From de2843cf66aefc427c2e8561364ace1aaf5a846c Mon Sep 17 00:00:00 2001 From: jonathan343 Date: Thu, 1 Oct 2026 03:52:11 -0400 Subject: [PATCH 1/4] Update all AWS service models to their latest versions with changelog entries --- ...ange-f40c0d76124a491a9e0565c867c026f9.json | 4 + ...ange-909c18b77d0d46f5bd620d2595edfc6f.json | 4 + ...ange-047c38dc82414219aa461e871b1b31c3.json | 4 + ...ange-b655f2599c2045df9aa9d90fe1196b08.json | 4 + ...ange-e89247b6c0b6442889c84bb3ee393354.json | 4 + ...ange-5add017152c04956a92e53d39251ae02.json | 4 + ...ange-6c3351942c1e4fe3ad684642defa8f69.json | 4 + ...ange-844dee90d23a4aa799f09f9d62d7bc37.json | 4 + ...ange-87bae98e60c24cc3a88a7b29b62f76c1.json | 4 + ...ange-8e3f4d43820c45d0a8be6243f79e13e6.json | 4 + ...ange-92aea09d6329494e8b30d5a4bf83cf56.json | 4 + ...ange-a0b801c4fa0c414080c5d9fe629abc84.json | 4 + ...ange-b67e2191d0fb48b19ba4f91d3af999cd.json | 4 + ...ange-c5894746ca3343bb95b201f975f6ff79.json | 4 + ...ange-1630ef298225460c80d3b2f90ad20f23.json | 4 + ...ange-40a720b2c1f84dc29333a7c5e7028f3a.json | 4 + ...ange-8da82235007f4833951e67a853187b10.json | 4 + ...ange-a27db77d05b14ac3b5043476393733eb.json | 4 + ...ange-dad2376372154182bfa7049089abedee.json | 4 + ...ange-26328844f1484af999f23e0d9a4dd845.json | 4 + ...ange-292d62f109eb469986b4212415abfda6.json | 4 + ...ange-c7d69aa57c4349d691c63bf933cbab1c.json | 4 + ...ange-b2ff9050933949f0b24c29b82cbb4bff.json | 4 + ...ange-e5dd515d516b4570922baca3ced22e2a.json | 4 + ...ange-3200132c8ef0400383710b588861e267.json | 4 + ...ange-3dbfa92697bc4b0390eda63c8680392a.json | 4 + ...ange-5205ed8026844301abe94dac42757b39.json | 4 + ...ange-58c78f463bfb4821bae292f385422403.json | 4 + ...ange-5f621ebe98cf4d0eb3de60313e555beb.json | 4 + ...ange-596a89194d6346d0a1186fc0bef1a5f6.json | 4 + ...ange-f794a103fce243158d8bcafa869869e5.json | 4 + ...ange-993e36a068354088acc6b75e39d22e7b.json | 4 + ...ange-9c5f55dd8b2f4de29489b349e16696f2.json | 4 + codegen/aws-models/api-gateway.json | 12 + codegen/aws-models/bedrock-agent-runtime.json | 59 +- codegen/aws-models/bedrock-agent.json | 1230 +++++++- .../aws-models/bedrock-agentcore-control.json | 1850 +++++++++++- codegen/aws-models/bedrock-agentcore.json | 497 ++- codegen/aws-models/bedrock.json | 14 +- codegen/aws-models/cloudtrail.json | 113 +- codegen/aws-models/connecthealth.json | 22 +- codegen/aws-models/dynamodb.json | 58 +- codegen/aws-models/guardduty.json | 2668 +++++++++++++++-- codegen/aws-models/lambda.json | 134 +- codegen/aws-models/sns.json | 18 +- codegen/aws-models/sts.json | 106 +- 46 files changed, 6421 insertions(+), 492 deletions(-) create mode 100644 clients/aws-sdk-api-gateway/.changes/next-release/aws-sdk-api-gateway-api-change-f40c0d76124a491a9e0565c867c026f9.json create mode 100644 clients/aws-sdk-bedrock-agent-runtime/.changes/next-release/aws-sdk-bedrock-agent-runtime-api-change-909c18b77d0d46f5bd620d2595edfc6f.json create mode 100644 clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-047c38dc82414219aa461e871b1b31c3.json create mode 100644 clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-b655f2599c2045df9aa9d90fe1196b08.json create mode 100644 clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-e89247b6c0b6442889c84bb3ee393354.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-5add017152c04956a92e53d39251ae02.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-6c3351942c1e4fe3ad684642defa8f69.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-844dee90d23a4aa799f09f9d62d7bc37.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-87bae98e60c24cc3a88a7b29b62f76c1.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-8e3f4d43820c45d0a8be6243f79e13e6.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-92aea09d6329494e8b30d5a4bf83cf56.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-a0b801c4fa0c414080c5d9fe629abc84.