNS records for the domain. See the [AWS SES API v2 Reference](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_DkimAttributes.html#SES-Type-DkimAttributes-Status) for supported statuses. */ status: string; /** * If you used Easy DKIM to configure DKIM authentication for the domain, then this object contains a set of unique strings that you use to create a set of CNAME records that you add to the DNS configuration for your domain. When Amazon SES detects these records in the DNS configuration for your domain, the DKIM authentication process is complete. If you configured DKIM authentication for the domain by providing your own public-private key pair, then this object contains the selector for the public key. */ tokens: string[]; } interface GetConfigurationSetDeliveryOption { /** * Maximum amount of time, in seconds, that Amazon SES API v2 attempts delivery of email. If specified, the value must be greater than or equal to 300 seconds (5 minutes) and less than or equal to 50400 seconds (840 minutes). */ maxDeliverySeconds: number; /** * Name of the dedicated IP pool to associate with the configuration set. */ sendingPoolName: string; /** * Whether messages that use the configuration set are required to use TLS. */ tlsPolicy: string; } interface GetConfigurationSetReputationOption { /** * Date and time (in Unix time) when the reputation metrics were last given a fresh start. */ lastFreshStart: string; /** * Whether tracking of reputation metrics is enabled. */ reputationMetricsEnabled: boolean; } interface GetConfigurationSetSendingOption { /** * Whether email sending is enabled. */ sendingEnabled: boolean; } interface GetConfigurationSetSuppressionOption { /** * List that contains the reasons that email addresses are automatically added to the suppression list for your account. */ suppressedReasons: string[]; } interface GetConfigurationSetTrackingOption { /** * Domain used for tracking open and click events. */ customRedirectDomain: string; /** * HTTPS policy used for tracking open and click events. Valid values are `REQUIRE`, `REQUIRE_OPEN_ONLY`, or `OPTIONAL`. */ httpsPolicy: string; } interface GetConfigurationSetVdmOption { /** * Additional settings for your VDM configuration as applicable to the Dashboard. */ dashboardOptions: outputs.sesv2.GetConfigurationSetVdmOptionDashboardOption[]; /** * Additional settings for your VDM configuration as applicable to the Guardian. */ guardianOptions: outputs.sesv2.GetConfigurationSetVdmOptionGuardianOption[]; } interface GetConfigurationSetVdmOptionDashboardOption { /** * Status of your VDM engagement metrics collection. */ engagementMetrics: string; } interface GetConfigurationSetVdmOptionGuardianOption { /** * Status of your VDM optimized shared delivery. */ optimizedSharedDelivery: string; } interface GetDedicatedIpPoolDedicatedIp { /** * IPv4 address. */ ip: string; /** * How complete the dedicated IP warm-up process is. When this value equals `1`, the address has completed the warm-up process and is ready for use. */ warmupPercentage: number; /** * Warm-up status of a dedicated IP address. Valid values: `IN_PROGRESS`, `DONE`. */ warmupStatus: string; } interface GetEmailIdentityDkimSigningAttribute { /** * [Easy DKIM] The key length of the DKIM key pair in use. */ currentSigningKeyLength: string; /** * [Bring Your Own DKIM] Private key used to generate DKIM signatures. */ domainSigningPrivateKey: string; /** * [Bring Your Own DKIM] Selector added to the DNS configuration for the domain. */ domainSigningSelector: string; /** * [Easy DKIM] The last time a key pair was generated for this identity. */ lastKeyGenerationTimestamp: string; /** * [Easy DKIM] The key length of the future DKIM key pair to be generated. This can be changed at most once per day. */ nextSigningKeyLength: string; /** * String that indicates how DKIM was configured for the identity. `AWS_SES` indicates that DKIM was configured for the identity by using Easy DKIM. `EXTERNAL` indicates that DKIM was configured for the identity by using Bring Your Own DKIM (BYODKIM). */ signingAttributesOrigin: string; /** * Whether or not Amazon SES has successfully located the DKIM records in the DNS records for the domain. See the [AWS SES API v2 Reference](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_DkimAttributes.html#SES-Type-DkimAttributes-Status) for supported statuses. */ status: string; /** * If you used Easy DKIM to configure DKIM authentication for the domain, then this object contains a set of unique strings that you use to create a set of CNAME records that you add to the DNS configuration for your domain. When Amazon SES detects these records in the DNS configuration for your domain, the DKIM authentication process is complete. If you configured DKIM authentication for the domain by providing your own public-private key pair, then this object contains the selector for the public key. */ tokens: string[]; } interface MultiRegionEndpointDetails { /** * Secondary region route configuration. See `routesDetails` Block below. */ routesDetails?: outputs.sesv2.MultiRegionEndpointDetailsRoutesDetails; } interface MultiRegionEndpointDetailsRoutesDetails { /** * Name of the secondary AWS region. */ region: string; } interface MultiRegionEndpointRoute { /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region: string; } interface MultiRegionEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace sfn { interface ActivityEncryptionConfiguration { /** * Maximum duration for which Activities will reuse data keys. When the period expires, Activities will call GenerateDataKey. This setting only applies to customer managed KMS key and does not apply to AWS owned KMS key. */ kmsDataKeyReusePeriodSeconds?: number; /** * The alias, alias ARN, key ID, or key ARN of the symmetric encryption KMS key that encrypts the data key. To specify a KMS key in a different AWS account, the customer must use the key ARN or alias ARN. For more information regarding kms_key_id, see [KeyId](https://docs.aws.amazon.com/kms/latest/APIReference/API_DescribeKey.html#API_DescribeKey_RequestParameters) in the KMS documentation. */ kmsKeyId?: string; /** * The encryption option specified for the activity. Valid values: `AWS_KMS_KEY`, `CUSTOMER_MANAGED_KMS_KEY` */ type?: string; } interface AliasRoutingConfiguration { /** * ARN of the state machine version. */ stateMachineVersionArn: string; /** * Percentage of traffic routed to the state machine version. */ weight: number; } interface GetAliasRoutingConfiguration { stateMachineVersionArn: string; weight: number; } interface StateMachineEncryptionConfiguration { /** * Maximum duration for which Step Functions will reuse data keys. When the period expires, Step Functions will call GenerateDataKey. This setting only applies to customer managed KMS key and does not apply when `type` is `AWS_OWNED_KEY`. */ kmsDataKeyReusePeriodSeconds?: number; /** * The alias, alias ARN, key ID, or key ARN of the symmetric encryption KMS key that encrypts the data key. To specify a KMS key in a different AWS account, the customer must use the key ARN or alias ARN. For more information regarding kms_key_id, see [KeyId](https://docs.aws.amazon.com/kms/latest/APIReference/API_DescribeKey.html#API_DescribeKey_RequestParameters) in the KMS documentation. */ kmsKeyId?: string; /** * The encryption option specified for the state machine. Valid values: `AWS_OWNED_KEY`, `CUSTOMER_MANAGED_KMS_KEY` */ type?: string; } interface StateMachineLoggingConfiguration { /** * Determines whether execution data is included in your log. When set to `false`, data is excluded. */ includeExecutionData?: boolean; /** * Defines which category of execution history events are logged. Valid values: `ALL`, `ERROR`, `FATAL`, `OFF` */ level?: string; /** * ARN of a CloudWatch log group. Make sure the State Machine has the correct IAM policies for logging. The ARN must end with `:*` */ logDestination?: string; } interface StateMachineTracingConfiguration { /** * When set to `true`, AWS X-Ray tracing is enabled. Make sure the State Machine has the correct IAM policies for logging. See the [AWS Step Functions Developer Guide](https://docs.aws.amazon.com/step-functions/latest/dg/xray-iam.html) for details. */ enabled?: boolean; } } export declare namespace shield { interface ApplicationLayerAutomaticResponseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DrtAccessLogBucketAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface DrtAccessRoleArnAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ProactiveEngagementEmergencyContact { /** * Additional notes regarding the contact. */ contactNotes?: string; /** * A valid email address that will be used for this contact. */ emailAddress: string; /** * A phone number, starting with `+` and up to 15 digits that will be used for this contact. */ phoneNumber?: string; } } export declare namespace signer { interface GetSigningJobRevocationRecord { reason: string; revokedAt: string; revokedBy: string; } interface GetSigningJobSignedObject { s3s: outputs.signer.GetSigningJobSignedObjectS3[]; } interface GetSigningJobSignedObjectS3 { bucket: string; key: string; } interface GetSigningJobSource { s3s: outputs.signer.GetSigningJobSourceS3[]; } interface GetSigningJobSourceS3 { bucket: string; key: string; version: string; } interface GetSigningProfileRevocationRecord { revocationEffectiveFrom: string; revokedAt: string; revokedBy: string; } interface GetSigningProfileSignatureValidityPeriod { type: string; value: number; } interface GetSigningProfileSigningMaterial { /** * ARN of the certificate used for signing. */ certificateArn: string; } interface SigningJobDestination { /** * A configuration block describing the S3 Destination object: See S3 Destination below for details. */ s3: outputs.signer.SigningJobDestinationS3; } interface SigningJobDestinationS3 { bucket: string; /** * An Amazon S3 object key prefix that you can use to limit signed objects keys to begin with the specified prefix. */ prefix?: string; } interface SigningJobRevocationRecord { reason: string; revokedAt: string; revokedBy: string; } interface SigningJobSignedObject { s3s: outputs.signer.SigningJobSignedObjectS3[]; } interface SigningJobSignedObjectS3 { bucket: string; /** * Key name of the object that contains your unsigned code. */ key: string; } interface SigningJobSource { /** * A configuration block describing the S3 Source object: See S3 Source below for details. */ s3: outputs.signer.SigningJobSourceS3; } interface SigningJobSourceS3 { bucket: string; /** * Key name of the object that contains your unsigned code. */ key: string; /** * Version of your source image in your version enabled S3 bucket. */ version: string; } interface SigningProfileRevocationRecord { /** * The time when revocation becomes effective. */ revocationEffectiveFrom: string; /** * The time when the signing profile was revoked. */ revokedAt: string; /** * The identity of the revoker. */ revokedBy: string; } interface SigningProfileSignatureValidityPeriod { /** * The time unit for signature validity. Valid values: `DAYS`, `MONTHS`, `YEARS`. */ type: string; /** * The numerical value of the time unit for signature validity. */ value: number; } interface SigningProfileSigningMaterial { /** * ARN of the certificates that is used to sign your code. */ certificateArn: string; } } export declare namespace sns { } export declare namespace sqs { } export declare namespace ssm { interface AssociationOutputLocation { /** * The S3 bucket name. */ s3BucketName: string; /** * The S3 bucket prefix. Results stored in the root if not configured. */ s3KeyPrefix?: string; /** * The S3 bucket region. * * Targets specify what instance IDs or tags to apply the document to and has these keys: */ s3Region?: string; } interface AssociationTarget { /** * User-defined criteria for sending commands that target managed nodes that meet the criteria. See the [AWS documentation](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_Target.html) for the list of available keys. */ key: string; /** * List of values that correspond to the specified `key`. See the [AWS documentation](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_Target.html) for details. */ values: string[]; } interface ContactsRotationRecurrence { dailySettings?: outputs.ssm.ContactsRotationRecurrenceDailySetting[]; /** * (Optional) Information about on-call rotations that recur monthly. See Monthly Settings for more details. */ monthlySettings?: outputs.ssm.ContactsRotationRecurrenceMonthlySetting[]; /** * (Required) The number of contacts, or shift team members designated to be on call concurrently during a shift. */ numberOfOnCalls: number; /** * (Required) The number of days, weeks, or months a single rotation lasts. */ recurrenceMultiplier: number; /** * (Optional) Information about the days of the week that the on-call rotation coverage includes. See Shift Coverages for more details. */ shiftCoverages?: outputs.ssm.ContactsRotationRecurrenceShiftCoverage[]; /** * (Optional) Information about on-call rotations that recur weekly. See Weekly Settings for more details. */ weeklySettings?: outputs.ssm.ContactsRotationRecurrenceWeeklySetting[]; } interface ContactsRotationRecurrenceDailySetting { /** * (Required) The hour of the day. */ hourOfDay: number; /** * (Required) The minutes of the hour. */ minuteOfHour: number; } interface ContactsRotationRecurrenceMonthlySetting { /** * (Required) The day of the month when monthly recurring on-call rotations begin. */ dayOfMonth: number; /** * (Required) The hand off time. See Hand Off Time for more details. */ handOffTime?: outputs.ssm.ContactsRotationRecurrenceMonthlySettingHandOffTime; } interface ContactsRotationRecurrenceMonthlySettingHandOffTime { /** * (Required) The hour of the day. */ hourOfDay: number; /** * (Required) The minutes of the hour. */ minuteOfHour: number; } interface ContactsRotationRecurrenceShiftCoverage { /** * (Required) Information about when an on-call shift begins and ends. See Coverage Times for more details. */ coverageTimes: outputs.ssm.ContactsRotationRecurrenceShiftCoverageCoverageTime[]; mapBlockKey: string; } interface ContactsRotationRecurrenceShiftCoverageCoverageTime { /** * (Required) The end time of the on-call shift. See Hand Off Time for more details. */ end?: outputs.ssm.ContactsRotationRecurrenceShiftCoverageCoverageTimeEnd; /** * (Required) The start time of the on-call shift. See Hand Off Time for more details. */ start?: outputs.ssm.ContactsRotationRecurrenceShiftCoverageCoverageTimeStart; } interface ContactsRotationRecurrenceShiftCoverageCoverageTimeEnd { /** * (Required) The hour of the day. */ hourOfDay: number; /** * (Required) The minutes of the hour. */ minuteOfHour: number; } interface ContactsRotationRecurrenceShiftCoverageCoverageTimeStart { /** * (Required) The hour of the day. */ hourOfDay: number; /** * (Required) The minutes of the hour. */ minuteOfHour: number; } interface ContactsRotationRecurrenceWeeklySetting { /** * (Required) The day of the week when the shift coverage occurs. */ dayOfWeek: string; /** * (Required) The hand off time. See Hand Off Time for more details. */ handOffTime?: outputs.ssm.ContactsRotationRecurrenceWeeklySettingHandOffTime; } interface ContactsRotationRecurrenceWeeklySettingHandOffTime { /** * (Required) The hour of the day. */ hourOfDay: number; /** * (Required) The minutes of the hour. */ minuteOfHour: number; } interface DocumentAttachmentsSource { /** * The key of a key-value pair that identifies the location of an attachment to the document. Valid values: `SourceUrl`, `S3FileUrl`, `AttachmentReference`. */ key: string; /** * The name of the document attachment file. */ name?: string; /** * The value of a key-value pair that identifies the location of an attachment to the document. The argument format is a list of a single string that depends on the type of key you specify - see the [API Reference](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_AttachmentsSource.html) for details. */ values: string[]; } interface DocumentParameter { /** * If specified, the default values for the parameters. Parameters without a default value are required. Parameters with a default value are optional. */ defaultValue: string; /** * A description of what the parameter does, how to use it, the default value, and whether or not the parameter is optional. */ description: string; /** * The name of the document. */ name: string; /** * The type of parameter. Valid values: `String`, `StringList`. */ type: string; } interface GetContactsRotationRecurrence { dailySettings: outputs.ssm.GetContactsRotationRecurrenceDailySetting[]; monthlySettings: outputs.ssm.GetContactsRotationRecurrenceMonthlySetting[]; numberOfOnCalls: number; recurrenceMultiplier: number; shiftCoverages: outputs.ssm.GetContactsRotationRecurrenceShiftCoverage[]; weeklySettings: outputs.ssm.GetContactsRotationRecurrenceWeeklySetting[]; } interface GetContactsRotationRecurrenceDailySetting { hourOfDay: number; minuteOfHour: number; } interface GetContactsRotationRecurrenceMonthlySetting { dayOfMonth: number; handOffTimes: outputs.ssm.GetContactsRotationRecurrenceMonthlySettingHandOffTime[]; } interface GetContactsRotationRecurrenceMonthlySettingHandOffTime { hourOfDay: number; minuteOfHour: number; } interface GetContactsRotationRecurrenceShiftCoverage { coverageTimes: outputs.ssm.GetContactsRotationRecurrenceShiftCoverageCoverageTime[]; mapBlockKey: string; } interface GetContactsRotationRecurrenceShiftCoverageCoverageTime { ends: outputs.ssm.GetContactsRotationRecurrenceShiftCoverageCoverageTimeEnd[]; starts: outputs.ssm.GetContactsRotationRecurrenceShiftCoverageCoverageTimeStart[]; } interface GetContactsRotationRecurrenceShiftCoverageCoverageTimeEnd { hourOfDay: number; minuteOfHour: number; } interface GetContactsRotationRecurrenceShiftCoverageCoverageTimeStart { hourOfDay: number; minuteOfHour: number; } interface GetContactsRotationRecurrenceWeeklySetting { dayOfWeek: string; handOffTimes: outputs.ssm.GetContactsRotationRecurrenceWeeklySettingHandOffTime[]; } interface GetContactsRotationRecurrenceWeeklySettingHandOffTime { hourOfDay: number; minuteOfHour: number; } interface GetInstancesFilter { /** * Name of the filter field. Valid values can be found in the [SSM InstanceInformationStringFilter API Reference](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_InstanceInformationStringFilter.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetMaintenanceWindowsFilter { /** * Name of the filter field. Valid values can be found in the [SSM DescribeMaintenanceWindows API Reference](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_DescribeMaintenanceWindows.html#API_DescribeMaintenanceWindows_RequestSyntax). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetPatchBaselineApprovalRule { /** * Number of days after the release date of each patch matched by the rule the patch is marked as approved in the patch baseline. */ approveAfterDays: number; /** * Cutoff date for auto approval of released patches. Any patches released on or before this date are installed automatically. Date is formatted as `YYYY-MM-DD`. Conflicts with `approveAfterDays` */ approveUntilDate: string; /** * Compliance level for patches approved by this rule. */ complianceLevel: string; /** * Boolean enabling the application of non-security updates. */ enableNonSecurity: boolean; /** * Patch filter group that defines the criteria for the rule. */ patchFilters: outputs.ssm.GetPatchBaselineApprovalRulePatchFilter[]; } interface GetPatchBaselineApprovalRulePatchFilter { /** * Key for the filter. */ key: string; /** * Value for the filter. */ values: string[]; } interface GetPatchBaselineGlobalFilter { /** * Key for the filter. */ key: string; /** * Value for the filter. */ values: string[]; } interface GetPatchBaselineSource { /** * Value of the yum repo configuration. */ configuration: string; /** * Name specified to identify the patch source. */ name: string; /** * Specific operating system versions a patch repository applies to. */ products: string[]; } interface GetPatchBaselinesBaselineIdentity { /** * Description of the patch baseline. */ baselineDescription: string; /** * ID of the patch baseline. */ baselineId: string; /** * Name of the patch baseline. */ baselineName: string; /** * Indicates whether this is the default baseline. AWS Systems Manager supports creating multiple default patch baselines. For example, you can create a default patch baseline for each operating system. */ defaultBaseline: boolean; /** * Operating system the patch baseline applies to. */ operatingSystem: string; } interface GetPatchBaselinesFilter { /** * Filter key. See the [AWS SSM documentation](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_DescribePatchBaselines.html) for valid values. */ key: string; /** * Filter values. See the [AWS SSM documentation](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_DescribePatchBaselines.html) for example values. */ values: string[]; } interface MaintenanceWindowTargetTarget { key: string; values: string[]; } interface MaintenanceWindowTaskTarget { key: string; /** * The array of strings. */ values: string[]; } interface MaintenanceWindowTaskTaskInvocationParameters { /** * The parameters for an AUTOMATION task type. Documented below. */ automationParameters?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersAutomationParameters; /** * The parameters for a LAMBDA task type. Documented below. */ lambdaParameters?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersLambdaParameters; /** * The parameters for a RUN_COMMAND task type. Documented below. */ runCommandParameters?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersRunCommandParameters; /** * The parameters for a STEP_FUNCTIONS task type. Documented below. */ stepFunctionsParameters?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersStepFunctionsParameters; } interface MaintenanceWindowTaskTaskInvocationParametersAutomationParameters { /** * The version of an Automation document to use during task execution. */ documentVersion?: string; /** * The parameters for the RUN_COMMAND task execution. Documented below. */ parameters?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersAutomationParametersParameter[]; } interface MaintenanceWindowTaskTaskInvocationParametersAutomationParametersParameter { /** * The parameter name. */ name: string; /** * The array of strings. */ values: string[]; } interface MaintenanceWindowTaskTaskInvocationParametersLambdaParameters { /** * Pass client-specific information to the Lambda function that you are invoking. */ clientContext?: string; /** * JSON to provide to your Lambda function as input. */ payload?: string; /** * Specify a Lambda function version or alias name. */ qualifier?: string; } interface MaintenanceWindowTaskTaskInvocationParametersRunCommandParameters { /** * Configuration options for sending command output to CloudWatch Logs. Documented below. */ cloudwatchConfig?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersRunCommandParametersCloudwatchConfig; /** * Information about the command(s) to execute. */ comment?: string; /** * The SHA-256 or SHA-1 hash created by the system when the document was created. SHA-1 hashes have been deprecated. */ documentHash?: string; /** * SHA-256 or SHA-1. SHA-1 hashes have been deprecated. Valid values: `Sha256` and `Sha1` */ documentHashType?: string; /** * The version of an Automation document to use during task execution. */ documentVersion?: string; /** * Configurations for sending notifications about command status changes on a per-instance basis. Documented below. */ notificationConfig?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersRunCommandParametersNotificationConfig; /** * The name of the Amazon S3 bucket. */ outputS3Bucket?: string; /** * The Amazon S3 bucket subfolder. */ outputS3KeyPrefix?: string; /** * The parameters for the RUN_COMMAND task execution. Documented below. */ parameters?: outputs.ssm.MaintenanceWindowTaskTaskInvocationParametersRunCommandParametersParameter[]; /** * ARN of the AWS Identity and Access Management (IAM) service role to use to publish Amazon Simple Notification Service (Amazon SNS) notifications for maintenance window Run Command tasks. */ serviceRoleArn?: string; /** * If this time is reached and the command has not already started executing, it doesn't run. */ timeoutSeconds?: number; } interface MaintenanceWindowTaskTaskInvocationParametersRunCommandParametersCloudwatchConfig { /** * The name of the CloudWatch log group where you want to send command output. If you don't specify a group name, Systems Manager automatically creates a log group for you. The log group uses the following naming format: aws/ssm/SystemsManagerDocumentName. */ cloudwatchLogGroupName: string; /** * Enables Systems Manager to send command output to CloudWatch Logs. */ cloudwatchOutputEnabled?: boolean; } interface MaintenanceWindowTaskTaskInvocationParametersRunCommandParametersNotificationConfig { /** * ARN for a Simple Notification Service (SNS) topic. Run Command pushes notifications about command status changes to this topic. */ notificationArn?: string; /** * The different events for which you can receive notifications. Valid values: `All`, `InProgress`, `Success`, `TimedOut`, `Cancelled`, and `Failed` */ notificationEvents?: string[]; /** * When specified with `Command`, receive notification when the status of a command changes. When specified with `Invocation`, for commands sent to multiple instances, receive notification on a per-instance basis when the status of a command changes. Valid values: `Command` and `Invocation` */ notificationType?: string; } interface MaintenanceWindowTaskTaskInvocationParametersRunCommandParametersParameter { /** * The parameter name. */ name: string; /** * The array of strings. */ values: string[]; } interface MaintenanceWindowTaskTaskInvocationParametersStepFunctionsParameters { /** * The inputs for the STEP_FUNCTION task. */ input?: string; /** * The name of the STEP_FUNCTION task. */ name?: string; } interface PatchBaselineApprovalRule { /** * Number of days after the release date of each patch matched by the rule the patch is marked as approved in the patch baseline. Valid Range: 0 to 360. Conflicts with `approveUntilDate`. */ approveAfterDays?: number; /** * Cutoff date for auto approval of released patches. Any patches released on or before this date are installed automatically. Date is formatted as `YYYY-MM-DD`. Conflicts with `approveAfterDays` */ approveUntilDate?: string; /** * Compliance level for patches approved by this rule. Valid values are `CRITICAL`, `HIGH`, `MEDIUM`, `LOW`, `INFORMATIONAL`, and `UNSPECIFIED`. The default value is `UNSPECIFIED`. */ complianceLevel?: string; /** * Boolean enabling the application of non-security updates. The default value is `false`. Valid for Linux instances only. */ enableNonSecurity?: boolean; /** * Patch filter group that defines the criteria for the rule. Up to 5 patch filters can be specified per approval rule using Key/Value pairs. Valid combinations of these Keys and the `operatingSystem` value can be found in the [SSM DescribePatchProperties API Reference](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_DescribePatchProperties.html). Valid Values are exact values for the patch property given as the key, or a wildcard `*`, which matches all values. `PATCH_SET` defaults to `OS` if unspecified */ patchFilters: outputs.ssm.PatchBaselineApprovalRulePatchFilter[]; } interface PatchBaselineApprovalRulePatchFilter { key: string; values: string[]; } interface PatchBaselineGlobalFilter { key: string; values: string[]; } interface PatchBaselineSource { /** * Value of the yum repo configuration. For information about other options available for your yum repository configuration, see the [`dnf.conf` documentation](https://man7.org/linux/man-pages/man5/dnf.conf.5.html) */ configuration: string; /** * Name specified to identify the patch source. */ name: string; /** * Specific operating system versions a patch repository applies to, such as `"Ubuntu16.04"`, `"AmazonLinux2016.09"`, `"RedhatEnterpriseLinux7.2"` or `"Suse12.7"`. For lists of supported product values, see [PatchFilter](https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_PatchFilter.html). */ products: string[]; } interface QuicksetupConfigurationManagerConfigurationDefinition { id: string; localDeploymentAdministrationRoleArn?: string; /** * Name of the IAM role used to deploy local configurations. */ localDeploymentExecutionRoleName?: string; /** * Parameters for the configuration definition type. Parameters for configuration definitions vary based the configuration type. See the [AWS API documentation](https://docs.aws.amazon.com/quick-setup/latest/APIReference/API_ConfigurationDefinitionInput.html) for a complete list of parameters for each configuration type. */ parameters: { [key: string]: string; }; /** * Type of the Quick Setup configuration. */ type: string; /** * Version of the Quick Setup type to use. */ typeVersion: string; } interface QuicksetupConfigurationManagerStatusSummary { /** * Current status. */ status: string; /** * When applicable, returns an informational message relevant to the current status and status type of the status summary object. */ statusMessage: string; /** * Type of a status summary. */ statusType: string; } interface QuicksetupConfigurationManagerTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ResourceDataSyncS3Destination { /** * Name of S3 bucket where the aggregated data is stored. */ bucketName: string; /** * Enables destination data sharing. * See `destinationDataSharing` below. */ destinationDataSharing?: outputs.ssm.ResourceDataSyncS3DestinationDestinationDataSharing; /** * ARN of an encryption key for a destination in Amazon S3. */ kmsKeyArn?: string; /** * Prefix for the bucket. */ prefix?: string; /** * Region with the bucket targeted by the Resource Data Sync. */ region: string; /** * A supported sync format. Only JsonSerDe is currently supported. Defaults to JsonSerDe. */ syncFormat?: string; } interface ResourceDataSyncS3DestinationDestinationDataSharing { /** * Data sharing type. * Only `Organization` is supported. */ destinationDataSharingType?: string; } } export declare namespace ssmcontacts { interface ContactChannelDeliveryAddress { /** * Details to engage this contact channel. The expected format depends on the contact channel type and is described in the [`ContactChannelAddress` section of the SSM Contacts API Reference](https://docs.aws.amazon.com/incident-manager/latest/APIReference/API_SSMContacts_ContactChannelAddress.html). */ simpleAddress: string; } interface GetContactChannelDeliveryAddress { simpleAddress: string; } interface GetPlanStage { durationInMinutes: number; targets: outputs.ssmcontacts.GetPlanStageTarget[]; } interface GetPlanStageTarget { channelTargetInfos: outputs.ssmcontacts.GetPlanStageTargetChannelTargetInfo[]; contactTargetInfos: outputs.ssmcontacts.GetPlanStageTargetContactTargetInfo[]; } interface GetPlanStageTargetChannelTargetInfo { contactChannelId: string; retryIntervalInMinutes: number; } interface GetPlanStageTargetContactTargetInfo { /** * ARN of the contact or escalation plan. */ contactId: string; isEssential: boolean; } interface PlanStage { /** * The time to wait until beginning the next stage. The duration can only be set to 0 if a target is specified. */ durationInMinutes: number; /** * One or more configuration blocks for specifying the contacts or contact methods that the escalation plan or engagement plan is engaging. See Target below for more details. */ targets?: outputs.ssmcontacts.PlanStageTarget[]; } interface PlanStageTarget { /** * A configuration block for specifying information about the contact channel that Incident Manager engages. See Channel Target Info for more details. */ channelTargetInfo?: outputs.ssmcontacts.PlanStageTargetChannelTargetInfo; /** * A configuration block for specifying information about the contact that Incident Manager engages. See Contact Target Info for more details. */ contactTargetInfo?: outputs.ssmcontacts.PlanStageTargetContactTargetInfo; } interface PlanStageTargetChannelTargetInfo { /** * The ARN of the contact channel. */ contactChannelId: string; /** * The number of minutes to wait before retrying to send engagement if the engagement initially failed. */ retryIntervalInMinutes?: number; } interface PlanStageTargetContactTargetInfo { /** * The ARN of the contact. */ contactId?: string; /** * A Boolean value determining if the contact's acknowledgement stops the progress of stages in the plan. */ isEssential: boolean; } } export declare namespace ssmincidents { interface GetReplicationSetRegion { /** * ARN of the KMS encryption key. */ kmsKeyArn: string; /** * The name of the Region. */ name: string; /** * The current status of the Region. * * Valid Values: `ACTIVE` | `CREATING` | `UPDATING` | `DELETING` | `FAILED` */ status: string; /** * More information about the status of a Region. */ statusMessage: string; } interface GetResponsePlanAction { /** * The Systems Manager automation document to start as the runbook at the beginning of the incident. The following values are supported: */ ssmAutomations: outputs.ssmincidents.GetResponsePlanActionSsmAutomation[]; } interface GetResponsePlanActionSsmAutomation { /** * The automation document's name. */ documentName: string; /** * The version of the automation document to use at runtime. */ documentVersion: string; /** * The key-value pair used to resolve dynamic parameter values when processing a Systems Manager Automation runbook. */ dynamicParameters: { [key: string]: string; }; /** * The key-value pair parameters used when the automation document runs. The following values are supported: */ parameters: outputs.ssmincidents.GetResponsePlanActionSsmAutomationParameter[]; /** * The ARN of the role that the automation document assumes when it runs commands. */ roleArn: string; /** * The account that runs the automation document. This can be in either the management account or an application account. */ targetAccount: string; } interface GetResponsePlanActionSsmAutomationParameter { /** * The name of the PagerDuty configuration. */ name: string; /** * The values for the associated parameter name. */ values: string[]; } interface GetResponsePlanIncidentTemplate { /** * A string used to stop Incident Manager from creating multiple incident records for the same incident. */ dedupeString: string; /** * The impact value of a generated incident. The following values are supported: */ impact: number; /** * The tags assigned to an incident template. When an incident starts, Incident Manager assigns the tags specified in the template to the incident. */ incidentTags: { [key: string]: string; }; /** * The Amazon Simple Notification Service (Amazon SNS) targets that this incident notifies when it is updated. The `notificationTarget` configuration block supports the following argument: */ notificationTargets: outputs.ssmincidents.GetResponsePlanIncidentTemplateNotificationTarget[]; /** * The summary of an incident. */ summary: string; /** * The title of a generated incident. */ title: string; } interface GetResponsePlanIncidentTemplateNotificationTarget { /** * The ARN of the Amazon SNS topic. */ snsTopicArn: string; } interface GetResponsePlanIntegration { /** * Details about the PagerDuty configuration for a response plan. The following values are supported: */ pagerduties: outputs.ssmincidents.GetResponsePlanIntegrationPagerduty[]; } interface GetResponsePlanIntegrationPagerduty { /** * The name of the PagerDuty configuration. */ name: string; /** * The ID of the AWS Secrets Manager secret that stores your PagerDuty key — either a General Access REST API Key or User Token REST API Key — and other user credentials. */ secretId: string; /** * The ID of the PagerDuty service that the response plan associates with an incident when it launches. */ serviceId: string; } interface ReplicationSetRegion { /** * ARN of the customer managed key. If omitted, AWS manages the AWS KMS keys for you, using an AWS owned key, as indicated by a default value of `DefaultKey`. */ kmsKeyArn?: string; /** * The name of the Region, such as `ap-southeast-2`. */ name: string; /** * The current status of the Region. * * Valid Values: `ACTIVE` | `CREATING` | `UPDATING` | `DELETING` | `FAILED` */ status: string; /** * More information about the status of a Region. */ statusMessage: string; } interface ResponsePlanAction { /** * The Systems Manager automation document to start as the runbook at the beginning of the incident. The following values are supported: */ ssmAutomations?: outputs.ssmincidents.ResponsePlanActionSsmAutomation[]; } interface ResponsePlanActionSsmAutomation { /** * The automation document's name. */ documentName: string; /** * The version of the automation document to use at runtime. */ documentVersion?: string; /** * The key-value pair to resolve dynamic parameter values when processing a Systems Manager Automation runbook. */ dynamicParameters?: { [key: string]: string; }; /** * The key-value pair parameters to use when the automation document runs. The following values are supported: */ parameters?: outputs.ssmincidents.ResponsePlanActionSsmAutomationParameter[]; /** * The ARN of the role that the automation document assumes when it runs commands. */ roleArn: