AWS CLI version 2, the latest major version of AWS CLI, is now stable and recommended for general use. To view this page for the AWS CLI version 2, click here. For more information see the AWS CLI version 2 installation instructions and migration guide.
Updates an existing work team with new member definitions or description.
See also: AWS API Documentation
update-workteam
--workteam-name <value>
[--member-definitions <value>]
[--description <value>]
[--notification-configuration <value>]
[--worker-access-configuration <value>]
[--cli-input-json <value>]
[--generate-cli-skeleton <value>]
[--debug]
[--endpoint-url <value>]
[--no-verify-ssl]
[--no-paginate]
[--output <value>]
[--query <value>]
[--profile <value>]
[--region <value>]
[--version <value>]
[--color <value>]
[--no-sign-request]
[--ca-bundle <value>]
[--cli-read-timeout <value>]
[--cli-connect-timeout <value>]
--workteam-name
(string)
The name of the work team to update.
--member-definitions
(list)
A list of
MemberDefinition
objects that contains objects that identify the workers that make up the work team.Workforces can be created using Amazon Cognito or your own OIDC Identity Provider (IdP). For private workforces created using Amazon Cognito use
CognitoMemberDefinition
. For workforces created using your own OIDC identity provider (IdP) useOidcMemberDefinition
. You should not provide input for both of these parameters in a single request.For workforces created using Amazon Cognito, private work teams correspond to Amazon Cognito user groups within the user pool used to create a workforce. All of the
CognitoMemberDefinition
objects that make up the member definition must have the sameClientId
andUserPool
values. To add a Amazon Cognito user group to an existing worker pool, see Adding groups to a User Pool . For more information about user pools, see `Amazon Cognito User Pools .For workforces created using your own OIDC IdP, specify the user groups that you want to include in your private work team in
OidcMemberDefinition
by listing those groups inGroups
. Be aware that user groups that are already in the work team must also be listed inGroups
when you make this request to remain on the work team. If you do not include these user groups, they will no longer be associated with the work team you update.(structure)
Defines an Amazon Cognito or your own OIDC IdP user group that is part of a work team.
CognitoMemberDefinition -> (structure)
The Amazon Cognito user group that is part of the work team.
UserPool -> (string)
An identifier for a user pool. The user pool must be in the same region as the service that you are calling.UserGroup -> (string)
An identifier for a user group.ClientId -> (string)
An identifier for an application client. You must create the app client ID using Amazon Cognito.OidcMemberDefinition -> (structure)
A list user groups that exist in your OIDC Identity Provider (IdP). One to ten groups can be used to create a single private work team. When you add a user group to the list of
Groups
, you can add that user group to one or more private work teams. If you add a user group to a private work team, all workers in that user group are added to the work team.Groups -> (list)
A list of comma seperated strings that identifies user groups in your OIDC IdP. Each user group is made up of a group of private workers.
(string)
Shorthand Syntax:
CognitoMemberDefinition={UserPool=string,UserGroup=string,ClientId=string},OidcMemberDefinition={Groups=[string,string]} ...
JSON Syntax:
[
{
"CognitoMemberDefinition": {
"UserPool": "string",
"UserGroup": "string",
"ClientId": "string"
},
"OidcMemberDefinition": {
"Groups": ["string", ...]
}
}
...
]
--description
(string)
An updated description for the work team.
--notification-configuration
(structure)
Configures SNS topic notifications for available or expiring work items
NotificationTopicArn -> (string)
The ARN for the Amazon SNS topic to which notifications should be published.
Shorthand Syntax:
NotificationTopicArn=string
JSON Syntax:
{
"NotificationTopicArn": "string"
}
--worker-access-configuration
(structure)
Use this optional parameter to constrain access to an Amazon S3 resource based on the IP address using supported IAM global condition keys. The Amazon S3 resource is accessed in the worker portal using a Amazon S3 presigned URL.
S3Presign -> (structure)
Defines any Amazon S3 resource constraints.
IamPolicyConstraints -> (structure)
Use this parameter to specify the allowed request source. Possible sources are either
SourceIp
orVpcSourceIp
.SourceIp -> (string)
WhenSourceIp
isEnabled
the worker's IP address when a task is rendered in the worker portal is added to the IAM policy as aCondition
used to generate the Amazon S3 presigned URL. This IP address is checked by Amazon S3 and must match in order for the Amazon S3 resource to be rendered in the worker portal.VpcSourceIp -> (string)
WhenVpcSourceIp
isEnabled
the worker's IP address when a task is rendered in private worker portal inside the VPC is added to the IAM policy as aCondition
used to generate the Amazon S3 presigned URL. To render the task successfully Amazon S3 checks that the presigned URL is being accessed over an Amazon S3 VPC Endpoint, and that the worker's IP address matches the IP address in the IAM policy. To learn more about configuring private worker portal, see Use Amazon VPC mode from a private worker portal .
