View a markdown version of this page

AWS::Redshift::RedshiftIdcApplication - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::Redshift::RedshiftIdcApplication

Contains properties for the Redshift IDC application.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::Redshift::RedshiftIdcApplication", "Properties" : { "ApplicationType" : String, "AuthorizedTokenIssuerList" : [ AuthorizedTokenIssuer, ... ], "IamRoleArn" : String, "IdcDisplayName" : String, "IdcInstanceArn" : String, "IdentityNamespace" : String, "RedshiftIdcApplicationName" : String, "ServiceIntegrations" : [ ServiceIntegrationsUnion, ... ], "SsoTagKeys" : [ String, ... ], "Tags" : [ Tag, ... ] } }

YAML

Type: AWS::Redshift::RedshiftIdcApplication Properties: ApplicationType: String AuthorizedTokenIssuerList: - AuthorizedTokenIssuer IamRoleArn: String IdcDisplayName: String IdcInstanceArn: String IdentityNamespace: String RedshiftIdcApplicationName: String ServiceIntegrations: - ServiceIntegrationsUnion SsoTagKeys: - String Tags: - Tag

Properties

ApplicationType

The type of application being created. Valid values are None or Lakehouse. Use Lakehouse to enable Amazon Redshift federated permissions on cluster.

Required: No

Type: String

Allowed values: None | Lakehouse

Update requires: Replacement

AuthorizedTokenIssuerList

The authorized token issuer list for the Amazon Redshift IAM Identity Center application.

Required: No

Type: Array of AuthorizedTokenIssuer

Update requires: No interruption

IamRoleArn

The ARN for the Amazon Redshift IAM Identity Center application. It has the required permissions to be assumed and invoke the IDC Identity Center API.

Required: Yes

Type: String

Pattern: ^arn:aws[a-zA-Z-]*:[a-zA-Z0-9-]+:[a-z0-9-]*:[0-9]*:.+$

Update requires: No interruption

IdcDisplayName

The display name for the Amazon Redshift IAM Identity Center application. It appears on the console.

Required: Yes

Type: String

Pattern: ^[\w+=,.@-]+$

Minimum: 1

Maximum: 127

Update requires: No interruption

IdcInstanceArn

The ARN for the IAM Identity Center instance that Redshift integrates with.

Required: Yes

Type: String

Pattern: ^arn:aws[a-zA-Z-]*:[a-zA-Z0-9-]+:[a-z0-9-]*:[0-9]*:.+$

Update requires: Replacement

IdentityNamespace

The identity namespace for the Amazon Redshift IAM Identity Center application. It determines which managed application verifies the connection token.

Required: No

Type: String

Pattern: ^[a-zA-Z0-9_+.#@$-]+$

Minimum: 1

Maximum: 127

Update requires: No interruption

RedshiftIdcApplicationName

The name of the Redshift application in IAM Identity Center.

Required: Yes

Type: String

Pattern: ^[a-z][a-z0-9]*(-[a-z0-9]+)*$

Minimum: 1

Maximum: 63

Update requires: Replacement

ServiceIntegrations

A list of service integrations for the Redshift IAM Identity Center application.

Required: No

Type: Array of ServiceIntegrationsUnion

Update requires: No interruption

SsoTagKeys

A list of tags keys that Redshift Identity Center applications copy to IAM Identity Center. For each input key, the tag corresponding to the key-value pair is propagated.

Required: No

Type: Array of String

Update requires: Replacement

Tags

A list of tags.

Required: No

Type: Array of Tag

Update requires: No interruption

Return values

Ref

Fn::GetAtt

IdcManagedApplicationArn

The ARN for the Amazon Redshift IAM Identity Center application.

IdcOnboardStatus

The onboarding status for the Amazon Redshift IAM Identity Center application.

RedshiftIdcApplicationArn

The ARN for the Redshift application that integrates with IAM Identity Center.