CfnOAuth2CredentialProvider

class aws_cdk.aws_bedrockagentcore.CfnOAuth2CredentialProvider(scope, id, *, credential_provider_vendor, name, oauth2_provider_config_input=None, tags=None)

Bases: CfnResource

Resource Type definition for AWS::BedrockAgentCore::OAuth2CredentialProvider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-bedrockagentcore-oauth2credentialprovider.html

CloudformationResource:

AWS::BedrockAgentCore::OAuth2CredentialProvider

ExampleMetadata:

fixture=_generated

Example:

from aws_cdk import CfnTag
# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

cfn_o_auth2_credential_provider = bedrockagentcore.CfnOAuth2CredentialProvider(self, "MyCfnOAuth2CredentialProvider",
    credential_provider_vendor="credentialProviderVendor",
    name="name",

    # the properties below are optional
    oauth2_provider_config_input=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2ProviderConfigInputProperty(
        atlassian_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.AtlassianOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        custom_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.CustomOauth2ProviderConfigInputProperty(
            oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2DiscoveryProperty(
                authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(
                    authorization_endpoint="authorizationEndpoint",
                    issuer="issuer",
                    token_endpoint="tokenEndpoint",

                    # the properties below are optional
                    response_types=["responseTypes"]
                ),
                discovery_url="discoveryUrl"
            ),

            # the properties below are optional
            client_authentication_method="clientAuthenticationMethod",
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource",
            on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProvider.OnBehalfOfTokenExchangeConfigProperty(
                grant_type="grantType",

                # the properties below are optional
                token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(
                    actor_token_content="actorTokenContent",

                    # the properties below are optional
                    actor_token_scopes=["actorTokenScopes"]
                )
            ),
            private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
                managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
                    endpoint_ip_address_type="endpointIpAddressType",
                    subnet_ids=["subnetIds"],
                    vpc_identifier="vpcIdentifier",

                    # the properties below are optional
                    routing_domain="routingDomain",
                    security_group_ids=["securityGroupIds"],
                    tags={
                        "tags_key": "tags"
                    }
                ),
                self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
                    resource_configuration_identifier="resourceConfigurationIdentifier"
                )
            ),
            private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointOverrideProperty(
                domain="domain",
                private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
                    managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
                        endpoint_ip_address_type="endpointIpAddressType",
                        subnet_ids=["subnetIds"],
                        vpc_identifier="vpcIdentifier",

                        # the properties below are optional
                        routing_domain="routingDomain",
                        security_group_ids=["securityGroupIds"],
                        tags={
                            "tags_key": "tags"
                        }
                    ),
                    self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
                        resource_configuration_identifier="resourceConfigurationIdentifier"
                    )
                )
            )],
            private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeyJwtConfigProperty(
                additional_header_claims={
                    "additional_header_claims_key": "additionalHeaderClaims"
                },
                additional_payload_claims={
                    "additional_payload_claims_key": "additionalPayloadClaims"
                },
                private_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeySourceProperty(
                    kms_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
                        kms_key_arn="kmsKeyArn"
                    )
                ),
                signing_algorithm="signingAlgorithm"
            )
        ),
        github_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.GithubOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        google_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.GoogleOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        included_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.IncludedOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            authorization_endpoint="authorizationEndpoint",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource",
            issuer="issuer",
            token_endpoint="tokenEndpoint"
        ),
        linkedin_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.LinkedinOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        microsoft_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.MicrosoftOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource",
            tenant_id="tenantId"
        ),
        salesforce_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.SalesforceOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        slack_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.SlackOauth2ProviderConfigInputProperty(
            client_id="clientId",

            # the properties below are optional
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        )
    ),
    tags=[CfnTag(
        key="key",
        value="value"
    )]
)

Create a new AWS::BedrockAgentCore::OAuth2CredentialProvider.

Parameters:
  • scope (Construct) – Scope in which this resource is defined.

  • id (str) – Construct identifier for this resource (unique in its scope).

  • credential_provider_vendor (str) – The vendor of the OAuth2 credential provider.

  • name (str) – The name of the OAuth2 credential provider.

  • oauth2_provider_config_input (Union[IResolvable, Oauth2ProviderConfigInputProperty, Dict[str, Any], None]) – Input configuration for an OAuth2 provider.

  • tags (Optional[Sequence[Union[CfnTag, Dict[str, Any]]]]) – Tags to assign to the OAuth2 credential provider.

Methods

add_deletion_override(path)

Syntactic sugar for addOverride(path, undefined).

Parameters:

path (str) – The path of the value to delete.

Return type:

None

add_dependency(target)

(deprecated) Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned.

This method has been renamed to addResourceDependency to more clearly set it apart from construct.node.addDependency. See the documentation of that function for more details.

Parameters:

target (CfnResource)

Deprecated:

Use addResourceDependency instead.

Stability:

deprecated

Return type:

None

add_depends_on(target)

(deprecated) Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned.

This can be used for resources across stacks (or nested stack) boundaries and the dependency will automatically be transferred to the relevant scope.

This method has been renamed to addResourceDependency, which makes it more clear that this method operates at a different level from the construct-level construct.node.addDependency() mechanism.

Parameters:

target (CfnResource)

Deprecated:

Use addResourceDependency instead.

Stability:

deprecated

Return type:

None

add_metadata(key, value)

Add a value to the CloudFormation Resource Metadata.

