/AWS1/CL_LMDSOURCEACCESSCONF¶
To secure and define access to your event source, you can specify the authentication protocol, VPC components, or virtual host.
CONSTRUCTOR¶
IMPORTING¶
Optional arguments:¶
iv_type TYPE /AWS1/LMDSOURCEACCESSTYPE /AWS1/LMDSOURCEACCESSTYPE¶
The type of authentication protocol, VPC components, or virtual host for your event source. For example:
"Type":"SASL_SCRAM_512_AUTH".
BASIC_AUTH– (Amazon MQ) The Secrets Manager secret that stores your broker credentials.
BASIC_AUTH– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key used for SASL/PLAIN authentication of your Apache Kafka brokers.
VPC_SUBNET– (Self-managed Apache Kafka) The subnets associated with your VPC. Lambda connects to these subnets to fetch data from your self-managed Apache Kafka cluster.
VPC_SECURITY_GROUP– (Self-managed Apache Kafka) The VPC security group used to manage access to your self-managed Apache Kafka brokers.
SASL_SCRAM_256_AUTH– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key used for SASL SCRAM-256 authentication of your self-managed Apache Kafka brokers.
SASL_SCRAM_512_AUTH– (Amazon MSK, Self-managed Apache Kafka) The Secrets Manager ARN of your secret key used for SASL SCRAM-512 authentication of your self-managed Apache Kafka brokers.
VIRTUAL_HOST–- (RabbitMQ) The name of the virtual host in your RabbitMQ broker. Lambda uses this RabbitMQ host as the event source. This property cannot be specified in an UpdateEventSourceMapping API call.
CLIENT_CERTIFICATE_TLS_AUTH– (Amazon MSK, self-managed Apache Kafka) The Secrets Manager ARN of your secret key containing the certificate chain (X.509 PEM), private key (PKCS#8 PEM), and private key password (optional) used for mutual TLS authentication of your MSK/Apache Kafka brokers.
SERVER_ROOT_CA_CERTIFICATE– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key containing the root CA certificate (X.509 PEM) used for TLS encryption of your Apache Kafka brokers.
OAUTHBEARER_AUTH– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key containing the OAuth 2.0 credentials that Lambda uses for SASL/OAUTHBEARER authentication with your Apache Kafka brokers. For the contents of the secret, see Configuring the OAuth secret.
OAUTHBEARER_SCOPE– (Self-managed Apache Kafka) The OAuth 2.0 scope that Lambda requests when it acquires an access token. TheURIfield holds the scope value, not a secret ARN. This type requiresOAUTHBEARER_AUTH.
OAUTHBEARER_AUDIENCE– (Self-managed Apache Kafka) The OAuth 2.0 audience that Lambda requests when it acquires an access token. TheURIfield holds the audience value, not a secret ARN. This type requires eitherOAUTHBEARER_AUTHorIAM_OAUTHBEARER_AUTH.
OAUTHBEARER_LOGICAL_CLUSTER– (Self-managed Apache Kafka) The logical cluster identifier that Lambda sends to a Confluent Cloud broker. TheURIfield holds the identifier, not a secret ARN. This type requiresOAUTHBEARER_AUTH.
OAUTHBEARER_IDENTITY_POOL– (Self-managed Apache Kafka) The identity pool identifier that Lambda sends to a Confluent Cloud broker. TheURIfield holds the identifier, not a secret ARN. This type requiresOAUTHBEARER_AUTH.
IAM_AUTH– (Self-managed Apache Kafka) Authenticate with Identity and Access Management (IAM). Your function's execution role signs each connection, so there is no secret to provide. Omit theURIfield for this type.
IAM_OAUTHBEARER_AUTH– (Self-managed Apache Kafka) Authenticate with an Amazon Web Services web identity token over SASL/OAUTHBEARER. Lambda requests the token for your function's execution role, so there is no secret to provide. Omit theURIfield for this type. This type requiresOAUTHBEARER_AUDIENCEand does not support the otherOAUTHBEARERtypes.
iv_uri TYPE /AWS1/LMDURI /AWS1/LMDURI¶
The value for your chosen configuration in
Type. For example:"URI": "arn:aws:secretsmanager:us-east-1:01234567890:secret:MyBrokerSecretName".
Queryable Attributes¶
Type¶
The type of authentication protocol, VPC components, or virtual host for your event source. For example:
"Type":"SASL_SCRAM_512_AUTH".
BASIC_AUTH– (Amazon MQ) The Secrets Manager secret that stores your broker credentials.