string; /** * The account that the automation document runs in. This can be in either the management account or an application account. */ targetAccount?: string; } interface ResponsePlanActionSsmAutomationParameter { /** * The name of parameter. */ name: string; /** * The values for the associated parameter name. */ values: string[]; } interface ResponsePlanIncidentTemplate { /** * A string used to stop Incident Manager from creating multiple incident records for the same incident. */ dedupeString?: string; /** * The impact value of a generated incident. The following values are supported: */ impact: number; /** * The tags assigned to an incident template. When an incident starts, Incident Manager assigns the tags specified in the template to the incident. */ incidentTags?: { [key: string]: string; }; /** * The Amazon Simple Notification Service (Amazon SNS) targets that this incident notifies when it is updated. The `notificationTarget` configuration block supports the following argument: */ notificationTargets?: outputs.ssmincidents.ResponsePlanIncidentTemplateNotificationTarget[]; /** * The summary of an incident. */ summary?: string; /** * The title of a generated incident. */ title: string; } interface ResponsePlanIncidentTemplateNotificationTarget { /** * The ARN of the Amazon SNS topic. */ snsTopicArn: string; } interface ResponsePlanIntegration { /** * Details about the PagerDuty configuration for a response plan. The following values are supported: */ pagerduties?: outputs.ssmincidents.ResponsePlanIntegrationPagerduty[]; } interface ResponsePlanIntegrationPagerduty { /** * The name of the PagerDuty configuration. */ name: string; /** * The ID of the AWS Secrets Manager secret that stores your PagerDuty key — either a General Access REST API Key or User Token REST API Key — and other user credentials. * * For more information about the constraints for each field, see [CreateResponsePlan](https://docs.aws.amazon.com/incident-manager/latest/APIReference/API_CreateResponsePlan.html) in the *AWS Systems Manager Incident Manager API Reference*. */ secretId: string; /** * The ID of the PagerDuty service that the response plan associated with the incident at launch. */ serviceId: string; } } export declare namespace ssoadmin { interface ApplicationPortalOptions { /** * Sign-in options for the access portal. See `signInOptions` below. */ signInOptions?: outputs.ssoadmin.ApplicationPortalOptionsSignInOptions; /** * Indicates whether this application is visible in the access portal. Valid values are `ENABLED` and `DISABLED`. */ visibility: string; } interface ApplicationPortalOptionsSignInOptions { /** * URL that accepts authentication requests for an application. */ applicationUrl?: string; /** * Determines how IAM Identity Center navigates the user to the target application. * Valid values are `APPLICATION` and `IDENTITY_CENTER`. * If `APPLICATION` is set, IAM Identity Center redirects the customer to the configured `applicationUrl`. * If `IDENTITY_CENTER` is set, IAM Identity Center uses SAML identity-provider initiated authentication to sign the customer directly into a SAML-based application. */ origin: string; } interface CustomerManagedPolicyAttachmentCustomerManagedPolicyReference { /** * Name of the customer managed IAM Policy to be attached. */ name: string; /** * The path to the IAM policy to be attached. The default is `/`. See [IAM Identifiers](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-friendly-names) for more information. */ path?: string; } interface CustomerManagedPolicyAttachmentsExclusiveCustomerManagedPolicyReference { /** * Name of the customer managed IAM Policy to be attached. */ name: string; /** * The path to the IAM policy to be attached. The default is `/`. See [IAM Identifiers](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-friendly-names) for more information. */ path: string; } interface CustomerManagedPolicyAttachmentsExclusiveTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface GetApplicationAssignmentsApplicationAssignment { /** * ARN of the application. */ applicationArn: string; /** * An identifier for an object in IAM Identity Center, such as a user or group. */ principalId: string; /** * Entity type for which the assignment will be created. Valid values are `USER` or `GROUP`. */ principalType: string; } interface GetApplicationPortalOption { /** * Sign-in options for the access portal. See `signInOptions` Block below. */ signInOptions: outputs.ssoadmin.GetApplicationPortalOptionSignInOption[]; /** * Whether the application is visible in the access portal. */ visibility: string; } interface GetApplicationPortalOptionSignInOption { /** * URL that accepts authentication requests for an application. */ applicationUrl: string; /** * How IAM Identity Center navigates the user to the target application. */ origin: string; } interface GetApplicationProvidersApplicationProvider { /** * ARN of the application provider. */ applicationProviderArn: string; /** * An object describing how IAM Identity Center represents the application provider in the portal. See `displayData` below. */ displayDatas: outputs.ssoadmin.GetApplicationProvidersApplicationProviderDisplayData[]; /** * Protocol that the application provider uses to perform federation. Valid values are `SAML` and `OAUTH`. */ federationProtocol: string; } interface GetApplicationProvidersApplicationProviderDisplayData { /** * Description of the application provider. */ description: string; /** * Name of the application provider. */ displayName: string; /** * URL that points to an icon that represents the application provider. */ iconUrl: string; } interface GetPrincipalApplicationAssignmentsApplicationAssignment { /** * ARN of the application. */ applicationArn: string; /** * An identifier for an object in IAM Identity Center, such as a user or group. */ principalId: string; /** * Entity type for which the assignment will be created. Valid values are `USER` or `GROUP`. */ principalType: string; } interface InstanceAccessControlAttributesAttribute { /** * The name of the attribute associated with your identities in your identity source. This is used to map a specified attribute in your identity source with an attribute in AWS SSO. */ key: string; /** * The value used for mapping a specified attribute to an identity source. See AccessControlAttributeValue */ values: outputs.ssoadmin.InstanceAccessControlAttributesAttributeValue[]; } interface InstanceAccessControlAttributesAttributeValue { /** * The identity source to use when mapping a specified attribute to AWS SSO. */ sources: string[]; } interface ManagedPolicyAttachmentsExclusiveTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface PermissionsBoundaryAttachmentPermissionsBoundary { /** * Specifies the name and path of a customer managed policy. See below. */ customerManagedPolicyReference?: outputs.ssoadmin.PermissionsBoundaryAttachmentPermissionsBoundaryCustomerManagedPolicyReference; /** * AWS-managed IAM policy ARN to use as the permissions boundary. */ managedPolicyArn?: string; } interface PermissionsBoundaryAttachmentPermissionsBoundaryCustomerManagedPolicyReference { /** * Name of the customer managed IAM Policy to be attached. */ name: string; /** * The path to the IAM policy to be attached. The default is `/`. See [IAM Identifiers](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-friendly-names) for more information. */ path?: string; } interface RegionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface TrustedTokenIssuerTrustedTokenIssuerConfiguration { /** * A block that describes the settings for a trusted token issuer that works with OpenID Connect (OIDC) by using JSON Web Tokens (JWT). See Documented below below. */ oidcJwtConfiguration: outputs.ssoadmin.TrustedTokenIssuerTrustedTokenIssuerConfigurationOidcJwtConfiguration; } interface TrustedTokenIssuerTrustedTokenIssuerConfigurationOidcJwtConfiguration { /** * Specifies the path of the source attribute in the JWT from the trusted token issuer. */ claimAttributePath: string; /** * Specifies path of the destination attribute in a JWT from IAM Identity Center. The attribute mapped by this JMESPath expression is compared against the attribute mapped by `claimAttributePath` when a trusted token issuer token is exchanged for an IAM Identity Center token. */ identityStoreAttributePath: string; /** * Specifies the URL that IAM Identity Center uses for OpenID Discovery. OpenID Discovery is used to obtain the information required to verify the tokens that the trusted token issuer generates. */ issuerUrl: string; /** * The method that the trusted token issuer can use to retrieve the JSON Web Key Set used to verify a JWT. Valid values are `OPEN_ID_DISCOVERY` */ jwksRetrievalOption: string; } } export declare namespace storagegateway { interface FileSystemAssociationCacheAttributes { /** * Refreshes a file share's cache by using Time To Live (TTL). * TTL is the length of time since the last refresh after which access to the directory would cause the file gateway * to first refresh that directory's contents from the Amazon S3 bucket. Valid Values: `0` or `300` to `2592000` seconds (5 minutes to 30 days). Defaults to `0` */ cacheStaleTimeoutInSeconds?: number; } interface GatewayGatewayNetworkInterface { /** * IP version 4 (IPv4) address of the interface. */ ipv4Address: string; } interface GatewayMaintenanceStartTime { /** * The day of the month component of the maintenance start time represented as an ordinal number from 1 to 28, where 1 represents the first day of the month and 28 represents the last day of the month. */ dayOfMonth?: string; /** * The day of the week component of the maintenance start time week represented as an ordinal number from 0 to 6, where 0 represents Sunday and 6 Saturday. */ dayOfWeek?: string; /** * The hour component of the maintenance start time represented as _hh_, where _hh_ is the hour (00 to 23). The hour of the day is in the time zone of the gateway. */ hourOfDay: number; /** * The minute component of the maintenance start time represented as _mm_, where _mm_ is the minute (00 to 59). The minute of the hour is in the time zone of the gateway. */ minuteOfHour?: number; } interface GatewaySmbActiveDirectorySettings { activeDirectoryStatus: string; /** * List of IPv4 addresses, NetBIOS names, or host names of your domain server. * If you need to specify the port number include it after the colon (“:”). For example, `mydc.mydomain.com:389`. */ domainControllers?: string[]; /** * The name of the domain that you want the gateway to join. */ domainName: string; /** * The organizational unit (OU) is a container in an Active Directory that can hold users, groups, * computers, and other OUs and this parameter specifies the OU that the gateway will join within the AD domain. */ organizationalUnit?: string; /** * The password of the user who has permission to add the gateway to the Active Directory domain. */ password: string; /** * Specifies the time in seconds, in which the JoinDomain operation must complete. The default is `20` seconds. */ timeoutInSeconds?: number; /** * The user name of user who has permission to add the gateway to the Active Directory domain. */ username: string; } interface NfsFileShareCacheAttributes { /** * Refreshes a file share's cache by using Time To Live (TTL). * TTL is the length of time since the last refresh after which access to the directory would cause the file gateway * to first refresh that directory's contents from the Amazon S3 bucket. Valid Values: 300 to 2,592,000 seconds (5 minutes to 30 days) */ cacheStaleTimeoutInSeconds?: number; } interface NfsFileShareNfsFileShareDefaults { /** * The Unix directory mode in the string form "nnnn". Defaults to `"0777"`. */ directoryMode?: string; /** * The Unix file mode in the string form "nnnn". Defaults to `"0666"`. */ fileMode?: string; /** * The default group ID for the file share (unless the files have another group ID specified). Defaults to `65534` (`nfsnobody`). Valid values: `0` through `4294967294`. */ groupId?: string; /** * The default owner ID for the file share (unless the files have another owner ID specified). Defaults to `65534` (`nfsnobody`). Valid values: `0` through `4294967294`. */ ownerId?: string; } interface SmbFileShareCacheAttributes { /** * Refreshes a file share's cache by using Time To Live (TTL). * TTL is the length of time since the last refresh after which access to the directory would cause the file gateway * to first refresh that directory's contents from the Amazon S3 bucket. Valid Values: 300 to 2,592,000 seconds (5 minutes to 30 days) */ cacheStaleTimeoutInSeconds?: number; } } export declare namespace synthetics { interface CanaryArtifactConfig { /** * Configuration of the encryption-at-rest settings for artifacts that the canary uploads to Amazon S3. See S3 Encryption. */ s3Encryption?: outputs.synthetics.CanaryArtifactConfigS3Encryption; } interface CanaryArtifactConfigS3Encryption { /** * The encryption method to use for artifacts created by this canary. Valid values are: `SSE_S3` and `SSE_KMS`. */ encryptionMode?: string; /** * The ARN of the customer-managed KMS key to use, if you specify `SSE_KMS` for `encryptionMode`. */ kmsKeyArn?: string; } interface CanaryRunConfig { /** * Whether this canary is to use active AWS X-Ray tracing when it runs. You can enable active tracing only for canaries that use version syn-nodejs-2.0 or later for their canary runtime. */ activeTracing?: boolean; /** * Map of environment variables that are accessible from the canary during execution. Please see [AWS Docs](https://docs.aws.amazon.com/lambda/latest/dg/configuration-envvars.html#configuration-envvars-runtime) for variables reserved for Lambda. */ environmentVariables?: { [key: string]: string; }; /** * Amount of ephemeral storage (in MB) allocated for the canary run during execution. Defaults to 1024. */ ephemeralStorage: number; /** * Maximum amount of memory available to the canary while it is running, in MB. The value you specify must be a multiple of 64. */ memoryInMb: number; /** * Number of seconds the canary is allowed to run before it must stop. If you omit this field, the frequency of the canary is used, up to a maximum of 840 (14 minutes). */ timeoutInSeconds: number; } interface CanarySchedule { /** * Duration in seconds, for the canary to continue making regular runs according to the schedule in the Expression value. */ durationInSeconds?: number; /** * Rate expression or cron expression that defines how often the canary is to run. For rate expression, the syntax is `rate(number unit)`. _unit_ can be `minute`, `minutes`, or `hour`. For cron expression, the syntax is `cron(expression)`. For more information about the syntax for cron expressions, see [Scheduling canary runs using cron](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch_Synthetics_Canaries_cron.html). */ expression: string; /** * Configuration block for canary retries. Detailed below. */ retryConfig: outputs.synthetics.CanaryScheduleRetryConfig; } interface CanaryScheduleRetryConfig { /** * Maximum number of retries. The value must be less than or equal to `2`. If `maxRetries` is `2`, `run_config.timeout_in_seconds` should be less than 600 seconds. Defaults to `0`. */ maxRetries: number; } interface CanaryTimeline { /** * Date and time the canary was created. */ created: string; /** * Date and time the canary was most recently modified. */ lastModified: string; /** * Date and time that the canary's most recent run started. */ lastStarted: string; /** * Date and time that the canary's most recent run ended. */ lastStopped: string; } interface CanaryVpcConfig { /** * If `true`, allow outbound IPv6 traffic on VPC canaries that are connected to dual-stack subnets. The default is `false`. */ ipv6AllowedForDualStack?: boolean; /** * IDs of the security groups for this canary. */ securityGroupIds?: string[]; /** * IDs of the subnets where this canary is to run. */ subnetIds?: string[]; /** * ID of the VPC where this canary is to run. */ vpcId: string; } interface GetRuntimeVersionsRuntimeVersion { /** * Date of deprecation if the runtme version is deprecated. */ deprecationDate: string; /** * Description of the runtime version, created by Amazon. */ description: string; /** * Date that the runtime version was released. */ releaseDate: string; /** * Name of the runtime version. * For a list of valid runtime versions, see [Canary Runtime Versions](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch_Synthetics_Canaries_Library.html). */ versionName: string; } } export declare namespace timestreaminfluxdb { interface DbClusterLogDeliveryConfiguration { /** * Configuration for S3 bucket log delivery. */ s3Configuration?: outputs.timestreaminfluxdb.DbClusterLogDeliveryConfigurationS3Configuration; } interface DbClusterLogDeliveryConfigurationS3Configuration { /** * Name of the S3 bucket to deliver logs to. */ bucketName: string; /** * Indicates whether log delivery to the S3 bucket is enabled. * * **Note**: The following arguments do updates in-place: `dbParameterGroupIdentifier`, `logDeliveryConfiguration`, `maintenanceSchedule`, `port`, `dbInstanceType`, `failoverMode`, and `tags`. Changes to any other argument after a cluster has been deployed will cause destruction and re-creation of the cluster. Additionally, when `dbParameterGroupIdentifier` is added to a cluster or modified, the cluster will be updated in-place but if `dbParameterGroupIdentifier` is removed from a cluster, the cluster will be destroyed and re-created. */ enabled: boolean; } interface DbClusterMaintenanceSchedule { /** * Preferred maintenance window in the format `ddd:HH:MM-ddd:HH:MM`. Day must be one of `Mon`, `Tue`, `Wed`, `Thu`, `Fri`, `Sat`, or `Sun`. Provide an empty string to let the system choose a window. */ preferredMaintenanceWindow: string; /** * IANA timezone identifier for the maintenance window. For example, `America/New_York` or `UTC`. */ timezone: string; } interface DbClusterTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface DbInstanceLogDeliveryConfiguration { /** * Configuration for S3 bucket log delivery. */ s3Configuration?: outputs.timestreaminfluxdb.DbInstanceLogDeliveryConfigurationS3Configuration; } interface DbInstanceLogDeliveryConfigurationS3Configuration { /** * Name of the S3 bucket to deliver logs to. */ bucketName: string; /** * Indicates whether log delivery to the S3 bucket is enabled. * * **Note**: The following arguments do updates in-place: `dbParameterGroupIdentifier`, `logDeliveryConfiguration`, `maintenanceSchedule`, `port`, `deploymentType`, `dbInstanceType`, and `tags`. Changes to any other argument after a DB instance has been deployed will cause destruction and re-creation of the DB instance. Additionally, when `dbParameterGroupIdentifier` is added to a DB instance or modified, the DB instance will be updated in-place but if `dbParameterGroupIdentifier` is removed from a DB instance, the DB instance will be destroyed and re-created. */ enabled: boolean; } interface DbInstanceMaintenanceSchedule { /** * Preferred maintenance window in the format `ddd:HH:MM-ddd:HH:MM`. Day must be one of `Mon`, `Tue`, `Wed`, `Thu`, `Fri`, `Sat`, or `Sun`. Provide an empty string to let the system choose a window. */ preferredMaintenanceWindow: string; /** * IANA timezone identifier for the maintenance window. For example, `America/New_York` or `UTC`. */ timezone: string; } interface DbInstanceTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace timestreamquery { interface ScheduledQueryErrorReportConfiguration { /** * Configuration block for the S3 configuration for the error reports. See below. */ s3Configuration: outputs.timestreamquery.ScheduledQueryErrorReportConfigurationS3Configuration; } interface ScheduledQueryErrorReportConfigurationS3Configuration { /** * Name of the S3 bucket under which error reports will be created. */ bucketName: string; /** * Encryption at rest options for the error reports. If no encryption option is specified, Timestream will choose `SSE_S3` as default. Valid values are `SSE_S3`, `SSE_KMS`. */ encryptionOption: string; /** * Prefix for the error report key. */ objectKeyPrefix?: string; } interface ScheduledQueryLastRunSummary { /** * S3 location for error report. */ errorReportLocations?: outputs.timestreamquery.ScheduledQueryLastRunSummaryErrorReportLocation[]; /** * Statistics for a single scheduled query run. */ executionStats?: outputs.timestreamquery.ScheduledQueryLastRunSummaryExecutionStat[]; /** * Error message for the scheduled query in case of failure. You might have to look at the error report to get more detailed error reasons. */ failureReason: string; /** * InvocationTime for this run. This is the time at which the query is scheduled to run. Parameter `@scheduled_runtime` can be used in the query to get the value. */ invocationTime: string; /** * Various insights and metrics related to the run summary of the scheduled query. */ queryInsightsResponses?: outputs.timestreamquery.ScheduledQueryLastRunSummaryQueryInsightsResponse[]; /** * Status of a scheduled query run. Valid values: `AUTO_TRIGGER_SUCCESS`, `AUTO_TRIGGER_FAILURE`, `MANUAL_TRIGGER_SUCCESS`, `MANUAL_TRIGGER_FAILURE`. */ runStatus: string; /** * Actual time when the query was run. */ triggerTime: string; } interface ScheduledQueryLastRunSummaryErrorReportLocation { /** * S3 location where error reports are written. */ s3ReportLocations?: outputs.timestreamquery.ScheduledQueryLastRunSummaryErrorReportLocationS3ReportLocation[]; } interface ScheduledQueryLastRunSummaryErrorReportLocationS3ReportLocation { /** * S3 bucket name. */ bucketName: string; /** * S3 key. */ objectKey: string; } interface ScheduledQueryLastRunSummaryExecutionStat { /** * Bytes metered for a single scheduled query run. */ bytesMetered: number; /** * Bytes scanned for a single scheduled query run. */ cumulativeBytesScanned: number; /** * Data writes metered for records ingested in a single scheduled query run. */ dataWrites: number; /** * Total time, measured in milliseconds, that was needed for the scheduled query run to complete. */ executionTimeInMillis: number; /** * Number of rows present in the output from running a query before ingestion to destination data source. */ queryResultRows: number; /** * Number of records ingested for a single scheduled query run. */ recordsIngested: number; } interface ScheduledQueryLastRunSummaryQueryInsightsResponse { /** * Size of query result set in bytes. You can use this data to validate if the result set has changed as part of the query tuning exercise. */ outputBytes: number; /** * Total number of rows returned as part of the query result set. You can use this data to validate if the number of rows in the result set have changed as part of the query tuning exercise. */ outputRows: number; /** * Insights into the spatial coverage of the query, including the table with sub-optimal (max) spatial pruning. This information can help you identify areas for improvement in your partitioning strategy to enhance spatial pruning. */ querySpatialCoverages?: outputs.timestreamquery.ScheduledQueryLastRunSummaryQueryInsightsResponseQuerySpatialCoverage[]; /** * Number of tables in the query. */ queryTableCount: number; /** * Insights into the temporal range of the query, including the table with the largest (max) time range. Following are some of the potential options for optimizing time-based pruning: add missing time-predicates, remove functions around the time predicates, add time predicates to all the sub-queries. */ queryTemporalRanges?: outputs.timestreamquery.ScheduledQueryLastRunSummaryQueryInsightsResponseQueryTemporalRange[]; } interface ScheduledQueryLastRunSummaryQueryInsightsResponseQuerySpatialCoverage { /** * Insights into the most sub-optimal performing table on the temporal axis: */ maxes?: outputs.timestreamquery.ScheduledQueryLastRunSummaryQueryInsightsResponseQuerySpatialCoverageMaxis[]; } interface ScheduledQueryLastRunSummaryQueryInsightsResponseQuerySpatialCoverageMaxis { /** * Partition key used for partitioning, which can be a default measureName or a customer defined partition key. */ partitionKeys: string[]; /** * ARN of the table which is queried with the largest time range. */ tableArn: string; /** * Maximum duration in nanoseconds between the start and end of the query. */ value: number; } interface ScheduledQueryLastRunSummaryQueryInsightsResponseQueryTemporalRange { /** * Insights into the most sub-optimal performing table on the temporal axis: */ maxes?: outputs.timestreamquery.ScheduledQueryLastRunSummaryQueryInsightsResponseQueryTemporalRangeMaxis[]; } interface ScheduledQueryLastRunSummaryQueryInsightsResponseQueryTemporalRangeMaxis { /** * ARN of the table which is queried with the largest time range. */ tableArn: string; /** * Maximum duration in nanoseconds between the start and end of the query. */ value: number; } interface ScheduledQueryNotificationConfiguration { /** * Configuration block for details about the Amazon Simple Notification Service (SNS) configuration. See below. */ snsConfiguration: outputs.timestreamquery.ScheduledQueryNotificationConfigurationSnsConfiguration; } interface ScheduledQueryNotificationConfigurationSnsConfiguration { /** * SNS topic ARN that the scheduled query status notifications will be sent to. */ topicArn: string; } interface ScheduledQueryRecentlyFailedRun { /** * S3 location for error report. */ errorReportLocations?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunErrorReportLocation[]; /** * Statistics for a single scheduled query run. */ executionStats?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunExecutionStat[]; /** * Error message for the scheduled query in case of failure. You might have to look at the error report to get more detailed error reasons. */ failureReason: string; /** * InvocationTime for this run. This is the time at which the query is scheduled to run. Parameter `@scheduled_runtime` can be used in the query to get the value. */ invocationTime: string; /** * Various insights and metrics related to the run summary of the scheduled query. */ queryInsightsResponses?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunQueryInsightsResponse[]; /** * Status of a scheduled query run. Valid values: `AUTO_TRIGGER_SUCCESS`, `AUTO_TRIGGER_FAILURE`, `MANUAL_TRIGGER_SUCCESS`, `MANUAL_TRIGGER_FAILURE`. */ runStatus: string; /** * Actual time when the query was run. */ triggerTime: string; } interface ScheduledQueryRecentlyFailedRunErrorReportLocation { /** * S3 location where error reports are written. */ s3ReportLocations?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunErrorReportLocationS3ReportLocation[]; } interface ScheduledQueryRecentlyFailedRunErrorReportLocationS3ReportLocation { /** * S3 bucket name. */ bucketName: string; /** * S3 key. */ objectKey: string; } interface ScheduledQueryRecentlyFailedRunExecutionStat { /** * Bytes metered for a single scheduled query run. */ bytesMetered: number; /** * Bytes scanned for a single scheduled query run. */ cumulativeBytesScanned: number; /** * Data writes metered for records ingested in a single scheduled query run. */ dataWrites: number; /** * Total time, measured in milliseconds, that was needed for the scheduled query run to complete. */ executionTimeInMillis: number; /** * Number of rows present in the output from running a query before ingestion to destination data source. */ queryResultRows: number; /** * Number of records ingested for a single scheduled query run. */ recordsIngested: number; } interface ScheduledQueryRecentlyFailedRunQueryInsightsResponse { /** * Size of query result set in bytes. You can use this data to validate if the result set has changed as part of the query tuning exercise. */ outputBytes: number; /** * Total number of rows returned as part of the query result set. You can use this data to validate if the number of rows in the result set have changed as part of the query tuning exercise. */ outputRows: number; /** * Insights into the spatial coverage of the query, including the table with sub-optimal (max) spatial pruning. This information can help you identify areas for improvement in your partitioning strategy to enhance spatial pruning. */ querySpatialCoverages?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunQueryInsightsResponseQuerySpatialCoverage[]; /** * Number of tables in the query. */ queryTableCount: number; /** * Insights into the temporal range of the query, including the table with the largest (max) time range. Following are some of the potential options for optimizing time-based pruning: add missing time-predicates, remove functions around the time predicates, add time predicates to all the sub-queries. */ queryTemporalRanges?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunQueryInsightsResponseQueryTemporalRange[]; } interface ScheduledQueryRecentlyFailedRunQueryInsightsResponseQuerySpatialCoverage { /** * Insights into the most sub-optimal performing table on the temporal axis: */ maxes?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunQueryInsightsResponseQuerySpatialCoverageMaxis[]; } interface ScheduledQueryRecentlyFailedRunQueryInsightsResponseQuerySpatialCoverageMaxis { /** * Partition key used for partitioning, which can be a default measureName or a customer defined partition key. */ partitionKeys: string[]; /** * ARN of the table which is queried with the largest time range. */ tableArn: string; /** * Maximum duration in nanoseconds between the start and end of the query. */ value: number; } interface ScheduledQueryRecentlyFailedRunQueryInsightsResponseQueryTemporalRange { /** * Insights into the most sub-optimal performing table on the temporal axis: */ maxes?: outputs.timestreamquery.ScheduledQueryRecentlyFailedRunQueryInsightsResponseQueryTemporalRangeMaxis[]; } interface ScheduledQueryRecentlyFailedRunQueryInsightsResponseQueryTemporalRangeMaxis { /** * ARN of the table which is queried with the largest time range. */ tableArn: string; /** * Maximum duration in nanoseconds between the start and end of the query. */ value: number; } interface ScheduledQueryScheduleConfiguration { /** * When to trigger the scheduled query run. This can be a cron expression or a rate expression. */ scheduleExpression: string; } interface ScheduledQueryTargetConfiguration { /** * Configuration block for information needed to write data into the Timestream database and table. See below. */ timestreamConfiguration: outputs.timestreamquery.ScheduledQueryTargetConfigurationTimestreamConfiguration; } interface ScheduledQueryTargetConfigurationTimestreamConfiguration { /** * Name of Timestream database to which the query result will be written. */ databaseName: string; /** * Configuration block for mapping of column(s) from the query result to the dimension in the destination table. See below. */ dimensionMappings: outputs.timestreamquery.ScheduledQueryTargetConfigurationTimestreamConfigurationDimensionMapping[]; /** * Name of the measure column. */ measureNameColumn?: string; /** * Configuration block for how to map measures to multi-measure records. See below. */ mixedMeasureMappings?: outputs.timestreamquery.ScheduledQueryTargetConfigurationTimestreamConfigurationMixedMeasureMapping[]; /** * Configuration block for multi-measure mappings. Only one of `mixedMeasureMappings` or `multiMeasureMappings` can be provided. `multiMeasureMappings` can be used to ingest data as multi measures in the derived table. See below. */ multiMeasureMappings?: outputs.timestreamquery.ScheduledQueryTargetConfigurationTimestreamConfigurationMultiMeasureMappings; /** * Name of Timestream table that the query result will be written to. The table should be within the same database that is provided in Timestream configuration. */ tableName: string; /** * Column from query result that should be used as the time column in destination table. Column type for this should be TIMESTAMP. */ timeColumn: string; } interface ScheduledQueryTargetConfigurationTimestreamConfigurationDimensionMapping { /** * Type for the dimension. Valid value: `VARCHAR`. */ dimensionValueType: string; /** * Column name from query result. */ name: string; } interface ScheduledQueryTargetConfigurationTimestreamConfigurationMixedMeasureMapping { /** * Refers to the value of measureName in a result row. This field is required if `measureNameColumn` is provided. */ measureName?: string; /** * Type of the value that is to be read from `sourceColumn`. Valid values are `BIGINT`, `BOOLEAN`, `DOUBLE`, `VARCHAR`, `MULTI`. */ measureValueType: string; /** * Configuration block for attribute mappings for `MULTI` value measures. Required when `measureValueType` is `MULTI`. See below. */ multiMeasureAttributeMappings?: outputs.timestreamquery.ScheduledQueryTargetConfigurationTimestreamConfigurationMixedMeasureMappingMultiMeasureAttributeMapping[]; /** * Source column from which measure-value is to be read for result materialization. */ sourceColumn?: string; /** * Target measure name to be used. If not provided, the target measure name by default is `measureName`, if provided, or `sourceColumn` otherwise. */ targetMeasureName?: string; } interface ScheduledQueryTargetConfigurationTimestreamConfigurationMixedMeasureMappingMultiMeasureAttributeMapping { /** * Type of the attribute to be read from the source column. Valid values are `BIGINT`, `BOOLEAN`, `DOUBLE`, `VARCHAR`, `TIMESTAMP`. */ measureValueType: string; /** * Source column from where the attribute value is to be read. */ sourceColumn: string; /** * Custom name to be used for attribute name in derived table. If not provided, `sourceColumn` is used. */ targetMultiMeasureAttributeName?: string; } interface ScheduledQueryTargetConfigurationTimestreamConfigurationMultiMeasureMappings { /** * Attribute mappings to be used for mapping query results to ingest data for multi-measure attributes. See above. */ multiMeasureAttributeMappings: outputs.timestreamquery.ScheduledQueryTargetConfigurationTimestreamConfigurationMultiMeasureMappingsMultiMeasureAttributeMapping[]; /** * Name of the target multi-measure name in the derived table. This input is required when `measureNameColumn` is not provided. If `measureNameColumn` is provided, then the value from that column will be used as the multi-measure name. */ targetMultiMeasureName?: string; } interface ScheduledQueryTargetConfigurationTimestreamConfigurationMultiMeasureMappingsMultiMeasureAttributeMapping { /** * Type of the attribute to be read from the source column. Valid values are `BIGINT`, `BOOLEAN`, `DOUBLE`, `VARCHAR`, `TIMESTAMP`. */ measureValueType: string; /** * Source column from where the attribute value is to be read. */ sourceColumn: string; /** * Custom name to be used for attribute name in derived table. If not provided, `sourceColumn` is used. */ targetMultiMeasureAttributeName?: string; } interface ScheduledQueryTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } export declare namespace timestreamwrite { interface GetTableMagneticStoreWriteProperty { /** * Flag that is set based on if magnetic store writes are enabled. */ enableMagneticStoreWrites: boolean; /** * Object containing the following attributes to describe error reports for records rejected during magnetic store writes. */ magneticStoreRejectedDataLocations: outputs.timestreamwrite.GetTableMagneticStoreWritePropertyMagneticStoreRejectedDataLocation[]; } interface GetTableMagneticStoreWritePropertyMagneticStoreRejectedDataLocation { /** * Object containing the following attributes to describe the configuration of an s3 location to write error reports for records rejected. */ s3Configurations: outputs.timestreamwrite.GetTableMagneticStoreWritePropertyMagneticStoreRejectedDataLocationS3Configuration[]; } interface GetTableMagneticStoreWritePropertyMagneticStoreRejectedDataLocationS3Configuration { /** * Name of S3 bucket. */ bucketName: string; encryptionOption: string; /** * AWS KMS key ID for S3 location with AWS maanged key. */ kmsKeyId: string; /** * Object key preview for S3 location. */ objectKeyPrefix: string; } interface GetTableRetentionProperty { /** * Duration in days in which the data must be stored in magnetic store. */ magneticStoreRetentionPeriodInDays: number; /** * Duration in hours in which the data must be stored in memory store. */ memoryStoreRetentionPeriodInHours: number; } interface GetTableSchema { compositePartitionKeys: outputs.timestreamwrite.GetTableSchemaCompositePartitionKey[]; } interface GetTableSchemaCompositePartitionKey { enforcementInRecord: string; /** * Name of the Timestream table. */ name: string; /** * Type of partition key. */ type: string; } interface TableMagneticStoreWriteProperties { /** * A flag to enable magnetic store writes. */ enableMagneticStoreWrites?: boolean; /** * The location to write error reports for records rejected asynchronously during magnetic store writes. See Magnetic Store Rejected Data Location below for more details. */ magneticStoreRejectedDataLocation?: outputs.timestreamwrite.TableMagneticStoreWritePropertiesMagneticStoreRejectedDataLocation; } interface TableMagneticStoreWritePropertiesMagneticStoreRejectedDataLocation { /** * Configuration of an S3 location to write error reports for records rejected, asynchronously, during magnetic store writes. See S3 Configuration below for more details. */ s3Configuration?: outputs.timestreamwrite.TableMagneticStoreWritePropertiesMagneticStoreRejectedDataLocationS3Configuration; } interface TableMagneticStoreWritePropertiesMagneticStoreRejectedDataLocationS3Configuration { /** * Bucket name of the customer S3 bucket. */ bucketName?: string; /** * Encryption option for the customer s3 location. Options are S3 server side encryption with an S3-managed key or KMS managed key. Valid values are `SSE_KMS` and `SSE_S3`. */ encryptionOption?: string; /** * KMS key arn for the customer s3 location when encrypting with a KMS managed key. */ kmsKeyId?: string; /** * Object key prefix for the customer S3 location. */ objectKeyPrefix?: string; } interface TableRetentionProperties { /** * The duration for which data must be stored in the magnetic store. Minimum value of 1. Maximum value of 73000. */ magneticStoreRetentionPeriodInDays: number; /** * The duration for which data must be stored in the memory store. Minimum value of 1. Maximum value of 8766. */ memoryStoreRetentionPeriodInHours: number; } interface TableSchema { /** * A non-empty list of partition keys defining the attributes used to partition the table data. The order of the list determines the partition hierarchy. The name and type of each partition key as well as the partition key order cannot be changed after the table is created. However, the enforcement level of each partition key can be changed. See Composite Partition Key below for more details. */ compositePartitionKey: outputs.timestreamwrite.TableSchemaCompositePartitionKey; } interface TableSchemaCompositePartitionKey { /** * The level of enforcement for the specification of a dimension key in ingested records. Valid values: `REQUIRED`, `OPTIONAL`. */ enforcementInRecord?: string; /** * The name of the attribute used for a dimension key. */ name?: string; /** * The type of the partition key. Valid values: `DIMENSION`, `MEASURE`. */ type: string; } } export declare namespace transcribe { interface LanguageModelInputDataConfig { /** * IAM role with access to S3 bucket. */ dataAccessRoleArn: string; /** * S3 URI where training data is located. */ s3Uri: string; /** * S3 URI where tuning data is located. */ tuningDataS3Uri: string; } } export declare namespace transfer { interface AccessHomeDirectoryMapping { /** * Logical directory entry that appears to your user. */ entry: string; /** * Map target that maps the entry to an actual S3 path. */ target: string; } interface AccessPosixProfile { /** * POSIX group ID used for all EFS operations by this user. */ gid: number; /** * Secondary POSIX group IDs used for all EFS operations by this user. */ secondaryGids?: number[]; /** * POSIX user ID used for all EFS operations by this user. */ uid: number; } interface ConnectorAs2Config { /** * Whether AS2 file is compressed. The valid values are ZLIB and DISABLED. */ compression: string; /** * Algorithm that is used to encrypt the file. The valid values are AES128_CBC | AES192_CBC | AES256_CBC | NONE. */ encryptionAlgorithm: string; /** * Unique identifier for the AS2 local profile. */ localProfileId: string; /** * Determines, for outbound requests, if a partner response for transfers is synchronous or asynchronous. The valid values are SYNC and NONE. */ mdnResponse: string; /** * Signing algorithm for the MDN response. The valid values are SHA256 | SHA384 | SHA512 | SHA1 | NONE | DEFAULT. */ mdnSigningAlgorithm?: string; /** * Subject HTTP header attribute used in AS2 messages that are being sent with the connector. */ messageSubject?: string; /** * Unique identifier for the AS2 partner profile. */ partnerProfileId: string; /** * Algorithm that is used to sign AS2 messages sent with the connector. The valid values are SHA256 | SHA384 | SHA512 | SHA1 | NONE . */ signingAlgorithm: string; } interface ConnectorEgressConfig { /** * VPC Lattice configuration for routing connector traffic through customer VPCs. See `vpcLattice` Block below. */ vpcLattice?: outputs.transfer.ConnectorEgressConfigVpcLattice; } interface ConnectorEgressConfigVpcLattice { /** * Port number for connecting to the SFTP server through VPC Lattice. Defaults to 22 if not specified. Must match the port on which the target SFTP server is listening. Valid values are between 1 and 65535. */ portNumber?: number; /** * ARN of the VPC Lattice Resource Configuration that defines the target SFTP server location. Must point to a valid Resource Configuration in a VPC with appropriate network connectivity to the SFTP server. */ resourceConfigurationArn: string; } interface ConnectorSftpConfig { /** * List of public portion of the host key, or keys, that are used to authenticate the user to the external server to which you are connecting.