Parameters:
  • key (str)

  • value (Any)

See:

Return type:

None

https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html

Note that this is a different set of metadata from CDK node metadata; this metadata ends up in the stack template under the resource, whereas CDK node metadata ends up in the Cloud Assembly.

add_override(path, value)

Adds an override to the synthesized CloudFormation resource.

To add a property override, either use addPropertyOverride or prefix path with “Properties.” (i.e. Properties.TopicName).

If the override is nested, separate each nested level using a dot (.) in the path parameter. If there is an array as part of the nesting, specify the index in the path.

To include a literal . in the property name, prefix with a \. In most programming languages you will need to write this as "\\." because the \ itself will need to be escaped.

For example:

cfn_resource.add_override("Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes", ["myattribute"])
cfn_resource.add_override("Properties.GlobalSecondaryIndexes.1.ProjectionType", "INCLUDE")

would add the overrides Example:

"Properties": {
  "GlobalSecondaryIndexes": [
    {
      "Projection": {
        "NonKeyAttributes": [ "myattribute" ]
        ...
      }
      ...
    },
    {
      "ProjectionType": "INCLUDE"
      ...
    },
  ]
  ...
}

The value argument to addOverride will not be processed or translated in any way. Pass raw JSON values in here with the correct capitalization for CloudFormation. If you pass CDK classes or structs, they will be rendered with lowercased key names, and CloudFormation will reject the template.

Parameters:
  • path (str) –

    • The path of the property, you can use dot notation to override values in complex types. Any intermediate keys will be created as needed.

  • value (Any) –

    • The value. Could be primitive or complex.

Return type:

None

add_property_deletion_override(property_path)

Adds an override that deletes the value of a property from the resource definition.

Parameters:

property_path (str) – The path to the property.

Return type:

None

add_property_override(property_path, value)

Adds an override to a resource property.

Syntactic sugar for addOverride("Properties.<...>", value).

Parameters:
  • property_path (str) – The path of the property.

  • value (Any) – The value.

Return type:

None

add_resource_dependency(target, reason=None)

Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned.

This can be used for resources across stacks (or nested stack) boundaries and the dependency will automatically be transferred to the relevant scope.

This method only adds dependencies between L1 resources. If you are looking for a generic construct-to-construct dependency mechanism that works for all constructs including L2s, use construct.node.addDependency instead.

Parameters:
Return type:

None

apply_cross_stack_reference_strength(strength)

Sets the cross-stack reference strength for this resource.

When set, any cross-stack reference to this resource will use the specified strength instead of the global default from the consuming stack’s context.

Parameters:

strength (ReferenceStrength) –

  • The reference strength to use for this resource.

Return type:

None

apply_removal_policy(policy=None, *, apply_to_update_replace_policy=None, default=None)

Sets the deletion policy of the resource based on the removal policy specified.

The Removal Policy controls what happens to this resource when it stops being managed by CloudFormation, either because you’ve removed it from the CDK application or because you’ve made a change that requires the resource to be replaced.

The resource can be deleted (RemovalPolicy.DESTROY), or left in your AWS account for data recovery and cleanup later (RemovalPolicy.RETAIN). In some cases, a snapshot can be taken of the resource prior to deletion (RemovalPolicy.SNAPSHOT). A list of resources that support this policy can be found in the following link:

Parameters:
  • policy (Optional[RemovalPolicy])

  • apply_to_update_replace_policy (Optional[bool]) – Apply the same deletion policy to the resource’s “UpdateReplacePolicy”. Default: true

  • default (Optional[RemovalPolicy]) – The default policy to apply in case the removal policy is not defined. Default: - Default value is resource specific. To determine the default value for a resource, please consult that specific resource’s documentation.

See:

https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-attribute-deletionpolicy.html#aws-attribute-deletionpolicy-options

Return type:

None

cfn_property_name(cdk_property_name)
Parameters:

cdk_property_name (str)

Return type:

Optional[str]

get_att(attribute_name, type_hint=None)

Returns a token for an runtime attribute of this resource.

Ideally, use generated attribute accessors (e.g. resource.arn), but this can be used for future compatibility in case there is no generated attribute.

Parameters:
  • attribute_name (str) – The name of the attribute.

  • type_hint (Optional[ResolutionTypeHint])

Return type:

Reference

get_metadata(key)

Retrieve a value value from the CloudFormation Resource Metadata.

Parameters:

key (str)

See:

Return type:

Any

https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html

Note that this is a different set of metadata from CDK node metadata; this metadata ends up in the stack template under the resource, whereas CDK node metadata ends up in the Cloud Assembly.

inspect(inspector)

Examines the CloudFormation resource and discloses attributes.

Parameters:

inspector (TreeInspector) – tree inspector to collect and process attributes.

Return type:

None

obtain_dependencies()

Retrieves an array of resources and stacks this resource depends on.

For resources depended on directly, returns the CfnResource object. For dependencies on other stacks, returns the Stack object. The order of the array is not guaranteed.

Return type:

List[Union[Stack, CfnResource]]

override_logical_id(new_logical_id)

Overrides the auto-generated logical ID with a specific ID.

Parameters:

new_logical_id (str) – The new logical ID to use for this stack element.

Return type:

None

remove_dependency(target)

(deprecated) Indicates that this resource no longer depends on another resource.

This can be used for resources across stacks (including nested stacks) and the dependency will automatically be removed from the relevant scope.

Parameters:

target (CfnResource)

Deprecated:

Use removeResourceDependency instead

Stability:

deprecated

Return type:

None

remove_resource_dependency(target)

Indicates that this resource no longer depends on another resource.

