This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::QuickSight::KnowledgeBase KbTemplateConfiguration
The template configuration for a knowledge base. This object contains connector-specific configuration that defines how data is crawled and indexed.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Template" :}
YAML
Template:
Properties
Template-
The connector configuration for the knowledge base data source. The structure depends on the connector type of the data source referenced by
DataSourceArn.The template must be a JSON object. All connector types share the following top-level keys. The value of
typeand the contents ofconnectionConfigurationvary by connector type.-
type– (Required) The connector type of the data source. This value identifies the connector. Valid values:S3V2,WEBCRAWLERV3,GOOGLEDRIVEV3,ONEDRIVEV3,SHAREPOINTV3. For the fields required by each connector, see the connector-specific list that follows. -
connectionConfiguration– (Required) The connection details for the data source. The keys in this object vary by connector type; see the connector-specific list that follows. -
filterConfiguration– (Optional) Rules that determine which content is crawled, such as inclusion and exclusion prefixes, patterns, or file-size limits. -
accessControlConfiguration– (Optional) Document-level access control (ACL) settings. Supported by all connector types except Web Crawler (WEBCRAWLERV3). The available fields depend on the connector type. -
deletionProtectionConfiguration– (Optional) Deletion-protection settings, supported by all connector types. ContainsenableDeletionProtection(Boolean) anddeletionProtectionThreshold(String; a value from 1 to 100).
The following list describes the valid
typevalue, theconnectionConfigurationcontents, and any connector-specific fields for each connector type:-
Amazon S3 (
type:S3V2) – Thetypevalue must beS3V2.connectionConfigurationis required and contains:-
bucketName– (Required) The name of the Amazon S3 bucket to crawl. Type: String. Length: 3–63 characters. Pattern:^[a-z0-9][.\-a-z0-9]{1,61}[a-z0-9]$. -
bucketOwnerAccountId– (Required) The ID of the AWS account that owns the bucket. Type: String. Pattern:^\d{12}$.
Amazon S3 supports the following optional
filterConfigurationfields:-
inclusionPrefixesorexclusionPrefixes– Amazon S3 key prefixes to include or exclude. Type: Array of String. Up to 350 items, each 1–1,024 characters. -
inclusionPatternsorexclusionPatterns– Patterns to include or exclude objects. Type: Array of String. Up to 350 items, each 1–1,024 characters. -
maxFileSizeInMegaBytes– The maximum size, in MB, of a file to ingest. Type: String. Pattern:^\d+$.
For Amazon S3,
accessControlConfigurationsupports the following fields:-
crawlAcl– Specifies whether the connector crawls and enforces document access control lists (ACLs). Type: Boolean. When set totrue, provide ACLs either in a global ACL configuration file (aclConfigurationFilePath) or in per-document metadata files. -
aclConfigurationFilePath– The Amazon S3 URI of the global ACL configuration file. Type: String. Length: 1–1,024 characters. Optional. If you don't provide a global ACL configuration file, define ACLs in per-document metadata files. -
defaultAccessType– The access behavior applied to Amazon S3 prefixes that are not listed in the ACL configuration. Type: String. The only supported value isALLOW.
metadataFilesPrefix– (Optional) The Amazon S3 prefix under which per-document metadata files are stored. Each metadata file describes a single source document and its indexable attributes. This is not the global ACL configuration file. For a single global ACL file, useaccessControlConfiguration.aclConfigurationFilePath. Type: String. Length: 1–1,024 characters. -
-
Google Drive (
type:GOOGLEDRIVEV3) – RequiresconnectionConfigurationwithauthTypeset toSERVICE_ACCOUNT. SupportsdataEntityConfigurationwithcrawlMyDrive,crawlSharedWithMe, andcrawlSharedDrives. -
OneDrive (
type:ONEDRIVEV3) – RequiresauthTypeat the template root level set toTWO_LEGGED_OAUTH. RequiresconnectionConfigurationwithtenantIdin UUID format. SupportsdataEntityConfigurationwithcrawlPersonalDrivesandcrawlSharedWithMe. -
SharePoint (
type:SHAREPOINTV3) – RequiresconnectionConfigurationwithtenantIdin UUID format. SupportsdataEntityConfigurationwithsiteUrls,crawlFiles, andcrawlPages. -
Web Crawler (
type:WEBCRAWLERV3) – RequiresconnectionConfigurationwithseedUrlsorsiteMapUrls(mutually exclusive) andauthType. SupportscrawlConfigurationfor crawl depth, rate limits, and scope. SupportsfilterConfigurationfor file size limits and URL patterns. Valid values forauthType:NO_AUTH,BASIC_AUTH,FORM,SAML.
Enabling document-level access control for Amazon S3
For an Amazon S3 (
S3V2) knowledge base, document-level access control is governed by two settings that must both be enabled:-
In this template, set
accessControlConfiguration.crawlAcltotrue. Define ACLs either in a global ACL configuration file, referenced byaccessControlConfiguration.aclConfigurationFilePath, or in per-document metadata files. To control access for prefixes that are not listed in the ACL file, you can also setaccessControlConfiguration.defaultAccessType. -
In the
CreateKnowledgeBaseorUpdateKnowledgeBaserequest, set the top-levelAccessControlConfiguration.isACLEnabledtotrue.
Required: No
Type:
Update requires: No interruption
-