Class: Aws::BedrockAgentCoreControl::Types::PolicyDefinition
- Inherits:
-
Struct
- Object
- Struct
- Aws::BedrockAgentCoreControl::Types::PolicyDefinition
- Defined in:
- gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb
Overview
PolicyDefinition is a union - when making an API calls you must set exactly one of the members.
PolicyDefinition is a union - when returned from an API call exactly one value will be set and the returned type will be a subclass of PolicyDefinition corresponding to the set member.
Represents the definition structure for policies within the AgentCore Policy system. This structure encapsulates different policy formats and languages that can be used to define access control rules.
Defined Under Namespace
Classes: Cedar, Policy, PolicyGeneration, Unknown
Constant Summary collapse
- SENSITIVE =
[]
Instance Attribute Summary collapse
-
#cedar ⇒ Types::CedarPolicy
The Cedar policy definition within the policy definition structure.
-
#policy ⇒ Types::PolicyStatement
The Dogwood policy statement that defines the access control rules.
-
#policy_generation ⇒ Types::PolicyGenerationDetails
The generated policy asset information within the policy definition structure.
-
#unknown ⇒ Object
Returns the value of attribute unknown.
Instance Attribute Details
#cedar ⇒ Types::CedarPolicy
The Cedar policy definition within the policy definition structure. This contains the Cedar policy statement that defines the authorization logic using Cedar's human-readable, analyzable policy language. Cedar policies specify principals (who can access), actions (what operations are allowed), resources (what can be accessed), and optional conditions for fine-grained control. Cedar provides a formal policy language designed for authorization with deterministic evaluation, making policies testable, reviewable, and auditable. All Cedar policies follow a default-deny model where actions are denied unless explicitly permitted, and forbid policies always override permit policies.
17683 17684 17685 17686 17687 17688 17689 17690 17691 17692 17693 17694 17695 17696 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17683 class PolicyDefinition < Struct.new( :cedar, :policy_generation, :policy, :unknown) SENSITIVE = [] include Aws::Structure include Aws::Structure::Union class Cedar < PolicyDefinition; end class PolicyGeneration < PolicyDefinition; end class Policy < PolicyDefinition; end class Unknown < PolicyDefinition; end end |
#policy ⇒ Types::PolicyStatement
The Dogwood policy statement that defines the access control rules. This policy definition can include Dogwood policies and supports temporal conditions and information providers such as guardrails.
17683 17684 17685 17686 17687 17688 17689 17690 17691 17692 17693 17694 17695 17696 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17683 class PolicyDefinition < Struct.new( :cedar, :policy_generation, :policy, :unknown) SENSITIVE = [] include Aws::Structure include Aws::Structure::Union class Cedar < PolicyDefinition; end class PolicyGeneration < PolicyDefinition; end class Policy < PolicyDefinition; end class Unknown < PolicyDefinition; end end |
#policy_generation ⇒ Types::PolicyGenerationDetails
The generated policy asset information within the policy definition structure. This contains information identifying a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Dogwood policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.
17683 17684 17685 17686 17687 17688 17689 17690 17691 17692 17693 17694 17695 17696 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17683 class PolicyDefinition < Struct.new( :cedar, :policy_generation, :policy, :unknown) SENSITIVE = [] include Aws::Structure include Aws::Structure::Union class Cedar < PolicyDefinition; end class PolicyGeneration < PolicyDefinition; end class Policy < PolicyDefinition; end class Unknown < PolicyDefinition; end end |
#unknown ⇒ Object
Returns the value of attribute unknown
17683 17684 17685 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17683 def unknown @unknown end |