This can be used for resources across stacks (including nested stacks) and the dependency will automatically be removed from the relevant scope.

Parameters:

target (CfnResource)

Return type:

None

replace_dependency(target, new_target)

Replaces one dependency with another.

Parameters:
Return type:

None

to_string()

Returns a string representation of this construct.

Return type:

str

Returns:

a string representation of this resource

with_(*mixins)

Applies one or more mixins to this construct.

Mixins are applied in order. The list of constructs is captured at the start of the call, so constructs added by a mixin will not be visited. Use multiple with() calls if subsequent mixins should apply to added constructs.

Parameters:

mixins (IMixin)

Return type:

IConstruct

Attributes

CFN_RESOURCE_TYPE_NAME = 'AWS::BedrockAgentCore::OAuth2CredentialProvider'
attr_callback_url

The callback URL for the OAuth2 authorization flow.

CloudformationAttribute:

CallbackUrl

attr_client_secret_arn

Contains information about a secret in AWS Secrets Manager.

CloudformationAttribute:

ClientSecretArn

attr_client_secret_json_key

The JSON key within the secret that contains the client secret value.

CloudformationAttribute:

ClientSecretJsonKey

attr_client_secret_source

The source of the client secret.

CloudformationAttribute:

ClientSecretSource

attr_created_time

The timestamp when the credential provider was created.

CloudformationAttribute:

CreatedTime

attr_credential_provider_arn

The Amazon Resource Name (ARN) of the OAuth2 credential provider.

CloudformationAttribute:

CredentialProviderArn

attr_last_updated_time

The timestamp when the credential provider was last updated.

CloudformationAttribute:

LastUpdatedTime

attr_oauth2_provider_config_output

Output configuration for an OAuth2 provider.

CloudformationAttribute:

Oauth2ProviderConfigOutput

attr_status

The current status of the OAuth2 credential provider.

CloudformationAttribute:

Status

cdk_tag_manager

Tag Manager which manages the tags for this resource.

cfn_options

Options for this resource, such as condition, update policy etc.

cfn_resource_type

AWS resource type.

creation_stack

return:

the stack trace of the point where this Resource was created from, sourced from the +metadata+ entry typed +aws:cdk:logicalId+, and with the bottom-most node +internal+ entries filtered.

credential_provider_vendor

The vendor of the OAuth2 credential provider.

env
logical_id

The logical ID for this CloudFormation stack element.

The logical ID of the element is calculated from the path of the resource node in the construct tree.

To override this value, use overrideLogicalId(newLogicalId).

Returns:

the logical ID as a stringified token. This value will only get resolved during synthesis.

name

The name of the OAuth2 credential provider.

node

The tree node.

o_auth2_credential_provider_ref

A reference to a OAuth2CredentialProvider resource.

oauth2_provider_config_input

Input configuration for an OAuth2 provider.

ref

Return a string that will be resolved to a CloudFormation { Ref } for this element.

If, by any chance, the intrinsic reference of a resource is not a string, you could coerce it to an IResolvable through Lazy.any({ produce: resource.ref }).

stack

The stack in which this element is defined.

CfnElements must be defined within a stack scope (directly or indirectly).

tags

Tags to assign to the OAuth2 credential provider.

Static Methods

classmethod is_cfn_element(x)

Returns true if a construct is a stack element (i.e. part of the synthesized cloudformation template).

Uses duck-typing instead of instanceof to allow stack elements from different versions of this library to be included in the same stack.

Parameters:

x (Any)

Return type:

bool

Returns:

The construct as a stack element or undefined if it is not a stack element.

classmethod is_cfn_o_auth2_credential_provider(x)

Checks whether the given object is a CfnOAuth2CredentialProvider.

Parameters:

x (Any)

Return type:

bool

classmethod is_cfn_resource(x)

Check whether the given object is a CfnResource.

Parameters:

x (Any)

Return type:

bool

classmethod is_construct(x)

Checks if x is a construct.

Use this method instead of instanceof to properly detect Construct instances, even when the construct library is symlinked.

Explanation: in JavaScript, multiple copies of the constructs library on disk are seen as independent, completely different libraries. As a consequence, the class Construct in each copy of the constructs library is seen as a different class, and an instance of one class will not test as instanceof the other class. npm install will not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of the constructs library can be accidentally installed, and instanceof will behave unpredictably. It is safest to avoid using instanceof, and using this type-testing method instead.

Parameters:

x (Any) – Any object.

Return type:

bool

Returns:

true if x is an object created from a class which extends Construct.

AtlassianOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.AtlassianOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for an Atlassian OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

atlassian_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.AtlassianOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientsecretsource

Type:

see

ClientSecretArnProperty

class CfnOAuth2CredentialProvider.ClientSecretArnProperty(*, secret_arn)

Bases: object

Contains information about a secret in AWS Secrets Manager.

Parameters:

secret_arn (str) – The ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-clientsecretarn.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

client_secret_arn_property = bedrockagentcore.CfnOAuth2CredentialProvider.ClientSecretArnProperty(
    secret_arn="secretArn"
)

Attributes

secret_arn

The ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-clientsecretarn.html#cfn-bedrockagentcore-oauth2credentialprovider-clientsecretarn-secretarn

CustomOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.CustomOauth2ProviderConfigInputProperty(*, oauth_discovery, client_authentication_method=None, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None, on_behalf_of_token_exchange_config=None, private_endpoint=None, private_endpoint_overrides=None, private_key_jwt_config=None)

Bases: object

Input configuration for a custom OAuth2 provider.