(https://docs.aws.amazon.com/transfer/latest/userguide/API_SftpConnectorConfig.html) */ trustedHostKeys?: string[]; /** * Identifier for the secret (in AWS Secrets Manager) that contains the SFTP user's private key, password, or both. The identifier can be either the ARN or the name of the secret. */ userSecretId?: string; } interface GetConnectorAs2Config { /** * Basic authentication for AS2 connector API. Returns a null value if not set. */ basicAuthSecretId: string; /** * Whether AS2 file is compressed. Will be ZLIB or DISABLED */ compression: string; /** * Algorithm used to encrypt file. Will be AES128_CBC or AES192_CBC or AES256_CBC or DES_EDE3_CBC or NONE. */ encryptionAlgorithm: string; /** * Unique identifier for AS2 local profile. */ localProfileId: string; /** * Whether outbound requests use an asynchronous response. Will be either SYNC or NONE. */ mdnResponse: string; /** * Signing algorithm for MDN response. Will be SHA256 or SHA384 or SHA512 or SHA1 or NONE or DEFAULT. */ mdnSigningAlgorithm: string; /** * Subject HTTP header attribute in outbound AS2 messages to the connector. */ messageSubject: string; /** * Unique identifier used by connector for partner profile. */ partnerProfileId: string; /** * Algorithm used for signing AS2 messages sent with the connector. */ singingAlgorithm: string; } interface GetConnectorEgressConfig { /** * VPC Lattice configuration. Contains the following attributes: */ vpcLattices: outputs.transfer.GetConnectorEgressConfigVpcLattice[]; } interface GetConnectorEgressConfigVpcLattice { /** * Port number for connecting to the SFTP server through VPC Lattice. */ portNumber: number; /** * ARN of the VPC Lattice Resource Configuration. */ resourceConfigurationArn: string; } interface GetConnectorSftpConfig { /** * List of the public portions of the host keys that are used to identify the servers the connector is connected to. */ trustedHostKeys: string[]; /** * Identifier for the secret in AWS Secrets Manager that contains the SFTP user's private key, and/or password. */ userSecretId: string; } interface ServerEndpointDetails { /** * List of address allocation IDs that are required to attach an Elastic IP address to your SFTP server's endpoint. This property can only be used when `endpointType` is set to `VPC`. */ addressAllocationIds?: string[]; /** * List of security groups IDs that are available to attach to your server's endpoint. If no security groups are specified, the VPC's default security groups are automatically assigned to your endpoint. This property can only be used when `endpointType` is set to `VPC`. */ securityGroupIds: string[]; /** * List of subnet IDs that are required to host your SFTP server endpoint in your VPC. This property can only be used when `endpointType` is set to `VPC`. */ subnetIds?: string[]; /** * ID of the VPC endpoint. This property can only be used when `endpointType` is set to `VPC_ENDPOINT` */ vpcEndpointId: string; /** * VPC ID of the VPC in which the SFTP server's endpoint will be hosted. This property can only be used when `endpointType` is set to `VPC`. */ vpcId?: string; } interface ServerProtocolDetails { /** * Transport method for the AS2 messages. Currently, only `HTTP` is supported. */ as2Transports: string[]; /** * Passive mode, for FTP and FTPS protocols. Enter a single IPv4 address, such as the public IP address of a firewall, router, or load balancer. */ passiveIp: string; /** * Use to ignore the error that is generated when the client attempts to use `SETSTAT` on a file you are uploading to an S3 bucket. Valid values: `DEFAULT`, `ENABLE_NO_OP`. */ setStatOption: string; /** * Property used with Transfer Family servers that use the FTPS protocol. Provides a mechanism to resume or share a negotiated secret key between the control and data connection for an FTPS session. Valid values: `DISABLED`, `ENABLED`, `ENFORCED`. */ tlsSessionResumptionMode: string; } interface ServerS3StorageOptions { /** * Whether performance for your Amazon S3 directories is optimized. Valid values are `DISABLED`, `ENABLED`. * * By default, home directory mappings have a `TYPE` of `DIRECTORY`. If you enable this option, you would then need to explicitly set the `HomeDirectoryMapEntry` Type to `FILE` if you want a mapping to have a file target. See [Using logical directories to simplify your Transfer Family directory structures](https://docs.aws.amazon.com/transfer/latest/userguide/logical-dir-mappings.html) for details. */ directoryListingOptimization: string; } interface ServerWorkflowDetails { /** * Trigger that starts a workflow if a file is only partially uploaded. See `onPartialUpload` Block below for details. */ onPartialUpload?: outputs.transfer.ServerWorkflowDetailsOnPartialUpload; /** * Trigger that starts a workflow: the workflow begins to execute after a file is uploaded. See `onUpload` Block below for details. */ onUpload?: outputs.transfer.ServerWorkflowDetailsOnUpload; } interface ServerWorkflowDetailsOnPartialUpload { /** * Includes the necessary permissions for S3, EFS, and Lambda operations that Transfer can assume, so that all workflow steps can operate on the required resources. */ executionRole: string; /** * Unique identifier for the workflow. */ workflowId: string; } interface ServerWorkflowDetailsOnUpload { /** * Includes the necessary permissions for S3, EFS, and Lambda operations that Transfer can assume, so that all workflow steps can operate on the required resources. */ executionRole: string; /** * Unique identifier for the workflow. */ workflowId: string; } interface UserHomeDirectoryMapping { /** * Logical directory entry that appears to your user. */ entry: string; /** * Map target that maps the entry to an actual S3 path. */ target: string; } interface UserPosixProfile { /** * POSIX group ID used for all EFS operations by this user. */ gid: number; /** * Secondary POSIX group IDs used for all EFS operations by this user. */ secondaryGids?: number[]; /** * POSIX user ID used for all EFS operations by this user. */ uid: number; } interface WebAppEndpointDetails { /** * Block defining VPC configuration for hosting the web app endpoint within a VPC. See `vpc` Block below. */ vpc?: outputs.transfer.WebAppEndpointDetailsVpc; } interface WebAppEndpointDetailsVpc { /** * List of security group IDs that control access to the web app endpoint. If not specified, the VPC's default security group is used. */ securityGroupIds: string[]; /** * List of subnet IDs within the VPC where the web app endpoint will be deployed. These subnets must be in the same VPC specified in the `vpcId` parameter. */ subnetIds: string[]; /** * ID of the VPC endpoint created for the web app. */ vpcEndpointId: string; /** * ID of the VPC where the web app endpoint will be hosted. The VPC must be dual-stack, meaning it supports both IPv4 and IPv6 addressing. */ vpcId: string; } interface WebAppIdentityProviderDetails { /** * Block that describes the values to use for the IAM Identity Center settings. See `identityCenterConfig` Block below. */ identityCenterConfig?: outputs.transfer.WebAppIdentityProviderDetailsIdentityCenterConfig; } interface WebAppIdentityProviderDetailsIdentityCenterConfig { /** * ARN of the IAM Identity Center application created for the web app. */ applicationArn: string; /** * ARN of the IAM Identity Center used for the web app. */ instanceArn?: string; /** * ARN of an identity bearer role for your web app. */ role?: string; } interface WebAppWebAppUnit { /** * Number of units of concurrent connections. */ provisioned: number; } interface WorkflowOnExceptionStep { /** * Details for a step that performs a file copy. See `copyStepDetails` Block below. */ copyStepDetails?: outputs.transfer.WorkflowOnExceptionStepCopyStepDetails; /** * Details for a step that invokes a lambda function. See `customStepDetails` Block below. */ customStepDetails?: outputs.transfer.WorkflowOnExceptionStepCustomStepDetails; /** * Details for a step that decrypts the file. See `decryptStepDetails` Block below. */ decryptStepDetails?: outputs.transfer.WorkflowOnExceptionStepDecryptStepDetails; /** * Details for a step that deletes the file. See `deleteStepDetails` Block below. */ deleteStepDetails?: outputs.transfer.WorkflowOnExceptionStepDeleteStepDetails; /** * Details for a step that creates one or more tags. See `tagStepDetails` Block below. */ tagStepDetails?: outputs.transfer.WorkflowOnExceptionStepTagStepDetails; /** * Step type. Valid values are `COPY`, `CUSTOM`, `DECRYPT`, `DELETE`, and `TAG`. */ type: string; } interface WorkflowOnExceptionStepCopyStepDetails { /** * Location for the file being copied. Use `${Transfer:username}` in this field to parametrize the destination prefix by username. See `destinationFileLocation` Block below. */ destinationFileLocation?: outputs.transfer.WorkflowOnExceptionStepCopyStepDetailsDestinationFileLocation; /** * Name of the step, used as an identifier. */ name?: string; /** * Flag that indicates whether or not to overwrite an existing file of the same name. The default is `FALSE`. Valid values are `TRUE` and `FALSE`. */ overwriteExisting?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; } interface WorkflowOnExceptionStepCopyStepDetailsDestinationFileLocation { /** * Details for the EFS file being copied. See `efsFileLocation` Block below. */ efsFileLocation?: outputs.transfer.WorkflowOnExceptionStepCopyStepDetailsDestinationFileLocationEfsFileLocation; /** * Details for the S3 file being copied. See `s3FileLocation` Block below. */ s3FileLocation?: outputs.transfer.WorkflowOnExceptionStepCopyStepDetailsDestinationFileLocationS3FileLocation; } interface WorkflowOnExceptionStepCopyStepDetailsDestinationFileLocationEfsFileLocation { /** * ID of the file system, assigned by Amazon EFS. */ fileSystemId?: string; /** * Pathname for the folder being used by a workflow. */ path?: string; } interface WorkflowOnExceptionStepCopyStepDetailsDestinationFileLocationS3FileLocation { /** * S3 bucket for the customer input file. */ bucket?: string; /** * Name assigned to the file when it was created in S3. You use the object key to retrieve the object. */ key?: string; } interface WorkflowOnExceptionStepCustomStepDetails { /** * Name of the step, used as an identifier. */ name?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; /** * ARN for the lambda function that is being called. */ target?: string; /** * Timeout, in seconds, for the step. */ timeoutSeconds?: number; } interface WorkflowOnExceptionStepDecryptStepDetails { /** * Location for the file being copied. Use `${Transfer:username}` in this field to parametrize the destination prefix by username. See `destinationFileLocation` Block below. */ destinationFileLocation?: outputs.transfer.WorkflowOnExceptionStepDecryptStepDetailsDestinationFileLocation; /** * Name of the step, used as an identifier. */ name?: string; /** * Flag that indicates whether or not to overwrite an existing file of the same name. The default is `FALSE`. Valid values are `TRUE` and `FALSE`. */ overwriteExisting?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; /** * Type of encryption used. Currently, this value must be `"PGP"`. */ type: string; } interface WorkflowOnExceptionStepDecryptStepDetailsDestinationFileLocation { /** * Details for the EFS file being copied. See `efsFileLocation` Block below. */ efsFileLocation?: outputs.transfer.WorkflowOnExceptionStepDecryptStepDetailsDestinationFileLocationEfsFileLocation; /** * Details for the S3 file being copied. See `s3FileLocation` Block below. */ s3FileLocation?: outputs.transfer.WorkflowOnExceptionStepDecryptStepDetailsDestinationFileLocationS3FileLocation; } interface WorkflowOnExceptionStepDecryptStepDetailsDestinationFileLocationEfsFileLocation { /** * ID of the file system, assigned by Amazon EFS. */ fileSystemId?: string; /** * Pathname for the folder being used by a workflow. */ path?: string; } interface WorkflowOnExceptionStepDecryptStepDetailsDestinationFileLocationS3FileLocation { /** * S3 bucket for the customer input file. */ bucket?: string; /** * Name assigned to the file when it was created in S3. You use the object key to retrieve the object. */ key?: string; } interface WorkflowOnExceptionStepDeleteStepDetails { /** * Name of the step, used as an identifier. */ name?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; } interface WorkflowOnExceptionStepTagStepDetails { /** * Name of the step, used as an identifier. */ name?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; /** * Array that contains from 1 to 10 key/value pairs. See `tags` Block below. */ tags?: outputs.transfer.WorkflowOnExceptionStepTagStepDetailsTag[]; } interface WorkflowOnExceptionStepTagStepDetailsTag { /** * Name assigned to the tag that you create. */ key: string; /** * Value that corresponds to the key. */ value: string; } interface WorkflowStep { /** * Details for a step that performs a file copy. See `copyStepDetails` Block below. */ copyStepDetails?: outputs.transfer.WorkflowStepCopyStepDetails; /** * Details for a step that invokes a lambda function. See `customStepDetails` Block below. */ customStepDetails?: outputs.transfer.WorkflowStepCustomStepDetails; /** * Details for a step that decrypts the file. See `decryptStepDetails` Block below. */ decryptStepDetails?: outputs.transfer.WorkflowStepDecryptStepDetails; /** * Details for a step that deletes the file. See `deleteStepDetails` Block below. */ deleteStepDetails?: outputs.transfer.WorkflowStepDeleteStepDetails; /** * Details for a step that creates one or more tags. See `tagStepDetails` Block below. */ tagStepDetails?: outputs.transfer.WorkflowStepTagStepDetails; /** * Step type. Valid values are `COPY`, `CUSTOM`, `DECRYPT`, `DELETE`, and `TAG`. */ type: string; } interface WorkflowStepCopyStepDetails { /** * Location for the file being copied. Use `${Transfer:username}` in this field to parametrize the destination prefix by username. See `destinationFileLocation` Block below. */ destinationFileLocation?: outputs.transfer.WorkflowStepCopyStepDetailsDestinationFileLocation; /** * Name of the step, used as an identifier. */ name?: string; /** * Flag that indicates whether or not to overwrite an existing file of the same name. The default is `FALSE`. Valid values are `TRUE` and `FALSE`. */ overwriteExisting?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; } interface WorkflowStepCopyStepDetailsDestinationFileLocation { /** * Details for the EFS file being copied. See `efsFileLocation` Block below. */ efsFileLocation?: outputs.transfer.WorkflowStepCopyStepDetailsDestinationFileLocationEfsFileLocation; /** * Details for the S3 file being copied. See `s3FileLocation` Block below. */ s3FileLocation?: outputs.transfer.WorkflowStepCopyStepDetailsDestinationFileLocationS3FileLocation; } interface WorkflowStepCopyStepDetailsDestinationFileLocationEfsFileLocation { /** * ID of the file system, assigned by Amazon EFS. */ fileSystemId?: string; /** * Pathname for the folder being used by a workflow. */ path?: string; } interface WorkflowStepCopyStepDetailsDestinationFileLocationS3FileLocation { /** * S3 bucket for the customer input file. */ bucket?: string; /** * Name assigned to the file when it was created in S3. You use the object key to retrieve the object. */ key?: string; } interface WorkflowStepCustomStepDetails { /** * Name of the step, used as an identifier. */ name?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; /** * ARN for the lambda function that is being called. */ target?: string; /** * Timeout, in seconds, for the step. */ timeoutSeconds?: number; } interface WorkflowStepDecryptStepDetails { /** * Location for the file being copied. Use `${Transfer:username}` in this field to parametrize the destination prefix by username. See `destinationFileLocation` Block below. */ destinationFileLocation?: outputs.transfer.WorkflowStepDecryptStepDetailsDestinationFileLocation; /** * Name of the step, used as an identifier. */ name?: string; /** * Flag that indicates whether or not to overwrite an existing file of the same name. The default is `FALSE`. Valid values are `TRUE` and `FALSE`. */ overwriteExisting?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; /** * Type of encryption used. Currently, this value must be `"PGP"`. */ type: string; } interface WorkflowStepDecryptStepDetailsDestinationFileLocation { /** * Details for the EFS file being copied. See `efsFileLocation` Block below. */ efsFileLocation?: outputs.transfer.WorkflowStepDecryptStepDetailsDestinationFileLocationEfsFileLocation; /** * Details for the S3 file being copied. See `s3FileLocation` Block below. */ s3FileLocation?: outputs.transfer.WorkflowStepDecryptStepDetailsDestinationFileLocationS3FileLocation; } interface WorkflowStepDecryptStepDetailsDestinationFileLocationEfsFileLocation { /** * ID of the file system, assigned by Amazon EFS. */ fileSystemId?: string; /** * Pathname for the folder being used by a workflow. */ path?: string; } interface WorkflowStepDecryptStepDetailsDestinationFileLocationS3FileLocation { /** * S3 bucket for the customer input file. */ bucket?: string; /** * Name assigned to the file when it was created in S3. You use the object key to retrieve the object. */ key?: string; } interface WorkflowStepDeleteStepDetails { /** * Name of the step, used as an identifier. */ name?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; } interface WorkflowStepTagStepDetails { /** * Name of the step, used as an identifier. */ name?: string; /** * File to use as input to the workflow step: either the output from the previous step, or the originally uploaded file for the workflow. Enter `${previous.file}` to use the previous file as the input. In this case, this workflow step uses the output file from the previous workflow step as input. This is the default value. Enter `${original.file}` to use the originally-uploaded file location as input for this step. */ sourceFileLocation?: string; /** * Array that contains from 1 to 10 key/value pairs. See `tags` Block below. */ tags?: outputs.transfer.WorkflowStepTagStepDetailsTag[]; } interface WorkflowStepTagStepDetailsTag { /** * Name assigned to the tag that you create. */ key: string; /** * Value that corresponds to the key. */ value: string; } } export declare namespace verifiedaccess { interface EndpointCidrOptions { cidr: string; portRanges: outputs.verifiedaccess.EndpointCidrOptionsPortRange[]; protocol?: string; subnetIds?: string[]; } interface EndpointCidrOptionsPortRange { fromPort: number; toPort: number; } interface EndpointLoadBalancerOptions { loadBalancerArn?: string; port?: number; portRanges?: outputs.verifiedaccess.EndpointLoadBalancerOptionsPortRange[]; protocol?: string; subnetIds?: string[]; } interface EndpointLoadBalancerOptionsPortRange { fromPort: number; toPort: number; } interface EndpointNetworkInterfaceOptions { networkInterfaceId?: string; port?: number; portRanges?: outputs.verifiedaccess.EndpointNetworkInterfaceOptionsPortRange[]; protocol?: string; } interface EndpointNetworkInterfaceOptionsPortRange { fromPort: number; toPort: number; } interface EndpointRdsOptions { port?: number; protocol?: string; rdsDbClusterArn?: string; rdsDbInstanceArn?: string; rdsDbProxyArn?: string; rdsEndpoint?: string; subnetIds?: string[]; } interface EndpointSseSpecification { customerManagedKeyEnabled?: boolean; kmsKeyArn?: string; } interface GroupSseConfiguration { /** * Boolean flag to indicate that the CMK should be used. */ customerManagedKeyEnabled?: boolean; /** * ARN of the KMS key to use. */ kmsKeyArn?: string; } interface InstanceLoggingConfigurationAccessLogs { /** * A block that specifies configures sending Verified Access logs to CloudWatch Logs. Detailed below. */ cloudwatchLogs?: outputs.verifiedaccess.InstanceLoggingConfigurationAccessLogsCloudwatchLogs; /** * Include trust data sent by trust providers into the logs. */ includeTrustContext: boolean; /** * A block that specifies configures sending Verified Access logs to Kinesis. Detailed below. */ kinesisDataFirehose?: outputs.verifiedaccess.InstanceLoggingConfigurationAccessLogsKinesisDataFirehose; /** * The logging version to use. Refer to [VerifiedAccessLogOptions](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_VerifiedAccessLogOptions.html) for the allowed values. */ logVersion: string; /** * A block that specifies configures sending Verified Access logs to S3. Detailed below. */ s3?: outputs.verifiedaccess.InstanceLoggingConfigurationAccessLogsS3; } interface InstanceLoggingConfigurationAccessLogsCloudwatchLogs { /** * Indicates whether logging is enabled. */ enabled: boolean; /** * The name of the CloudWatch Logs Log Group. */ logGroup?: string; } interface InstanceLoggingConfigurationAccessLogsKinesisDataFirehose { /** * The name of the delivery stream. */ deliveryStream?: string; /** * Indicates whether logging is enabled. */ enabled: boolean; } interface InstanceLoggingConfigurationAccessLogsS3 { /** * The name of S3 bucket. */ bucketName?: string; /** * The ID of the AWS account that owns the Amazon S3 bucket. */ bucketOwner: string; /** * Indicates whether logging is enabled. */ enabled: boolean; /** * The bucket prefix. */ prefix?: string; } interface InstanceVerifiedAccessTrustProvider { /** * A description for the AWS Verified Access Instance. */ description: string; /** * The type of device-based trust provider. */ deviceTrustProviderType: string; /** * The type of trust provider (user- or device-based). */ trustProviderType: string; /** * The type of user-based trust provider. */ userTrustProviderType: string; /** * The ID of the trust provider. */ verifiedAccessTrustProviderId: string; } interface TrustProviderDeviceOptions { tenantId?: string; } interface TrustProviderNativeApplicationOidcOptions { authorizationEndpoint?: string; clientId?: string; clientSecret: string; issuer?: string; publicSigningKeyEndpoint?: string; scope?: string; tokenEndpoint?: string; userInfoEndpoint?: string; } interface TrustProviderOidcOptions { authorizationEndpoint?: string; clientId?: string; clientSecret: string; issuer?: string; scope?: string; tokenEndpoint?: string; userInfoEndpoint?: string; } interface TrustProviderSseSpecification { customerManagedKeyEnabled?: boolean; kmsKeyArn?: string; } } export declare namespace verifiedpermissions { interface GetPolicyStoreValidationSetting { mode: string; } interface IdentitySourceConfiguration { /** * Specifies the configuration details of an Amazon Cognito user pool that Verified Permissions can use as a source of authenticated identities as entities. See Cognito User Pool Configuration below. */ cognitoUserPoolConfiguration?: outputs.verifiedpermissions.IdentitySourceConfigurationCognitoUserPoolConfiguration; /** * Specifies the configuration details of an OpenID Connect (OIDC) identity provider, or identity source, that Verified Permissions can use to generate entities from authenticated identities. See Open ID Connect Configuration below. */ openIdConnectConfiguration?: outputs.verifiedpermissions.IdentitySourceConfigurationOpenIdConnectConfiguration; } interface IdentitySourceConfigurationCognitoUserPoolConfiguration { /** * The unique application client IDs that are associated with the specified Amazon Cognito user pool. */ clientIds: string[]; /** * The type of entity that a policy store maps to groups from an Amazon Cognito user pool identity source. See Group Configuration below. */ groupConfiguration?: outputs.verifiedpermissions.IdentitySourceConfigurationCognitoUserPoolConfigurationGroupConfiguration; /** * ARN of the Amazon Cognito user pool that contains the identities to be authorized. */ userPoolArn: string; } interface IdentitySourceConfigurationCognitoUserPoolConfigurationGroupConfiguration { /** * The name of the schema entity type that's mapped to the user pool group. Defaults to `AWS::CognitoGroup`. */ groupEntityType: string; } interface IdentitySourceConfigurationOpenIdConnectConfiguration { /** * A descriptive string that you want to prefix to user entities from your OIDC identity provider. */ entityIdPrefix?: string; /** * The type of entity that a policy store maps to groups from an Amazon Cognito user pool identity source. See Group Configuration below. */ groupConfiguration?: outputs.verifiedpermissions.IdentitySourceConfigurationOpenIdConnectConfigurationGroupConfiguration; /** * The issuer URL of an OIDC identity provider. This URL must have an OIDC discovery endpoint at the path `.well-known/openid-configuration`. */ issuer: string; /** * The token type that you want to process from your OIDC identity provider. Your policy store can process either identity (ID) or access tokens from a given OIDC identity source. See Token Selection below. */ tokenSelection: outputs.verifiedpermissions.IdentitySourceConfigurationOpenIdConnectConfigurationTokenSelection; } interface IdentitySourceConfigurationOpenIdConnectConfigurationGroupConfiguration { /** * The token claim that you want Verified Permissions to interpret as group membership. For example, `groups`. */ groupClaim: string; /** * The name of the schema entity type that's mapped to the user pool group. Defaults to `AWS::CognitoGroup`. */ groupEntityType: string; } interface IdentitySourceConfigurationOpenIdConnectConfigurationTokenSelection { /** * The OIDC configuration for processing access tokens. See Access Token Only below. */ accessTokenOnly?: outputs.verifiedpermissions.IdentitySourceConfigurationOpenIdConnectConfigurationTokenSelectionAccessTokenOnly; /** * The OIDC configuration for processing identity (ID) tokens. See Identity Token Only below. */ identityTokenOnly?: outputs.verifiedpermissions.IdentitySourceConfigurationOpenIdConnectConfigurationTokenSelectionIdentityTokenOnly; } interface IdentitySourceConfigurationOpenIdConnectConfigurationTokenSelectionAccessTokenOnly { /** * The access token aud claim values that you want to accept in your policy store. */ audiences?: string[]; /** * The claim that determines the principal in OIDC access tokens. */ principalIdClaim?: string; } interface IdentitySourceConfigurationOpenIdConnectConfigurationTokenSelectionIdentityTokenOnly { /** * The ID token audience, or client ID, claim values that you want to accept in your policy store from an OIDC identity provider. */ clientIds?: string[]; /** * The claim that determines the principal in OIDC identity tokens. */ principalIdClaim?: string; } interface PolicyDefinition { /** * The static policy statement. See Static below. */ static?: outputs.verifiedpermissions.PolicyDefinitionStatic; /** * The template linked policy. See Template Linked below. */ templateLinked?: outputs.verifiedpermissions.PolicyDefinitionTemplateLinked; } interface PolicyDefinitionStatic { /** * The description of the static policy. */ description?: string; /** * The statement of the static policy. */ statement: string; } interface PolicyDefinitionTemplateLinked { /** * The ID of the template. */ policyTemplateId: string; /** * The principal of the template linked policy. */ principal?: outputs.verifiedpermissions.PolicyDefinitionTemplateLinkedPrincipal; /** * The resource of the template linked policy. */ resource?: outputs.verifiedpermissions.PolicyDefinitionTemplateLinkedResource; } interface PolicyDefinitionTemplateLinkedPrincipal { /** * The entity ID of the principal. */ entityId: string; /** * The entity type of the principal. */ entityType: string; } interface PolicyDefinitionTemplateLinkedResource { /** * The entity ID of the resource. */ entityId: string; /** * The entity type of the resource. */ entityType: string; } interface PolicyStoreValidationSettings { /** * The mode for the validation settings. Valid values: `OFF`, `STRICT`. * * The following arguments are optional: */ mode: string; } interface SchemaDefinition { /** * A JSON string representation of the schema. */ value: string; } } export declare namespace vpc { interface EndpointServicePrivateDnsVerificationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; } interface GetEndpointAssociationsAssociation { /** * Accessibility of the resource. */ associatedResourceAccessibility: string; /** * ARN of the resource for this association. */ associatedResourceArn: string; /** * DNS entries for the Association. DNS entry blocks are documented below. */ dnsEntries: outputs.vpc.GetEndpointAssociationsAssociationDnsEntry[]; id: string; /** * DNS entries for the Association. Private DNS entry blocks are documented below. */ privateDnsEntries: outputs.vpc.GetEndpointAssociationsAssociationPrivateDnsEntry[]; /** * ARN of the Resource Group if the Resource is a member of a group. */ resourceConfigurationGroupArn: string; /** * Service Network ARN. Applicable for endpoints of type `ServiceNetwork`. */ serviceNetworkArn: string; /** * Service Network Name. Applicable for endpoints of type `ServiceNetwork`. */ serviceNetworkName: string; /** * Tags of the association. */ tags: { [key: string]: string; }; } interface GetEndpointAssociationsAssociationDnsEntry { /** * DNS name. */ dnsName: string; /** * ID of the private hosted zone. */ hostedZoneId: string; } interface GetEndpointAssociationsAssociationPrivateDnsEntry { /** * DNS name. */ dnsName: string; /** * ID of the private hosted zone. */ hostedZoneId: string; } interface GetSecurityGroupRuleFilter { /** * Name of the filter field. Valid values can be found in the EC2 [`DescribeSecurityGroupRules`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupRules.html) API Reference. */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetSecurityGroupRulesFilter { /** * Name of the field to filter by, as defined by * [the underlying AWS API](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupRules.html). */ name: string; /** * Set of values that are accepted for the given field. * * Security group rule IDs will be selected if any one of the given values match. */ values: string[]; } interface RouteServerEndpointTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface RouteServerPeerBgpOptions { /** * The Border Gateway Protocol (BGP) Autonomous System Number (ASN) for the appliance. Valid values are from 1 to 4294967295. We recommend using a private ASN in the 64512–65534 (16-bit ASN) or 4200000000–4294967294 (32-bit ASN) range. */ peerAsn: number; /** * The requested liveness detection protocol for the BGP peer. Valid values are `bgp-keepalive` and `bfd`. Default value is `bgp-keepalive`. */ peerLivenessDetection: string; } interface RouteServerPeerTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface RouteServerPropagationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface RouteServerTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface RouteServerVpcAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface SecurityGroupVpcAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace vpclattice { interface GetListenerDefaultAction { /** * Fixed response action. See `fixedResponse` Block below. */ fixedResponses: outputs.vpclattice.GetListenerDefaultActionFixedResponse[]; /** * Forward action. See `forward` Block below. */ forwards: outputs.vpclattice.GetListenerDefaultActionForward[]; } interface GetListenerDefaultActionFixedResponse { /** * Custom HTTP status code to return. */ statusCode: number; } interface GetListenerDefaultActionForward { /** * Target groups that the listener forwards traffic to. See `targetGroups` Block below. */ targetGroups: outputs.vpclattice.GetListenerDefaultActionForwardTargetGroup[]; } interface GetListenerDefaultActionForwardTargetGroup { /** * ID or ARN of the target group. */ targetGroupIdentifier: string; /** * Weight assigned to the target group that determines the proportion of traffic it receives. */ weight: number; } interface GetServiceDnsEntry { /** * DNS name for the service. */ domainName: string; /** * Hosted zone ID where the DNS name is registered. */ hostedZoneId: string; } interface GetServiceNetworkServiceAssociationsItem { /** * ARN of the association. */ arn: string; /** * Date and time the association was created, in RFC 3339 format. */ createdAt: string; /** * Account that created the association. */ createdBy: string; /** * Custom domain name of the service. */ customDomainName: string; /** * List of objects with DNS names. */ dnsEntries: outputs.vpclattice.GetServiceNetworkServiceAssociationsItemDnsEntry[]; /** * ID of the association. */ id: string; /** * ARN of the associated service. */ serviceArn: string; /** * ID of the associated service. */ serviceId: string; /** * Name of the associated service. */ serviceName: string; /** * ARN of the service network the service is associated with. */ serviceNetworkArn: string; /** * ID of the service network the service is associated with. */ serviceNetworkId: string; /** * Name of the service network the service is associated with. */ serviceNetworkName: string; /** * Status of the association. One of `CREATE_IN_PROGRESS`, `ACTIVE`, `DELETE_IN_PROGRESS`, `CREATE_FAILED`, or `DELETE_FAILED`. */ status: string; } interface GetServiceNetworkServiceAssociationsItemDnsEntry { /** * Domain name of the service. */ domainName: string; /** * ID of the hosted zone. */ hostedZoneId: string; } interface ListenerDefaultAction { /** * Configuration block for returning a fixed response. See `fixedResponse` Block below. */ fixedResponse?: outputs.vpclattice.ListenerDefaultActionFixedResponse; /** * Route requests to one or more target groups. See `forward` Block below. * * > **NOTE:** You must specify exactly one of the following argument blocks: `fixedResponse` or `forward`. */ forwards?: outputs.vpclattice.ListenerDefaultActionForward[]; } interface ListenerDefaultActionFixedResponse { /** * Custom HTTP status code to return, e.g. a 404 response code. See [Listeners](https://docs.aws.amazon.com/vpc-lattice/latest/ug/listeners.html) in the AWS documentation for a list of supported codes. */ statusCode: number; } interface ListenerDefaultActionForward { /** * One or more target group blocks. See `targetGroups` Block below. */ targetGroups?: outputs.vpclattice.ListenerDefaultActionForwardTargetGroup[]; } interface ListenerDefaultActionForwardTargetGroup { /** * ID or ARN of the target group. */ targetGroupIdentifier?: string; /** * Weight that controls how requests are distributed to the target group. Only required if you specify multiple target groups for a forward action. For example, if you specify two target groups, one with a weight of 10 and the other with a weight of 20, the target group with a weight of 20 receives twice as many requests as the other target group. See [Listener rules](https://docs.aws.amazon.com/vpc-lattice/latest/ug/listeners.html#listener-rules) in the AWS documentation for additional examples. Default: `100`. */ weight?: number; } interface ListenerRuleAction { /** * Rule action that returns a custom HTTP response. See `fixedResponse` Block for details. */ fixedResponse?: outputs.vpclattice.ListenerRuleActionFixedResponse; /** * Forward action. Traffic that matches the rule is forwarded to the specified target groups. See `forward` Block for details. */ forward?: outputs.vpclattice.ListenerRuleActionForward; } interface ListenerRuleActionFixedResponse { /** * HTTP response code. */ statusCode: number; } interface ListenerRuleActionForward { /** * Target groups that traffic matching the rule is forwarded to. See `targetGroups` Block for details. */ targetGroups: outputs.vpclattice.ListenerRuleActionForwardTargetGroup[]; } interface ListenerRuleActionForwardTargetGroup { /** * ID or ARN of the target group. */ targetGroupIdentifier: string; /** * Weight assigned to the target group, controlling the prioritization and selection of each target group so that requests are distributed based on their weights. Default is `100`. */ weight?: number; } interface ListenerRuleMatch { /** * HTTP criteria that a rule must match. See `httpMatch` Block for details. */ httpMatch: outputs.vpclattice.ListenerRuleMatchHttpMatch; } interface ListenerRuleMatchHttpMatch { /** * Header matches that match incoming requests based on the request header value before applying the rule action. See `headerMatches` Block for details. */ headerMatches?: outputs.vpclattice.ListenerRuleMatchHttpMatchHeaderMatch[]; /** * HTTP method type. */ method?: string; /** * Path match. See `pathMatch` Block for details. */ pathMatch?: outputs.vpclattice.ListenerRuleMatchHttpMatchPathMatch; } interface ListenerRuleMatchHttpMatchHeaderMatch { /** * Whether the match is case sensitive. Default is `false`. */ caseSensitive?: boolean; /** * Header match type. See `match.http_match.header_matches.match` Block for details. */ match: outputs.vpclattice.ListenerRuleMatchHttpMatchHeaderMatchMatch; /** * Name of the header. */ name: string; } interface ListenerRuleMatchHttpMatchHeaderMatchMatch { /** * Value that the header must contain to match. */ contains?: string; /** * Exact type match. */ exact?: string; /** * Prefix type match. Matches the value with the prefix. */ prefix?: string; } interface ListenerRuleMatchHttpMatchPathMatch { /** * Whether the match is case sensitive. Default is `false`. */ caseSensitive?: boolean; /** * Path match type. See `match.http_match.path_match.match` Block for details. */ match: outputs.vpclattice.ListenerRuleMatchHttpMatchPathMatchMatch; } interface ListenerRuleMatchHttpMatchPathMatchMatch { /** * Exact type match. */ exact?: string; /** * Prefix type match. Matches the value with the prefix. */ prefix?: string; } interface ResourceConfigurationResourceConfigurationDefinition { /** * Resource DNS Configuration. See `arnResource` Block for details. */ arnResource?: outputs.vpclattice.ResourceConfigurationResourceConfigurationDefinitionArnResource; /** * Resource DNS Configuration. See `dnsResource` Block for details. */ dnsResource?: outputs.vpclattice.ResourceConfigurationResourceConfigurationDefinitionDnsResource; /** * Resource DNS Configuration. See `ipResource` Block for details. */ ipResource?: outputs.vpclattice.ResourceConfigurationResourceConfigurationDefinitionIpResource; } interface ResourceConfigurationResourceConfigurationDefinitionArnResource { /** * ARN of the Resource for this configuration. */ arn: string; } interface ResourceConfigurationResourceConfigurationDefinitionDnsResource { /** * Hostname of the Resource for this configuration. */ domainName: string; /** * IP Address type either `IPV4` or `IPV6` */ ipAddressType: string; } interface ResourceConfigurationResourceConfigurationDefinitionIpResource { /** * IP Address of the Resource for this configuration. */ ipAddress: string; } interface ResourceConfigurationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ResourceGatewayTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface ServiceDnsEntry { /** * Domain name of the service. */ domainName: string; /** * ID of the hosted zone. */ hostedZoneId: string; } interface ServiceNetworkResourceAssociationDnsEntry { /** * Domain name of the association in the service network. */ domainName: string; /** * ID of the hosted zone containing the domain name. */ hostedZoneId: string; } interface ServiceNetworkResourceAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface ServiceNetworkServiceAssociationDnsEntry { /** * Domain name of the service. */ domainName: string; /** * ID of the hosted zone. */ hostedZoneId: string; } interface ServiceNetworkVpcAssociationDnsOptions { /** * Preference for which private domains have a private hosted zone created for and associated with the specified VPC. Only supported when `privateDnsEnabled` is `true`. Valid Values are `VERIFIED_DOMAINS_ONLY`, `ALL_DOMAINS`, `VERIFIED_DOMAINS_AND_SPECIFIED_DOMAINS` and `SPECIFIED_DOMAINS_ONLY`. */ privateDnsPreference?: string; /** * Private domains to create private hosted zones for and associate with the specified VPC. Only supported when `privateDnsEnabled` is `true` and `privateDnsPreference` is `VERIFIED_DOMAINS_AND_SPECIFIED_DOMAINS` or `SPECIFIED_DOMAINS_ONLY`. */ privateDnsSpecifiedDomains: string[]; } interface TargetGroupAttachmentTarget { /** * ID of the target. If the target type of the target group is INSTANCE, this is an instance ID. If the target type is IP , this is an IP address. If the target type is LAMBDA, this is the ARN of the Lambda function. If the target type is ALB, this is the ARN of the Application Load Balancer. */ id: string; /** * Port used for routing traffic to the target, and defaults to the target group port. However, you can override the default and specify a custom port. */ port: number; } interface TargetGroupConfig { /** * Health check configuration. See `healthCheck` Block below. */ healthCheck?: outputs.vpclattice.TargetGroupConfigHealthCheck; /** * Type of IP address used for the target group. Valid values: `IPV4` or `IPV6`. */ ipAddressType: string; /** * Version of the event structure that the Lambda function receives. Supported only if `type` is `LAMBDA`. Valid values are `V1` or `V2`. */ lambdaEventStructureVersion: string; /** * Port on which the targets are listening. */ port: number; /** * Protocol to use for routing traffic to the targets. Valid values are `HTTP` or `HTTPS`. */ protocol: string; /** * Protocol version. Valid values are `HTTP1`, `HTTP2`, or `GRPC`. Default value is `HTTP1`. */ protocolVersion: string; /** * ID of the VPC. */ vpcIdentifier?: string; } interface TargetGroupConfigHealthCheck { /** * Whether health checking is enabled. Defaults to `true`. */ enabled?: boolean; /** * Approximate amount of time, in seconds, between health checks of an individual target. The range is 5–300 seconds. The default is 30 seconds. */ healthCheckIntervalSeconds?: number; /** * Amount of time, in seconds, to wait before reporting a target as unhealthy. The range is 1–120 seconds. The default is 5 seconds. */ healthCheckTimeoutSeconds?: number; /** * Number of consecutive successful health checks required before considering an unhealthy target healthy. The range is 2–10. The default is 5. */ healthyThresholdCount?: number; /** * Codes to use when checking for a successful response from a target. See `matcher` Block below. */ matcher?: outputs.vpclattice.TargetGroupConfigHealthCheckMatcher; /** * Destination for health checks on the targets. If the protocol version is HTTP/1.1 or HTTP/2, specify a valid URI (for example, /path?query). The default path is `/`. Health checks are not supported if the protocol version is gRPC, however, you can choose HTTP/1.1 or HTTP/2 and specify a valid URI. */ path?: string; /** * Port used when performing health checks on targets. The default setting is the port that a target receives traffic on. */ port: number; /** * Protocol used when performing health checks on targets. The possible protocols are `HTTP` and `HTTPS`. */ protocol: string; /** * Protocol version used when performing health checks on targets. The possible protocol versions are `HTTP1` and `HTTP2`. The default is `HTTP1`. */ protocolVersion?: string; /** * Number of consecutive failed health checks required before considering a target unhealthy. The range is 2–10. The default is 2. */ unhealthyThresholdCount?: number; } interface TargetGroupConfigHealthCheckMatcher { /** * HTTP codes to use when checking for a successful response from a target. */ value?: string; } } export declare namespace vpn { interface GetConnectionFilter { /** * Name of the filter field. Valid values can be found in the [EC2 `DescribeVPNConnections` API Reference](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnConnections.html). */ name: string; /** * Set of values that are accepted for the given filter field. Results will be selected if any given value matches. */ values: string[]; } interface GetConnectionRoute { destinationCidrBlock: string; source: string; /** * Current state of the VPN connection. */ state: string; } interface GetConnectionVgwTelemetry { acceptedRouteCount: number; lastStatusChange: string; outsideIpAddress: string; status: string; statusMessage: string; } } export declare namespace waf { interface ByteMatchSetByteMatchTuple { /** * The part of a web request that you want to search, such as a specified header or a query string. */ fieldToMatch: outputs.waf.ByteMatchSetByteMatchTupleFieldToMatch; /** * Within the portion of a web request that you want to search * (for example, in the query string, if any), specify where you want to search. * e.g., `CONTAINS`, `CONTAINS_WORD` or `EXACTLY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_ByteMatchTuple.html#WAF-Type-ByteMatchTuple-PositionalConstraint) * for all supported values. */ positionalConstraint: string; /** * The value that you want to search for within the field specified by `fieldToMatch`, e.g., `badrefer1`. * See [docs](https://docs.aws.amazon.com/waf/latest/APIReference/API_waf_ByteMatchTuple.html) * for all supported values. */ targetString?: string; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * If you specify a transformation, AWS WAF performs the transformation on `targetString` before inspecting a request for a match. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_ByteMatchTuple.html#WAF-Type-ByteMatchTuple-TextTransformation) * for all supported values. */ textTransformation: string; } interface ByteMatchSetByteMatchTupleFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) * for all supported values. */ type: string; } interface GeoMatchSetGeoMatchConstraint { /** * The type of geographical area you want AWS WAF to search for. Currently Country is the only valid value. */ type: string; /** * The country that you want AWS WAF to search for. * This is the two-letter country code, e.g., `US`, `CA`, `RU`, `CN`, etc. * See [docs](https://docs.aws.amazon.com/waf/latest/APIReference/API_GeoMatchConstraint.html) for all supported values. */ value: string; } interface IpSetIpSetDescriptor { /** * Type of the IP address - `IPV4` or `IPV6`. */ type: string; /** * An IPv4 or IPv6 address specified via CIDR notationE.g., `192.0.2.44/32` or `1111:0000:0000:0000:0000:0000:0000:0000/64` */ value: string; } interface RateBasedRulePredicate { /** * A unique identifier for a predicate in the rule, such as Byte Match Set ID or IPSet ID. */ dataId: string; /** * Set this to `false` if you want to allow, block, or count requests * based on the settings in the specified `ByteMatchSet`, `IPSet`, `SqlInjectionMatchSet`, `XssMatchSet`, or `SizeConstraintSet`. * For example, if an IPSet includes the IP address `192.0.2.44`, AWS WAF will allow or block requests based on that IP address. * If set to `true`, AWS WAF will allow, block, or count requests based on all IP addresses _except_ `192.0.2.44`. */ negated: boolean; /** * The type of predicate in a rule. Valid values: `ByteMatch`, `GeoMatch`, `IPMatch`, `RegexMatch`, `SizeConstraint`, `SqlInjectionMatch`, or `XssMatch`. */ type: string; } interface RegexMatchSetRegexMatchTuple { /** * The part of a web request that you want to search, such as a specified header or a query string. */ fieldToMatch: outputs.waf.RegexMatchSetRegexMatchTupleFieldToMatch; /** * The ID of a Regex Pattern Set. */ regexPatternSetId: string; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_ByteMatchTuple.html#WAF-Type-ByteMatchTuple-TextTransformation) * for all supported values. */ textTransformation: string; } interface RegexMatchSetRegexMatchTupleFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) * for all supported values. */ type: string; } interface RuleGroupActivatedRule { /** * Specifies the action that CloudFront or AWS WAF takes when a web request matches the conditions in the rule. */ action: outputs.waf.RuleGroupActivatedRuleAction; /** * Specifies the order in which the rules are evaluated. Rules with a lower value are evaluated before rules with a higher value. */ priority: number; /** * The ID of a rule */ ruleId: string; type?: string; } interface RuleGroupActivatedRuleAction { type: string; } interface RulePredicate { /** * A unique identifier for a predicate in the rule, such as Byte Match Set ID or IPSet ID. */ dataId: string; /** * Set this to `false` if you want to allow, block, or count requests * based on the settings in the specified waf_byte_match_set, waf_ipset, aws_waf_size_constraint_set, aws.waf.SqlInjectionMatchSet or aws_waf_xss_match_set. * For example, if an IPSet includes the IP address `192.0.2.44`, AWS WAF will allow or block requests based on that IP address. * If set to `true`, AWS WAF will allow, block, or count requests based on all IP addresses except `192.0.2.44`. */ negated: boolean; /** * The type of predicate in a rule. Valid values: `ByteMatch`, `GeoMatch`, `IPMatch`, `RegexMatch`, `SizeConstraint`, `SqlInjectionMatch`, or `XssMatch`. */ type: string; } interface SizeConstraintSetSizeConstraint { /** * Type of comparison you want to perform, such as `EQ`, `NE`, `LT`, or `GT`. Please refer to the [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_wafRegional_SizeConstraint.html) for a complete list of supported values. */ comparisonOperator: string; /** * Parameter that specifies where in a web request to look for the size constraint. */ fieldToMatch: outputs.waf.SizeConstraintSetSizeConstraintFieldToMatch; /** * Size in bytes that you want to compare against the size of the specified `fieldToMatch`. Valid values for `size` are between 0 and 21474836480 bytes (0 and 20 GB). */ size: number; /** * Parameter is used to eliminate unusual formatting that attackers may use in web requests to bypass AWS WAF. When a transformation is specified, AWS WAF performs the transformation on the `fieldToMatch` before inspecting the request for a match. Some examples of supported transformations are `CMD_LINE`, `HTML_ENTITY_DECODE`, and `NONE`. You can find a complete list of supported values in the [AWS WAF API Reference](http://docs.aws.amazon.com/waf/latest/APIReference/API_SizeConstraint.html#WAF-Type-SizeConstraint-TextTransformation). * **Note:** If you choose `BODY` as the `type`, you must also choose `NONE` because CloudFront only forwards the first 8192 bytes for inspection. */ textTransformation: string; } interface SizeConstraintSetSizeConstraintFieldToMatch { /** * When the `type` is `HEADER`, specify the name of the header that you want to search using the `data` field, for example, `User-Agent` or `Referer`. If the `type` is any other value, you can omit this field. */ data?: string; /** * Part of the web request that you want AWS WAF to search for a specified string. For example, `HEADER`, `METHOD`, or `BODY`. See the [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) for all supported values. */ type: string; } interface SqlInjectionMatchSetSqlInjectionMatchTuple { /** * Specifies where in a web request to look for snippets of malicious SQL code. */ fieldToMatch: outputs.waf.SqlInjectionMatchSetSqlInjectionMatchTupleFieldToMatch; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * If you specify a transformation, AWS WAF performs the transformation on `fieldToMatch` before inspecting a request for a match. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_SqlInjectionMatchTuple.html#WAF-Type-SqlInjectionMatchTuple-TextTransformation) * for all supported values. */ textTransformation: string; } interface SqlInjectionMatchSetSqlInjectionMatchTupleFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) * for all supported values. */ type: string; } interface WebAclDefaultAction { /** * Specifies how you want AWS WAF to respond to requests that don't match the criteria in any of the `rules`. * e.g., `ALLOW` or `BLOCK` */ type: string; } interface WebAclLoggingConfiguration { /** * ARN of Kinesis Firehose Delivery Stream */ logDestination: string; /** * Configuration block containing parts of the request that you want redacted from the logs. Detailed below. */ redactedFields?: outputs.waf.WebAclLoggingConfigurationRedactedFields; } interface WebAclLoggingConfigurationRedactedFields { /** * Set of configuration blocks for fields to redact. Detailed below. */ fieldToMatches: outputs.waf.WebAclLoggingConfigurationRedactedFieldsFieldToMatch[]; } interface WebAclLoggingConfigurationRedactedFieldsFieldToMatch { /** * When the value of `type` is `HEADER`, enter the name of the header that you want the WAF to search, for example, `User-Agent` or `Referer`. If the value of `type` is any other value, omit `data`. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified stringE.g., `HEADER` or `METHOD` */ type: string; } interface WebAclRule { /** * The action that CloudFront or AWS WAF takes when a web request matches the conditions in the rule. Not used if `type` is `GROUP`. */ action?: outputs.waf.WebAclRuleAction; /** * Override the action that a group requests CloudFront or AWS WAF takes when a web request matches the conditions in the rule. Only used if `type` is `GROUP`. */ overrideAction?: outputs.waf.WebAclRuleOverrideAction; /** * Specifies the order in which the rules in a WebACL are evaluated. * Rules with a lower value are evaluated before rules with a higher value. */ priority: number; /** * ID of the associated WAF (Global) rule (e.g., `aws.waf.Rule`). WAF (Regional) rules cannot be used. */ ruleId: string; /** * The rule type, either `REGULAR`, as defined by [Rule](http://docs.aws.amazon.com/waf/latest/APIReference/API_Rule.html), `RATE_BASED`, as defined by [RateBasedRule](http://docs.aws.amazon.com/waf/latest/APIReference/API_RateBasedRule.html), or `GROUP`, as defined by [RuleGroup](https://docs.aws.amazon.com/waf/latest/APIReference/API_RuleGroup.html). The default is REGULAR. If you add a RATE_BASED rule, you need to set `type` as `RATE_BASED`. If you add a GROUP rule, you need to set `type` as `GROUP`. */ type?: string; } interface WebAclRuleAction { /** * valid values are: `BLOCK`, `ALLOW`, or `COUNT` */ type: string; } interface WebAclRuleOverrideAction { /** * valid values are: `NONE` or `COUNT` */ type: string; } interface XssMatchSetXssMatchTuple { /** * Specifies where in a web request to look for cross-site scripting attacks. */ fieldToMatch: outputs.waf.XssMatchSetXssMatchTupleFieldToMatch; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * If you specify a transformation, AWS WAF performs the transformation on `targetString` before inspecting a request for a match. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_XssMatchTuple.html#WAF-Type-XssMatchTuple-TextTransformation) * for all supported values. */ textTransformation: string; } interface XssMatchSetXssMatchTupleFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) * for all supported values. */ type: string; } } export declare namespace wafregional { interface ByteMatchSetByteMatchTuple { /** * Settings for the ByteMatchTuple. FieldToMatch documented below. */ fieldToMatch: outputs.wafregional.ByteMatchSetByteMatchTupleFieldToMatch; /** * Within the portion of a web request that you want to search. */ positionalConstraint: string; /** * The value that you want AWS WAF to search for. The maximum length of the value is 50 bytes. */ targetString?: string; /** * The formatting way for web request. * * FieldToMatch(field_to_match) support following: */ textTransformation: string; } interface ByteMatchSetByteMatchTupleFieldToMatch { /** * When the value of Type is HEADER, enter the name of the header that you want AWS WAF to search, for example, User-Agent or Referer. If the value of Type is any other value, omit Data. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. */ type: string; } interface GeoMatchSetGeoMatchConstraint { /** * Type of geographical area you want AWS WAF to search for. Currently `Country` is the only valid value. */ type: string; /** * Two-letter country code that you want AWS WAF to search for, e.g., `US`, `CA`, `RU`, `CN`. See [docs](https://docs.aws.amazon.com/waf/latest/APIReference/API_GeoMatchConstraint.html) for all supported values. */ value: string; } interface IpSetIpSetDescriptor { /** * The string like IPV4 or IPV6. */ type: string; /** * The CIDR notation. */ value: string; } interface RateBasedRulePredicate { /** * A unique identifier for a predicate in the rule, such as Byte Match Set ID or IPSet ID. */ dataId: string; /** * Set this to `false` if you want to allow, block, or count requests * based on the settings in the specified `ByteMatchSet`, `IPSet`, `SqlInjectionMatchSet`, `XssMatchSet`, or `SizeConstraintSet`. * For example, if an IPSet includes the IP address `192.0.2.44`, AWS WAF will allow or block requests based on that IP address. * If set to `true`, AWS WAF will allow, block, or count requests based on all IP addresses _except_ `192.0.2.44`. */ negated: boolean; /** * The type of predicate in a rule. Valid values: `ByteMatch`, `GeoMatch`, `IPMatch`, `RegexMatch`, `SizeConstraint`, `SqlInjectionMatch`, or `XssMatch`. */ type: string; } interface RegexMatchSetRegexMatchTuple { /** * The part of a web request that you want to search, such as a specified header or a query string. */ fieldToMatch: outputs.wafregional.RegexMatchSetRegexMatchTupleFieldToMatch; /** * The ID of a Regex Pattern Set. */ regexPatternSetId: string; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_ByteMatchTuple.html#WAF-Type-ByteMatchTuple-TextTransformation) * for all supported values. */ textTransformation: string; } interface RegexMatchSetRegexMatchTupleFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) * for all supported values. */ type: string; } interface RuleGroupActivatedRule { /** * Specifies the action that CloudFront or AWS WAF takes when a web request matches the conditions in the rule. */ action: outputs.wafregional.RuleGroupActivatedRuleAction; /** * Specifies the order in which the rules are evaluated. Rules with a lower value are evaluated before rules with a higher value. */ priority: number; /** * The ID of a rule */ ruleId: string; type?: string; } interface RuleGroupActivatedRuleAction { type: string; } interface RulePredicate { /** * The unique identifier of a predicate, such as the ID of a `ByteMatchSet` or `IPSet`. */ dataId: string; /** * Whether to use the settings or the negated settings that you specified in the objects. */ negated: boolean; /** * The type of predicate in a rule. Valid values: `ByteMatch`, `GeoMatch`, `IPMatch`, `RegexMatch`, `SizeConstraint`, `SqlInjectionMatch`, or `XssMatch` */ type: string; } interface SizeConstraintSetSizeConstraint { /** * The type of comparison you want to perform. * e.g., `EQ`, `NE`, `LT`, `GT`. * See [docs](https://docs.aws.amazon.com/waf/latest/APIReference/API_wafRegional_SizeConstraint.html) for all supported values. */ comparisonOperator: string; /** * Specifies where in a web request to look for the size constraint. */ fieldToMatch: outputs.wafregional.SizeConstraintSetSizeConstraintFieldToMatch; /** * The size in bytes that you want to compare against the size of the specified `fieldToMatch`. * Valid values are between 0 - 21474836480 bytes (0 - 20 GB). */ size: number; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * If you specify a transformation, AWS WAF performs the transformation on `fieldToMatch` before inspecting a request for a match. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_SizeConstraint.html#WAF-Type-SizeConstraint-TextTransformation) * for all supported values. * **Note:** if you choose `BODY` as `type`, you must choose `NONE` because CloudFront forwards only the first 8192 bytes for inspection. */ textTransformation: string; } interface SizeConstraintSetSizeConstraintFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](http://docs.aws.amazon.com/waf/latest/APIReference/API_FieldToMatch.html) * for all supported values. */ type: string; } interface SqlInjectionMatchSetSqlInjectionMatchTuple { /** * Specifies where in a web request to look for snippets of malicious SQL code. */ fieldToMatch: outputs.wafregional.SqlInjectionMatchSetSqlInjectionMatchTupleFieldToMatch; /** * Text transformations used to eliminate unusual formatting that attackers use in web requests in an effort to bypass AWS WAF. * If you specify a transformation, AWS WAF performs the transformation on `fieldToMatch` before inspecting a request for a match. * e.g., `CMD_LINE`, `HTML_ENTITY_DECODE` or `NONE`. * See [docs](https://docs.aws.amazon.com/waf/latest/APIReference/API_regional_SqlInjectionMatchTuple.html#WAF-Type-regional_SqlInjectionMatchTuple-TextTransformation) * for all supported values. */ textTransformation: string; } interface SqlInjectionMatchSetSqlInjectionMatchTupleFieldToMatch { /** * When `type` is `HEADER`, enter the name of the header that you want to search, e.g., `User-Agent` or `Referer`. * If `type` is any other value, omit this field. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified string. * e.g., `HEADER`, `METHOD` or `BODY`. * See [docs](https://docs.aws.amazon.com/waf/latest/APIReference/API_regional_FieldToMatch.html) * for all supported values. */ type: string; } interface WebAclDefaultAction { /** * Specifies how you want AWS WAF Regional to respond to requests that match the settings in a ruleE.g., `ALLOW`, `BLOCK` or `COUNT` */ type: string; } interface WebAclLoggingConfiguration { /** * ARN of Kinesis Firehose Delivery Stream */ logDestination: string; /** * Configuration block containing parts of the request that you want redacted from the logs. Detailed below. */ redactedFields?: outputs.wafregional.WebAclLoggingConfigurationRedactedFields; } interface WebAclLoggingConfigurationRedactedFields { /** * Set of configuration blocks for fields to redact. Detailed below. */ fieldToMatches: outputs.wafregional.WebAclLoggingConfigurationRedactedFieldsFieldToMatch[]; } interface WebAclLoggingConfigurationRedactedFieldsFieldToMatch { /** * When the value of `type` is `HEADER`, enter the name of the header that you want the WAF to search, for example, `User-Agent` or `Referer`. If the value of `type` is any other value, omit `data`. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified stringE.g., `HEADER` or `METHOD` */ type: string; } interface WebAclRule { /** * Configuration block of the action that CloudFront or AWS WAF takes when a web request matches the conditions in the rule. Not used if `type` is `GROUP`. Detailed below. */ action?: outputs.wafregional.WebAclRuleAction; /** * Configuration block of the override the action that a group requests CloudFront or AWS WAF takes when a web request matches the conditions in the rule. Only used if `type` is `GROUP`. Detailed below. */ overrideAction?: outputs.wafregional.WebAclRuleOverrideAction; /** * Specifies the order in which the rules in a WebACL are evaluated. * Rules with a lower value are evaluated before rules with a higher value. */ priority: number; /** * ID of the associated WAF (Regional) rule (e.g., `aws.wafregional.Rule`). WAF (Global) rules cannot be used. */ ruleId: string; /** * The rule type, either `REGULAR`, as defined by [Rule](http://docs.aws.amazon.com/waf/latest/APIReference/API_Rule.html), `RATE_BASED`, as defined by [RateBasedRule](http://docs.aws.amazon.com/waf/latest/APIReference/API_RateBasedRule.html), or `GROUP`, as defined by [RuleGroup](https://docs.aws.amazon.com/waf/latest/APIReference/API_RuleGroup.html). The default is REGULAR. If you add a RATE_BASED rule, you need to set `type` as `RATE_BASED`. If you add a GROUP rule, you need to set `type` as `GROUP`. */ type?: string; } interface WebAclRuleAction { /** * Specifies how you want AWS WAF Regional to respond to requests that match the settings in a rule. Valid values for `action` are `ALLOW`, `BLOCK` or `COUNT`. Valid values for `overrideAction` are `COUNT` and `NONE`. */ type: string; } interface WebAclRuleOverrideAction { type: string; } interface XssMatchSetXssMatchTuple { /** * Specifies where in a web request to look for cross-site scripting attacks. */ fieldToMatch: outputs.wafregional.XssMatchSetXssMatchTupleFieldToMatch; /** * Which text transformation, if any, to perform on the web request before inspecting the request for cross-site scripting attacks. */ textTransformation: string; } interface XssMatchSetXssMatchTupleFieldToMatch { /** * When the value of `type` is `HEADER`, enter the name of the header that you want the WAF to search, for example, `User-Agent` or `Referer`. If the value of `type` is any other value, omit `data`. */ data?: string; /** * The part of the web request that you want AWS WAF to search for a specified stringE.g., `HEADER` or `METHOD` */ type: string; } } export declare namespace wafv2 { interface GetManagedRuleGroupAvailableLabel { /** * Managed rule group name. */ name: string; } interface GetManagedRuleGroupConsumedLabel { /** * Managed rule group name. */ name: string; } interface GetManagedRuleGroupRule { /** * Action taken on a web request when it matches a rule's statement. See `action` Block for details. */ actions: outputs.wafv2.GetManagedRuleGroupRuleAction[]; /** * Managed rule group name. */ name: string; } interface GetManagedRuleGroupRuleAction { /** * Rule action that allows the request. See `allow` Block for details. */ allows: outputs.wafv2.GetManagedRuleGroupRuleActionAllow[]; /** * Rule action that blocks the request. See `block` Block for details. */ blocks: outputs.wafv2.GetManagedRuleGroupRuleActionBlock[]; /** * Rule action that requires CAPTCHA verification. See `captcha` Block for details. */ captchas: outputs.wafv2.GetManagedRuleGroupRuleActionCaptcha[]; /** * Rule action that requires challenge verification. See `challenge` Block for details. */ challenges: outputs.wafv2.GetManagedRuleGroupRuleActionChallenge[]; /** * Rule action that counts the request without taking other action. See `count` Block for details. */ counts: outputs.wafv2.GetManagedRuleGroupRuleActionCount[]; } interface GetManagedRuleGroupRuleActionAllow { /** * Custom handling for the counted request. See `customRequestHandling` Block for details. */ customRequestHandlings: outputs.wafv2.GetManagedRuleGroupRuleActionAllowCustomRequestHandling[]; } interface GetManagedRuleGroupRuleActionAllowCustomRequestHandling { /** * Headers inserted into the request. See `insertHeader` Block for details. */ insertHeaders: outputs.wafv2.GetManagedRuleGroupRuleActionAllowCustomRequestHandlingInsertHeader[]; } interface GetManagedRuleGroupRuleActionAllowCustomRequestHandlingInsertHeader { /** * Managed rule group name. */ name: string; /** * Value of the header. */ value: string; } interface GetManagedRuleGroupRuleActionBlock { /** * Custom response for the blocked request. See `customResponse` Block for details. */ customResponses: outputs.wafv2.GetManagedRuleGroupRuleActionBlockCustomResponse[]; } interface GetManagedRuleGroupRuleActionBlockCustomResponse { /** * Key of the custom response body to use. */ customResponseBodyKey: string; /** * HTTP response code returned. */ responseCode: number; /** * Headers included in the response. See `responseHeader` Block for details. */ responseHeaders: outputs.wafv2.GetManagedRuleGroupRuleActionBlockCustomResponseResponseHeader[]; } interface GetManagedRuleGroupRuleActionBlockCustomResponseResponseHeader { /** * Managed rule group name. */ name: string; /** * Value of the header. */ value: string; } interface GetManagedRuleGroupRuleActionCaptcha { /** * Custom handling for the counted request. See `customRequestHandling` Block for details. */ customRequestHandlings: outputs.wafv2.GetManagedRuleGroupRuleActionCaptchaCustomRequestHandling[]; } interface GetManagedRuleGroupRuleActionCaptchaCustomRequestHandling { /** * Headers inserted into the request. See `insertHeader` Block for details. */ insertHeaders: outputs.wafv2.GetManagedRuleGroupRuleActionCaptchaCustomRequestHandlingInsertHeader[]; } interface GetManagedRuleGroupRuleActionCaptchaCustomRequestHandlingInsertHeader { /** * Managed rule group name. */ name: string; /** * Value of the header. */ value: string; } interface GetManagedRuleGroupRuleActionChallenge { /** * Custom handling for the counted request. See `customRequestHandling` Block for details. */ customRequestHandlings: outputs.wafv2.GetManagedRuleGroupRuleActionChallengeCustomRequestHandling[]; } interface GetManagedRuleGroupRuleActionChallengeCustomRequestHandling { /** * Headers inserted into the request. See `insertHeader` Block for details. */ insertHeaders: outputs.wafv2.GetManagedRuleGroupRuleActionChallengeCustomRequestHandlingInsertHeader[]; } interface GetManagedRuleGroupRuleActionChallengeCustomRequestHandlingInsertHeader { /** * Managed rule group name. */ name: string; /** * Value of the header. */ value: string; } interface GetManagedRuleGroupRuleActionCount { /** * Custom handling for the counted request. See `customRequestHandling` Block for details. */ customRequestHandlings: outputs.wafv2.GetManagedRuleGroupRuleActionCountCustomRequestHandling[]; } interface GetManagedRuleGroupRuleActionCountCustomRequestHandling { /** * Headers inserted into the request. See `insertHeader` Block for details. */ insertHeaders: outputs.wafv2.GetManagedRuleGroupRuleActionCountCustomRequestHandlingInsertHeader[]; } interface GetManagedRuleGroupRuleActionCountCustomRequestHandlingInsertHeader { /** * Managed rule group name. */ name: string; /** * Value of the header. */ value: string; } interface GetRegexPatternSetRegularExpression { /** * (Required) String representing the regular expression, see the AWS WAF [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-regex-pattern-set-creating.html) for more information. */ regexString: string; } interface RegexPatternSetRegularExpression { /** * The string representing the regular expression, see the AWS WAF [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-regex-pattern-set-creating.html) for more information. */ regexString: string; } interface RuleGroupCustomResponseBody { /** * The payload of the custom response. */ content: string; /** * The type of content in the payload that you are defining in the `content` argument. Valid values are `TEXT_PLAIN`, `TEXT_HTML`, or `APPLICATION_JSON`. */ contentType: string; /** * A unique key identifying the custom response body. This is referenced by the `customResponseBodyKey` argument in the Custom Response block. */ key: string; } interface RuleGroupRule { /** * The action that AWS WAF should take on a web request when it matches the rule's statement. Settings at the `aws.wafv2.WebAcl` level can override the rule action setting. See Action below