CfnOAuth2CredentialProviderPropsMixin

class aws_cdk.cfn_property_mixins.aws_bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin(props, *, strategy=None)

Bases: Mixin

Resource Type definition for AWS::BedrockAgentCore::OAuth2CredentialProvider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-bedrockagentcore-oauth2credentialprovider.html

CloudformationResource:

AWS::BedrockAgentCore::OAuth2CredentialProvider

Mixin:

true

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore
import aws_cdk as cdk

# merge_strategy: cdk.IMergeStrategy

cfn_o_auth2_credential_provider_props_mixin = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin(bedrockagentcore.CfnOAuth2CredentialProviderMixinProps(
    credential_provider_vendor="credentialProviderVendor",
    name="name",
    oauth2_provider_config_input=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2ProviderConfigInputProperty(
        atlassian_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.AtlassianOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        custom_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.CustomOauth2ProviderConfigInputProperty(
            client_authentication_method="clientAuthenticationMethod",
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource",
            oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2DiscoveryProperty(
                authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(
                    authorization_endpoint="authorizationEndpoint",
                    issuer="issuer",
                    response_types=["responseTypes"],
                    token_endpoint="tokenEndpoint"
                ),
                discovery_url="discoveryUrl"
            ),
            on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.OnBehalfOfTokenExchangeConfigProperty(
                grant_type="grantType",
                token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(
                    actor_token_content="actorTokenContent",
                    actor_token_scopes=["actorTokenScopes"]
                )
            ),
            private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
                managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
                    endpoint_ip_address_type="endpointIpAddressType",
                    routing_domain="routingDomain",
                    security_group_ids=["securityGroupIds"],
                    subnet_ids=["subnetIds"],
                    tags={
                        "tags_key": "tags"
                    },
                    vpc_identifier="vpcIdentifier"
                ),
                self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
                    resource_configuration_identifier="resourceConfigurationIdentifier"
                )
            ),
            private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointOverrideProperty(
                domain="domain",
                private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
                    managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
                        endpoint_ip_address_type="endpointIpAddressType",
                        routing_domain="routingDomain",
                        security_group_ids=["securityGroupIds"],
                        subnet_ids=["subnetIds"],
                        tags={
                            "tags_key": "tags"
                        },
                        vpc_identifier="vpcIdentifier"
                    ),
                    self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
                        resource_configuration_identifier="resourceConfigurationIdentifier"
                    )
                )
            )],
            private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeyJwtConfigProperty(
                additional_header_claims={
                    "additional_header_claims_key": "additionalHeaderClaims"
                },
                additional_payload_claims={
                    "additional_payload_claims_key": "additionalPayloadClaims"
                },
                private_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(
                    kms_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
                        kms_key_arn="kmsKeyArn"
                    )
                ),
                signing_algorithm="signingAlgorithm"
            )
        ),
        github_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.GithubOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        google_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.GoogleOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        included_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.IncludedOauth2ProviderConfigInputProperty(
            authorization_endpoint="authorizationEndpoint",
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource",
            issuer="issuer",
            token_endpoint="tokenEndpoint"
        ),
        linkedin_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.LinkedinOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        microsoft_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.MicrosoftOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource",
            tenant_id="tenantId"
        ),
        salesforce_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SalesforceOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        ),
        slack_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SlackOauth2ProviderConfigInputProperty(
            client_id="clientId",
            client_secret="clientSecret",
            client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
                json_key="jsonKey",
                secret_id="secretId"
            ),
            client_secret_source="clientSecretSource"
        )
    ),
    tags=[cdk.CfnTag(
        key="key",
        value="value"
    )]
),
    strategy=merge_strategy
)

Create a mixin to apply properties to AWS::BedrockAgentCore::OAuth2CredentialProvider.

Parameters:

Methods

apply_to(construct)

Apply the mixin properties to the construct.

Parameters:

construct (IConstruct)

Return type:

None

supports(construct)

Check if this mixin supports the given construct.

Parameters:

construct (IConstruct)

Return type:

bool

Attributes

CFN_PROPERTY_KEYS = ['credentialProviderVendor', 'name', 'oauth2ProviderConfigInput', 'tags']

Static Methods

classmethod is_mixin(x)

Checks if x is a Mixin.

Parameters:

x (Any) – Any object.

Return type:

bool

Returns:

true if x is an object created from a class which extends Mixin.

AtlassianOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.AtlassianOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for an Atlassian OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

atlassian_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.AtlassianOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-atlassianoauth2providerconfiginput-clientsecretsource

Type:

see

ClientSecretArnProperty

class CfnOAuth2CredentialProviderPropsMixin.ClientSecretArnProperty(*, secret_arn=None)

Bases: object

Contains information about a secret in AWS Secrets Manager.

Parameters:

secret_arn (Optional[str]) – The ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-clientsecretarn.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

client_secret_arn_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ClientSecretArnProperty(
    secret_arn="secretArn"
)

Attributes

secret_arn

The ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-clientsecretarn.html#cfn-bedrockagentcore-oauth2credentialprovider-clientsecretarn-secretarn

CustomOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.CustomOauth2ProviderConfigInputProperty(*, client_authentication_method=None, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None, oauth_discovery=None, on_behalf_of_token_exchange_config=None, private_endpoint=None, private_endpoint_overrides=None, private_key_jwt_config=None)

Bases: object

Input configuration for a custom OAuth2 provider.

Parameters:
  • client_authentication_method (Optional[str]) – The client authentication method to use when authenticating with the token endpoint.

  • client_id (Optional[str]) – The client ID for the custom OAuth2 provider.

  • client_secret (Optional[str]) – The client secret for the custom OAuth2 provider.

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str]) – The source of the client secret.

  • oauth_discovery (Union[IResolvable, Oauth2DiscoveryProperty, Dict[str, Any], None]) – Discovery information for an OAuth2 provider.

  • on_behalf_of_token_exchange_config (Union[IResolvable, OnBehalfOfTokenExchangeConfigProperty, Dict[str, Any], None]) – Configuration for on-behalf-of token exchange.

  • private_endpoint (Union[IResolvable, PrivateEndpointProperty, Dict[str, Any], None]) – The private endpoint configuration for connecting to private resources in your VPC.

  • private_endpoint_overrides (Union[IResolvable, Sequence[Union[IResolvable, PrivateEndpointOverrideProperty, Dict[str, Any]]], None]) – A list of private endpoint overrides. Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

  • private_key_jwt_config (Union[IResolvable, PrivateKeyJwtConfigProperty, Dict[str, Any], None]) – Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

custom_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.CustomOauth2ProviderConfigInputProperty(
    client_authentication_method="clientAuthenticationMethod",
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource",
    oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2DiscoveryProperty(
        authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(
            authorization_endpoint="authorizationEndpoint",
            issuer="issuer",
            response_types=["responseTypes"],
            token_endpoint="tokenEndpoint"
        ),
        discovery_url="discoveryUrl"
    ),
    on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.OnBehalfOfTokenExchangeConfigProperty(
        grant_type="grantType",
        token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(
            actor_token_content="actorTokenContent",
            actor_token_scopes=["actorTokenScopes"]
        )
    ),
    private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
        managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
            endpoint_ip_address_type="endpointIpAddressType",
            routing_domain="routingDomain",
            security_group_ids=["securityGroupIds"],
            subnet_ids=["subnetIds"],
            tags={
                "tags_key": "tags"
            },
            vpc_identifier="vpcIdentifier"
        ),
        self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
            resource_configuration_identifier="resourceConfigurationIdentifier"
        )
    ),
    private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointOverrideProperty(
        domain="domain",
        private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
            managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
                endpoint_ip_address_type="endpointIpAddressType",
                routing_domain="routingDomain",
                security_group_ids=["securityGroupIds"],
                subnet_ids=["subnetIds"],
                tags={
                    "tags_key": "tags"
                },
                vpc_identifier="vpcIdentifier"
            ),
            self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
                resource_configuration_identifier="resourceConfigurationIdentifier"
            )
        )
    )],
    private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeyJwtConfigProperty(
        additional_header_claims={
            "additional_header_claims_key": "additionalHeaderClaims"
        },
        additional_payload_claims={
            "additional_payload_claims_key": "additionalPayloadClaims"
        },
        private_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(
            kms_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
                kms_key_arn="kmsKeyArn"
            )
        ),
        signing_algorithm="signingAlgorithm"
    )
)

Attributes

client_authentication_method

The client authentication method to use when authenticating with the token endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientauthenticationmethod

client_id

The client ID for the custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientid

client_secret

The client secret for the custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientsecret

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientsecretconfig

client_secret_source

The source of the client secret.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-clientsecretsource

oauth_discovery

Discovery information for an OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-oauthdiscovery

on_behalf_of_token_exchange_config

Configuration for on-behalf-of token exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-onbehalfoftokenexchangeconfig

private_endpoint

The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-privateendpoint

private_endpoint_overrides

A list of private endpoint overrides.

Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-privateendpointoverrides

private_key_jwt_config

Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-customoauth2providerconfiginput-privatekeyjwtconfig

GithubOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.GithubOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a GitHub OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

github_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.GithubOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-githuboauth2providerconfiginput-clientsecretsource

Type:

see

GoogleOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.GoogleOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a Google OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

google_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.GoogleOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-googleoauth2providerconfiginput-clientsecretsource

Type:

see

IncludedOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.IncludedOauth2ProviderConfigInputProperty(*, authorization_endpoint=None, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None, issuer=None, token_endpoint=None)

Bases: object

Input configuration for a supported non-custom OAuth2 provider.

Parameters:
  • authorization_endpoint (Optional[str]) – OAuth2 authorization endpoint for your isolated OAuth2 application tenant.

  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

  • issuer (Optional[str]) – Token issuer of your isolated OAuth2 application tenant.

  • token_endpoint (Optional[str]) – OAuth2 token endpoint for your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

included_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.IncludedOauth2ProviderConfigInputProperty(
    authorization_endpoint="authorizationEndpoint",
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource",
    issuer="issuer",
    token_endpoint="tokenEndpoint"
)

Attributes

authorization_endpoint

OAuth2 authorization endpoint for your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-authorizationendpoint

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-clientsecretsource

Type:

see

issuer

Token issuer of your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-issuer

token_endpoint

OAuth2 token endpoint for your isolated OAuth2 application tenant.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-includedoauth2providerconfiginput-tokenendpoint

KmsKeySourceTypeProperty

class CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(*, kms_key_arn=None)

Bases: object

Contains the KMS key configuration for a JWT client assertion.

Parameters:

kms_key_arn (Optional[str]) – The Amazon Resource Name (ARN) of the KMS key used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-kmskeysourcetype.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

kms_key_source_type_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
    kms_key_arn="kmsKeyArn"
)

Attributes

kms_key_arn

The Amazon Resource Name (ARN) of the KMS key used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-kmskeysourcetype.html#cfn-bedrockagentcore-oauth2credentialprovider-kmskeysourcetype-kmskeyarn

LinkedinOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.LinkedinOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a LinkedIn OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

linkedin_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.LinkedinOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-linkedinoauth2providerconfiginput-clientsecretsource

Type:

see

ManagedVpcResourceProperty

class CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(*, endpoint_ip_address_type=None, routing_domain=None, security_group_ids=None, subnet_ids=None, tags=None, vpc_identifier=None)

Bases: object

Configuration for a managed VPC Lattice resource.

AgentCore creates and manages the VPC Lattice resource gateway and resource configuration on your behalf.

Parameters:
  • endpoint_ip_address_type (Optional[str]) – The IP address type for the resource configuration endpoint.

  • routing_domain (Optional[str]) – An intermediate publicly resolvable domain used as the VPC Lattice resource configuration endpoint.

  • security_group_ids (Optional[Sequence[str]]) – The security group IDs to associate with the VPC Lattice resource gateway.

  • subnet_ids (Optional[Sequence[str]]) – The subnet IDs within the VPC where the VPC Lattice resource gateway is placed.

  • tags (Optional[Mapping[str, str]]) – A map of tags (key-value pairs) to apply to a resource.

  • vpc_identifier (Optional[str]) – The ID of the VPC that contains your private resource.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

managed_vpc_resource_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
    endpoint_ip_address_type="endpointIpAddressType",
    routing_domain="routingDomain",
    security_group_ids=["securityGroupIds"],
    subnet_ids=["subnetIds"],
    tags={
        "tags_key": "tags"
    },
    vpc_identifier="vpcIdentifier"
)

