/AWS1/CL_IDSNETWORKCONF¶
The network configuration that controls how an identity store can be accessed. You provide this object in a request.
CONSTRUCTOR¶
IMPORTING¶
Required arguments:¶
iv_vpceaccessrequired TYPE /AWS1/IDSBOOLEANTYPE /AWS1/IDSBOOLEANTYPE¶
Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to
true, requests must originate from a VPC endpoint.This value must be set to either
trueorfalsewhen you provideNetworkConfigurationin a request.
Optional arguments:¶
it_apirestrictsourcevpcs TYPE /AWS1/CL_IDSVPCIDLIST_W=>TT_VPCIDLIST TT_VPCIDLIST¶
A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in
ApiAllowSourceIpsif you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set byVpceAccessRequiredstill applies.
it_apiallowsourceips TYPE /AWS1/CL_IDSIPCIDRLIST_W=>TT_IPCIDRLIST TT_IPCIDRLIST¶
A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by
VpceAccessRequired, and even if it doesn't originate from a VPC inApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.
it_scimallowsourceips TYPE /AWS1/CL_IDSIPCIDRLIST_W=>TT_IPCIDRLIST TT_IPCIDRLIST¶
A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by
VpceAccessRequired.For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set
VpceAccessRequiredtotrueand set this value to0.0.0.0/0.
Queryable Attributes¶
VpceAccessRequired¶
Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to
true, requests must originate from a VPC endpoint.This value must be set to either
trueorfalsewhen you provideNetworkConfigurationin a request.
Accessible with the following methods¶
| Method | Description |
|---|---|
GET_VPCEACCESSREQUIRED() |
Getter for VPCEACCESSREQUIRED, with configurable default |
ASK_VPCEACCESSREQUIRED() |
Getter for VPCEACCESSREQUIRED w/ exceptions if field has no |
HAS_VPCEACCESSREQUIRED() |
Determine if VPCEACCESSREQUIRED has a value |
ApiRestrictSourceVpcs¶
A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in
ApiAllowSourceIpsif you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set byVpceAccessRequiredstill applies.
Accessible with the following methods¶
| Method | Description |
|---|---|
GET_APIRESTRICTSOURCEVPCS() |
Getter for APIRESTRICTSOURCEVPCS, with configurable default |
ASK_APIRESTRICTSOURCEVPCS() |
Getter for APIRESTRICTSOURCEVPCS w/ exceptions if field has |
HAS_APIRESTRICTSOURCEVPCS() |
Determine if APIRESTRICTSOURCEVPCS has a value |
ApiAllowSourceIps¶
A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by
VpceAccessRequired, and even if it doesn't originate from a VPC inApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.
Accessible with the following methods¶
| Method | Description |
|---|---|
GET_APIALLOWSOURCEIPS() |
Getter for APIALLOWSOURCEIPS, with configurable default |
ASK_APIALLOWSOURCEIPS() |
Getter for APIALLOWSOURCEIPS w/ exceptions if field has no v |
HAS_APIALLOWSOURCEIPS() |
Determine if APIALLOWSOURCEIPS has a value |
ScimAllowSourceIps¶
A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by
VpceAccessRequired.For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set
VpceAccessRequiredtotrueand set this value to0.0.0.0/0.
Accessible with the following methods¶
| Method | Description |
|---|---|
GET_SCIMALLOWSOURCEIPS() |
Getter for SCIMALLOWSOURCEIPS, with configurable default |
ASK_SCIMALLOWSOURCEIPS() |
Getter for SCIMALLOWSOURCEIPS w/ exceptions if field has no |
HAS_SCIMALLOWSOURCEIPS() |
Determine if SCIMALLOWSOURCEIPS has a value |