Shorthand Syntax:
S3Presign={IamPolicyConstraints={SourceIp=string,VpcSourceIp=string}}
JSON Syntax:
{
"S3Presign": {
"IamPolicyConstraints": {
"SourceIp": "Enabled"|"Disabled",
"VpcSourceIp": "Enabled"|"Disabled"
}
}
}
--cli-input-json
(string)
Performs service operation based on the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton
. If other arguments are provided on the command line, the CLI values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally.
--generate-cli-skeleton
(string)
Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input
, prints a sample input JSON that can be used as an argument for --cli-input-json
. If provided with the value output
, it validates the command inputs and returns a sample output JSON for that command.
--debug
(boolean)
Turn on debug logging.
--endpoint-url
(string)
Override command's default URL with the given URL.
--no-verify-ssl
(boolean)
By default, the AWS CLI uses SSL when communicating with AWS services. For each SSL connection, the AWS CLI will verify SSL certificates. This option overrides the default behavior of verifying SSL certificates.
--no-paginate
(boolean)
Disable automatic pagination. If automatic pagination is disabled, the AWS CLI will only make one call, for the first page of results.
--output
(string)
The formatting style for command output.
--query
(string)
A JMESPath query to use in filtering the response data.
--profile
(string)
Use a specific profile from your credential file.
--region
(string)
The region to use. Overrides config/env settings.
--version
(string)
Display the version of this tool.
--color
(string)
Turn on/off color output.
--no-sign-request
(boolean)
Do not sign requests. Credentials will not be loaded if this argument is provided.
--ca-bundle
(string)
The CA certificate bundle to use when verifying SSL certificates. Overrides config/env settings.
--cli-read-timeout
(int)
The maximum socket read time in seconds. If the value is set to 0, the socket read will be blocking and not timeout. The default value is 60 seconds.
--cli-connect-timeout
(int)
The maximum socket connect time in seconds. If the value is set to 0, the socket connect will be blocking and not timeout. The default value is 60 seconds.
Workteam -> (structure)
A
Workteam
object that describes the updated work team.WorkteamName -> (string)
The name of the work team.MemberDefinitions -> (list)
A list of
MemberDefinition
objects that contains objects that identify the workers that make up the work team.Workforces can be created using Amazon Cognito or your own OIDC Identity Provider (IdP). For private workforces created using Amazon Cognito use
CognitoMemberDefinition
. For workforces created using your own OIDC identity provider (IdP) useOidcMemberDefinition
.(structure)
Defines an Amazon Cognito or your own OIDC IdP user group that is part of a work team.
CognitoMemberDefinition -> (structure)
The Amazon Cognito user group that is part of the work team.
UserPool -> (string)
An identifier for a user pool. The user pool must be in the same region as the service that you are calling.UserGroup -> (string)
An identifier for a user group.ClientId -> (string)
An identifier for an application client. You must create the app client ID using Amazon Cognito.OidcMemberDefinition -> (structure)
A list user groups that exist in your OIDC Identity Provider (IdP). One to ten groups can be used to create a single private work team. When you add a user group to the list of
Groups
, you can add that user group to one or more private work teams. If you add a user group to a private work team, all workers in that user group are added to the work team.Groups -> (list)
A list of comma seperated strings that identifies user groups in your OIDC IdP. Each user group is made up of a group of private workers.
(string)
WorkteamArn -> (string)
The Amazon Resource Name (ARN) that identifies the work team.WorkforceArn -> (string)
The Amazon Resource Name (ARN) of the workforce.ProductListingIds -> (list)
The Amazon Marketplace identifier for a vendor's work team.
(string)
Description -> (string)
A description of the work team.SubDomain -> (string)
The URI of the labeling job's user interface. Workers open this URI to start labeling your data objects.CreateDate -> (timestamp)
The date and time that the work team was created (timestamp).LastUpdatedDate -> (timestamp)
The date and time that the work team was last updated (timestamp).NotificationConfiguration -> (structure)
Configures SNS notifications of available or expiring work items for work teams.
NotificationTopicArn -> (string)
The ARN for the Amazon SNS topic to which notifications should be published.WorkerAccessConfiguration -> (structure)
Describes any access constraints that have been defined for Amazon S3 resources.
S3Presign -> (structure)
Defines any Amazon S3 resource constraints.
IamPolicyConstraints -> (structure)
Use this parameter to specify the allowed request source. Possible sources are either
SourceIp
orVpcSourceIp
.SourceIp -> (string)
WhenSourceIp
isEnabled
the worker's IP address when a task is rendered in the worker portal is added to the IAM policy as aCondition
used to generate the Amazon S3 presigned URL. This IP address is checked by Amazon S3 and must match in order for the Amazon S3 resource to be rendered in the worker portal.VpcSourceIp -> (string)
WhenVpcSourceIp
isEnabled
the worker's IP address when a task is rendered in private worker portal inside the VPC is added to the IAM policy as aCondition
used to generate the Amazon S3 presigned URL. To render the task successfully Amazon S3 checks that the presigned URL is being accessed over an Amazon S3 VPC Endpoint, and that the worker's IP address matches the IP address in the IAM policy. To learn more about configuring private worker portal, see Use Amazon VPC mode from a private worker portal .