Attributes

endpoint_ip_address_type

The IP address type for the resource configuration endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-endpointipaddresstype

routing_domain

An intermediate publicly resolvable domain used as the VPC Lattice resource configuration endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-routingdomain

security_group_ids

The security group IDs to associate with the VPC Lattice resource gateway.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-securitygroupids

subnet_ids

The subnet IDs within the VPC where the VPC Lattice resource gateway is placed.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-subnetids

tags

A map of tags (key-value pairs) to apply to a resource.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-tags

vpc_identifier

The ID of the VPC that contains your private resource.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-managedvpcresource.html#cfn-bedrockagentcore-oauth2credentialprovider-managedvpcresource-vpcidentifier

MicrosoftOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.MicrosoftOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None, tenant_id=None)

Bases: object

Input configuration for a Microsoft OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

  • tenant_id (Optional[str]) – The Microsoft Entra ID tenant ID.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

microsoft_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.MicrosoftOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource",
    tenant_id="tenantId"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-clientsecretsource

Type:

see

tenant_id

The Microsoft Entra ID tenant ID.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-microsoftoauth2providerconfiginput-tenantid

Oauth2AuthorizationServerMetadataProperty

class CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(*, authorization_endpoint=None, issuer=None, response_types=None, token_endpoint=None)

Bases: object

Authorization server metadata for the OAuth2 provider.

Parameters:
  • authorization_endpoint (Optional[str]) – The authorization endpoint URL.

  • issuer (Optional[str]) – The issuer URL for the OAuth2 authorization server.

  • response_types (Optional[Sequence[str]]) – The supported response types.

  • token_endpoint (Optional[str]) – The token endpoint URL.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

oauth2_authorization_server_metadata_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(
    authorization_endpoint="authorizationEndpoint",
    issuer="issuer",
    response_types=["responseTypes"],
    token_endpoint="tokenEndpoint"
)

Attributes

authorization_endpoint

The authorization endpoint URL.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-authorizationendpoint

issuer

The issuer URL for the OAuth2 authorization server.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-issuer

response_types

The supported response types.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-responsetypes

token_endpoint

The token endpoint URL.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2authorizationservermetadata-tokenendpoint

Oauth2DiscoveryProperty

class CfnOAuth2CredentialProviderPropsMixin.Oauth2DiscoveryProperty(*, authorization_server_metadata=None, discovery_url=None)

Bases: object

Discovery information for an OAuth2 provider.

Parameters:
See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2discovery.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

oauth2_discovery_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2DiscoveryProperty(
    authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(
        authorization_endpoint="authorizationEndpoint",
        issuer="issuer",
        response_types=["responseTypes"],
        token_endpoint="tokenEndpoint"
    ),
    discovery_url="discoveryUrl"
)

Attributes

authorization_server_metadata

Authorization server metadata for the OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2discovery.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2discovery-authorizationservermetadata

discovery_url

The discovery URL for the OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2discovery.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2discovery-discoveryurl

Oauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.Oauth2ProviderConfigInputProperty(*, atlassian_oauth2_provider_config=None, custom_oauth2_provider_config=None, github_oauth2_provider_config=None, google_oauth2_provider_config=None, included_oauth2_provider_config=None, linkedin_oauth2_provider_config=None, microsoft_oauth2_provider_config=None, salesforce_oauth2_provider_config=None, slack_oauth2_provider_config=None)

Bases: object

Input configuration for an OAuth2 provider.