for details. */ action: outputs.wafv2.RuleGroupRuleAction; /** * Specifies how AWS WAF should handle CAPTCHA evaluations. See Captcha Configuration below for details. */ captchaConfig?: outputs.wafv2.RuleGroupRuleCaptchaConfig; /** * A friendly name of the rule. */ name: string; /** * If you define more than one Rule in a WebACL, AWS WAF evaluates each request against the `rules` in order based on the value of `priority`. AWS WAF processes rules with lower priority first. */ priority: number; /** * Labels to apply to web requests that match the rule match statement. See Rule Label below for details. */ ruleLabels?: outputs.wafv2.RuleGroupRuleRuleLabel[]; /** * The AWS WAF processing statement for the rule, for example `byteMatchStatement` or `geoMatchStatement`. See Statement below for details. */ statement: outputs.wafv2.RuleGroupRuleStatement; /** * Defines and enables Amazon CloudWatch metrics and web request sample collection. See Visibility Configuration below for details. */ visibilityConfig: outputs.wafv2.RuleGroupRuleVisibilityConfig; } interface RuleGroupRuleAction { /** * Instructs AWS WAF to allow the web request. See Allow below for details. */ allow?: outputs.wafv2.RuleGroupRuleActionAllow; /** * Instructs AWS WAF to block the web request. See Block below for details. */ block?: outputs.wafv2.RuleGroupRuleActionBlock; /** * Instructs AWS WAF to run a `CAPTCHA` check against the web request. See Captcha below for details. */ captcha?: outputs.wafv2.RuleGroupRuleActionCaptcha; /** * Instructs AWS WAF to run a check against the request to verify that the request is coming from a legitimate client session. See Challenge below for details. */ challenge?: outputs.wafv2.RuleGroupRuleActionChallenge; /** * Instructs AWS WAF to count the web request and allow it. See Count below for details. */ count?: outputs.wafv2.RuleGroupRuleActionCount; } interface RuleGroupRuleActionAllow { /** * Defines custom handling for the web request. See Custom Request Handling below for details. */ customRequestHandling?: outputs.wafv2.RuleGroupRuleActionAllowCustomRequestHandling; } interface RuleGroupRuleActionAllowCustomRequestHandling { /** * The `insertHeader` blocks used to define HTTP headers added to the request. See Custom HTTP Header below for details. */ insertHeaders: outputs.wafv2.RuleGroupRuleActionAllowCustomRequestHandlingInsertHeader[]; } interface RuleGroupRuleActionAllowCustomRequestHandlingInsertHeader { /** * A friendly name of the rule group. */ name: string; /** * The value of the custom header. */ value: string; } interface RuleGroupRuleActionBlock { /** * Defines a custom response for the web request. See Custom Response below for details. */ customResponse?: outputs.wafv2.RuleGroupRuleActionBlockCustomResponse; } interface RuleGroupRuleActionBlockCustomResponse { /** * References the response body that you want AWS WAF to return to the web request client. This must reference a `key` defined in a `customResponseBody` block of this resource. */ customResponseBodyKey?: string; /** * The HTTP status code to return to the client. */ responseCode: number; /** * The `responseHeader` blocks used to define the HTTP response headers added to the response. See Custom HTTP Header below for details. */ responseHeaders?: outputs.wafv2.RuleGroupRuleActionBlockCustomResponseResponseHeader[]; } interface RuleGroupRuleActionBlockCustomResponseResponseHeader { /** * A friendly name of the rule group. */ name: string; /** * The value of the custom header. */ value: string; } interface RuleGroupRuleActionCaptcha { /** * Defines custom handling for the web request. See Custom Request Handling below for details. */ customRequestHandling?: outputs.wafv2.RuleGroupRuleActionCaptchaCustomRequestHandling; } interface RuleGroupRuleActionCaptchaCustomRequestHandling { /** * The `insertHeader` blocks used to define HTTP headers added to the request. See Custom HTTP Header below for details. */ insertHeaders: outputs.wafv2.RuleGroupRuleActionCaptchaCustomRequestHandlingInsertHeader[]; } interface RuleGroupRuleActionCaptchaCustomRequestHandlingInsertHeader { /** * A friendly name of the rule group. */ name: string; /** * The value of the custom header. */ value: string; } interface RuleGroupRuleActionChallenge { /** * Defines custom handling for the web request. See Custom Request Handling below for details. */ customRequestHandling?: outputs.wafv2.RuleGroupRuleActionChallengeCustomRequestHandling; } interface RuleGroupRuleActionChallengeCustomRequestHandling { /** * The `insertHeader` blocks used to define HTTP headers added to the request. See Custom HTTP Header below for details. */ insertHeaders: outputs.wafv2.RuleGroupRuleActionChallengeCustomRequestHandlingInsertHeader[]; } interface RuleGroupRuleActionChallengeCustomRequestHandlingInsertHeader { /** * A friendly name of the rule group. */ name: string; /** * The value of the custom header. */ value: string; } interface RuleGroupRuleActionCount { /** * Defines custom handling for the web request. See Custom Request Handling below for details. */ customRequestHandling?: outputs.wafv2.RuleGroupRuleActionCountCustomRequestHandling; } interface RuleGroupRuleActionCountCustomRequestHandling { /** * The `insertHeader` blocks used to define HTTP headers added to the request. See Custom HTTP Header below for details. */ insertHeaders: outputs.wafv2.RuleGroupRuleActionCountCustomRequestHandlingInsertHeader[]; } interface RuleGroupRuleActionCountCustomRequestHandlingInsertHeader { /** * A friendly name of the rule group. */ name: string; /** * The value of the custom header. */ value: string; } interface RuleGroupRuleCaptchaConfig { /** * Defines custom immunity time. See Immunity Time Property below for details. */ immunityTimeProperty?: outputs.wafv2.RuleGroupRuleCaptchaConfigImmunityTimeProperty; } interface RuleGroupRuleCaptchaConfigImmunityTimeProperty { /** * The amount of time, in seconds, that a CAPTCHA or challenge timestamp is considered valid by AWS WAF. The default setting is 300. */ immunityTime?: number; } interface RuleGroupRuleRuleLabel { /** * The label string. */ name: string; } interface RuleGroupRuleStatement { /** * A logical rule statement used to combine other rule statements with AND logic. See AND Statement below for details. */ andStatement?: outputs.wafv2.RuleGroupRuleStatementAndStatement; /** * Rule statement that inspects web traffic based on the Autonomous System Number (ASN) associated with the request's IP address. See ASN Match Statement below for details. */ asnMatchStatement?: outputs.wafv2.RuleGroupRuleStatementAsnMatchStatement; /** * A rule statement that defines a string match search for AWS WAF to apply to web requests. See Byte Match Statement below for details. */ byteMatchStatement?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatement; /** * A rule statement used to identify web requests based on country of origin. See GEO Match Statement below for details. */ geoMatchStatement?: outputs.wafv2.RuleGroupRuleStatementGeoMatchStatement; /** * A rule statement used to detect web requests coming from particular IP addresses or address ranges. See IP Set Reference Statement below for details. */ ipSetReferenceStatement?: outputs.wafv2.RuleGroupRuleStatementIpSetReferenceStatement; /** * A rule statement that defines a string match search against labels that have been added to the web request by rules that have already run in the web ACL. See Label Match Statement below for details. */ labelMatchStatement?: outputs.wafv2.RuleGroupRuleStatementLabelMatchStatement; /** * A logical rule statement used to negate the results of another rule statement. See NOT Statement below for details. */ notStatement?: outputs.wafv2.RuleGroupRuleStatementNotStatement; /** * A logical rule statement used to combine other rule statements with OR logic. See OR Statement below for details. */ orStatement?: outputs.wafv2.RuleGroupRuleStatementOrStatement; /** * A rate-based rule tracks the rate of requests for each originating `IP address`, and triggers the rule action when the rate exceeds a limit that you specify on the number of requests in any `5-minute` time span. This statement can not be nested. See Rate Based Statement below for details. */ rateBasedStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatement; /** * A rule statement used to search web request components for a match against a single regular expression. See Regex Match Statement below for details. */ regexMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatement; /** * A rule statement used to search web request components for matches with regular expressions. See Regex Pattern Set Reference Statement below for details. */ regexPatternSetReferenceStatement?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatement; /** * A rule statement that compares a number of bytes against the size of a request component, using a comparison operator, such as greater than (>) or less than (<). See Size Constraint Statement below for more details. */ sizeConstraintStatement?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatement; /** * An SQL injection match condition identifies the part of web requests, such as the URI or the query string, that you want AWS WAF to inspect. See SQL Injection Match Statement below for details. */ sqliMatchStatement?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatement; /** * A rule statement that defines a cross-site scripting (XSS) match search for AWS WAF to apply to web requests. See XSS Match Statement below for details. */ xssMatchStatement?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatement; } interface RuleGroupRuleStatementAndStatement { /** * The statements to combine with `AND` logic. You can use any statements that can be nested. See Statement above for details. */ statements: outputs.wafv2.RuleGroupRuleStatement[]; } interface RuleGroupRuleStatementAsnMatchStatement { /** * List of Autonomous System Numbers (ASNs). */ asnLists: number[]; /** * Configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. See Forwarded IP Config below for more details. */ forwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementAsnMatchStatementForwardedIpConfig; } interface RuleGroupRuleStatementAsnMatchStatementForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; } interface RuleGroupRuleStatementByteMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatch; /** * The area within the portion of a web request that you want AWS WAF to search for `searchString`. Valid values include the following: `EXACTLY`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CONTAINS_WORD`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_ByteMatchStatement.html) for more information. */ positionalConstraint: string; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementPreParseTextTransformation[]; /** * A string value that you want AWS WAF to search for. AWS WAF searches only in the part of web requests that you designate for inspection in `fieldToMatch`. The maximum length of the value is 50 bytes. */ searchString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementByteMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementByteMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementByteMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementGeoMatchStatement { /** * An array of two-character country codes, for example, [ "US", "CN" ], from the alpha-2 country ISO codes of the `ISO 3166` international standard. See the [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_GeoMatchStatement.html) for valid values. */ countryCodes: string[]; /** * The configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. See Forwarded IP Config below for details. */ forwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementGeoMatchStatementForwardedIpConfig; } interface RuleGroupRuleStatementGeoMatchStatementForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; } interface RuleGroupRuleStatementIpSetReferenceStatement { /** * ARN of the IP Set that this statement references. */ arn: string; /** * The configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. See IPSet Forwarded IP Config below for more details. */ ipSetForwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementIpSetReferenceStatementIpSetForwardedIpConfig; } interface RuleGroupRuleStatementIpSetReferenceStatementIpSetForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; /** * The position in the header to search for the IP address. Valid values include: `FIRST`, `LAST`, or `ANY`. If `ANY` is specified and the header contains more than 10 IP addresses, AWS WAFv2 inspects the last 10. */ position: string; } interface RuleGroupRuleStatementLabelMatchStatement { /** * The string to match against. */ key: string; /** * Specify whether you want to match using the label name or just the namespace. Valid values are `LABEL` or `NAMESPACE`. */ scope: string; } interface RuleGroupRuleStatementNotStatement { /** * The statement to negate. You can use any statement that can be nested. See Statement above for details. */ statements: outputs.wafv2.RuleGroupRuleStatement[]; } interface RuleGroupRuleStatementOrStatement { /** * The statements to combine with `OR` logic. You can use any statements that can be nested. See Statement above for details. */ statements: outputs.wafv2.RuleGroupRuleStatement[]; } interface RuleGroupRuleStatementRateBasedStatement { /** * Setting that indicates how to aggregate the request counts. Valid values include: `CONSTANT`, `CUSTOM_KEYS`, `FORWARDED_IP` or `IP`. Default: `IP`. */ aggregateKeyType?: string; /** * Aggregate the request counts using one or more web request components as the aggregate keys. See `customKey` below for details. */ customKeys?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKey[]; /** * The amount of time, in seconds, that AWS WAF should include in its request counts, looking back from the current time. Valid values are `60`, `120`, `300`, and `600`. Defaults to `300` (5 minutes). * * **NOTE:** This setting doesn't determine how often AWS WAF checks the rate, but how far back it looks each time it checks. AWS WAF checks the rate about every 10 seconds. */ evaluationWindowSec?: number; /** * The configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. If `aggregateKeyType` is set to `FORWARDED_IP`, this block is required. See Forwarded IP Config below for details. */ forwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementForwardedIpConfig; /** * Limit on requests per 5-minute (or `evaluationWindowSec`) period for a single originating IP address (or for other aggregate key, depending on `aggregateKeyType` and `customKey`). */ limit: number; /** * An optional nested statement that narrows the scope of the rate-based statement to matching web requests. This can be any nestable statement, and you can nest statements at any level below this scope-down statement. See Statement above for details. If `aggregateKeyType` is set to `CONSTANT`, this block is required. */ scopeDownStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatement; } interface RuleGroupRuleStatementRateBasedStatementCustomKey { asn?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyAsn; /** * (Optional) Use the value of a cookie in the request as an aggregate key. See RateLimit `cookie` below for details. */ cookie?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyCookie; /** * (Optional) Use the first IP address in an HTTP header as an aggregate key. See `forwardedIp` below for details. */ forwardedIp?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyForwardedIp; /** * (Optional) Use the value of a header in the request as an aggregate key. See RateLimit `header` below for details. */ header?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyHeader; /** * (Optional) Use the request's HTTP method as an aggregate key. See RateLimit `httpMethod` below for details. */ httpMethod?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyHttpMethod; /** * (Optional) Use the request's originating IP address as an aggregate key. See `RateLimit ip` below for details. */ ip?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyIp; /** * (Optional) Use the JA3 fingerprint in the request as an aggregate key. See `RateLimit ip` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyJa3Fingerprint; /** * (Optional) Use the JA3 fingerprint in the request as an aggregate key. See `RateLimit ip` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyJa4Fingerprint; /** * (Optional) Use the specified label namespace as an aggregate key. See RateLimit `labelNamespace` below for details. */ labelNamespace?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyLabelNamespace; /** * (Optional) Use the specified query argument as an aggregate key. See RateLimit `queryArgument` below for details. */ queryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyQueryArgument; /** * (Optional) Use the request's query string as an aggregate key. See RateLimit `queryString` below for details. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyQueryString; /** * (Optional) Use the request's URI path as an aggregate key. See RateLimit `uriPath` below for details. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyUriPath; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyAsn { } interface RuleGroupRuleStatementRateBasedStatementCustomKeyCookie { /** * A friendly name of the rule group. */ name: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. They are used in rate-based rule statements, to transform request components before using them as custom aggregation keys. Atleast one transformation is required. See Text Transformation above for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyCookieTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyCookieTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyForwardedIp { } interface RuleGroupRuleStatementRateBasedStatementCustomKeyHeader { /** * A friendly name of the rule group. */ name: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. They are used in rate-based rule statements, to transform request components before using them as custom aggregation keys. Atleast one transformation is required. See Text Transformation above for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyHeaderTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyHeaderTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyHttpMethod { } interface RuleGroupRuleStatementRateBasedStatementCustomKeyIp { } interface RuleGroupRuleStatementRateBasedStatementCustomKeyJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyLabelNamespace { /** * The namespace to use for aggregation */ namespace: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyQueryArgument { /** * A friendly name of the rule group. */ name: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. They are used in rate-based rule statements, to transform request components before using them as custom aggregation keys. Atleast one transformation is required. See Text Transformation above for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyQueryArgumentTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyQueryArgumentTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyQueryString { /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. They are used in rate-based rule statements, to transform request components before using them as custom aggregation keys. Atleast one transformation is required. See Text Transformation above for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyQueryStringTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyQueryStringTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyUriPath { /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. They are used in rate-based rule statements, to transform request components before using them as custom aggregation keys. Atleast one transformation is required. See Text Transformation above for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementCustomKeyUriPathTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementCustomKeyUriPathTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatement { /** * A logical rule statement used to combine other rule statements with AND logic. See AND Statement below for details. */ andStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementAndStatement; /** * Rule statement that inspects web traffic based on the Autonomous System Number (ASN) associated with the request's IP address. See ASN Match Statement below for details. */ asnMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatement; /** * A rule statement that defines a string match search for AWS WAF to apply to web requests. See Byte Match Statement below for details. */ byteMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatement; /** * A rule statement used to identify web requests based on country of origin. See GEO Match Statement below for details. */ geoMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatement; /** * A rule statement used to detect web requests coming from particular IP addresses or address ranges. See IP Set Reference Statement below for details. */ ipSetReferenceStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatement; /** * A rule statement that defines a string match search against labels that have been added to the web request by rules that have already run in the web ACL. See Label Match Statement below for details. */ labelMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementLabelMatchStatement; /** * A logical rule statement used to negate the results of another rule statement. See NOT Statement below for details. */ notStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementNotStatement; /** * A logical rule statement used to combine other rule statements with OR logic. See OR Statement below for details. */ orStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementOrStatement; /** * A rule statement used to search web request components for a match against a single regular expression. See Regex Match Statement below for details. */ regexMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatement; /** * A rule statement used to search web request components for matches with regular expressions. See Regex Pattern Set Reference Statement below for details. */ regexPatternSetReferenceStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatement; /** * A rule statement that compares a number of bytes against the size of a request component, using a comparison operator, such as greater than (>) or less than (<). See Size Constraint Statement below for more details. */ sizeConstraintStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatement; /** * An SQL injection match condition identifies the part of web requests, such as the URI or the query string, that you want AWS WAF to inspect. See SQL Injection Match Statement below for details. */ sqliMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatement; /** * A rule statement that defines a cross-site scripting (XSS) match search for AWS WAF to apply to web requests. See XSS Match Statement below for details. */ xssMatchStatement?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatement; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementAndStatement { /** * The statements to combine with `AND` logic. You can use any statements that can be nested. See Statement above for details. */ statements: outputs.wafv2.RuleGroupRuleStatement[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatement { /** * List of Autonomous System Numbers (ASNs). */ asnLists: number[]; /** * Configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. See Forwarded IP Config below for more details. */ forwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatementForwardedIpConfig; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatementForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatch; /** * The area within the portion of a web request that you want AWS WAF to search for `searchString`. Valid values include the following: `EXACTLY`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CONTAINS_WORD`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_ByteMatchStatement.html) for more information. */ positionalConstraint: string; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementPreParseTextTransformation[]; /** * A string value that you want AWS WAF to search for. AWS WAF searches only in the part of web requests that you designate for inspection in `fieldToMatch`. The maximum length of the value is 50 bytes. */ searchString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatement { /** * An array of two-character country codes, for example, [ "US", "CN" ], from the alpha-2 country ISO codes of the `ISO 3166` international standard. See the [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_GeoMatchStatement.html) for valid values. */ countryCodes: string[]; /** * The configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. See Forwarded IP Config below for details. */ forwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatementForwardedIpConfig; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatementForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatement { /** * ARN of the IP Set that this statement references. */ arn: string; /** * The configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. See IPSet Forwarded IP Config below for more details. */ ipSetForwardedIpConfig?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatementIpSetForwardedIpConfig; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatementIpSetForwardedIpConfig { /** * The match status to assign to the web request if the request doesn't have a valid IP address in the specified position. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; /** * The name of the HTTP header to use for the IP address. */ headerName: string; /** * The position in the header to search for the IP address. Valid values include: `FIRST`, `LAST`, or `ANY`. If `ANY` is specified and the header contains more than 10 IP addresses, AWS WAFv2 inspects the last 10. */ position: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementLabelMatchStatement { /** * The string to match against. */ key: string; /** * Specify whether you want to match using the label name or just the namespace. Valid values are `LABEL` or `NAMESPACE`. */ scope: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementNotStatement { /** * The statement to negate. You can use any statement that can be nested. See Statement above for details. */ statements: outputs.wafv2.RuleGroupRuleStatement[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementOrStatement { /** * The statements to combine with `OR` logic. You can use any statements that can be nested. See Statement above for details. */ statements: outputs.wafv2.RuleGroupRuleStatement[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementPreParseTextTransformation[]; /** * The string representing the regular expression. **Note:** The fixed quota for the maximum number of characters in each regex pattern is 200, which can't be changed. See [AWS WAF quotas](https://docs.aws.amazon.com/waf/latest/developerguide/limits.html) for details. */ regexString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatement { /** * ARN of the Regex Pattern Set that this statement references. */ arn: string; /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementPreParseTextTransformation[]; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatement { /** * The operator to use to compare the request part to the size setting. Valid values include: `EQ`, `NE`, `LE`, `LT`, `GE`, or `GT`. */ comparisonOperator: string; /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementPreParseTextTransformation[]; /** * The size, in bytes, to compare to the request part, after any transformations. Valid values are integers between 0 and 21474836480, inclusive. */ size: number; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementPreParseTextTransformation[]; /** * Sensitivity that you want AWS WAF to use to inspect for SQL injection attacks. Valid values include: `LOW`, `HIGH`. */ sensitivityLevel?: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementPreParseTextTransformation[]; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRegexMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementPreParseTextTransformation[]; /** * The string representing the regular expression. **Note:** The fixed quota for the maximum number of characters in each regex pattern is 200, which can't be changed. See [AWS WAF quotas](https://docs.aws.amazon.com/waf/latest/developerguide/limits.html) for details. */ regexString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRegexMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRegexMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRegexMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatement { /** * ARN of the Regex Pattern Set that this statement references. */ arn: string; /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementPreParseTextTransformation[]; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementTextTransformation[]; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchMethod { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementRegexPatternSetReferenceStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementSizeConstraintStatement { /** * The operator to use to compare the request part to the size setting. Valid values include: `EQ`, `NE`, `LE`, `LT`, `GE`, or `GT`. */ comparisonOperator: string; /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementPreParseTextTransformation[]; /** * The size, in bytes, to compare to the request part, after any transformations. Valid values are integers between 0 and 21474836480, inclusive. */ size: number; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementTextTransformation[]; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchMethod { } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementSizeConstraintStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementSizeConstraintStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementSizeConstraintStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementSqliMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementPreParseTextTransformation[]; /** * Sensitivity that you want AWS WAF to use to inspect for SQL injection attacks. Valid values include: `LOW`, `HIGH`. */ sensitivityLevel?: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementSqliMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementSqliMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementSqliMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementXssMatchStatement { /** * The part of a web request that you want AWS WAF to inspect. See Field to Match below for details. */ fieldToMatch?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatch; /** * Text transformations to apply to the raw query string before AWS WAF parses the string into individual query arguments, and before any `textTransformation` is applied. Supported only when `fieldToMatch` specifies `singleQueryArgument` or `allQueryArguments`. Maximum of 10. See Pre-Parse Text Transformation below for details. */ preParseTextTransformations?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementPreParseTextTransformation[]; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. * At least one required. * See Text Transformation below for details. */ textTransformations: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementTextTransformation[]; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body, which immediately follows the request headers. */ body?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchBody; /** * Inspect the cookies in the web request. See Cookies below for details. */ cookies?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchCookies; /** * Inspect the request headers. See Header Order below for details. */ headerOrders?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below for details. */ headers?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchHeader[]; /** * Inspect the JA3 fingerprint. See `ja3Fingerprint` below for details. */ ja3Fingerprint?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchJa3Fingerprint; /** * Inspect the JA4 fingerprint. See `ja4Fingerprint` below for details. */ ja4Fingerprint?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body for details. */ jsonBody?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchMethod; /** * Inspect the query string. This is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below for details. */ singleHeader?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below for details. */ singleQueryArgument?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect the part of a URL that follows the "#" symbol, providing additional information about the resource. See URI Fragment below for details. */ uriFragment?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. This is the part of a web request that identifies a resource, for example, `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchUriPath; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchAllQueryArguments { } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchBody { oversizeHandling?: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchCookies { /** * The filter to use to identify the subset of cookies to inspect in a web request. You must specify exactly one setting: either `all`, `includedCookies` or `excludedCookies`. More details: [CookieMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_CookieMatchPattern.html) */ matchPatterns: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchCookiesMatchPattern[]; /** * The parts of the cookies to inspect with the rule inspection criteria. If you specify All, AWS WAF inspects both keys and values. Valid values: `ALL`, `KEY`, `VALUE` */ matchScope: string; /** * What AWS WAF should do if the cookies of the request are larger than AWS WAF can inspect. AWS WAF does not support inspecting the entire contents of request cookies when they exceed 8 KB (8192 bytes) or 200 total cookies. The underlying host service forwards a maximum of 200 cookies and at most 8 KB of cookie contents to AWS WAF. