{
  "description": "Service configuration for adding AWS S3 through Amplify",
  "type": "object",
  "properties": {
    "version": {
      "type": "number",
      "enum": [1]
    },
    "serviceConfiguration": {
      "$ref": "#/definitions/AddS3ServiceConfiguration"
    }
  },
  "required": ["serviceConfiguration", "version"],
  "definitions": {
    "AddS3ServiceConfiguration": {
      "description": "Service configuration for AWS S3 through Amplify",
      "type": "object",
      "properties": {
        "permissions": {
          "$ref": "#/definitions/S3Permissions",
          "description": "The permissions that should be applied to the bucket"
        },
        "resourceName": {
          "description": "Amplify resource name",
          "type": "string"
        },
        "bucketName": {
          "description": "Globally unique bucket name - bucket names must be lowercase",
          "type": "string"
        },
        "lambdaTrigger": {
          "$ref": "#/definitions/LambdaTriggerConfig",
          "description": "Optional parameter specifying a lambda that should run when the bucket is modified"
        },
        "serviceName": {
          "description": "Descriminant used to determine the service config type",
          "type": "string",
          "enum": ["S3"]
        }
      },
      "required": ["permissions", "serviceName"]
    },
    "S3Permissions": {
      "description": "Permissions that should be applied to the bucket",
      "type": "object",
      "properties": {
        "auth": {
          "description": "Permissions for authenticated users",
          "type": "array",
          "items": {
            "enum": ["CREATE_AND_UPDATE", "DELETE", "READ"],
            "type": "string"
          }
        },
        "guest": {
          "description": "Permissions for unauthenticated users",
          "type": "array",
          "items": {
            "enum": ["CREATE_AND_UPDATE", "DELETE", "READ"],
            "type": "string"
          }
        },
        "groups": {
          "$ref": "#/definitions/PermissionGroups",
          "description": "Permissions for Cognito user groups"
        }
      },
      "required": ["auth"]
    },
    "PermissionGroups": {
      "description": "Permissions for Cognito user groups",
      "type": "object",
      "additionalProperties": {
        "type": "array",
        "items": {
          "enum": ["CREATE_AND_UPDATE", "DELETE", "READ"],
          "type": "string"
        }
      }
    },
    "LambdaTriggerConfig": {
      "description": "Lambda function that runs on bucket change",
      "type": "object",
      "properties": {
        "mode": {
          "enum": ["existing", "new"],
          "type": "string"
        },
        "name": {
          "type": "string"
        }
      },
      "required": ["mode", "name"]
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