Parameters:
See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2ProviderConfigInputProperty(
    atlassian_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.AtlassianOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    custom_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.CustomOauth2ProviderConfigInputProperty(
        client_authentication_method="clientAuthenticationMethod",
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource",
        oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2DiscoveryProperty(
            authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(
                authorization_endpoint="authorizationEndpoint",
                issuer="issuer",
                response_types=["responseTypes"],
                token_endpoint="tokenEndpoint"
            ),
            discovery_url="discoveryUrl"
        ),
        on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.OnBehalfOfTokenExchangeConfigProperty(
            grant_type="grantType",
            token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(
                actor_token_content="actorTokenContent",
                actor_token_scopes=["actorTokenScopes"]
            )
        ),
        private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
            managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
                endpoint_ip_address_type="endpointIpAddressType",
                routing_domain="routingDomain",
                security_group_ids=["securityGroupIds"],
                subnet_ids=["subnetIds"],
                tags={
                    "tags_key": "tags"
                },
                vpc_identifier="vpcIdentifier"
            ),
            self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
                resource_configuration_identifier="resourceConfigurationIdentifier"
            )
        ),
        private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointOverrideProperty(
            domain="domain",
            private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
                managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
                    endpoint_ip_address_type="endpointIpAddressType",
                    routing_domain="routingDomain",
                    security_group_ids=["securityGroupIds"],
                    subnet_ids=["subnetIds"],
                    tags={
                        "tags_key": "tags"
                    },
                    vpc_identifier="vpcIdentifier"
                ),
                self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
                    resource_configuration_identifier="resourceConfigurationIdentifier"
                )
            )
        )],
        private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeyJwtConfigProperty(
            additional_header_claims={
                "additional_header_claims_key": "additionalHeaderClaims"
            },
            additional_payload_claims={
                "additional_payload_claims_key": "additionalPayloadClaims"
            },
            private_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(
                kms_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
                    kms_key_arn="kmsKeyArn"
                )
            ),
            signing_algorithm="signingAlgorithm"
        )
    ),
    github_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.GithubOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    google_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.GoogleOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    included_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.IncludedOauth2ProviderConfigInputProperty(
        authorization_endpoint="authorizationEndpoint",
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource",
        issuer="issuer",
        token_endpoint="tokenEndpoint"
    ),
    linkedin_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.LinkedinOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    microsoft_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.MicrosoftOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource",
        tenant_id="tenantId"
    ),
    salesforce_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SalesforceOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    ),
    slack_oauth2_provider_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SlackOauth2ProviderConfigInputProperty(
        client_id="clientId",
        client_secret="clientSecret",
        client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
            json_key="jsonKey",
            secret_id="secretId"
        ),
        client_secret_source="clientSecretSource"
    )
)

Attributes

atlassian_oauth2_provider_config

Input configuration for an Atlassian OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-atlassianoauth2providerconfig

custom_oauth2_provider_config

Input configuration for a custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-customoauth2providerconfig

github_oauth2_provider_config

Input configuration for a GitHub OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-githuboauth2providerconfig

google_oauth2_provider_config

Input configuration for a Google OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-googleoauth2providerconfig

included_oauth2_provider_config

Input configuration for a supported non-custom OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-includedoauth2providerconfig

linkedin_oauth2_provider_config

Input configuration for a LinkedIn OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-linkedinoauth2providerconfig

microsoft_oauth2_provider_config

Input configuration for a Microsoft OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-microsoftoauth2providerconfig

salesforce_oauth2_provider_config

Input configuration for a Salesforce OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-salesforceoauth2providerconfig

slack_oauth2_provider_config

Input configuration for a Slack OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfiginput-slackoauth2providerconfig

Oauth2ProviderConfigOutputProperty

class CfnOAuth2CredentialProviderPropsMixin.Oauth2ProviderConfigOutputProperty(*, client_authentication_method=None, client_id=None, oauth_discovery=None, on_behalf_of_token_exchange_config=None, private_endpoint=None, private_endpoint_overrides=None, private_key_jwt_config=None)

Bases: object

Output configuration for an OAuth2 provider.

Parameters:
  • client_authentication_method (Optional[str]) – The client authentication method used when authenticating with the token endpoint.

  • client_id (Optional[str])

  • oauth_discovery (Union[IResolvable, Oauth2DiscoveryProperty, Dict[str, Any], None]) – Discovery information for an OAuth2 provider.

  • on_behalf_of_token_exchange_config (Union[IResolvable, OnBehalfOfTokenExchangeConfigProperty, Dict[str, Any], None]) – Configuration for on-behalf-of token exchange.

  • private_endpoint (Union[IResolvable, PrivateEndpointProperty, Dict[str, Any], None]) – The private endpoint configuration for connecting to private resources in your VPC.

  • private_endpoint_overrides (Union[IResolvable, Sequence[Union[IResolvable, PrivateEndpointOverrideProperty, Dict[str, Any]]], None]) – The list of private endpoint overrides for the OAuth2 provider. Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

