Interface CfnRuntime.CustomJWTAuthorizerConfigurationProperty
- All Superinterfaces:
software.amazon.jsii.JsiiSerializable
- All Known Implementing Classes:
CfnRuntime.CustomJWTAuthorizerConfigurationProperty.Jsii$Proxy
- Enclosing class:
CfnRuntime
@Stability(Stable)
public static interface CfnRuntime.CustomJWTAuthorizerConfigurationProperty
extends software.amazon.jsii.JsiiSerializable
Configuration for custom JWT authorizer.
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import software.amazon.awscdk.services.bedrockagentcore.*;
CustomJWTAuthorizerConfigurationProperty customJWTAuthorizerConfigurationProperty = CustomJWTAuthorizerConfigurationProperty.builder()
.discoveryUrl("discoveryUrl")
// the properties below are optional
.allowedAudience(List.of("allowedAudience"))
.allowedClients(List.of("allowedClients"))
.allowedScopes(List.of("allowedScopes"))
.allowedWorkloadConfiguration(AllowedWorkloadConfigurationProperty.builder()
.hostingEnvironments(List.of(HostingEnvironmentProperty.builder()
.arn("arn")
.build()))
.workloadIdentities(List.of("workloadIdentities"))
.build())
.customClaims(List.of(CustomClaimValidationTypeProperty.builder()
.authorizingClaimMatchValue(AuthorizingClaimMatchValueTypeProperty.builder()
.claimMatchOperator("claimMatchOperator")
.claimMatchValue(ClaimMatchValueTypeProperty.builder()
.matchValueString("matchValueString")
.matchValueStringList(List.of("matchValueStringList"))
.build())
.build())
.inboundTokenClaimName("inboundTokenClaimName")
.inboundTokenClaimValueType("inboundTokenClaimValueType")
.build()))
.privateEndpoint(PrivateEndpointProperty.builder()
.managedVpcResource(ManagedVpcResourceProperty.builder()
.endpointIpAddressType("endpointIpAddressType")
.subnetIds(List.of("subnetIds"))
.vpcIdentifier("vpcIdentifier")
// the properties below are optional
.routingDomain("routingDomain")
.securityGroupIds(List.of("securityGroupIds"))
.tags(Map.of(
"tagsKey", "tags"))
.build())
.selfManagedLatticeResource(SelfManagedLatticeResourceProperty.builder()
.resourceConfigurationIdentifier("resourceConfigurationIdentifier")
.build())
.build())
.privateEndpointOverrides(List.of(PrivateEndpointOverrideProperty.builder()
.domain("domain")
.privateEndpoint(PrivateEndpointProperty.builder()
.managedVpcResource(ManagedVpcResourceProperty.builder()
.endpointIpAddressType("endpointIpAddressType")
.subnetIds(List.of("subnetIds"))
.vpcIdentifier("vpcIdentifier")
// the properties below are optional
.routingDomain("routingDomain")
.securityGroupIds(List.of("securityGroupIds"))
.tags(Map.of(
"tagsKey", "tags"))
.build())
.selfManagedLatticeResource(SelfManagedLatticeResourceProperty.builder()
.resourceConfigurationIdentifier("resourceConfigurationIdentifier")
.build())
.build())
.build()))
.build();
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeInterfaceDescriptionstatic final classA builder forCfnRuntime.CustomJWTAuthorizerConfigurationPropertystatic final classAn implementation forCfnRuntime.CustomJWTAuthorizerConfigurationProperty -
Method Summary
Modifier and TypeMethodDescriptionbuilder()Represents inbound authorization configuration options used to authenticate incoming requests.Represents individual client IDs that are validated in the incoming JWT token validation process.List of allowed scopes.default ObjectAllow-list of upstream workloads permitted to reach this resource via the workload identity chain.default ObjectList of required custom claims.The configuration authorization.default ObjectPrivate endpoint configuration.default ObjectList of private endpoint overrides.Methods inherited from interface software.amazon.jsii.JsiiSerializable
$jsii$toJson
-
Method Details
-
getDiscoveryUrl
The configuration authorization.- See Also:
-
getAllowedAudience
Represents inbound authorization configuration options used to authenticate incoming requests.- See Also:
-
getAllowedClients
Represents individual client IDs that are validated in the incoming JWT token validation process.- See Also:
-
getAllowedScopes
List of allowed scopes.- See Also:
-
getAllowedWorkloadConfiguration
Allow-list of upstream workloads permitted to reach this resource via the workload identity chain.When set, the data plane enforces that the introspected workload chain's caller matches one of the configured hosting environments or workload identities; absent means no chain enforcement.
Returns union: either
IResolvableorCfnRuntime.AllowedWorkloadConfigurationProperty- See Also:
-
getCustomClaims
List of required custom claims.Returns union: either
IResolvableor Listinvalid input: '<'eitherIResolvableorCfnRuntime.CustomClaimValidationTypeProperty>- See Also:
-
getPrivateEndpoint
Private endpoint configuration.Exactly one of SelfManagedLatticeResource or ManagedVpcResource must be specified.
Returns union: either
IResolvableorCfnRuntime.PrivateEndpointProperty- See Also:
-
getPrivateEndpointOverrides
List of private endpoint overrides.Returns union: either
IResolvableor Listinvalid input: '<'eitherIResolvableorCfnRuntime.PrivateEndpointOverrideProperty>- See Also:
-
builder
-