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json create mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-c5894746ca3343bb95b201f975f6ff79.json create mode 100644 clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-1630ef298225460c80d3b2f90ad20f23.json create mode 100644 clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-40a720b2c1f84dc29333a7c5e7028f3a.json create mode 100644 clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-8da82235007f4833951e67a853187b10.json create mode 100644 clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-a27db77d05b14ac3b5043476393733eb.json create mode 100644 clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-dad2376372154182bfa7049089abedee.json create mode 100644 clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-26328844f1484af999f23e0d9a4dd845.json create mode 100644 clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-292d62f109eb469986b4212415abfda6.json create mode 100644 clients/aws-sdk-cloudtrail/.changes/next-release/aws-sdk-cloudtrail-api-change-c7d69aa57c4349d691c63bf933cbab1c.json create mode 100644 clients/aws-sdk-connecthealth/.changes/next-release/aws-sdk-connecthealth-api-change-b2ff9050933949f0b24c29b82cbb4bff.json create mode 100644 clients/aws-sdk-dynamodb/.changes/next-release/aws-sdk-dynamodb-api-change-e5dd515d516b4570922baca3ced22e2a.json create mode 100644 clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3200132c8ef0400383710b588861e267.json create mode 100644 clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3dbfa92697bc4b0390eda63c8680392a.json create mode 100644 clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5205ed8026844301abe94dac42757b39.json create mode 100644 clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-58c78f463bfb4821bae292f385422403.json create mode 100644 clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5f621ebe98cf4d0eb3de60313e555beb.json create mode 100644 clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-596a89194d6346d0a1186fc0bef1a5f6.json create mode 100644 clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-f794a103fce243158d8bcafa869869e5.json create mode 100644 clients/aws-sdk-sns/.changes/next-release/aws-sdk-sns-api-change-993e36a068354088acc6b75e39d22e7b.json create mode 100644 clients/aws-sdk-sts/.changes/next-release/aws-sdk-sts-api-change-9c5f55dd8b2f4de29489b349e16696f2.json diff --git a/clients/aws-sdk-api-gateway/.changes/next-release/aws-sdk-api-gateway-api-change-f40c0d76124a491a9e0565c867c026f9.json b/clients/aws-sdk-api-gateway/.changes/next-release/aws-sdk-api-gateway-api-change-f40c0d76124a491a9e0565c867c026f9.json new file mode 100644 index 00000000..41c5d54b --- /dev/null +++ b/clients/aws-sdk-api-gateway/.changes/next-release/aws-sdk-api-gateway-api-change-f40c0d76124a491a9e0565c867c026f9.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "API Gateway now supports two new security policies for REST APIs and custom domain names, SecurityPolicy-TLS13-1-2-Ext2-PQ-2025-09 (TLS 1.3 1.2 with post-quantum cryptography) and SecurityPolicy-TLS13-1-2-Ext2-FIPS-PQ-2025-09 (adds FIPS). Both retain legacy algorithms for backward compatibility." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agent-runtime/.changes/next-release/aws-sdk-bedrock-agent-runtime-api-change-909c18b77d0d46f5bd620d2595edfc6f.json b/clients/aws-sdk-bedrock-agent-runtime/.changes/next-release/aws-sdk-bedrock-agent-runtime-api-change-909c18b77d0d46f5bd620d2595edfc6f.json new file mode 100644 index 00000000..cbb126a6 --- /dev/null +++ b/clients/aws-sdk-bedrock-agent-runtime/.changes/next-release/aws-sdk-bedrock-agent-runtime-api-change-909c18b77d0d46f5bd620d2595edfc6f.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock Agentic Retrieve now supports the Bedrock Mantle (OpenAI Responses) endpoint via a new MantleFoundationModel configuration with an optional projectId." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-047c38dc82414219aa461e871b1b31c3.json b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-047c38dc82414219aa461e871b1b31c3.json new file mode 100644 index 00000000..99349f6e --- /dev/null +++ b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-047c38dc82414219aa461e871b1b31c3.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "TwelveLabs Marengo 3.0 is now an embedding model option in Amazon Bedrock Managed Knowledge Base. Create multimodal embeddings for video, audio, and image content that capture visual scenes, speech, and video cues, not just transcribed text." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-b655f2599c2045df9aa9d90fe1196b08.json b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-b655f2599c2045df9aa9d90fe1196b08.json new file mode 100644 index 00000000..058ad697 --- /dev/null +++ b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-b655f2599c2045df9aa9d90fe1196b08.