  • private_key_jwt_config (Union[IResolvable, PrivateKeyJwtConfigProperty, Dict[str, Any], None]) – Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

oauth2_provider_config_output_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2ProviderConfigOutputProperty(
    client_authentication_method="clientAuthenticationMethod",
    client_id="clientId",
    oauth_discovery=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2DiscoveryProperty(
        authorization_server_metadata=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.Oauth2AuthorizationServerMetadataProperty(
            authorization_endpoint="authorizationEndpoint",
            issuer="issuer",
            response_types=["responseTypes"],
            token_endpoint="tokenEndpoint"
        ),
        discovery_url="discoveryUrl"
    ),
    on_behalf_of_token_exchange_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.OnBehalfOfTokenExchangeConfigProperty(
        grant_type="grantType",
        token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(
            actor_token_content="actorTokenContent",
            actor_token_scopes=["actorTokenScopes"]
        )
    ),
    private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
        managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
            endpoint_ip_address_type="endpointIpAddressType",
            routing_domain="routingDomain",
            security_group_ids=["securityGroupIds"],
            subnet_ids=["subnetIds"],
            tags={
                "tags_key": "tags"
            },
            vpc_identifier="vpcIdentifier"
        ),
        self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
            resource_configuration_identifier="resourceConfigurationIdentifier"
        )
    ),
    private_endpoint_overrides=[bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointOverrideProperty(
        domain="domain",
        private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
            managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
                endpoint_ip_address_type="endpointIpAddressType",
                routing_domain="routingDomain",
                security_group_ids=["securityGroupIds"],
                subnet_ids=["subnetIds"],
                tags={
                    "tags_key": "tags"
                },
                vpc_identifier="vpcIdentifier"
            ),
            self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
                resource_configuration_identifier="resourceConfigurationIdentifier"
            )
        )
    )],
    private_key_jwt_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeyJwtConfigProperty(
        additional_header_claims={
            "additional_header_claims_key": "additionalHeaderClaims"
        },
        additional_payload_claims={
            "additional_payload_claims_key": "additionalPayloadClaims"
        },
        private_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(
            kms_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
                kms_key_arn="kmsKeyArn"
            )
        ),
        signing_algorithm="signingAlgorithm"
    )
)

Attributes

client_authentication_method

The client authentication method used when authenticating with the token endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-clientauthenticationmethod

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-clientid

Type:

see

oauth_discovery

Discovery information for an OAuth2 provider.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-oauthdiscovery

on_behalf_of_token_exchange_config

Configuration for on-behalf-of token exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-onbehalfoftokenexchangeconfig

private_endpoint

The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-privateendpoint

private_endpoint_overrides

The list of private endpoint overrides for the OAuth2 provider.

Each override maps a specific domain to a private endpoint, enabling secure connectivity through VPC Lattice resource configurations.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-privateendpointoverrides

private_key_jwt_config

Configuration for private_key_jwt client authentication (RFC 7523).

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput.html#cfn-bedrockagentcore-oauth2credentialprovider-oauth2providerconfigoutput-privatekeyjwtconfig

OnBehalfOfTokenExchangeConfigProperty

class CfnOAuth2CredentialProviderPropsMixin.OnBehalfOfTokenExchangeConfigProperty(*, grant_type=None, token_exchange_grant_type_config=None)

Bases: object

Configuration for on-behalf-of token exchange.

Parameters:
  • grant_type (Optional[str]) – The grant type for on-behalf-of token exchange.

  • token_exchange_grant_type_config (Union[IResolvable, TokenExchangeGrantTypeConfigProperty, Dict[str, Any], None]) – Configuration for RFC 8693 Token Exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

on_behalf_of_token_exchange_config_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.OnBehalfOfTokenExchangeConfigProperty(
    grant_type="grantType",
    token_exchange_grant_type_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(
        actor_token_content="actorTokenContent",
        actor_token_scopes=["actorTokenScopes"]
    )
)

Attributes

grant_type

The grant type for on-behalf-of token exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig-granttype

token_exchange_grant_type_config

Configuration for RFC 8693 Token Exchange.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-onbehalfoftokenexchangeconfig-tokenexchangegranttypeconfig

PrivateEndpointOverrideProperty

class CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointOverrideProperty(*, domain=None, private_endpoint=None)

Bases: object

A mapping of a specific domain to a private endpoint for secure connectivity through a VPC Lattice resource configuration.

Parameters:
  • domain (Optional[str]) – The domain to override with a private endpoint.