Parameters:
  • oauth_discovery (Union[IResolvable, Oauth2DiscoveryProperty, Dict[str, Any]]) – Discovery information for an OAuth2 provider.

  • client_authentication_method (Optional[str]) – The client authentication method to use when authenticating with the token endpoint.

  • client_id (Optional[str]) – The client ID for the custom OAuth2 provider.

  • client_secret (Optional[str]) – The client secret for the custom OAuth2 provider.

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str]) – The source of the client secret.

  • on_behalf_of_token_exchange_config (Union[IResolvable, OnBehalfOfTokenExchangeConfigProperty, Dict[str, Any], None]) – Configuration for on-behalf-of token exchange.

  • private_endpoint (Union[IResolvable, PrivateEndpointProperty, Dict[str, Any], None]) – The private endpoint configuration for connecting to private resources in your VPC.

  • private_endpoint_overrides (Union[IResolvable, Sequence[Union[IResolvable, PrivateEndpointOverrideProperty, Dict[str, Any]]], None]) – A list of private endpoint overrides. Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

  • private_key_jwt_config (Union[IResolvable, PrivateKeyJwtConfigProperty, Dict[str, Any], None]) – Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

custom_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.CustomOauth2ProviderConfigInputProperty(
    oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2DiscoveryProperty(
        authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(
            authorization_endpoint="authorizationEndpoint",
            issuer="issuer",
            token_endpoint="tokenEndpoint",

            # the properties below are optional
            response_types=["responseTypes"]
        ),
        discovery_url="discoveryUrl"
    ),

    # the properties below are optional
    client_authentication_method="clientAuthenticationMethod",
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource",
    on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProvider.OnBehalfOfTokenExchangeConfigProperty(
        grant_type="grantType",

        # the properties below are optional
        token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(
            actor_token_content="actorTokenContent",

            # the properties below are optional
            actor_token_scopes=["actorTokenScopes"]
        )
    ),
    private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
        managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
            endpoint_ip_address_type="endpointIpAddressType",
            subnet_ids=["subnetIds"],
            vpc_identifier="vpcIdentifier",

            # the properties below are optional
            routing_domain="routingDomain",
            security_group_ids=["securityGroupIds"],
            tags={
                "tags_key": "tags"
            }
        ),
        self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
            resource_configuration_identifier="resourceConfigurationIdentifier"
        )
    ),
    private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointOverrideProperty(
        domain="domain",
        private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
            managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
                endpoint_ip_address_type="endpointIpAddressType",
                subnet_ids=["subnetIds"],
                vpc_identifier="vpcIdentifier",

                # the properties below are optional
                routing_domain="routingDomain",
                security_group_ids=["securityGroupIds"],
                tags={
                    "tags_key": "tags"
                }
            ),
            self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
                resource_configuration_identifier="resourceConfigurationIdentifier"
            )
        )
    )],
    private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeyJwtConfigProperty(
        additional_header_claims={
            "additional_header_claims_key": "additionalHeaderClaims"
        },
        additional_payload_claims={
            "additional_payload_claims_key": "additionalPayloadClaims"
        },
        private_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeySourceProperty(
            kms_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
                kms_key_arn="kmsKeyArn"
            )
        ),
        signing_algorithm="signingAlgorithm"
    )
)

Attributes

client_authentication_method

The client authentication method to use when authenticating with the token endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientauthenticationmethod

client_id

The client ID for the custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientid

client_secret

The client secret for the custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientsecret

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientsecretconfig

client_secret_source

The source of the client secret.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientsecretsource

oauth_discovery

Discovery information for an OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-oauthdiscovery

on_behalf_of_token_exchange_config

Configuration for on-behalf-of token exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-onbehalfoftokenexchangeconfig

private_endpoint

The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-privateendpoint

private_endpoint_overrides

A list of private endpoint overrides.

Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-privateendpointoverrides

private_key_jwt_config

Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-privatekeyjwtconfig

GithubOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.GithubOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a GitHub OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

github_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.GithubOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientsecretsource

Type:

see

GoogleOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.GoogleOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a Google OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

google_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.GoogleOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientsecretsource

Type:

see

IncludedOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.IncludedOauth2ProviderConfigInputProperty(*, client_id, authorization_endpoint=None, client_secret=None, client_secret_config=None, client_secret_source=None, issuer=None, token_endpoint=None)

Bases: object

Input configuration for a supported non-custom OAuth2 provider.

Parameters:
  • client_id (str)

  • authorization_endpoint (Optional[str]) – OAuth2 authorization endpoint for your isolated OAuth2 application tenant.

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

  • issuer (Optional[str]) – Token issuer of your isolated OAuth2 application tenant.

  • token_endpoint (Optional[str]) – OAuth2 token endpoint for your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

included_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.IncludedOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    authorization_endpoint="authorizationEndpoint",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource",
    issuer="issuer",
    token_endpoint="tokenEndpoint"
)

Attributes

authorization_endpoint

OAuth2 authorization endpoint for your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-authorizationendpoint

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientsecretsource

Type:

see

issuer

Token issuer of your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-issuer

token_endpoint

OAuth2 token endpoint for your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-tokenendpoint

KmsKeySourceTypeProperty

class CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(*, kms_key_arn)

Bases: object

Contains the KMS key configuration for a JWT client assertion.