BASIC_AUTH– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key used for SASL/PLAIN authentication of your Apache Kafka brokers.
VPC_SUBNET– (Self-managed Apache Kafka) The subnets associated with your VPC. Lambda connects to these subnets to fetch data from your self-managed Apache Kafka cluster.
VPC_SECURITY_GROUP– (Self-managed Apache Kafka) The VPC security group used to manage access to your self-managed Apache Kafka brokers.
SASL_SCRAM_256_AUTH– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key used for SASL SCRAM-256 authentication of your self-managed Apache Kafka brokers.
SASL_SCRAM_512_AUTH– (Amazon MSK, Self-managed Apache Kafka) The Secrets Manager ARN of your secret key used for SASL SCRAM-512 authentication of your self-managed Apache Kafka brokers.
VIRTUAL_HOST–- (RabbitMQ) The name of the virtual host in your RabbitMQ broker. Lambda uses this RabbitMQ host as the event source. This property cannot be specified in an UpdateEventSourceMapping API call.
CLIENT_CERTIFICATE_TLS_AUTH– (Amazon MSK, self-managed Apache Kafka) The Secrets Manager ARN of your secret key containing the certificate chain (X.509 PEM), private key (PKCS#8 PEM), and private key password (optional) used for mutual TLS authentication of your MSK/Apache Kafka brokers.
SERVER_ROOT_CA_CERTIFICATE– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key containing the root CA certificate (X.509 PEM) used for TLS encryption of your Apache Kafka brokers.
OAUTHBEARER_AUTH– (Self-managed Apache Kafka) The Secrets Manager ARN of your secret key containing the OAuth 2.0 credentials that Lambda uses for SASL/OAUTHBEARER authentication with your Apache Kafka brokers. For the contents of the secret, see Configuring the OAuth secret.
OAUTHBEARER_SCOPE– (Self-managed Apache Kafka) The OAuth 2.0 scope that Lambda requests when it acquires an access token. TheURIfield holds the scope value, not a secret ARN. This type requiresOAUTHBEARER_AUTH.
OAUTHBEARER_AUDIENCE– (Self-managed Apache Kafka) The OAuth 2.0 audience that Lambda requests when it acquires an access token. TheURIfield holds the audience value, not a secret ARN. This type requires eitherOAUTHBEARER_AUTHorIAM_OAUTHBEARER_AUTH.
OAUTHBEARER_LOGICAL_CLUSTER– (Self-managed Apache Kafka) The logical cluster identifier that Lambda sends to a Confluent Cloud broker. TheURIfield holds the identifier, not a secret ARN. This type requiresOAUTHBEARER_AUTH.
OAUTHBEARER_IDENTITY_POOL– (Self-managed Apache Kafka) The identity pool identifier that Lambda sends to a Confluent Cloud broker. TheURIfield holds the identifier, not a secret ARN. This type requiresOAUTHBEARER_AUTH.
IAM_AUTH– (Self-managed Apache Kafka) Authenticate with Identity and Access Management (IAM). Your function's execution role signs each connection, so there is no secret to provide. Omit theURIfield for this type.
IAM_OAUTHBEARER_AUTH– (Self-managed Apache Kafka) Authenticate with an Amazon Web Services web identity token over SASL/OAUTHBEARER. Lambda requests the token for your function's execution role, so there is no secret to provide. Omit theURIfield for this type. This type requiresOAUTHBEARER_AUDIENCEand does not support the otherOAUTHBEARERtypes.
Accessible with the following methods¶
| Method | Description |
|---|---|
GET_TYPE() |
Getter for TYPE, with configurable default |
ASK_TYPE() |
Getter for TYPE w/ exceptions if field has no value |
HAS_TYPE() |
Determine if TYPE has a value |
URI¶
The value for your chosen configuration in
Type. For example:"URI": "arn:aws:secretsmanager:us-east-1:01234567890:secret:MyBrokerSecretName".
Accessible with the following methods¶
| Method | Description |
|---|---|
GET_URI() |
Getter for URI, with configurable default |
ASK_URI() |
Getter for URI w/ exceptions if field has no value |
HAS_URI() |
Determine if URI has a value |
Public Local Types In This Class¶
Internal table types, representing arrays and maps of this class, are defined as local types:
TT_SOURCEACCESSCONFIGURATIONS¶
TYPES TT_SOURCEACCESSCONFIGURATIONS TYPE STANDARD TABLE OF REF TO /AWS1/CL_LMDSOURCEACCESSCONF WITH DEFAULT KEY
.