  • private_endpoint (Union[IResolvable, PrivateEndpointProperty, Dict[str, Any], None]) – The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpointoverride.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

private_endpoint_override_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointOverrideProperty(
    domain="domain",
    private_endpoint=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
        managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
            endpoint_ip_address_type="endpointIpAddressType",
            routing_domain="routingDomain",
            security_group_ids=["securityGroupIds"],
            subnet_ids=["subnetIds"],
            tags={
                "tags_key": "tags"
            },
            vpc_identifier="vpcIdentifier"
        ),
        self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
            resource_configuration_identifier="resourceConfigurationIdentifier"
        )
    )
)

Attributes

domain

The domain to override with a private endpoint.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpointoverride.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpointoverride-domain

private_endpoint

The private endpoint configuration for connecting to private resources in your VPC.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpointoverride.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpointoverride-privateendpoint

PrivateEndpointProperty

class CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(*, managed_vpc_resource=None, self_managed_lattice_resource=None)

Bases: object

The private endpoint configuration for connecting to private resources in your VPC.

Parameters:
  • managed_vpc_resource (Union[IResolvable, ManagedVpcResourceProperty, Dict[str, Any], None]) – Configuration for a managed VPC Lattice resource. AgentCore creates and manages the VPC Lattice resource gateway and resource configuration on your behalf.

  • self_managed_lattice_resource (Union[IResolvable, SelfManagedLatticeResourceProperty, Dict[str, Any], None]) – Configuration for a self-managed VPC Lattice resource. You create and manage the VPC Lattice resource gateway and resource configuration, then provide the resource configuration identifier.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpoint.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

private_endpoint_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateEndpointProperty(
    managed_vpc_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.ManagedVpcResourceProperty(
        endpoint_ip_address_type="endpointIpAddressType",
        routing_domain="routingDomain",
        security_group_ids=["securityGroupIds"],
        subnet_ids=["subnetIds"],
        tags={
            "tags_key": "tags"
        },
        vpc_identifier="vpcIdentifier"
    ),
    self_managed_lattice_resource=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
        resource_configuration_identifier="resourceConfigurationIdentifier"
    )
)

Attributes

managed_vpc_resource

Configuration for a managed VPC Lattice resource.

AgentCore creates and manages the VPC Lattice resource gateway and resource configuration on your behalf.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpoint.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpoint-managedvpcresource

self_managed_lattice_resource

Configuration for a self-managed VPC Lattice resource.

You create and manage the VPC Lattice resource gateway and resource configuration, then provide the resource configuration identifier.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privateendpoint.html#cfn-bedrockagentcore-oauth2credentialprovider-privateendpoint-selfmanagedlatticeresource

PrivateKeyJwtConfigProperty

class CfnOAuth2CredentialProviderPropsMixin.PrivateKeyJwtConfigProperty(*, additional_header_claims=None, additional_payload_claims=None, private_key_source=None, signing_algorithm=None)

Bases: object

Configuration for private_key_jwt client authentication (RFC 7523).

Parameters:
  • additional_header_claims (Union[IResolvable, Mapping[str, str], None]) – A map of additional claims to include in the JWT client assertion.

  • additional_payload_claims (Union[IResolvable, Mapping[str, str], None]) – A map of additional claims to include in the JWT client assertion.

  • private_key_source (Union[IResolvable, PrivateKeySourceProperty, Dict[str, Any], None]) – Contains the private key source configuration for a JWT client assertion.

  • signing_algorithm (Optional[str]) – The algorithm used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

private_key_jwt_config_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeyJwtConfigProperty(
    additional_header_claims={
        "additional_header_claims_key": "additionalHeaderClaims"
    },
    additional_payload_claims={
        "additional_payload_claims_key": "additionalPayloadClaims"
    },
    private_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(
        kms_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
            kms_key_arn="kmsKeyArn"
        )
    ),
    signing_algorithm="signingAlgorithm"
)

Attributes

additional_header_claims

A map of additional claims to include in the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-additionalheaderclaims

additional_payload_claims

A map of additional claims to include in the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-additionalpayloadclaims

private_key_source

Contains the private key source configuration for a JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-privatekeysource

signing_algorithm

The algorithm used to sign the JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeyjwtconfig-signingalgorithm

PrivateKeySourceProperty

class CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(*, kms_key_source=None)

Bases: object

Contains the private key source configuration for a JWT client assertion.

Parameters:

kms_key_source (Union[IResolvable, KmsKeySourceTypeProperty, Dict[str, Any], None]) – Contains the KMS key configuration for a JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeysource.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

private_key_source_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.PrivateKeySourceProperty(
    kms_key_source=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.KmsKeySourceTypeProperty(
        kms_key_arn="kmsKeyArn"
    )
)

Attributes

kms_key_source

Contains the KMS key configuration for a JWT client assertion.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-privatekeysource.html#cfn-bedrockagentcore-oauth2credentialprovider-privatekeysource-kmskeysource

SalesforceOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.SalesforceOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a Salesforce OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

salesforce_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SalesforceOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-salesforceoauth2providerconfiginput-clientsecretsource

Type:

see

SecretReferenceProperty

class CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(*, json_key=None, secret_id=None)

Bases: object

A reference to a customer-provided secret stored in AWS Secrets Manager.