Parameters:

kms_key_arn (str) – The Amazon Resource Name (ARN) of the KMS key used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-kmskeysourcetype.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

kms_key_source_type_property = bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
    kms_key_arn="kmsKeyArn"
)

Attributes

kms_key_arn

The Amazon Resource Name (ARN) of the KMS key used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-kmskeysourcetype.html#cfn-bedrockagentcore-oauth2credentialprovider-kmskeysourcetype-kmskeyarn

LinkedinOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.LinkedinOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a LinkedIn OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

linkedin_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.LinkedinOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientsecretsource

Type:

see

ManagedVpcResourceProperty

class CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(*, endpoint_ip_address_type, subnet_ids, vpc_identifier, routing_domain=None, security_group_ids=None, tags=None)

Bases: object

Configuration for a managed VPC Lattice resource.

AgentCore creates and manages the VPC Lattice resource gateway and resource configuration on your behalf.

Parameters:
  • endpoint_ip_address_type (str) – The IP address type for the resource configuration endpoint.

  • subnet_ids (Sequence[str]) – The subnet IDs within the VPC where the VPC Lattice resource gateway is placed.

  • vpc_identifier (str) – The ID of the VPC that contains your private resource.

  • routing_domain (Optional[str]) – An intermediate publicly resolvable domain used as the VPC Lattice resource configuration endpoint.

  • security_group_ids (Optional[Sequence[str]]) – The security group IDs to associate with the VPC Lattice resource gateway.

  • tags (Optional[Mapping[str, str]]) – A map of tags (key-value pairs) to apply to a resource.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

managed_vpc_resource_property = bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
    endpoint_ip_address_type="endpointIpAddressType",
    subnet_ids=["subnetIds"],
    vpc_identifier="vpcIdentifier",

    # the properties below are optional
    routing_domain="routingDomain",
    security_group_ids=["securityGroupIds"],
    tags={
        "tags_key": "tags"
    }
)

Attributes

endpoint_ip_address_type

The IP address type for the resource configuration endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-endpointipaddresstype

routing_domain

An intermediate publicly resolvable domain used as the VPC Lattice resource configuration endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-routingdomain

security_group_ids

The security group IDs to associate with the VPC Lattice resource gateway.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-securitygroupids

subnet_ids

The subnet IDs within the VPC where the VPC Lattice resource gateway is placed.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-subnetids

tags

A map of tags (key-value pairs) to apply to a resource.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-tags

vpc_identifier

The ID of the VPC that contains your private resource.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-vpcidentifier

MicrosoftOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.MicrosoftOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None, tenant_id=None)

Bases: object

Input configuration for a Microsoft OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

  • tenant_id (Optional[str]) – The Microsoft Entra ID tenant ID.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

microsoft_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.MicrosoftOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource",
    tenant_id="tenantId"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientsecretsource

Type:

see

tenant_id

The Microsoft Entra ID tenant ID.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-tenantid

Oauth2AuthorizationServerMetadataProperty

class CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(*, authorization_endpoint, issuer, token_endpoint, response_types=None)

Bases: object

Authorization server metadata for the OAuth2 provider.

Parameters:
  • authorization_endpoint (str) – The authorization endpoint URL.

  • issuer (str) – The issuer URL for the OAuth2 authorization server.

  • token_endpoint (str) – The token endpoint URL.

  • response_types (Optional[Sequence[str]]) – The supported response types.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

oauth2_authorization_server_metadata_property = bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(
    authorization_endpoint="authorizationEndpoint",
    issuer="issuer",
    token_endpoint="tokenEndpoint",

    # the properties below are optional
    response_types=["responseTypes"]
)

Attributes

authorization_endpoint

The authorization endpoint URL.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-authorizationendpoint

issuer

The issuer URL for the OAuth2 authorization server.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-issuer

response_types

The supported response types.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-responsetypes

token_endpoint

The token endpoint URL.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-tokenendpoint

Oauth2DiscoveryProperty

class CfnOAuth2CredentialProvider.Oauth2DiscoveryProperty(*, authorization_server_metadata=None, discovery_url=None)

Bases: object

Discovery information for an OAuth2 provider.

Parameters:
See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2discovery.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

oauth2_discovery_property = bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2DiscoveryProperty(
    authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(
        authorization_endpoint="authorizationEndpoint",
        issuer="issuer",
        token_endpoint="tokenEndpoint",

        # the properties below are optional
        response_types=["responseTypes"]
    ),
    discovery_url="discoveryUrl"
)

Attributes

authorization_server_metadata

Authorization server metadata for the OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2discovery.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2discovery-authorizationservermetadata

discovery_url

The discovery URL for the OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2discovery.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2discovery-discoveryurl

Oauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.Oauth2ProviderConfigInputProperty(*, atlassian_oauth2_provider_config=None, custom_oauth2_provider_config=None, github_oauth2_provider_config=None, google_oauth2_provider_config=None, included_oauth2_provider_config=None, linkedin_oauth2_provider_config=None, microsoft_oauth2_provider_config=None, salesforce_oauth2_provider_config=None, slack_oauth2_provider_config=None)

Bases: object

Input configuration for an OAuth2 provider.