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH` */ oversizeHandling: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchCookiesMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll; excludedCookies?: string[]; includedCookies?: string[]; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll { } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchHeader { /** * The filter to use to identify the subset of headers to inspect in a web request. The `matchPattern` block supports only one of the following arguments: */ matchPattern: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchHeaderMatchPattern; /** * The parts of the headers to inspect with the rule inspection criteria. If you specify `All`, AWS WAF inspects both keys and values. Valid values include the following: `ALL`, `Key`, `Value`. */ matchScope: string; /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchHeaderMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll; /** * An array of strings that will be used for inspecting headers that do not have a key that matches one of the provided values. */ excludedHeaders?: string[]; /** * An array of strings that will be used for inspecting headers that have a key that matches one of the provided values. */ includedHeaders?: string[]; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll { } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchHeaderOrder { /** * Oversize handling tells AWS WAF what to do with a web request when the request component that the rule inspects is over the limits. Valid values include the following: `CONTINUE`, `MATCH`, `NO_MATCH`. See the AWS [documentation](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-oversize-handling.html) for more information. */ oversizeHandling: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchJa3Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA3 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchJa4Fingerprint { /** * The match status to assign to the web request if the request doesn't have a JA4 fingerprint. Valid values include: `MATCH` or `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchJsonBody { /** * What to do when JSON parsing fails. Defaults to evaluating up to the first parsing failure. Valid values are `EVALUATE_AS_STRING`, `MATCH` and `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * The patterns to look for in the JSON body. You must specify exactly one setting: either `all` or `includedPaths`. See [JsonMatchPattern](https://docs.aws.amazon.com/waf/latest/APIReference/API_JsonMatchPattern.html) for details. */ matchPattern: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern; /** * The parts of the JSON to match against using the `matchPattern`. Valid values are `ALL`, `KEY` and `VALUE`. */ matchScope: string; /** * What to do if the body is larger than can be inspected. Valid values are `CONTINUE` (default), `MATCH` and `NO_MATCH`. */ oversizeHandling?: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern { /** * An empty configuration block that is used for inspecting all headers. */ all?: outputs.wafv2.RuleGroupRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll; includedPaths?: string[]; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchMethod { } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchQueryString { } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchSingleHeader { /** * The name of the header to inspect. Maximum length of 64. AWS returns header names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchSingleQueryArgument { /** * The name of the query argument to inspect. Maximum length of 30. AWS returns query argument names in lower case, so provide the name as lower case characters to avoid a perpetual diff. */ name: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchUriFragment { /** * What AWS WAF should do if it fails to completely parse the JSON body. Valid values are `MATCH` (default) and `NO_MATCH`. */ fallbackBehavior: string; } interface RuleGroupRuleStatementXssMatchStatementFieldToMatchUriPath { } interface RuleGroupRuleStatementXssMatchStatementPreParseTextTransformation { /** * The relative processing order for the pre-parse text transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before parsing the query string. */ priority: number; /** * The pre-parse text transformation to apply to the raw query string. Valid values are `NONE`, `URL_DECODE`, `URL_DECODE_UNI`, `COMBINE_DUPLICATE_QUERY_ARGS_BY_COMMA`, and `REPLACE_SEMICOLONS_WITH_AMPERSANDS`. See the Pre-Parse Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_PreParseTextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleStatementXssMatchStatementTextTransformation { /** * The relative processing order for multiple transformations that are defined for a rule statement. AWS WAF processes all transformations, from lowest priority to highest, before inspecting the transformed content. */ priority: number; /** * The transformation to apply, please refer to the Text Transformation [documentation](https://docs.aws.amazon.com/waf/latest/APIReference/API_TextTransformation.html) for more details. */ type: string; } interface RuleGroupRuleVisibilityConfig { /** * A boolean indicating whether the associated resource sends metrics to CloudWatch. For the list of available metrics, see [AWS WAF Metrics](https://docs.aws.amazon.com/waf/latest/developerguide/monitoring-cloudwatch.html#waf-metrics). */ cloudwatchMetricsEnabled: boolean; /** * A friendly name of the CloudWatch metric. The name can contain only alphanumeric characters (A-Z, a-z, 0-9) hyphen(-) and underscore (_), with length from one to 128 characters. It can't contain whitespace or metric names reserved for AWS WAF, for example `All` and `Default_Action`. */ metricName: string; /** * A boolean indicating whether AWS WAF should store a sampling of the web requests that match the rules. You can view the sampled requests through the AWS WAF console. */ sampledRequestsEnabled: boolean; } interface RuleGroupVisibilityConfig { /** * A boolean indicating whether the associated resource sends metrics to CloudWatch. For the list of available metrics, see [AWS WAF Metrics](https://docs.aws.amazon.com/waf/latest/developerguide/monitoring-cloudwatch.html#waf-metrics). */ cloudwatchMetricsEnabled: boolean; /** * A friendly name of the CloudWatch metric. The name can contain only alphanumeric characters (A-Z, a-z, 0-9) hyphen(-) and underscore (_), with length from one to 128 characters. It can't contain whitespace or metric names reserved for AWS WAF, for example `All` and `Default_Action`. */ metricName: string; /** * A boolean indicating whether AWS WAF should store a sampling of the web requests that match the rules. You can view the sampled requests through the AWS WAF console. */ sampledRequestsEnabled: boolean; } interface WebAclAssociationConfig { /** * Customizes the request body that your protected resource forward to AWS WAF for inspection. See `requestBody` below for details. */ requestBodies?: outputs.wafv2.WebAclAssociationConfigRequestBody[]; } interface WebAclAssociationConfigRequestBody { /** * Customizes the request body that your protected Amazon API Gateway REST APIs forward to AWS WAF for inspection. Applicable only when `scope` is set to `CLOUDFRONT`. See `apiGateway` below for details. */ apiGateway?: outputs.wafv2.WebAclAssociationConfigRequestBodyApiGateway; /** * Customizes the request body that your protected Amazon App Runner services forward to AWS WAF for inspection. Applicable only when `scope` is set to `REGIONAL`. See `appRunnerService` below for details. */ appRunnerService?: outputs.wafv2.WebAclAssociationConfigRequestBodyAppRunnerService; /** * Customizes the request body that your protected Amazon CloudFront distributions forward to AWS WAF for inspection. Applicable only when `scope` is set to `REGIONAL`. See `cloudfront` below for details. */ cloudfront?: outputs.wafv2.WebAclAssociationConfigRequestBodyCloudfront; /** * Customizes the request body that your protected Amazon Cognito user pools forward to AWS WAF for inspection. Applicable only when `scope` is set to `REGIONAL`. See `cognitoUserPool` below for details. */ cognitoUserPool?: outputs.wafv2.WebAclAssociationConfigRequestBodyCognitoUserPool; /** * Customizes the request body that your protected AWS Verfied Access instances forward to AWS WAF for inspection. Applicable only when `scope` is set to `REGIONAL`. See `verifiedAccessInstance` below for details. */ verifiedAccessInstance?: outputs.wafv2.WebAclAssociationConfigRequestBodyVerifiedAccessInstance; } interface WebAclAssociationConfigRequestBodyApiGateway { /** * Specifies the maximum size of the web request body component that an associated Amazon API Gateway REST APIs should send to AWS WAF for inspection. This applies to statements in the web ACL that inspect the body or JSON body. Valid values are `KB_16`, `KB_32`, `KB_48` and `KB_64`. */ defaultSizeInspectionLimit: string; } interface WebAclAssociationConfigRequestBodyAppRunnerService { /** * Specifies the maximum size of the web request body component that an associated Amazon App Runner services should send to AWS WAF for inspection. This applies to statements in the web ACL that inspect the body or JSON body. Valid values are `KB_16`, `KB_32`, `KB_48` and `KB_64`. */ defaultSizeInspectionLimit: string; } interface WebAclAssociationConfigRequestBodyCloudfront { /** * Specifies the maximum size of the web request body component that an associated Amazon CloudFront distribution should send to AWS WAF for inspection. This applies to statements in the web ACL that inspect the body or JSON body. Valid values are `KB_16`, `KB_32`, `KB_48` and `KB_64`. */ defaultSizeInspectionLimit: string; } interface WebAclAssociationConfigRequestBodyCognitoUserPool { /** * Specifies the maximum size of the web request body component that an associated Amazon Cognito user pools should send to AWS WAF for inspection. This applies to statements in the web ACL that inspect the body or JSON body. Valid values are `KB_16`, `KB_32`, `KB_48` and `KB_64`. */ defaultSizeInspectionLimit: string; } interface WebAclAssociationConfigRequestBodyVerifiedAccessInstance { /** * Specifies the maximum size of the web request body component that an associated AWS Verified Access instances should send to AWS WAF for inspection. This applies to statements in the web ACL that inspect the body or JSON body. Valid values are `KB_16`, `KB_32`, `KB_48` and `KB_64`. */ defaultSizeInspectionLimit: string; } interface WebAclCaptchaConfig { /** * Defines custom immunity time. See `immunityTimeProperty` below for details. */ immunityTimeProperty?: outputs.wafv2.WebAclCaptchaConfigImmunityTimeProperty; } interface WebAclCaptchaConfigImmunityTimeProperty { /** * The amount of time, in seconds, that a CAPTCHA or challenge timestamp is considered valid by AWS WAF. The default setting is 300. */ immunityTime?: number; } interface WebAclChallengeConfig { /** * Defines custom immunity time. See `immunityTimeProperty` below for details. */ immunityTimeProperty?: outputs.wafv2.WebAclChallengeConfigImmunityTimeProperty; } interface WebAclChallengeConfigImmunityTimeProperty { /** * The amount of time, in seconds, that a CAPTCHA or challenge timestamp is considered valid by AWS WAF. The default setting is 300. */ immunityTime?: number; } interface WebAclCustomResponseBody { /** * Payload of the custom response. */ content: string; /** * Type of content in the payload that you are defining in the `content` argument. Valid values are `TEXT_PLAIN`, `TEXT_HTML`, or `APPLICATION_JSON`. */ contentType: string; /** * Unique key identifying the custom response body. This is referenced by the `customResponseBodyKey` argument in the `customResponse` block. */ key: string; } interface WebAclDataProtectionConfig { /** * A block for data protection configurations for specific web request field types. See `dataProtection` block for details. */ dataProtections?: outputs.wafv2.WebAclDataProtectionConfigDataProtection[]; } interface WebAclDataProtectionConfigDataProtection { /** * Specifies how to protect the field. Valid values are `SUBSTITUTION` or `HASH`. */ action: string; /** * Boolean to specify whether to also exclude any rate-based rule details from the data protection you have enabled for a given field. */ excludeRateBasedDetails?: boolean; /** * Boolean to specify whether to also exclude any rule match details from the data protection you have enabled for a given field. AWS WAF logs these details for non-terminating matching rules and for the terminating matching rule. */ excludeRuleMatchDetails?: boolean; /** * Specifies the field type and optional keys to apply the protection behavior to. See `field` block below for details. */ field: outputs.wafv2.WebAclDataProtectionConfigDataProtectionField; } interface WebAclDataProtectionConfigDataProtectionField { /** * Array of strings to specify the keys to protect for the specified field type. If you don't specify any key, then all keys for the field type are protected. */ fieldKeys?: string[]; /** * Specifies the web request component type to protect. Valid Values are `SINGLE_HEADER`, `SINGLE_COOKIE`, `SINGLE_QUERY_ARGUMENT`, `QUERY_STRING`, `BODY`. */ fieldType: string; } interface WebAclDefaultAction { /** * Specifies that AWS WAF should allow requests by default. See `allow` below for details. */ allow?: outputs.wafv2.WebAclDefaultActionAllow; /** * Specifies that AWS WAF should block requests by default. See `block` below for details. */ block?: outputs.wafv2.WebAclDefaultActionBlock; } interface WebAclDefaultActionAllow { /** * Defines custom handling for the web request. See `customRequestHandling` below for details. */ customRequestHandling?: outputs.wafv2.WebAclDefaultActionAllowCustomRequestHandling; } interface WebAclDefaultActionAllowCustomRequestHandling { /** * The `insertHeader` blocks used to define HTTP headers added to the request. See `insertHeader` below for details. */ insertHeaders: outputs.wafv2.WebAclDefaultActionAllowCustomRequestHandlingInsertHeader[]; } interface WebAclDefaultActionAllowCustomRequestHandlingInsertHeader { /** * Name of the custom header. For custom request header insertion, when AWS WAF inserts the header into the request, it prefixes this name `x-amzn-waf-`, to avoid confusion with the headers that are already in the request. For example, for the header name `sample`, AWS WAF inserts the header `x-amzn-waf-sample`. */ name: string; /** * Value of the custom header. */ value: string; } interface WebAclDefaultActionBlock { /** * Defines a custom response for the web request. See `customResponse` below for details. */ customResponse?: outputs.wafv2.WebAclDefaultActionBlockCustomResponse; } interface WebAclDefaultActionBlockCustomResponse { /** * References the response body that you want AWS WAF to return to the web request client. This must reference a `key` defined in a `customResponseBody` block of this resource. */ customResponseBodyKey?: string; /** * The HTTP status code to return to the client. */ responseCode: number; /** * The `responseHeader` blocks used to define the HTTP response headers added to the response. See `responseHeader` below for details. */ responseHeaders?: outputs.wafv2.WebAclDefaultActionBlockCustomResponseResponseHeader[]; } interface WebAclDefaultActionBlockCustomResponseResponseHeader { /** * Name of the custom header. For custom request header insertion, when AWS WAF inserts the header into the request, it prefixes this name `x-amzn-waf-`, to avoid confusion with the headers that are already in the request. For example, for the header name `sample`, AWS WAF inserts the header `x-amzn-waf-sample`. */ name: string; /** * Value of the custom header. */ value: string; } interface WebAclLoggingConfigurationLoggingFilter { /** * Default handling for logs that don't match any of the specified filtering conditions. Valid values for `defaultBehavior` are `KEEP` or `DROP`. */ defaultBehavior: string; /** * Filter(s) that you want to apply to the logs. See Filter below for more details. */ filters: outputs.wafv2.WebAclLoggingConfigurationLoggingFilterFilter[]; } interface WebAclLoggingConfigurationLoggingFilterFilter { /** * Parameter that determines how to handle logs that meet the conditions and requirements of the filter. The valid values for `behavior` are `KEEP` or `DROP`. */ behavior: string; /** * Match condition(s) for the filter. See Condition below for more details. */ conditions: outputs.wafv2.WebAclLoggingConfigurationLoggingFilterFilterCondition[]; /** * Logic to apply to the filtering conditions. You can specify that a log must match all conditions or at least one condition in order to satisfy the filter. Valid values for `requirement` are `MEETS_ALL` or `MEETS_ANY`. */ requirement: string; } interface WebAclLoggingConfigurationLoggingFilterFilterCondition { /** * Configuration for a single action condition. See Action Condition below for more details. */ actionCondition?: outputs.wafv2.WebAclLoggingConfigurationLoggingFilterFilterConditionActionCondition; /** * Condition for a single label name. See Label Name Condition below for more details. */ labelNameCondition?: outputs.wafv2.WebAclLoggingConfigurationLoggingFilterFilterConditionLabelNameCondition; } interface WebAclLoggingConfigurationLoggingFilterFilterConditionActionCondition { /** * Action setting that a log record must contain in order to meet the condition. Valid values for `action` are `ALLOW`, `BLOCK`, `COUNT`, `CAPTCHA`, `CHALLENGE` and `EXCLUDED_AS_COUNT`. */ action: string; } interface WebAclLoggingConfigurationLoggingFilterFilterConditionLabelNameCondition { /** * Name of the label that a log record must contain in order to meet the condition. It must be a [fully qualified label name](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-label-requirements.html#waf-rule-label-syntax), which includes a prefix, optional namespaces, and the label name itself. The prefix identifies the rule group or web ACL context of the rule that added the label. */ labelName: string; } interface WebAclLoggingConfigurationRedactedField { /** * HTTP method to be redacted. It must be specified as an empty configuration block `{}`. The method indicates the type of operation that the request is asking the origin to perform. */ method?: outputs.wafv2.WebAclLoggingConfigurationRedactedFieldMethod; /** * Whether to redact the query string. It must be specified as an empty configuration block `{}`. The query string is the part of a URL that appears after a `?` character, if any. */ queryString?: outputs.wafv2.WebAclLoggingConfigurationRedactedFieldQueryString; /** * "singleHeader" refers to the redaction of a single header. For more information, please see the details below under Single Header. */ singleHeader?: outputs.wafv2.WebAclLoggingConfigurationRedactedFieldSingleHeader; /** * Configuration block that redacts the request URI path. It should be specified as an empty configuration block `{}`. The URI path is the part of a web request that identifies a resource, such as `/images/daily-ad.jpg`. */ uriPath?: outputs.wafv2.WebAclLoggingConfigurationRedactedFieldUriPath; } interface WebAclLoggingConfigurationRedactedFieldMethod { } interface WebAclLoggingConfigurationRedactedFieldQueryString { } interface WebAclLoggingConfigurationRedactedFieldSingleHeader { /** * Name of the query header to redact. This setting must be provided in lowercase characters. */ name: string; } interface WebAclLoggingConfigurationRedactedFieldUriPath { } interface WebAclRule { /** * Action that AWS WAF should take on a web request when it matches the rule's statement. This is used only for rules whose **statements do not reference a rule group**. See `action` for details. */ action?: outputs.wafv2.WebAclRuleAction; /** * Specifies how AWS WAF should handle CAPTCHA evaluations. See `captchaConfig` below for details. */ captchaConfig?: outputs.wafv2.WebAclRuleCaptchaConfig; /** * Specifies how AWS WAF should handle Challenge evaluations on the rule level. See `challengeConfig` below for details. */ challengeConfig?: outputs.wafv2.WebAclRuleChallengeConfig; /** * Friendly name of the rule. Note that the provider assumes that rules with names matching this pattern, `^ShieldMitigationRuleGroup___.*`, are AWS-added for [automatic application layer DDoS mitigation activities](https://docs.aws.amazon.com/waf/latest/developerguide/ddos-automatic-app-layer-response-rg.html). Such rules will be ignored by the provider unless you explicitly include them in your configuration (for example, by using the AWS CLI to discover their properties and creating matching configuration). However, since these rules are owned and managed by AWS, you may get permission errors. */ name: string; /** * Override action to apply to the rules in a rule group. Used only for rule **statements that reference a rule group**, like `ruleGroupReferenceStatement` and `managedRuleGroupStatement`. See `overrideAction` below for details. */ overrideAction?: outputs.wafv2.WebAclRuleOverrideAction; /** * If you define more than one Rule in a WebACL, AWS WAF evaluates each request against the `rules` in order based on the value of `priority`. AWS WAF processes rules with lower priority first. */ priority: number; /** * Labels to apply to web requests that match the rule match statement. See `ruleLabel` below for details. */ ruleLabels?: outputs.wafv2.WebAclRuleRuleLabel[]; /** * The AWS WAF processing statement for the rule, for example `byteMatchStatement` or `geoMatchStatement`. See `statement` below for details. */ statement: outputs.wafv2.WebAclRuleStatement; /** * Defines and enables Amazon CloudWatch metrics and web request sample collection. See `visibilityConfig` below for details. */ visibilityConfig: outputs.wafv2.WebAclRuleVisibilityConfig; } interface WebAclRuleAction { /** * Allow the request. See Allow below. */ allow?: outputs.wafv2.WebAclRuleActionAllow; /** * Block the request. See Block below. */ block?: outputs.wafv2.WebAclRuleActionBlock; /** * Present a CAPTCHA challenge. See Captcha below. */ captcha?: outputs.wafv2.WebAclRuleActionCaptcha; /** * Present a silent challenge. See Challenge below. */ challenge?: outputs.wafv2.WebAclRuleActionChallenge; /** * Count the request without blocking. See Count below. */ count?: outputs.wafv2.WebAclRuleActionCount; } interface WebAclRuleActionAllow { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleActionAllowCustomRequestHandling; } interface WebAclRuleActionAllowCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleActionAllowCustomRequestHandlingInsertHeader[]; } interface WebAclRuleActionAllowCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleActionBlock { /** * Custom response configuration. See Custom Response below. */ customResponse?: outputs.wafv2.WebAclRuleActionBlockCustomResponse; } interface WebAclRuleActionBlockCustomResponse { /** * Key of a custom response body defined in the Web ACL. */ customResponseBodyKey?: string; /** * HTTP status code to return (200-599). */ responseCode: number; /** * Custom headers to include in the response. See Response Header below. */ responseHeaders?: outputs.wafv2.WebAclRuleActionBlockCustomResponseResponseHeader[]; } interface WebAclRuleActionBlockCustomResponseResponseHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleActionCaptcha { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleActionCaptchaCustomRequestHandling; } interface WebAclRuleActionCaptchaCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleActionCaptchaCustomRequestHandlingInsertHeader[]; } interface WebAclRuleActionCaptchaCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleActionChallenge { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleActionChallengeCustomRequestHandling; } interface WebAclRuleActionChallengeCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleActionChallengeCustomRequestHandlingInsertHeader[]; } interface WebAclRuleActionChallengeCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleActionCount { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleActionCountCustomRequestHandling; } interface WebAclRuleActionCountCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleActionCountCustomRequestHandlingInsertHeader[]; } interface WebAclRuleActionCountCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleCaptchaConfig { /** * Immunity time configuration. See Immunity Time Property below. */ immunityTimeProperty?: outputs.wafv2.WebAclRuleCaptchaConfigImmunityTimeProperty; } interface WebAclRuleCaptchaConfigImmunityTimeProperty { /** * Immunity time in seconds (60-259200). */ immunityTime?: number; } interface WebAclRuleChallengeConfig { /** * Immunity time configuration. See Immunity Time Property below. */ immunityTimeProperty?: outputs.wafv2.WebAclRuleChallengeConfigImmunityTimeProperty; } interface WebAclRuleChallengeConfigImmunityTimeProperty { /** * Immunity time in seconds (60-259200). */ immunityTime?: number; } interface WebAclRuleGroupAssociationManagedRuleGroup { /** * Additional information that's used by a managed rule group. Only one rule attribute is allowed in each config. See below. */ managedRuleGroupConfigs?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigs; /** * Name of the managed rule group. */ name: string; /** * Override actions for specific rules within the rule group. See below. */ ruleActionOverrides?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverride[]; /** * Name of the managed rule group vendor. For AWS managed rule groups, this is `AWS`. */ vendorName: string; /** * Version of the managed rule group. If not specified, the default version is used. */ version?: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigs { /** * Additional configuration for using the Account Creation Fraud Prevention managed rule group. Use this to specify information such as the registration page of your application and the type of content to accept or reject from the client. See below. */ awsManagedRulesAcfpRuleSet?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSet; /** * Configuration for using the anti-DDoS managed rule group. See below. */ awsManagedRulesAntiDdosRuleSet?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSet; /** * Additional configuration for using the Account Takeover Protection managed rule group. Use this to specify information such as the sign-in page of your application and the type of content to accept or reject from the client. See below. */ awsManagedRulesAtpRuleSet?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSet; /** * Additional configuration for using the Bot Control managed rule group. Use this to specify the inspection level that you want to use. See below. */ awsManagedRulesBotControlRuleSet?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesBotControlRuleSet; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSet { /** * Path of the account creation endpoint for your application. This is the page on your website that accepts the completed registration form for a new user. This page must accept POST requests. */ creationPath: string; /** * Whether or not to allow the use of regular expressions in the login page path. */ enableRegexInPath: boolean; /** * Path of the account registration endpoint for your application. This is the page on your website that presents the registration form to new users. This page must accept GET text/html requests. */ registrationPagePath: string; /** * Criteria for inspecting login requests, used by the ATP rule group to validate credentials usage. See below. */ requestInspection?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspection; /** * Criteria for inspecting responses to login requests, used by the ATP rule group to track login failure rates. Note that Response Inspection is available only on web ACLs that protect CloudFront distributions. See below. */ responseInspection?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspection; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspection { /** * Names of the fields in the request payload that contain your customer's primary physical address. See below. */ addressFields?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionAddressFields; /** * Name of the field in the request payload that contains your customer's email. See below. */ emailField?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionEmailField; /** * Details about your login page password field. See below. */ passwordField?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionPasswordField; /** * Payload type for your login endpoint, either JSON or form encoded. */ payloadType: string; /** * Names of the fields in the request payload that contain your customer's primary phone number. See below. */ phoneNumberFields?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionPhoneNumberFields; /** * Details about your login page username field. See below. */ usernameField?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionUsernameField; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionAddressFields { /** * Names of the address fields. */ identifiers: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionEmailField { /** * Name of the field in the request payload that contains your customer's email. */ identifier: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionPasswordField { /** * Name of the password field. */ identifier: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionPhoneNumberFields { /** * Names of the phone number fields. */ identifiers: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetRequestInspectionUsernameField { /** * Name of the username field. */ identifier: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspection { /** * Configures inspection of the response body. See below. */ bodyContains?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionBodyContains; /** * Configures inspection of the response header. See below. */ header?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionHeader; /** * Configures inspection of the response JSON. See below. */ json?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionJson; /** * Configures inspection of the response status code. See below. */ statusCode?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionStatusCode; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionBodyContains { /** * Strings in the body of the response that indicate a failed login attempt. */ failureStrings: string[]; /** * Strings in the body of the response that indicate a successful login attempt. */ successStrings: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionHeader { /** * Values in the response header with the specified name that indicate a failed login attempt. */ failureValues: string[]; /** * Name of the header to match against. The name must be an exact match, including case. */ name: string; /** * Values in the response header with the specified name that indicate a successful login attempt. */ successValues: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionJson { /** * Strings that indicate a failed login or account creation attempt */ failureValues: string[]; /** * Identifier for the value to match against in the JSON. */ identifier: string; /** * Strings that indicate a successful login or account creation attempt */ successValues: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAcfpRuleSetResponseInspectionStatusCode { /** * Status codes in the response that indicate a failed login attempt. */ failureCodes: number[]; /** * Status codes in the response that indicate a successful login attempt. */ successCodes: number[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSet { /** * Configuration for the request handling that's applied by the managed rule group rules `ChallengeAllDuringEvent` and `ChallengeDDoSRequests` during a distributed denial of service (DDoS) attack. See below. */ clientSideActionConfig?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSetClientSideActionConfig; /** * Sensitivity that the rule group rule DDoSRequests uses when matching against the DDoS suspicion labeling on a request. Valid values are `LOW` (Default), `MEDIUM`, and `HIGH`. */ sensitivityToBlock: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSetClientSideActionConfig { /** * Configuration for the use of the `AWSManagedRulesAntiDDoSRuleSet` rules `ChallengeAllDuringEvent` and `ChallengeDDoSRequests`. See below. */ challenge?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallenge; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallenge { /** * Block for the list of the regular expressions to match against the web request URI, used to identify requests that can't handle a silent browser challenge. See below. */ exemptUriRegularExpressions?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallengeExemptUriRegularExpression[]; /** * Sensitivity that the rule group rule ChallengeDDoSRequests uses when matching against the DDoS suspicion labeling on a request. Valid values are `LOW`, `MEDIUM` and `HIGH` (Default). */ sensitivity: string; /** * Configuration whether to use the `AWSManagedRulesAntiDDoSRuleSet` rules `ChallengeAllDuringEvent` and `ChallengeDDoSRequests` in the rule group evaluation. Valid values are `ENABLED` and `DISABLED`. */ usageOfAction: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallengeExemptUriRegularExpression { /** * Regular expression string. */ regexString?: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSet { /** * Whether or not to allow the use of regular expressions in the login page path. */ enableRegexInPath: boolean; /** * Path of the login endpoint for your application. */ loginPath: string; /** * Criteria for inspecting login requests, used by the ATP rule group to validate credentials usage. See below. */ requestInspection?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetRequestInspection; /** * Criteria for inspecting responses to login requests, used by the ATP rule group to track login failure rates. Note that Response Inspection is available only on web ACLs that protect CloudFront distributions. See below. */ responseInspection?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspection; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetRequestInspection { /** * Details about your login page password field. See below. */ passwordField?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetRequestInspectionPasswordField; /** * Payload type for your login endpoint, either JSON or form encoded. */ payloadType: string; /** * Details about your login page username field. See below. */ usernameField?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetRequestInspectionUsernameField; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetRequestInspectionPasswordField { /** * Name of the password field. */ identifier: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetRequestInspectionUsernameField { /** * Name of the username field. */ identifier: string; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspection { /** * Configures inspection of the response body. See below. */ bodyContains?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionBodyContains; /** * Configures inspection of the response header. See below. */ header?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionHeader; /** * Configures inspection of the response JSON. See below. */ json?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionJson; /** * Configures inspection of the response status code. See below. */ statusCode?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionStatusCode; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionBodyContains { /** * Strings in the body of the response that indicate a failed login attempt. */ failureStrings: string[]; /** * Strings in the body of the response that indicate a successful login attempt. */ successStrings: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionHeader { /** * Values in the response header with the specified name that indicate a failed login attempt. */ failureValues: string[]; /** * Name of the header to match against. The name must be an exact match, including case. */ name: string; /** * Values in the response header with the specified name that indicate a successful login attempt. */ successValues: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionJson { /** * Strings that indicate a failed login or account creation attempt */ failureValues: string[]; /** * Identifier for the value to match against in the JSON. */ identifier: string; /** * Strings that indicate a successful login or account creation attempt */ successValues: string[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesAtpRuleSetResponseInspectionStatusCode { /** * Status codes in the response that indicate a failed login attempt. */ failureCodes: number[]; /** * Status codes in the response that indicate a successful login attempt. */ successCodes: number[]; } interface WebAclRuleGroupAssociationManagedRuleGroupManagedRuleGroupConfigsAwsManagedRulesBotControlRuleSet { /** * Applies only to the targeted inspection level. Determines whether to use machine learning (ML) to analyze your web traffic for bot-related activity. Defaults to `false`. */ enableMachineLearning: boolean; /** * Inspection level to use for the Bot Control rule group. */ inspectionLevel: string; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverride { /** * Action to use instead of the rule's original action. See below. */ actionToUse?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUse; /** * Name of the rule to override within the rule group. Verify the name carefully. With managed rule groups, WAF silently ignores any override that uses an invalid rule name. With customer-owned rule groups, invalid rule names in your overrides will cause web ACL updates to fail. An invalid rule name is any name that doesn't exactly match the case-sensitive name of an existing rule in the rule group. */ name: string; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUse { /** * Allow the request. See below. */ allow?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseAllow; /** * Block the request. See below. */ block?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseBlock; /** * Require CAPTCHA verification. See below. */ captcha?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCaptcha; /** * Require challenge verification. See below. */ challenge?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseChallenge; /** * Count the request without taking action. See below. */ count?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCount; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseAllow { /** * Custom handling for allowed requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseAllowCustomRequestHandling; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseAllowCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseBlock { /** * Custom response for blocked requests. See below. */ customResponse?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseBlockCustomResponse; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseBlockCustomResponse { /** * Key of a custom response body to use. */ customResponseBodyKey?: string; /** * HTTP response code to return (200-599). */ responseCode: number; /** * Headers to include in the response. See below. */ responseHeaders?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseBlockCustomResponseResponseHeader[]; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseBlockCustomResponseResponseHeader { /** * Name of the response header. */ name: string; /** * Value of the response header. */ value: string; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCaptcha { /** * Custom handling for CAPTCHA requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCaptchaCustomRequestHandling; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCaptchaCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseChallenge { /** * Custom handling for challenge requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseChallengeCustomRequestHandling; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseChallengeCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCount { /** * Custom handling for counted requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCountCustomRequestHandling; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCountCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationManagedRuleGroupRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationRuleGroupReference { /** * ARN of the Rule Group to associate with the Web ACL. */ arn: string; /** * Override actions for specific rules within the rule group. See below. */ ruleActionOverrides?