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds an optional syncSchedule field to CreateDataSource and UpdateDataSource for Managed Knowledge Bases data source connectors, so a data source can sync automatically on a daily, weekly, or monthly schedule." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-e89247b6c0b6442889c84bb3ee393354.json b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-e89247b6c0b6442889c84bb3ee393354.json new file mode 100644 index 00000000..bc4a5146 --- /dev/null +++ b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-e89247b6c0b6442889c84bb3ee393354.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds support for calling VPC configuration API's in Bedrock. These configurations allow the use of On Prem connectors in Bedrock Managed Knowledge bases." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-5add017152c04956a92e53d39251ae02.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-5add017152c04956a92e53d39251ae02.json new file mode 100644 index 00000000..31a982b6 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-5add017152c04956a92e53d39251ae02.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-6c3351942c1e4fe3ad684642defa8f69.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-6c3351942c1e4fe3ad684642defa8f69.json new file mode 100644 index 00000000..57ba6400 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-6c3351942c1e4fe3ad684642defa8f69.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock AgentCore Gateway now supports returning the complete MCP tools list in a single response by disabling pagination for the tools list operation. This feature is available in limited preview." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-844dee90d23a4aa799f09f9d62d7bc37.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-844dee90d23a4aa799f09f9d62d7bc37.json new file mode 100644 index 00000000..e5872628 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-844dee90d23a4aa799f09f9d62d7bc37.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "This release adds support for private certificate authorities on Amazon Bedrock AgentCore Gateway targets. The new certificateConfigurations parameter on CreateGatewayTarget and UpdateGatewayTarget references a PEM-encoded CA certificate in Amazon S3 or AWS Secrets Manager." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-87bae98e60c24cc3a88a7b29b62f76c1.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-87bae98e60c24cc3a88a7b29b62f76c1.json new file mode 100644 index 00000000..55c90800 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-87bae98e60c24cc3a88a7b29b62f76c1.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock AgentCore Runtime now supports specifying the platform version of an agent runtime through the new platformVersion field on CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-8e3f4d43820c45d0a8be6243f79e13e6.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-8e3f4d43820c45d0a8be6243f79e13e6.json new file mode 100644 index 00000000..03c701a2 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-8e3f4d43820c45d0a8be6243f79e13e6.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Online evaluation configurations now support up to 25 evaluators. CloudWatch Logs data sources for online evaluation now support up to 10 log groups." +} diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-92aea09d6329494e8b30d5a4bf83cf56.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-92aea09d6329494e8b30d5a4bf83cf56.json new file mode 100644 index 00000000..acdf9bac --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-92aea09d6329494e8b30d5a4bf83cf56.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock AgentCore Payments now supports credential rotation for payment connectors, letting you rotate API and wallet secrets for Quick Create payment auths from the console. This release also adds Type and Creation type columns to the payment managers views." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-a0b801c4fa0c414080c5d9fe629abc84.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-a0b801c4fa0c414080c5d9fe629abc84.json new file mode 100644 index 00000000..9e0e6b1a --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-a0b801c4fa0c414080c5d9fe629abc84.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds support for a new DELETE FAILED status for Bedrock AgentCore Runtimes and Bedrock AgentCore Runtime Endpoints." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json new file mode 100644 index 00000000..d72660e9 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Update Dataset schema to THIRDPARTYEVALUATIONV1." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-c5894746ca3343bb95b201f975f6ff79.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-c5894746ca3343bb95b201f975f6ff79.json new file mode 100644 index 00000000..a6dce16e --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-c5894746ca3343bb95b201f975f6ff79.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "AgentCore Identity adds Consent Portal APIs to manage portals that let end users grant OAuth authorization for agents to access resources. AgentCore Evaluation adds trace source selection by log group prefix, custom or source log group result destinations, and metrics namespace customization." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-1630ef298225460c80d3b2f90ad20f23.json b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-1630ef298225460c80d3b2f90ad20f23.json new file mode 100644 index 00000000..cef328b6 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-1630ef298225460c80d3b2f90ad20f23.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "AgentCore Memory now supports direct ingestion into long-term memory via IngestData API." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-40a720b2c1f84dc29333a7c5e7028f3a.json b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-40a720b2c1f84dc29333a7c5e7028f3a.json new file mode 100644 index 00000000..21e97947 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-40a720b2c1f84dc29333a7c5e7028f3a.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Batch evaluation now supports up to 10 CloudWatch log groups per CloudWatchLogsSource." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-8da82235007f4833951e67a853187b10.json b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-8da82235007f4833951e67a853187b10.json new file mode 100644 index 00000000..815b8175 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-8da82235007f4833951e67a853187b10.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Batch evaluation now supports evaluating specific traces within a session. Each session can specify up to 100 trace IDs to evaluate." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-a27db77d05b14ac3b5043476393733eb.json b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-a27db77d05b14ac3b5043476393733eb.json new file mode 100644 index 00000000..65d463c6 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-a27db77d05b14ac3b5043476393733eb.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds log group name prefix trace source selection, custom or source log group result destinations, and metrics namespace customization." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-dad2376372154182bfa7049089abedee.json b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-dad2376372154182bfa7049089abedee.json new file mode 100644 index 00000000..31a982b6 --- /dev/null +++ b/clients/aws-sdk-bedrock-agentcore/.changes/next-release/aws-sdk-bedrock-agentcore-api-change-dad2376372154182bfa7049089abedee.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-26328844f1484af999f23e0d9a4dd845.json b/clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-26328844f1484af999f23e0d9a4dd845.json new file mode 100644 index 00000000..2a74b96f --- /dev/null +++ b/clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-26328844f1484af999f23e0d9a4dd845.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon Bedrock Automated Reasoning policies now accept Unicode letters in identifier names such as type names, type value names, and variable names. You can now author policies in non-English languages using accented or non-Latin characters." +} \ No newline at end of file diff --git a/clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-292d62f109eb469986b4212415abfda6.json b/clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-292d62f109eb469986b4212415abfda6.json new file mode 100644 index 00000000..b409711d --- /dev/null +++ b/clients/aws-sdk-bedrock/.changes/next-release/aws-sdk-bedrock-api-change-292d62f109eb469986b4212415abfda6.