Parameters:
See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2ProviderConfigInputProperty(
    atlassian_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.AtlassianOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    custom_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.CustomOauth2ProviderConfigInputProperty(
        oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2DiscoveryProperty(
            authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(
                authorization_endpoint="authorizationEndpoint",
                issuer="issuer",
                token_endpoint="tokenEndpoint",

                # the properties below are optional
                response_types=["responseTypes"]
            ),
            discovery_url="discoveryUrl"
        ),

        # the properties below are optional
        client_authentication_method="clientAuthenticationMethod",
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource",
        on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProvider.OnBehalfOfTokenExchangeConfigProperty(
            grant_type="grantType",

            # the properties below are optional
            token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(
                actor_token_content="actorTokenContent",

                # the properties below are optional
                actor_token_scopes=["actorTokenScopes"]
            )
        ),
        private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
            managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
                endpoint_ip_address_type="endpointIpAddressType",
                subnet_ids=["subnetIds"],
                vpc_identifier="vpcIdentifier",

                # the properties below are optional
                routing_domain="routingDomain",
                security_group_ids=["securityGroupIds"],
                tags={
                    "tags_key": "tags"
                }
            ),
            self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
                resource_configuration_identifier="resourceConfigurationIdentifier"
            )
        ),
        private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointOverrideProperty(
            domain="domain",
            private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
                managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
                    endpoint_ip_address_type="endpointIpAddressType",
                    subnet_ids=["subnetIds"],
                    vpc_identifier="vpcIdentifier",

                    # the properties below are optional
                    routing_domain="routingDomain",
                    security_group_ids=["securityGroupIds"],
                    tags={
                        "tags_key": "tags"
                    }
                ),
                self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
                    resource_configuration_identifier="resourceConfigurationIdentifier"
                )
            )
        )],
        private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeyJwtConfigProperty(
            additional_header_claims={
                "additional_header_claims_key": "additionalHeaderClaims"
            },
            additional_payload_claims={
                "additional_payload_claims_key": "additionalPayloadClaims"
            },
            private_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeySourceProperty(
                kms_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
                    kms_key_arn="kmsKeyArn"
                )
            ),
            signing_algorithm="signingAlgorithm"
        )
    ),
    github_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.GithubOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    google_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.GoogleOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    included_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.IncludedOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        authorization_endpoint="authorizationEndpoint",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource",
        issuer="issuer",
        token_endpoint="tokenEndpoint"
    ),
    linkedin_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.LinkedinOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    microsoft_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.MicrosoftOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource",
        tenant_id="tenantId"
    ),
    salesforce_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.SalesforceOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    slack_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProvider.SlackOauth2ProviderConfigInputProperty(
        client_id="clientId",

        # the properties below are optional
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    )
)

Attributes

atlassian_oauth2_provider_config

Input configuration for an Atlassian OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-atlassianoauth2providerconfig

custom_oauth2_provider_config

Input configuration for a custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-customoauth2providerconfig

github_oauth2_provider_config

Input configuration for a GitHub OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-githuboauth2providerconfig

google_oauth2_provider_config

Input configuration for a Google OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-googleoauth2providerconfig

included_oauth2_provider_config

Input configuration for a supported non-custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-includedoauth2providerconfig

linkedin_oauth2_provider_config

Input configuration for a LinkedIn OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-linkedinoauth2providerconfig

microsoft_oauth2_provider_config

Input configuration for a Microsoft OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-microsoftoauth2providerconfig

salesforce_oauth2_provider_config

Input configuration for a Salesforce OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-salesforceoauth2providerconfig

slack_oauth2_provider_config

Input configuration for a Slack OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-slackoauth2providerconfig

Oauth2ProviderConfigOutputProperty

class CfnOAuth2CredentialProvider.Oauth2ProviderConfigOutputProperty(*, client_authentication_method=None, client_id=None, oauth_discovery=None, on_behalf_of_token_exchange_config=None, private_endpoint=None, private_endpoint_overrides=None, private_key_jwt_config=None)

Bases: object

Output configuration for an OAuth2 provider.

Parameters:
  • client_authentication_method (Optional[str]) – The client authentication method used when authenticating with the token endpoint.

  • client_id (Optional[str])

  • oauth_discovery (Union[IResolvable, Oauth2DiscoveryProperty, Dict[str, Any], None]) – Discovery information for an OAuth2 provider.

  • on_behalf_of_token_exchange_config (Union[IResolvable, OnBehalfOfTokenExchangeConfigProperty, Dict[str, Any], None]) – Configuration for on-behalf-of token exchange.

  • private_endpoint (Union[IResolvable, PrivateEndpointProperty, Dict[str, Any], None]) – The private endpoint configuration for connecting to private resources in your VPC.

  • private_endpoint_overrides (Union[IResolvable, Sequence[Union[IResolvable, PrivateEndpointOverrideProperty, Dict[str, Any]]], None]) – The list of private endpoint overrides for the OAuth2 provider. Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

  • private_key_jwt_config (Union[IResolvable, PrivateKeyJwtConfigProperty, Dict[str, Any], None]) – Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

oauth2_provider_config_output_property = bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2ProviderConfigOutputProperty(
    client_authentication_method="clientAuthenticationMethod",
    client_id="clientId",
    oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2DiscoveryProperty(
        authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProvider.Oauth2AuthorizationServerMetadataProperty(
            authorization_endpoint="authorizationEndpoint",
            issuer="issuer",
            token_endpoint="tokenEndpoint",

            # the properties below are optional
            response_types=["responseTypes"]
        ),
        discovery_url="discoveryUrl"
    ),
    on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProvider.OnBehalfOfTokenExchangeConfigProperty(
        grant_type="grantType",

        # the properties below are optional
        token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(
            actor_token_content="actorTokenContent",

            # the properties below are optional
            actor_token_scopes=["actorTokenScopes"]
        )
    ),
    private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
        managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
            endpoint_ip_address_type="endpointIpAddressType",
            subnet_ids=["subnetIds"],
            vpc_identifier="vpcIdentifier",