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverride[]; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverride { /** * Action to use instead of the rule's original action. See below. */ actionToUse?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUse; /** * Name of the rule to override within the rule group. Verify the name carefully. With managed rule groups, WAF silently ignores any override that uses an invalid rule name. With customer-owned rule groups, invalid rule names in your overrides will cause web ACL updates to fail. An invalid rule name is any name that doesn't exactly match the case-sensitive name of an existing rule in the rule group. */ name: string; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUse { /** * Allow the request. See below. */ allow?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseAllow; /** * Block the request. See below. */ block?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseBlock; /** * Require CAPTCHA verification. See below. */ captcha?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCaptcha; /** * Require challenge verification. See below. */ challenge?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseChallenge; /** * Count the request without taking action. See below. */ count?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCount; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseAllow { /** * Custom handling for allowed requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseAllowCustomRequestHandling; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseAllowCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseBlock { /** * Custom response for blocked requests. See below. */ customResponse?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseBlockCustomResponse; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseBlockCustomResponse { /** * Key of a custom response body to use. */ customResponseBodyKey?: string; /** * HTTP response code to return (200-599). */ responseCode: number; /** * Headers to include in the response. See below. */ responseHeaders?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseBlockCustomResponseResponseHeader[]; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseBlockCustomResponseResponseHeader { /** * Name of the response header. */ name: string; /** * Value of the response header. */ value: string; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCaptcha { /** * Custom handling for CAPTCHA requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCaptchaCustomRequestHandling; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCaptchaCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseChallenge { /** * Custom handling for challenge requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseChallengeCustomRequestHandling; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseChallengeCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCount { /** * Custom handling for counted requests. See below. */ customRequestHandling?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCountCustomRequestHandling; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCountCustomRequestHandling { /** * Headers to insert into the request. See below. */ insertHeaders?: outputs.wafv2.WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader[]; } interface WebAclRuleGroupAssociationRuleGroupReferenceRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader { /** * Name of the header to insert. */ name: string; /** * Value of the header to insert. */ value: string; } interface WebAclRuleGroupAssociationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface WebAclRuleGroupAssociationVisibilityConfig { /** * Whether the associated resource sends metrics to CloudWatch. For the list of available metrics, see [AWS WAF Metrics](https://docs.aws.amazon.com/waf/latest/developerguide/monitoring-cloudwatch.html#waf-metrics). */ cloudwatchMetricsEnabled: boolean; /** * Friendly name of the CloudWatch metric. The name can contain only alphanumeric characters (A-Z, a-z, 0-9) hyphen(-) and underscore (\_), with length from one to 128 characters. It can't contain whitespace or metric names reserved for AWS WAF, for example `All` and `Default_Action`. */ metricName: string; /** * Whether AWS WAF should store a sampling of the web requests that match the rules. You can view the sampled requests through the AWS WAF console. */ sampledRequestsEnabled: boolean; } interface WebAclRuleOverrideAction { /** * Override the rule action with count. */ count?: outputs.wafv2.WebAclRuleOverrideActionCount; /** * Don't override the rule action. */ none?: outputs.wafv2.WebAclRuleOverrideActionNone; } interface WebAclRuleOverrideActionCount { } interface WebAclRuleOverrideActionNone { } interface WebAclRuleRuleLabel { /** * Label string (1-1024 characters, alphanumeric, underscore, hyphen, and colon characters only). */ name: string; } interface WebAclRuleStatement { /** * Logical AND statement that combines multiple statements. See And Statement below. */ andStatement?: outputs.wafv2.WebAclRuleStatementAndStatement; /** * Match requests based on Autonomous System Number (ASN). See ASN Match Statement below. */ asnMatchStatement?: outputs.wafv2.WebAclRuleStatementAsnMatchStatement; /** * Match requests based on byte patterns. See Byte Match Statement below. */ byteMatchStatement?: outputs.wafv2.WebAclRuleStatementByteMatchStatement; /** * Match requests by geographic location. See Geo Match Statement below. */ geoMatchStatement?: outputs.wafv2.WebAclRuleStatementGeoMatchStatement; /** * Reference to an IP set. See IP Set Reference Statement below. */ ipSetReferenceStatement?: outputs.wafv2.WebAclRuleStatementIpSetReferenceStatement; /** * Match requests based on labels. See Label Match Statement below. */ labelMatchStatement?: outputs.wafv2.WebAclRuleStatementLabelMatchStatement; /** * Reference to a managed rule group. See Managed Rule Group Statement below. */ managedRuleGroupStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatement; /** * Logical NOT statement that negates a single statement. See Not Statement below. */ notStatement?: outputs.wafv2.WebAclRuleStatementNotStatement; /** * Logical OR statement that combines multiple statements. See Or Statement below. */ orStatement?: outputs.wafv2.WebAclRuleStatementOrStatement; /** * Rate-based rule to track request rates. See Rate Based Statement below. */ rateBasedStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatement; /** * Match requests using regex patterns. See Regex Match Statement below. */ regexMatchStatement?: outputs.wafv2.WebAclRuleStatementRegexMatchStatement; /** * Reference to a regex pattern set. See Regex Pattern Set Reference Statement below. */ regexPatternSetReferenceStatement?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatement; /** * Reference to a rule group. See Rule Group Reference Statement below. */ ruleGroupReferenceStatement?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatement; /** * Match requests based on size constraints. See Size Constraint Statement below. */ sizeConstraintStatement?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatement; /** * Match requests that appear to contain SQL injection attacks. See SQL Injection Match Statement below. */ sqliMatchStatement?: outputs.wafv2.WebAclRuleStatementSqliMatchStatement; /** * Match requests that appear to contain cross-site scripting attacks. See Cross-Site Scripting Match Statement below. * * > **NOTE:** Logical statements (`andStatement`, `notStatement`, `orStatement`) can be nested up to 3 levels deep. This matches the nesting limit of the `aws.wafv2.WebAcl` resource. */ xssMatchStatement?: outputs.wafv2.WebAclRuleStatementXssMatchStatement; } interface WebAclRuleStatementAndStatement { /** * List of statements to combine. At least one statement is required. Each nested statement supports the same statement types listed above. */ statements?: outputs.wafv2.WebAclRuleStatement[]; } interface WebAclRuleStatementAsnMatchStatement { /** * List of Autonomous System Numbers (ASNs) to match against. ASNs are unique identifiers assigned to large internet networks managed by organizations such as internet service providers, enterprises, universities, or government agencies. */ asnLists: number[]; /** * Configuration for inspecting IP addresses in an HTTP header instead of using the web request origin. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementAsnMatchStatementForwardedIpConfig; } interface WebAclRuleStatementAsnMatchStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementByteMatchStatement { /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatch; /** * Area within the portion of the web request that you want WAF to search for `searchString`. Valid values: `EXACTLY`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CONTAINS_WORD`. */ positionalConstraint: string; /** * String value to search for within the request (1-200 characters). */ searchString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementByteMatchStatementTextTransformation[]; } interface WebAclRuleStatementByteMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementByteMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementByteMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementByteMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementByteMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementByteMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementByteMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementByteMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementByteMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementByteMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementGeoMatchStatement { /** * List of two-character country codes (ISO 3166-1 alpha-2). */ countryCodes: string[]; /** * Configuration for inspecting forwarded IP headers. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementGeoMatchStatementForwardedIpConfig; } interface WebAclRuleStatementGeoMatchStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementIpSetReferenceStatement { /** * ARN of the IP set to reference. */ arn: string; /** * Configuration for inspecting forwarded IP headers. See IP Set Forwarded IP Config below. */ ipSetForwardedIpConfig?: outputs.wafv2.WebAclRuleStatementIpSetReferenceStatementIpSetForwardedIpConfig; } interface WebAclRuleStatementIpSetReferenceStatementIpSetForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; /** * Position in the header to use. Valid values: `FIRST`, `LAST`, `ANY`. */ position: string; } interface WebAclRuleStatementLabelMatchStatement { /** * String to match against. For `LABEL` scope, include the name and any preceding namespace specifications. For `NAMESPACE` scope, include namespace strings. Labels are case sensitive and components must be separated by colon (e.g., `NS1:NS2:name`). */ key: string; /** * Whether to match using the label name or namespace. Valid values: `LABEL`, `NAMESPACE`. */ scope: string; } interface WebAclRuleStatementManagedRuleGroupStatement { managedRuleGroupConfigs?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfig[]; /** * Name of the managed rule group. */ name: string; /** * Override actions for specific rules within the managed rule group. See Rule Action Override below. */ ruleActionOverrides?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverride[]; /** * Additional statement to narrow the scope of requests that the managed rule group evaluates. See Scope Down Statement below. */ scopeDownStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatement; /** * Name of the managed rule group vendor (e.g., "AWS"). */ vendorName: string; /** * Version of the managed rule group. */ version?: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfig { awsManagedRulesAcfpRuleSet?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSet; awsManagedRulesAntiDdosRuleSet?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSet; awsManagedRulesAtpRuleSet?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSet; awsManagedRulesBotControlRuleSet?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesBotControlRuleSet; /** * @deprecated Use awsManagedRulesAtpRuleSet login_path */ loginPath?: string; /** * @deprecated Use awsManagedRulesAtpRuleSet request_inspection password_field */ passwordField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigPasswordField; /** * @deprecated Use awsManagedRulesAtpRuleSet request_inspection payload_type */ payloadType: string; /** * @deprecated Use awsManagedRulesAtpRuleSet request_inspection username_field */ usernameField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigUsernameField; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSet { creationPath: string; enableRegexInPath: boolean; registrationPagePath: string; requestInspection?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspection; responseInspection?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspection; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspection { addressFields?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionAddressFields; emailField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionEmailField; passwordField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionPasswordField; payloadType: string; phoneNumberFields?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionPhoneNumberFields; usernameField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionUsernameField; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionAddressFields { identifiers: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionEmailField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionPasswordField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionPhoneNumberFields { identifiers: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetRequestInspectionUsernameField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspection { bodyContains?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionBodyContains; /** * Use a header as an aggregate key. See Custom Key Header below. */ header?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionHeader; json?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionJson; statusCode?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionStatusCode; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionBodyContains { failureStrings: string[]; successStrings: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionHeader { failureValues: string[]; /** * Name of the rule. Must be unique within the Web ACL. */ name: string; successValues: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionJson { failureValues: string[]; identifier: string; successValues: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAcfpRuleSetResponseInspectionStatusCode { failureCodes: number[]; successCodes: number[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSet { clientSideActionConfig?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSetClientSideActionConfig; sensitivityToBlock: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSetClientSideActionConfig { /** * Present a silent challenge. See Challenge below. */ challenge?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallenge; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallenge { exemptUriRegularExpressions?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallengeExemptUriRegularExpression[]; sensitivity: string; usageOfAction: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAntiDdosRuleSetClientSideActionConfigChallengeExemptUriRegularExpression { /** * Regular expression pattern to match against the web request component. */ regexString?: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSet { enableRegexInPath: boolean; loginPath: string; requestInspection?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetRequestInspection; responseInspection?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspection; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetRequestInspection { passwordField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetRequestInspectionPasswordField; payloadType: string; usernameField?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetRequestInspectionUsernameField; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetRequestInspectionPasswordField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetRequestInspectionUsernameField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspection { bodyContains?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionBodyContains; /** * Use a header as an aggregate key. See Custom Key Header below. */ header?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionHeader; json?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionJson; statusCode?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionStatusCode; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionBodyContains { failureStrings: string[]; successStrings: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionHeader { failureValues: string[]; /** * Name of the rule. Must be unique within the Web ACL. */ name: string; successValues: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionJson { failureValues: string[]; identifier: string; successValues: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesAtpRuleSetResponseInspectionStatusCode { failureCodes: number[]; successCodes: number[]; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigAwsManagedRulesBotControlRuleSet { enableMachineLearning: boolean; inspectionLevel: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigPasswordField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementManagedRuleGroupConfigUsernameField { identifier: string; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverride { /** * Override action to use for the rule. See Action below. */ actionToUse?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUse; /** * Name of the rule to override. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUse { /** * Allow the request. See Allow below. */ allow?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseAllow; /** * Block the request. See Block below. */ block?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseBlock; /** * Present a CAPTCHA challenge. See Captcha below. */ captcha?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCaptcha; /** * Present a silent challenge. See Challenge below. */ challenge?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseChallenge; count?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCount; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseAllow { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseAllowCustomRequestHandling; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseAllowCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseBlock { /** * Custom response configuration. See Custom Response below. */ customResponse?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseBlockCustomResponse; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseBlockCustomResponse { /** * Key of a custom response body defined in the Web ACL. */ customResponseBodyKey?: string; /** * HTTP status code to return (200-599). */ responseCode: number; /** * Custom headers to include in the response. See Response Header below. */ responseHeaders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseBlockCustomResponseResponseHeader[]; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseBlockCustomResponseResponseHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCaptcha { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandling; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseChallenge { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseChallengeCustomRequestHandling; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseChallengeCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCount { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCountCustomRequestHandling; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCountCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementManagedRuleGroupStatementRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatement { /** * Logical AND statement that combines multiple statements. See And Statement above. */ andStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementAndStatement; /** * Match requests based on Autonomous System Number (ASN). See ASN Match Statement above. */ asnMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementAsnMatchStatement; /** * Match requests based on byte patterns. See Byte Match Statement above. */ byteMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatement; /** * Match requests by geographic location. See Geo Match Statement above. */ geoMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementGeoMatchStatement; /** * Reference to an IP set. See IP Set Reference Statement above. */ ipSetReferenceStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementIpSetReferenceStatement; /** * Match requests based on labels. See Label Match Statement above. */ labelMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementLabelMatchStatement; /** * Logical NOT statement that negates a single statement. See Not Statement above. */ notStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementNotStatement; /** * Logical OR statement that combines multiple statements. See Or Statement above. */ orStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementOrStatement; /** * Match requests using regex patterns. See Regex Match Statement above. */ regexMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatement; /** * Rule statement used to search web request components for matches with regular expressions from a RegexPatternSet. */ regexPatternSetReferenceStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatement; /** * Match requests based on size constraints. See Size Constraint Statement above. */ sizeConstraintStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatement; /** * Match requests that appear to contain SQL injection attacks. */ sqliMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatement; /** * Match requests that appear to contain cross-site scripting attacks. * * > **NOTE:** Logical statements (`andStatement`, `notStatement`, `orStatement`) within a scope down statement wrap the leaf statement types listed above. */ xssMatchStatement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatement; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementAndStatement { /** * List of statements to combine. At least one statement is required. Each nested statement supports the same statement types listed above. */ statements?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatement[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementAsnMatchStatement { /** * List of Autonomous System Numbers (ASNs) to match against. ASNs are unique identifiers assigned to large internet networks managed by organizations such as internet service providers, enterprises, universities, or government agencies. */ asnLists: number[]; /** * Configuration for inspecting IP addresses in an HTTP header instead of using the web request origin. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementAsnMatchStatementForwardedIpConfig; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementAsnMatchStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatement { /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatch; /** * Area within the portion of the web request that you want WAF to search for `searchString`. Valid values: `EXACTLY`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CONTAINS_WORD`. */ positionalConstraint: string; /** * String value to search for within the request (1-200 characters). */ searchString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementTextTransformation[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementByteMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementGeoMatchStatement { /** * List of two-character country codes (ISO 3166-1 alpha-2). */ countryCodes: string[]; /** * Configuration for inspecting forwarded IP headers. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementGeoMatchStatementForwardedIpConfig; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementGeoMatchStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementIpSetReferenceStatement { /** * ARN of the IP set to reference. */ arn: string; /** * Configuration for inspecting forwarded IP headers. See IP Set Forwarded IP Config below. */ ipSetForwardedIpConfig?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementIpSetReferenceStatementIpSetForwardedIpConfig; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementIpSetReferenceStatementIpSetForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; /** * Position in the header to use. Valid values: `FIRST`, `LAST`, `ANY`. */ position: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementLabelMatchStatement { /** * String to match against. For `LABEL` scope, include the name and any preceding namespace specifications. For `NAMESPACE` scope, include namespace strings. Labels are case sensitive and components must be separated by colon (e.g., `NS1:NS2:name`). */ key: string; /** * Whether to match using the label name or namespace. Valid values: `LABEL`, `NAMESPACE`. */ scope: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementNotStatement { /** * Single statement to negate. Exactly one statement must be specified. */ statement?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatement; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementOrStatement { /** * List of statements to combine. At least one statement is required. Each nested statement supports the same statement types listed above. */ statements?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatement[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatement { /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatch; /** * Regular expression pattern to match against the web request component. */ regexString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementTextTransformation[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatement { /** * ARN of the regex pattern set to reference. */ arn: string; /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatch; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementTextTransformation[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriPath; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchMethod { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchQueryString { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriPath { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementRegexPatternSetReferenceStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatement { /** * Operator to use to compare the request part to the size setting. Valid values: `EQ`, `NE`, `LE`, `LT`, `GE`, `GT`. */ comparisonOperator: string; /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatch; /** * Size, in bytes, to compare to the request part, after any transformations. */ size: number; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementTextTransformation[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriPath; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchMethod { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchQueryString { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriPath { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSizeConstraintStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatement { fieldToMatch?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatch; /** * Sensitivity level for detecting SQL injection attacks. Valid values: `HIGH`, `LOW`. */ sensitivityLevel: string; textTransformations?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementTextTransformation[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementSqliMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatement { fieldToMatch?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatch; textTransformations?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementTextTransformation[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementManagedRuleGroupStatementScopeDownStatementXssMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementNotStatement { /** * Single statement to negate. Exactly one statement must be specified. */ statement?: outputs.wafv2.WebAclRuleStatement; } interface WebAclRuleStatementOrStatement { /** * List of statements to combine. At least one statement is required. Each nested statement supports the same statement types listed above. */ statements?: outputs.wafv2.WebAclRuleStatement[]; } interface WebAclRuleStatementRateBasedStatement { /** * Setting that indicates how to aggregate the request counts. Defaults to `IP`. Valid values: `IP`, `FORWARDED_IP`, `CUSTOM_KEYS`, `CONSTANT`. */ aggregateKeyType: string; /** * Aggregate the request counts using one or more web request components as the aggregate keys. See Custom Keys below. */ customKeys?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKey[]; /** * Time window for which the rate limit applies, in seconds. Defaults to `300` (5 minutes). Valid values: `60`, `120`, `300`, `600`. */ evaluationWindowSec: number; /** * Configuration for inspecting IP addresses in an HTTP header instead of using the web request origin. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementRateBasedStatementForwardedIpConfig; /** * Rate limit threshold (requests per evaluation window period). */ limit: number; /** * Additional statement to narrow the scope of requests that the rate-based rule evaluates. See Scope Down Statement below. */ scopeDownStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatement; } interface WebAclRuleStatementRateBasedStatementCustomKey { asn?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyAsn; /** * Use a cookie as an aggregate key. See Custom Key Cookie below. */ cookie?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyCookie; /** * Use the forwarded IP address as an aggregate key. */ forwardedIp?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyForwardedIp; /** * Use a header as an aggregate key. See Custom Key Header below. */ header?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyHeader; /** * Use the HTTP method as an aggregate key. */ httpMethod?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyHttpMethod; /** * Use the IP address as an aggregate key. */ ip?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyIp; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyJa4Fingerprint; /** * Use a label namespace as an aggregate key. See Custom Key Label Namespace below. */ labelNamespace?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyLabelNamespace; /** * Use a query argument as an aggregate key. See Custom Key Query Argument below. */ queryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyQueryArgument; /** * Use the query string as an aggregate key. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyQueryString; /** * Use the URI path as an aggregate key. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyUriPath; } interface WebAclRuleStatementRateBasedStatementCustomKeyAsn { } interface WebAclRuleStatementRateBasedStatementCustomKeyCookie { /** * Name of the rule. Must be unique within the Web ACL. */ name: string; textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyCookieTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementCustomKeyCookieTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyForwardedIp { } interface WebAclRuleStatementRateBasedStatementCustomKeyHeader { /** * Name of the rule. Must be unique within the Web ACL. */ name: string; textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyHeaderTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementCustomKeyHeaderTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyHttpMethod { } interface WebAclRuleStatementRateBasedStatementCustomKeyIp { } interface WebAclRuleStatementRateBasedStatementCustomKeyJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyLabelNamespace { /** * Label namespace to use as the custom key. */ namespace: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyQueryArgument { /** * Name of the rule. Must be unique within the Web ACL. */ name: string; textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyQueryArgumentTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementCustomKeyQueryArgumentTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyQueryString { textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyQueryStringTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementCustomKeyQueryStringTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementCustomKeyUriPath { textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementCustomKeyUriPathTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementCustomKeyUriPathTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatement { /** * Logical AND statement that combines multiple statements. See And Statement above. */ andStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementAndStatement; /** * Match requests based on Autonomous System Number (ASN). See ASN Match Statement above. */ asnMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatement; /** * Match requests based on byte patterns. See Byte Match Statement above. */ byteMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatement; /** * Match requests by geographic location. See Geo Match Statement above. */ geoMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatement; /** * Reference to an IP set. See IP Set Reference Statement above. */ ipSetReferenceStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatement; /** * Match requests based on labels. See Label Match Statement above. */ labelMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementLabelMatchStatement; /** * Logical NOT statement that negates a single statement. See Not Statement above. */ notStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementNotStatement; /** * Logical OR statement that combines multiple statements. See Or Statement above. */ orStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementOrStatement; /** * Match requests using regex patterns. See Regex Match Statement above. */ regexMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatement; /** * Rule statement used to search web request components for matches with regular expressions from a RegexPatternSet. */ regexPatternSetReferenceStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatement; /** * Match requests based on size constraints. See Size Constraint Statement above. */ sizeConstraintStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatement; /** * Match requests that appear to contain SQL injection attacks. */ sqliMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatement; /** * Match requests that appear to contain cross-site scripting attacks. * * > **NOTE:** Logical statements (`andStatement`, `notStatement`, `orStatement`) within a scope down statement wrap the leaf statement types listed above. */ xssMatchStatement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatement; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementAndStatement { /** * List of statements to combine. At least one statement is required. Each nested statement supports the same statement types listed above. */ statements?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatement[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatement { /** * List of Autonomous System Numbers (ASNs) to match against. ASNs are unique identifiers assigned to large internet networks managed by organizations such as internet service providers, enterprises, universities, or government agencies. */ asnLists: number[]; /** * Configuration for inspecting IP addresses in an HTTP header instead of using the web request origin. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatementForwardedIpConfig; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementAsnMatchStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatement { /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatch; /** * Area within the portion of the web request that you want WAF to search for `searchString`. Valid values: `EXACTLY`, `STARTS_WITH`, `ENDS_WITH`, `CONTAINS`, `CONTAINS_WORD`. */ positionalConstraint: string; /** * String value to search for within the request (1-200 characters). */ searchString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementByteMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatement { /** * List of two-character country codes (ISO 3166-1 alpha-2). */ countryCodes: string[]; /** * Configuration for inspecting forwarded IP headers. See Forwarded IP Config below. */ forwardedIpConfig?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatementForwardedIpConfig; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementGeoMatchStatementForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatement { /** * ARN of the IP set to reference. */ arn: string; /** * Configuration for inspecting forwarded IP headers. See IP Set Forwarded IP Config below. */ ipSetForwardedIpConfig?