Parameters:
  • json_key (Optional[str]) – The JSON key within the secret that contains the credential value.

  • secret_id (Optional[str]) – The ID or ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-secretreference.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

secret_reference_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
    json_key="jsonKey",
    secret_id="secretId"
)

Attributes

json_key

The JSON key within the secret that contains the credential value.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-secretreference.html#cfn-bedrockagentcore-oauth2credentialprovider-secretreference-jsonkey

secret_id

The ID or ARN of the secret in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-secretreference.html#cfn-bedrockagentcore-oauth2credentialprovider-secretreference-secretid

SelfManagedLatticeResourceProperty

class CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(*, resource_configuration_identifier=None)

Bases: object

Configuration for a self-managed VPC Lattice resource.

You create and manage the VPC Lattice resource gateway and resource configuration, then provide the resource configuration identifier.

Parameters:

resource_configuration_identifier (Optional[str]) – The ARN or ID of the VPC Lattice resource configuration.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-selfmanagedlatticeresource.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

self_managed_lattice_resource_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SelfManagedLatticeResourceProperty(
    resource_configuration_identifier="resourceConfigurationIdentifier"
)

Attributes

resource_configuration_identifier

The ARN or ID of the VPC Lattice resource configuration.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-selfmanagedlatticeresource.html#cfn-bedrockagentcore-oauth2credentialprovider-selfmanagedlatticeresource-resourceconfigurationidentifier

SlackOauth2ProviderConfigInputProperty

class CfnOAuth2CredentialProviderPropsMixin.SlackOauth2ProviderConfigInputProperty(*, client_id=None, client_secret=None, client_secret_config=None, client_secret_source=None)

Bases: object

Input configuration for a Slack OAuth2 provider.

Parameters:
  • client_id (Optional[str])

  • client_secret (Optional[str])

  • client_secret_config (Union[IResolvable, SecretReferenceProperty, Dict[str, Any], None]) – A reference to a customer-provided secret stored in AWS Secrets Manager.

  • client_secret_source (Optional[str])

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

slack_oauth2_provider_config_input_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SlackOauth2ProviderConfigInputProperty(
    client_id="clientId",
    client_secret="clientSecret",
    client_secret_config=bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.SecretReferenceProperty(
        json_key="jsonKey",
        secret_id="secretId"
    ),
    client_secret_source="clientSecretSource"
)

Attributes

client_id

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientid

Type:

see

client_secret

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientsecret

Type:

see

client_secret_config

A reference to a customer-provided secret stored in AWS Secrets Manager.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientsecretconfig

client_secret_source

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput.html#cfn-bedrockagentcore-oauth2credentialprovider-slackoauth2providerconfiginput-clientsecretsource

Type:

see

TokenExchangeGrantTypeConfigProperty

class CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(*, actor_token_content=None, actor_token_scopes=None)

Bases: object

Configuration for RFC 8693 Token Exchange.

Parameters:
  • actor_token_content (Optional[str]) – The actor token content type.

  • actor_token_scopes (Optional[Sequence[str]]) – The actor token scopes. Only valid when ActorTokenContent is M2M.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig.html

ExampleMetadata:

fixture=_generated

Example:

# The code below shows an example of how to instantiate this type.
# The values are placeholders you should change.
from aws_cdk.cfn_property_mixins import aws_bedrockagentcore as bedrockagentcore

token_exchange_grant_type_config_property = bedrockagentcore.CfnOAuth2CredentialProviderPropsMixin.TokenExchangeGrantTypeConfigProperty(
    actor_token_content="actorTokenContent",
    actor_token_scopes=["actorTokenScopes"]
)

Attributes

actor_token_content

The actor token content type.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig-actortokencontent

actor_token_scopes

The actor token scopes.

Only valid when ActorTokenContent is M2M.

See:

http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig.html#cfn-bedrockagentcore-oauth2credentialprovider-tokenexchangegranttypeconfig-actortokenscopes