            # the properties below are optional
            routing_domain="routingDomain",
            security_group_ids=["securityGroupIds"],
            tags={
                "tags_key": "tags"
            }
        ),
        self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
            resource_configuration_identifier="resourceConfigurationIdentifier"
        )
    ),
    private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointOverrideProperty(
        domain="domain",
        private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
            managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
                endpoint_ip_address_type="endpointIpAddressType",
                subnet_ids=["subnetIds"],
                vpc_identifier="vpcIdentifier",

                # the properties below are optional
                routing_domain="routingDomain",
                security_group_ids=["securityGroupIds"],
                tags={
                    "tags_key": "tags"
                }
            ),
            self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
                resource_configuration_identifier="resourceConfigurationIdentifier"
            )
        )
    )],
    private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeyJwtConfigProperty(
        additional_header_claims={
            "additional_header_claims_key": "additionalHeaderClaims"
        },
        additional_payload_claims={
            "additional_payload_claims_key": "additionalPayloadClaims"
        },
        private_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeySourceProperty(
            kms_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
                kms_key_arn="kmsKeyArn"
            )
        ),
        signing_algorithm="signingAlgorithm"
    )
)

Attributes

client_authentication_method

The client authentication method used when authenticating with the token endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-clientauthenticationmethod

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-clientid

Type:

see

oauth_discovery

Discovery information for an OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-oauthdiscovery

on_behalf_of_token_exchange_config

Configuration for on-behalf-of token exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-onbehalfoftokenexchangeconfig

private_endpoint

The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-privateendpoint

private_endpoint_overrides

The list of private endpoint overrides for the OAuth2 provider.

Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-privateendpointoverrides

private_key_jwt_config

Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-privatekeyjwtconfig

OnBehalfOfTokenExchangeConfigProperty

class CfnOAuth2CredentialProvider.OnBehalfOfTokenExchangeConfigProperty(*, grant_type, token_exchange_grant_type_config=None)

Bases: object

Configuration for on-behalf-of token exchange.

Parameters:
See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

on_behalf_of_token_exchange_config_property = bedrockagentcore.CfnOAuth2CredentialProvider.OnBehalfOfTokenExchangeConfigProperty(
    grant_type="grantType",

    # the properties below are optional
    token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(
        actor_token_content="actorTokenContent",

        # the properties below are optional
        actor_token_scopes=["actorTokenScopes"]
    )
)

Attributes

grant_type

The grant type for on-behalf-of token exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig-granttype

token_exchange_grant_type_config

Configuration for RFC 8693 Token Exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig-tokenexchangegranttypeconfig

PrivateEndpointOverrideProperty

class CfnOAuth2CredentialProvider.PrivateEndpointOverrideProperty(*, domain, private_endpoint)

Bases: object

A mapping of a specific domain to a private endpoint for secure connectivity through a VPC Lattice resource configuration.

Parameters:
  • domain (str) – The domain to override with a private endpoint.

  • private_endpoint (Union[IResolvable, PrivateEndpointProperty, Dict[str, Any]]) – The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpointoverride.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

private_endpoint_override_property = bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointOverrideProperty(
    domain="domain",
    private_endpoint=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
        managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
            endpoint_ip_address_type="endpointIpAddressType",
            subnet_ids=["subnetIds"],
            vpc_identifier="vpcIdentifier",

            # the properties below are optional
            routing_domain="routingDomain",
            security_group_ids=["securityGroupIds"],
            tags={
                "tags_key": "tags"
            }
        ),
        self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
            resource_configuration_identifier="resourceConfigurationIdentifier"
        )
    )
)

Attributes

domain

The domain to override with a private endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpointoverride.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpointoverride-domain

private_endpoint

The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpointoverride.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpointoverride-privateendpoint

PrivateEndpointProperty

class CfnOAuth2CredentialProvider.PrivateEndpointProperty(*, managed_vpc_resource=None, self_managed_lattice_resource=None)

Bases: object

The private endpoint configuration for connecting to private resources in your VPC.

Parameters:
  • managed_vpc_resource (Union[IResolvable, ManagedVpcResourceProperty, Dict[str, Any], None]) – Configuration for a managed VPC Lattice resource. AgentCore creates and manages the VPC Lattice resource gateway and resource configuration on your behalf.

  • self_managed_lattice_resource (Union[IResolvable, SelfManagedLatticeResourceProperty, Dict[str, Any], None]) – Configuration for a self-managed VPC Lattice resource. You create and manage the VPC Lattice resource gateway and resource configuration, then provide the resource configuration identifier.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpoint.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

private_endpoint_property = bedrockagentcore.CfnOAuth2CredentialProvider.PrivateEndpointProperty(
    managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProvider.ManagedVpcResourceProperty(
        endpoint_ip_address_type="endpointIpAddressType",
        subnet_ids=["subnetIds"],
        vpc_identifier="vpcIdentifier",

        # the properties below are optional
        routing_domain="routingDomain",
        security_group_ids=["securityGroupIds"],
        tags={
            "tags_key": "tags"
        }
    ),
    self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
        resource_configuration_identifier="resourceConfigurationIdentifier"
    )
)

Attributes

managed_vpc_resource

Configuration for a managed VPC Lattice resource.

AgentCore creates and manages the VPC Lattice resource gateway and resource configuration on your behalf.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpoint.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpoint-managedvpcresource

self_managed_lattice_resource

Configuration for a self-managed VPC Lattice resource.