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatementIpSetForwardedIpConfig; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementIpSetReferenceStatementIpSetForwardedIpConfig { /** * Action to take when the IP address in the header is invalid. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; /** * Name of the header containing the forwarded IP address. */ headerName: string; /** * Position in the header to use. Valid values: `FIRST`, `LAST`, `ANY`. */ position: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementLabelMatchStatement { /** * String to match against. For `LABEL` scope, include the name and any preceding namespace specifications. For `NAMESPACE` scope, include namespace strings. Labels are case sensitive and components must be separated by colon (e.g., `NS1:NS2:name`). */ key: string; /** * Whether to match using the label name or namespace. Valid values: `LABEL`, `NAMESPACE`. */ scope: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementNotStatement { /** * Single statement to negate. Exactly one statement must be specified. */ statement?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatement; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementOrStatement { /** * List of statements to combine. At least one statement is required. Each nested statement supports the same statement types listed above. */ statements?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatement[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatement { /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatch; /** * Regular expression pattern to match against the web request component. */ regexString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatement { /** * ARN of the regex pattern set to reference. */ arn: string; /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatch; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriPath; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchMethod { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchQueryString { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementFieldToMatchUriPath { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementRegexPatternSetReferenceStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatement { /** * Operator to use to compare the request part to the size setting. Valid values: `EQ`, `NE`, `LE`, `LT`, `GE`, `GT`. */ comparisonOperator: string; /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatch; /** * Size, in bytes, to compare to the request part, after any transformations. */ size: number; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriPath; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchMethod { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchQueryString { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementFieldToMatchUriPath { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSizeConstraintStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatement { fieldToMatch?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatch; /** * Sensitivity level for detecting SQL injection attacks. Valid values: `HIGH`, `LOW`. */ sensitivityLevel: string; textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementSqliMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatement { fieldToMatch?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatch; textTransformations?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementTextTransformation[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementRateBasedStatementScopeDownStatementXssMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRegexMatchStatement { /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatch; /** * Regular expression pattern to match against the web request component. */ regexString: string; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementTextTransformation[]; } interface WebAclRuleStatementRegexMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRegexMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRegexMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRegexMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRegexMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementRegexMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementRegexMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRegexMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementRegexMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatement { /** * ARN of the regex pattern set to reference. */ arn: string; /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatch; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementTextTransformation[]; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriPath; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchMethod { } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchQueryString { } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementRegexPatternSetReferenceStatementFieldToMatchUriPath { } interface WebAclRuleStatementRegexPatternSetReferenceStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementRuleGroupReferenceStatement { /** * ARN of the rule group to reference. */ arn: string; /** * Rules to exclude from the rule group. See Excluded Rule below. */ excludedRules?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementExcludedRule[]; /** * Override actions for specific rules within the rule group. See Rule Action Override below. */ ruleActionOverrides?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverride[]; } interface WebAclRuleStatementRuleGroupReferenceStatementExcludedRule { /** * Name of the rule to exclude from the rule group. */ name: string; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverride { /** * Override action to use for the rule. See Action below. */ actionToUse?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUse; /** * Name of the rule to override. */ name: string; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUse { /** * Allow the request. See Allow below. */ allow?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseAllow; /** * Block the request. See Block below. */ block?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseBlock; /** * Present a CAPTCHA challenge. See Captcha below. */ captcha?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCaptcha; /** * Present a silent challenge. See Challenge below. */ challenge?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseChallenge; count?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCount; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseAllow { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseAllowCustomRequestHandling; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseAllowCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseAllowCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseBlock { /** * Custom response configuration. See Custom Response below. */ customResponse?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseBlockCustomResponse; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseBlockCustomResponse { /** * Key of a custom response body defined in the Web ACL. */ customResponseBodyKey?: string; /** * HTTP status code to return (200-599). */ responseCode: number; /** * Custom headers to include in the response. See Response Header below. */ responseHeaders?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseBlockCustomResponseResponseHeader[]; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseBlockCustomResponseResponseHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCaptcha { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandling; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCaptchaCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseChallenge { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseChallengeCustomRequestHandling; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseChallengeCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseChallengeCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCount { /** * Custom request handling configuration. See Custom Request Handling below. */ customRequestHandling?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCountCustomRequestHandling; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCountCustomRequestHandling { /** * Custom headers to insert into the request. See Insert Header below. */ insertHeaders?: outputs.wafv2.WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader[]; } interface WebAclRuleStatementRuleGroupReferenceStatementRuleActionOverrideActionToUseCountCustomRequestHandlingInsertHeader { /** * Header name. */ name: string; /** * Header value. */ value: string; } interface WebAclRuleStatementSizeConstraintStatement { /** * Operator to use to compare the request part to the size setting. Valid values: `EQ`, `NE`, `LE`, `LT`, `GE`, `GT`. */ comparisonOperator: string; /** * Part of the web request that you want WAF to inspect. See Field to Match below. */ fieldToMatch?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatch; /** * Size, in bytes, to compare to the request part, after any transformations. */ size: number; /** * Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to bypass detection. See Text Transformation below. */ textTransformations?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementTextTransformation[]; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchUriPath; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchMethod { } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchQueryString { } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementSizeConstraintStatementFieldToMatchUriPath { } interface WebAclRuleStatementSizeConstraintStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementSqliMatchStatement { fieldToMatch?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatch; /** * Sensitivity level for detecting SQL injection attacks. Valid values: `HIGH`, `LOW`. */ sensitivityLevel: string; textTransformations?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementTextTransformation[]; } interface WebAclRuleStatementSqliMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementSqliMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementSqliMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementSqliMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementSqliMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementSqliMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementSqliMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementSqliMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementSqliMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleStatementXssMatchStatement { fieldToMatch?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatch; textTransformations?: outputs.wafv2.WebAclRuleStatementXssMatchStatementTextTransformation[]; } interface WebAclRuleStatementXssMatchStatementFieldToMatch { /** * Inspect all query arguments. */ allQueryArguments?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchAllQueryArguments; /** * Inspect the request body as plain text. See Body below. */ body?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchBody; /** * Inspect the request cookies. See Cookies below. */ cookies?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchCookies; /** * Inspect a string containing the list of the request's header names, ordered as they appear in the web request. See Header Order below. */ headerOrders?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchHeaderOrder[]; /** * Inspect the request headers. See Headers below. */ headers?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchHeader[]; /** * Match against the request's JA3 fingerprint (CloudFront and ALB only). See JA3 Fingerprint below. */ ja3Fingerprint?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchJa3Fingerprint; /** * Match against the request's JA4 fingerprint (CloudFront and ALB only). See JA4 Fingerprint below. */ ja4Fingerprint?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchJa4Fingerprint; /** * Inspect the request body as JSON. See JSON Body below. */ jsonBody?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchJsonBody; /** * Inspect the HTTP method. */ method?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchMethod; /** * Inspect the query string. */ queryString?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchQueryString; /** * Inspect a single header. See Single Header below. */ singleHeader?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchSingleHeader; /** * Inspect a single query argument. See Single Query Argument below. */ singleQueryArgument?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchSingleQueryArgument; /** * Inspect fragments of the request URI. See URI Fragment below. */ uriFragment?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchUriFragment; /** * Inspect the request URI path. */ uriPath?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchUriPath; } interface WebAclRuleStatementXssMatchStatementFieldToMatchAllQueryArguments { } interface WebAclRuleStatementXssMatchStatementFieldToMatchBody { /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchCookies { /** * Cookies to inspect. See Cookies Match Pattern below. */ matchPatterns?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchCookiesMatchPattern[]; /** * Parts of the cookies to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with cookies larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchCookiesMatchPattern { all?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll; /** * List of cookie names to exclude from inspection. */ excludedCookies?: string[]; /** * List of cookie names to inspect. */ includedCookies?: string[]; } interface WebAclRuleStatementXssMatchStatementFieldToMatchCookiesMatchPatternAll { } interface WebAclRuleStatementXssMatchStatementFieldToMatchHeader { /** * Headers to inspect. See Headers Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchHeaderMatchPattern; /** * Parts of the headers to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchHeaderMatchPattern { all?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll; /** * List of header names to exclude from inspection. */ excludedHeaders?: string[]; /** * List of header names to inspect. */ includedHeaders?: string[]; } interface WebAclRuleStatementXssMatchStatementFieldToMatchHeaderMatchPatternAll { } interface WebAclRuleStatementXssMatchStatementFieldToMatchHeaderOrder { /** * How to handle requests with headers larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. */ oversizeHandling: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchJa3Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchJa4Fingerprint { /** * Action to take if WAF cannot calculate the fingerprint. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchJsonBody { /** * How to handle requests with invalid JSON body. Valid values: `EVALUATE_AS_STRING`, `MATCH`, `NO_MATCH`. */ invalidFallbackBehavior?: string; /** * JSON content to inspect. See JSON Body Match Pattern below. */ matchPattern?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern; /** * Parts of the JSON to inspect. Valid values: `ALL`, `KEY`, `VALUE`. */ matchScope: string; /** * How to handle requests with a body larger than the inspection limit. Valid values: `CONTINUE`, `MATCH`, `NO_MATCH`. Defaults to `CONTINUE`. */ oversizeHandling: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPattern { all?: outputs.wafv2.WebAclRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll; /** * List of JSON pointer expressions to inspect (e.g., `/foo/bar`). */ includedPaths: string[]; } interface WebAclRuleStatementXssMatchStatementFieldToMatchJsonBodyMatchPatternAll { } interface WebAclRuleStatementXssMatchStatementFieldToMatchMethod { } interface WebAclRuleStatementXssMatchStatementFieldToMatchQueryString { } interface WebAclRuleStatementXssMatchStatementFieldToMatchSingleHeader { /** * Name of the header to inspect (case insensitive). */ name: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchSingleQueryArgument { /** * Name of the query argument to inspect. */ name: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchUriFragment { /** * How to handle requests with a URI fragment that is too large to inspect. Valid values: `MATCH`, `NO_MATCH`. */ fallbackBehavior: string; } interface WebAclRuleStatementXssMatchStatementFieldToMatchUriPath { } interface WebAclRuleStatementXssMatchStatementTextTransformation { /** * Relative processing order for multiple transformations (0-based). */ priority: number; /** * Transformation to apply. Valid values: `NONE`, `COMPRESS_WHITE_SPACE`, `HTML_ENTITY_DECODE`, `LOWERCASE`, `CMD_LINE`, `URL_DECODE`, `BASE64_DECODE`, `HEX_DECODE`, `MD5`, `REPLACE_COMMENTS`, `ESCAPE_SEQ_DECODE`, `SQL_HEX_DECODE`, `CSS_DECODE`, `JS_DECODE`, `NORMALIZE_PATH`, `NORMALIZE_PATH_WIN`, `REMOVE_NULLS`, `REPLACE_NULLS`, `BASE64_DECODE_EXT`, `URL_DECODE_UNI`, `UTF8_TO_UNICODE`. */ type: string; } interface WebAclRuleTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface WebAclRuleVisibilityConfig { /** * Whether to enable CloudWatch metrics. */ cloudwatchMetricsEnabled: boolean; /** * Name of the CloudWatch metric. */ metricName: string; /** * Whether to store sampled requests. */ sampledRequestsEnabled: boolean; } interface WebAclVisibilityConfig { /** * Whether the associated resource sends metrics to CloudWatch. For the list of available metrics, see [AWS WAF Metrics](https://docs.aws.amazon.com/waf/latest/developerguide/monitoring-cloudwatch.html#waf-metrics). */ cloudwatchMetricsEnabled: boolean; /** * A friendly name of the CloudWatch metric. The name can contain only alphanumeric characters (A-Z, a-z, 0-9) hyphen(-) and underscore (\_), with length from one to 128 characters. It can't contain whitespace or metric names reserved for AWS WAF, for example `All` and `Default_Action`. */ metricName: string; /** * Whether AWS WAF should store a sampling of the web requests that match the rules. You can view the sampled requests through the AWS WAF console. */ sampledRequestsEnabled: boolean; } } export declare namespace workmail { interface DomainRecord { /** * DNS record hostname. */ hostname: string; /** * DNS record type (e.g. `CNAME`, `MX`, `TXT`). */ type: string; /** * DNS record value. */ value: string; } interface OrganizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } } export declare namespace workspaces { interface ConnectionAliasTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; } interface DirectoryActiveDirectoryConfig { /** * Fully qualified domain name of the AWS Directory Service directory. */ domainName: string; /** * ARN of the Secrets Manager secret that contains the credentials for the service account. For more information, see [Service Account Details](https://docs.aws.amazon.com/workspaces/latest/adminguide/pools-service-account-details.html). */ serviceAccountSecretArn: string; } interface DirectoryCertificateBasedAuthProperties { /** * ARN of the certificate manager private certificate authority (ACM-PCA) that is used for certificate-based authentication. */ certificateAuthorityArn?: string; /** * Status of certificate-based authentication. Default `DISABLED`. */ status: string; } interface DirectorySamlProperties { /** * The relay state parameter name supported by the SAML 2.0 identity provider (IdP). Default `RelayState`. */ relayStateParameterName?: string; /** * Status of SAML 2.0 authentication. Default `DISABLED`. */ status?: string; /** * The SAML 2.0 identity provider (IdP) user access URL. */ userAccessUrl?: string; } interface DirectorySelfServicePermissions { /** * Whether WorkSpaces directory users can change the compute type (bundle) for their workspace. Default `false`. */ changeComputeType?: boolean; /** * Whether WorkSpaces directory users can increase the volume size of the drives on their workspace. Default `false`. */ increaseVolumeSize?: boolean; /** * Whether WorkSpaces directory users can rebuild the operating system of a workspace to its original state. Default `false`. */ rebuildWorkspace?: boolean; /** * Whether WorkSpaces directory users can restart their workspace. Default `true`. */ restartWorkspace?: boolean; /** * Whether WorkSpaces directory users can switch the running mode of their workspace. Default `false`. */ switchRunningMode?: boolean; } interface DirectoryWorkspaceAccessProperties { /** * Configuration for accessing WorkSpaces through VPC endpoints instead of the public internet. Defined below. */ accessEndpointConfig?: outputs.workspaces.DirectoryWorkspaceAccessPropertiesAccessEndpointConfig; /** * Indicates whether users can use Android devices to access their WorkSpaces. */ deviceTypeAndroid?: string; /** * Indicates whether users can use Chromebooks to access their WorkSpaces. */ deviceTypeChromeos?: string; /** * Indicates whether users can use iOS devices to access their WorkSpaces. */ deviceTypeIos?: string; /** * Indicates whether users can use Linux clients to access their WorkSpaces. */ deviceTypeLinux?: string; /** * Indicates whether users can use macOS clients to access their WorkSpaces. */ deviceTypeOsx?: string; /** * Indicates whether users can access their WorkSpaces through a web browser. */ deviceTypeWeb?: string; /** * Indicates whether users can use Windows clients to access their WorkSpaces. */ deviceTypeWindows?: string; /** * Indicates whether users can use zero client devices to access their WorkSpaces. */ deviceTypeZeroclient?: string; } interface DirectoryWorkspaceAccessPropertiesAccessEndpointConfig { /** * Set of access endpoints used to control the network paths that users use to access their WorkSpaces. Defined below. */ accessEndpoints: outputs.workspaces.DirectoryWorkspaceAccessPropertiesAccessEndpointConfigAccessEndpoint[]; /** * List of protocols that fall back to the public internet when streaming over a VPC endpoint is unavailable. Valid value is `PCOIP`. */ internetFallbackProtocols?: string[]; } interface DirectoryWorkspaceAccessPropertiesAccessEndpointConfigAccessEndpoint { /** * Type of access endpoint. Valid value is `STREAMING_WSP`. */ accessEndpointType: string; /** * Identifier of the VPC endpoint that the access endpoint uses. */ vpcEndpointId: string; } interface DirectoryWorkspaceCreationProperties { /** * The identifier of your custom security group. Should relate to the same VPC, where workspaces reside in. */ customSecurityGroupId?: string; /** * The default organizational unit (OU) for your WorkSpace directories. Should conform `"OU=,DC=,...,DC="` pattern. */ defaultOu?: string; /** * Indicates whether internet access is enabled for your WorkSpaces. */ enableInternetAccess?: boolean; /** * Indicates whether maintenance mode is enabled for your WorkSpaces. Valid only if `workspaceType` is set to `PERSONAL`. */ enableMaintenanceMode?: boolean; /** * Indicates whether users are local administrators of their WorkSpaces. Valid only if `workspaceType` is set to `PERSONAL`. */ userEnabledAsLocalAdministrator?: boolean; } interface GetBundleComputeType { /** * Name of the bundle. You cannot combine this parameter with `bundleId`. */ name: string; } interface GetBundleRootStorage { /** * Size of the user storage. */ capacity: string; } interface GetBundleUserStorage { /** * Size of the user storage. */ capacity: string; } interface GetDirectoryActiveDirectoryConfig { /** * Fully qualified domain name of the AWS Directory Service directory. */ domainName: string; /** * ARN of the Secrets Manager secret that contains the credentials for the service account. */ serviceAccountSecretArn: string; } interface GetDirectoryCertificateBasedAuthProperty { certificateAuthorityArn: string; status: string; } interface GetDirectorySamlProperty { relayStateParameterName: string; status: string; userAccessUrl: string; } interface GetDirectorySelfServicePermission { /** * Whether WorkSpaces directory users can change the compute type (bundle) for their workspace. */ changeComputeType: boolean; /** * Whether WorkSpaces directory users can increase the volume size of the drives on their workspace. */ increaseVolumeSize: boolean; /** * Whether WorkSpaces directory users can rebuild the operating system of a workspace to its original state. */ rebuildWorkspace: boolean; /** * Whether WorkSpaces directory users can restart their workspace. */ restartWorkspace: boolean; /** * Whether WorkSpaces directory users can switch the running mode of their workspace. */ switchRunningMode: boolean; } interface GetDirectoryWorkspaceAccessProperty { /** * Configuration for accessing WorkSpaces through VPC endpoints instead of the public internet. */ accessEndpointConfigs: outputs.workspaces.GetDirectoryWorkspaceAccessPropertyAccessEndpointConfig[]; /** * (Optional) Indicates whether users can use Android devices to access their WorkSpaces. */ deviceTypeAndroid: string; /** * (Optional) Indicates whether users can use Chromebooks to access their WorkSpaces. */ deviceTypeChromeos: string; /** * (Optional) Indicates whether users can use iOS devices to access their WorkSpaces. */ deviceTypeIos: string; /** * (Optional) Indicates whether users can use Linux clients to access their WorkSpaces. */ deviceTypeLinux: string; /** * (Optional) Indicates whether users can use macOS clients to access their WorkSpaces. */ deviceTypeOsx: string; /** * (Optional) Indicates whether users can access their WorkSpaces through a web browser. */ deviceTypeWeb: string; /** * (Optional) Indicates whether users can use Windows clients to access their WorkSpaces. */ deviceTypeWindows: string; /** * (Optional) Indicates whether users can use zero client devices to access their WorkSpaces. */ deviceTypeZeroclient: string; } interface GetDirectoryWorkspaceAccessPropertyAccessEndpointConfig { /** * Set of access endpoints used to control the network paths that users use to access their WorkSpaces. */ accessEndpoints: outputs.workspaces.GetDirectoryWorkspaceAccessPropertyAccessEndpointConfigAccessEndpoint[]; /** * List of protocols that fall back to the public internet when streaming over a VPC endpoint is unavailable. */ internetFallbackProtocols: string[]; } interface GetDirectoryWorkspaceAccessPropertyAccessEndpointConfigAccessEndpoint { /** * Type of access endpoint. */ accessEndpointType: string; /** * Identifier of the VPC endpoint that the access endpoint uses. */ vpcEndpointId: string; } interface GetDirectoryWorkspaceCreationProperty { /** * The identifier of your custom security group. Should relate to the same VPC, where workspaces reside in. */ customSecurityGroupId: string; /** * The default organizational unit (OU) for your WorkSpace directories. */ defaultOu: string; /** * Indicates whether internet access is enabled for your WorkSpaces. */ enableInternetAccess: boolean; /** * Indicates whether maintenance mode is enabled for your WorkSpaces. For more information, see [WorkSpace Maintenance](https://docs.aws.amazon.com/workspaces/latest/adminguide/workspace-maintenance.html). */ enableMaintenanceMode: boolean; /** * Indicates whether users are local administrators of their WorkSpaces. */ userEnabledAsLocalAdministrator: boolean; } interface GetWorkspaceWorkspaceProperty { /** * Compute type. For more information, see [Amazon WorkSpaces Bundles](http://aws.amazon.com/workspaces/details/#Amazon_WorkSpaces_Bundles). Valid values are `VALUE`, `STANDARD`, `PERFORMANCE`, `POWER`, `GRAPHICS`, `POWERPRO` and `GRAPHICSPRO`. */ computeTypeName: string; /** * Size of the root volume. */ rootVolumeSizeGib: number; /** * Running mode. For more information, see [Manage the WorkSpace Running Mode](https://docs.aws.amazon.com/workspaces/latest/adminguide/running-mode.html). Valid values are `AUTO_STOP` and `ALWAYS_ON`. */ runningMode: string; /** * Time after a user logs off when WorkSpaces are automatically stopped. Configured in 60-minute intervals. */ runningModeAutoStopTimeoutInMinutes: number; /** * Size of the user storage. */ userVolumeSizeGib: number; } interface IpGroupRule { /** * The description of the IP group. */ description?: string; /** * The IP address range, in CIDR notation, e.g., `10.0.0.0/16` */ source: string; } interface PoolApplicationSetting { /** * Name of the settings group for the application settings. */ settingsGroup: string; /** * Status of the application settings. Valid values are `ENABLED` and `DISABLED`. */ status: string; } interface PoolCapacity { /** * Desired number of user sessions for the WorkSpaces Pool. */ desiredUserSessions: number; } interface PoolCapacityStatus { /** * Number of user sessions that are currently being used for WorkSpaces in the pool. */ activeUserSessions: number; /** * Number of user sessions currently being used for WorkSpaces in the pool. */ actualUserSessions: number; /** * Number of user sessions available for WorkSpaces in the pool. */ availableUserSessions: number; /** * Number of user sessions required for WorkSpaces in the pool. */ desiredUserSessions: number; } interface PoolTimeoutSetting { /** * Time after disconnection when a user is logged out of their WorkSpace. Must be between 1 and 36000. */ disconnectTimeoutInSeconds: number; /** * Time after inactivity when a user is disconnected from their WorkSpace. Must be between 1 and 36000. */ idleDisconnectTimeoutInSeconds: number; /** * Maximum time that a user can be connected to their WorkSpace. Must be between 1 and 432000. */ maxUserDurationInSeconds: number; } interface PoolTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface WorkspaceWorkspaceProperties { /** * The compute type. For more information, see [Amazon WorkSpaces Bundles](http://aws.amazon.com/workspaces/details/#Amazon_WorkSpaces_Bundles). Valid values are `VALUE`, `STANDARD`, `PERFORMANCE`, `POWER`, `GRAPHICS`, `POWERPRO`, `GENERALPURPOSE_4XLARGE`, `GENERALPURPOSE_8XLARGE`, `GRAPHICSPRO`, `GRAPHICS_G4DN`, `GRAPHICSPRO_G4DN`, `GRAPHICS_G6_XLARGE`, `GRAPHICS_G6_2XLARGE`, `GRAPHICS_G6_4XLARGE`, `GRAPHICS_G6_8XLARGE`, `GRAPHICS_G6_16XLARGE`, `GRAPHICS_GR6_4XLARGE`, `GRAPHICS_GR6_8XLARGE`, `GRAPHICS_G6F_LARGE`, `GRAPHICS_G6F_XLARGE`, `GRAPHICS_G6F_2XLARGE`, `GRAPHICS_G6F_4XLARGE`, and `GRAPHICS_GR6F_4XLARGE`. */ computeTypeName?: string; /** * The size of the root volume. */ rootVolumeSizeGib?: number; /** * The running mode. For more information, see [Manage the WorkSpace Running Mode](https://docs.aws.amazon.com/workspaces/latest/adminguide/running-mode.html). Valid values are `AUTO_STOP` and `ALWAYS_ON`. */ runningMode?: string; /** * The time after a user logs off when WorkSpaces are automatically stopped. Configured in 60-minute intervals. */ runningModeAutoStopTimeoutInMinutes: number; /** * The size of the user storage. */ userVolumeSizeGib?: number; } } export declare namespace workspacesweb { interface DataProtectionSettingsInlineRedactionConfiguration { /** * The global confidence level for the inline redaction configuration. This indicates the certainty of data type matches in the redaction process. Values range from 1 (low confidence) to 3 (high confidence). */ globalConfidenceLevel?: number; /** * The global enforced URL configuration for the inline redaction configuration. */ globalEnforcedUrls?: string[]; /** * The global exempt URL configuration for the inline redaction configuration. */ globalExemptUrls?: string[]; /** * The inline redaction patterns to be enabled for the inline redaction configuration. Detailed below. */ inlineRedactionPatterns: outputs.workspacesweb.DataProtectionSettingsInlineRedactionConfigurationInlineRedactionPattern[]; } interface DataProtectionSettingsInlineRedactionConfigurationInlineRedactionPattern { /** * The built-in pattern from the list of preconfigured patterns. Either a `customPattern` or `builtInPatternId` is required. */ builtInPatternId?: string; /** * The confidence level for inline redaction pattern. This indicates the certainty of data type matches in the redaction process. Values range from 1 (low confidence) to 3 (high confidence). */ confidenceLevel?: number; /** * The configuration for a custom pattern. Either a `customPattern` or `builtInPatternId` is required. Detailed below. */ customPattern?: outputs.workspacesweb.DataProtectionSettingsInlineRedactionConfigurationInlineRedactionPatternCustomPattern; /** * The enforced URL configuration for the inline redaction pattern. */ enforcedUrls?: string[]; /** * The exempt URL configuration for the inline redaction pattern. */ exemptUrls?: string[]; /** * The redaction placeholder that will replace the redacted text in session. Detailed below. */ redactionPlaceHolders?: outputs.workspacesweb.DataProtectionSettingsInlineRedactionConfigurationInlineRedactionPatternRedactionPlaceHolder[]; } interface DataProtectionSettingsInlineRedactionConfigurationInlineRedactionPatternCustomPattern { /** * The keyword regex for the customer pattern. */ keywordRegex?: string; /** * The pattern description for the customer pattern. */ patternDescription?: string; /** * The pattern name for the custom pattern. */ patternName: string; /** * The pattern regex for the customer pattern. The format must follow JavaScript regex format. */ patternRegex: string; } interface DataProtectionSettingsInlineRedactionConfigurationInlineRedactionPatternRedactionPlaceHolder { /** * The redaction placeholder text that will replace the redacted text in session for the custom text redaction placeholder type. */ redactionPlaceHolderText?: string; /** * The redaction placeholder type that will replace the redacted text in session. Currently, only `CustomText` is supported. */ redactionPlaceHolderType: string; } interface IpAccessSettingsIpRule { /** * The description of the IP access settings. */ description?: string; /** * The IP range of the IP rule. */ ipRange: string; } interface PortalTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } interface SessionLoggerEventFilter { /** * Block that specifies to monitor all events. Set to `{}` to monitor all events. */ all?: outputs.workspacesweb.SessionLoggerEventFilterAll; /** * List of specific events to monitor. Valid values include session events like `SessionStart`, `SessionEnd`, etc. */ includes?: string[]; } interface SessionLoggerEventFilterAll { } interface SessionLoggerLogConfiguration { /** * Configuration block for S3 log delivery. See S3 Configuration below. */ s3?: outputs.workspacesweb.SessionLoggerLogConfigurationS3; } interface SessionLoggerLogConfigurationS3 { /** * S3 bucket name where logs are delivered. */ bucket: string; /** * Expected bucket owner of the target S3 bucket. */ bucketOwner: string; /** * Folder structure that defines the organizational structure for log files in S3. Valid values: `FlatStructure`, `DateBasedStructure`. */ folderStructure: string; /** * S3 path prefix that determines where log files are stored. */ keyPrefix?: string; /** * Format of the log file written to S3. Valid values: `Json`, `Parquet`. */ logFileFormat: string; } interface TrustStoreCertificate { /** * Certificate body in PEM format. */ body: string; /** * Certificate issuer. */ issuer: string; /** * Date and time when the certificate expires in RFC3339 format. */ notValidAfter: string; /** * Date and time when the certificate becomes valid in RFC3339 format. */ notValidBefore: string; /** * Certificate subject. */ subject: string; /** * Certificate thumbprint. */ thumbprint: string; } interface UserSettingsCookieSynchronizationConfiguration { /** * List of cookie specifications that are allowed to be synchronized to the remote browser. */ allowlists?: outputs.workspacesweb.UserSettingsCookieSynchronizationConfigurationAllowlist[]; /** * List of cookie specifications that are blocked from being synchronized to the remote browser. */ blocklists?: outputs.workspacesweb.UserSettingsCookieSynchronizationConfigurationBlocklist[]; } interface UserSettingsCookieSynchronizationConfigurationAllowlist { /** * Domain of the cookie. */ domain: string; /** * Name of the cookie. */ name?: string; /** * Path of the cookie. */ path?: string; } interface UserSettingsCookieSynchronizationConfigurationBlocklist { /** * Domain of the cookie. */ domain: string; /** * Name of the cookie. */ name?: string; /** * Path of the cookie. */ path?: string; } interface UserSettingsToolbarConfiguration { /** * List of toolbar items to be hidden. */ hiddenToolbarItems?: string[]; /** * Maximum display resolution that is allowed for the session. */ maxDisplayResolution?: string; /** * Type of toolbar displayed during the session. */ toolbarType?: string; /** * Visual mode of the toolbar. */ visualMode?: string; } } export declare namespace xray { interface GroupInsightsConfiguration { /** * Specifies whether insights are enabled. */ insightsEnabled: boolean; /** * Specifies whether insight notifications are enabled. */ notificationsEnabled: boolean; } interface IndexingRuleRule { /** * Indexing rule configuration used to probabilistically sample traceIds. See `probabilistic` Block below. */ probabilistic?: outputs.xray.IndexingRuleRuleProbabilistic; } interface IndexingRuleRuleProbabilistic { actualSamplingPercentage: number; /** * Configured sampling percentage of traceIds. */ desiredSamplingPercentage: number; } interface TraceSegmentDestinationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } } //# sourceMappingURL=output.d.ts.map