You create and manage the VPC Lattice resource gateway and resource configuration, then provide the resource configuration identifier.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpoint.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpoint-selfmanagedlatticeresource

PrivateKeyJwtConfigProperty

class CfnOAuth2CredentialProvider.PrivateKeyJwtConfigProperty(*, additional_header_claims=None, additional_payload_claims=None, private_key_source=None, signing_algorithm=None)

Bases: object

Configuration for private_key_jwt client authentication (RFC 7523).

Parameters:
  • additional_header_claims (Union[IResolvable, Mapping[str, str], None]) – A map of additional claims to include in the JWT client assertion.

  • additional_payload_claims (Union[IResolvable, Mapping[str, str], None]) – A map of additional claims to include in the JWT client assertion.

  • private_key_source (Union[IResolvable, PrivateKeySourceProperty, Dict[str, Any], None]) – Contains the private key source configuration for a JWT client assertion.

  • signing_algorithm (Optional[str]) – The algorithm used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

private_key_jwt_config_property = bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeyJwtConfigProperty(
    additional_header_claims={
        "additional_header_claims_key": "additionalHeaderClaims"
    },
    additional_payload_claims={
        "additional_payload_claims_key": "additionalPayloadClaims"
    },
    private_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeySourceProperty(
        kms_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
            kms_key_arn="kmsKeyArn"
        )
    ),
    signing_algorithm="signingAlgorithm"
)

Attributes

additional_header_claims

A map of additional claims to include in the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-additionalheaderclaims

additional_payload_claims

A map of additional claims to include in the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-additionalpayloadclaims

private_key_source

Contains the private key source configuration for a JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-privatekeysource

signing_algorithm

The algorithm used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-signingalgorithm

PrivateKeySourceProperty

class CfnOAuth2CredentialProvider.PrivateKeySourceProperty(*, kms_key_source=None)

Bases: object

Contains the private key source configuration for a JWT client assertion.

Parameters:

kms_key_source (Union[IResolvable, KmsKeySourceTypeProperty, Dict[str, Any], None]) – Contains the KMS key configuration for a JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeysource.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

private_key_source_property = bedrockagentcore.CfnOAuth2CredentialProvider.PrivateKeySourceProperty(
    kms_key_source=bedrockagentcore.CfnOAuth2CredentialProvider.KmsKeySourceTypeProperty(
        kms_key_arn="kmsKeyArn"
    )
)

Attributes

kms_key_source

Contains the KMS key configuration for a JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeysource.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeysource-kmskeysource

SalesforceOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.SalesforceOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a Salesforce OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

salesforce_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.SalesforceOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientsecretsource

Type:

see

SecretReferenceProperty

class CfnOAuth2CredentialProvider.SecretReferenceProperty(*, json_key, secret_id)

Bases: object

A reference to a customer-provided secret stored in AWS Secrets Manager.

Parameters:
  • json_key (str) – The JSON key within the secret that contains the credential value.

  • secret_id (str) – The ID or ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-secretreference.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

secret_reference_property = bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
    json_key="jsonKey",
    secret_id="secretId"
)

Attributes

json_key

The JSON key within the secret that contains the credential value.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-secretreference.html#cfn-bedrockagentcore-oauth2credentialprovider-secretreference-jsonkey

secret_id

The ID or ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-secretreference.html#cfn-bedrockagentcore-oauth2credentialprovider-secretreference-secretid

SelfManagedLatticeResourceProperty

class CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(*, resource_configuration_identifier)

Bases: object

Configuration for a self-managed VPC Lattice resource.

You create and manage the VPC Lattice resource gateway and resource configuration, then provide the resource configuration identifier.

Parameters:

resource_configuration_identifier (str) – The ARN or ID of the VPC Lattice resource configuration.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-selfmanagedlatticeresource.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

self_managed_lattice_resource_property = bedrockagentcore.CfnOAuth2CredentialProvider.SelfManagedLatticeResourceProperty(
    resource_configuration_identifier="resourceConfigurationIdentifier"
)

Attributes

resource_configuration_identifier

The ARN or ID of the VPC Lattice resource configuration.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-selfmanagedlatticeresource.html#cfn-bedrockagentcore-oauth2credentialprovider-selfmanagedlatticeresource-resourceconfigurationidentifier

SlackOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProvider.SlackOauth2ProviderConfigInputProperty(*, client_id, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a Slack OAuth2 provider.

Parameters:
  • client_id (str)

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

slack_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProvider.SlackOauth2ProviderConfigInputProperty(
    client_id="clientId",

    # the properties below are optional
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProvider.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientsecretsource

Type:

see

TokenExchangeGrantTypeConfigProperty

class CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(*, actor_token_content, actor_token_scopes=None)

Bases: object

Configuration for RFC 8693 Token Exchange.

Parameters:
  • actor_token_content (str) – The actor token content type.

  • actor_token_scopes (Optional[Sequence[str]]) – The actor token scopes. Only valid when ActorTokenContent is M2M.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk import aws_bedrockagentcore as bedrockagentcore

token_exchange_grant_type_config_property = bedrockagentcore.CfnOAuth2CredentialProvider.TokenExchangeGrantTypeConfigProperty(
    actor_token_content="actorTokenContent",

    # the properties below are optional
    actor_token_scopes=["actorTokenScopes"]
)

Attributes

actor_token_content

The actor token content type.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig-actortokencontent

actor_token_scopes

The actor token scopes.

Only valid when ActorTokenContent is M2M.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig-actortokenscopes