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "New AWS REVIEW mode as supported data retention mode for Bedrock models." +} \ No newline at end of file diff --git a/clients/aws-sdk-cloudtrail/.changes/next-release/aws-sdk-cloudtrail-api-change-c7d69aa57c4349d691c63bf933cbab1c.json b/clients/aws-sdk-cloudtrail/.changes/next-release/aws-sdk-cloudtrail-api-change-c7d69aa57c4349d691c63bf933cbab1c.json new file mode 100644 index 00000000..19c47db3 --- /dev/null +++ b/clients/aws-sdk-cloudtrail/.changes/next-release/aws-sdk-cloudtrail-api-change-c7d69aa57c4349d691c63bf933cbab1c.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds support for the RecursiveLogging trail setting, which suppresses recursive events generated when CloudTrail delivers logs to a trail's destinations." +} \ No newline at end of file diff --git a/clients/aws-sdk-connecthealth/.changes/next-release/aws-sdk-connecthealth-api-change-b2ff9050933949f0b24c29b82cbb4bff.json b/clients/aws-sdk-connecthealth/.changes/next-release/aws-sdk-connecthealth-api-change-b2ff9050933949f0b24c29b82cbb4bff.json new file mode 100644 index 00000000..6336f3dc --- /dev/null +++ b/clients/aws-sdk-connecthealth/.changes/next-release/aws-sdk-connecthealth-api-change-b2ff9050933949f0b24c29b82cbb4bff.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Multi language support with code switching, custom template sectionHeader now allows underscores." +} \ No newline at end of file diff --git a/clients/aws-sdk-dynamodb/.changes/next-release/aws-sdk-dynamodb-api-change-e5dd515d516b4570922baca3ced22e2a.json b/clients/aws-sdk-dynamodb/.changes/next-release/aws-sdk-dynamodb-api-change-e5dd515d516b4570922baca3ced22e2a.json new file mode 100644 index 00000000..0dd54df0 --- /dev/null +++ b/clients/aws-sdk-dynamodb/.changes/next-release/aws-sdk-dynamodb-api-change-e5dd515d516b4570922baca3ced22e2a.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds support for filtering exported table data using FilterExpression, ProjectionExpression and KeyConditionExpression with ExportTableToPointInTime." +} \ No newline at end of file diff --git a/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3200132c8ef0400383710b588861e267.json b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3200132c8ef0400383710b588861e267.json new file mode 100644 index 00000000..14a4b79d --- /dev/null +++ b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3200132c8ef0400383710b588861e267.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adding awsServiceName field to GuardDuty Findings." +} \ No newline at end of file diff --git a/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3dbfa92697bc4b0390eda63c8680392a.json b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3dbfa92697bc4b0390eda63c8680392a.json new file mode 100644 index 00000000..b4979d97 --- /dev/null +++ b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-3dbfa92697bc4b0390eda63c8680392a.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adding support for Sequence Activities in GuardDuty Findings." +} \ No newline at end of file diff --git a/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5205ed8026844301abe94dac42757b39.json b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5205ed8026844301abe94dac42757b39.json new file mode 100644 index 00000000..166c4c90 --- /dev/null +++ b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5205ed8026844301abe94dac42757b39.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "This change surfaces AI Protection resources on existing public IAM attack sequences. Customers will now see which model was accessed and whether a guardrail intervened as part of the credential-compromise sequence." +} \ No newline at end of file diff --git a/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-58c78f463bfb4821bae292f385422403.json b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-58c78f463bfb4821bae292f385422403.json new file mode 100644 index 00000000..b783909f --- /dev/null +++ b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-58c78f463bfb4821bae292f385422403.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Amazon GuardDuty now supports custom detection rules, including APIs to manage rule associations and organization-level configurations." +} \ No newline at end of file diff --git a/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5f621ebe98cf4d0eb3de60313e555beb.json b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5f621ebe98cf4d0eb3de60313e555beb.json new file mode 100644 index 00000000..5a62ee7e --- /dev/null +++ b/clients/aws-sdk-guardduty/.changes/next-release/aws-sdk-guardduty-api-change-5f621ebe98cf4d0eb3de60313e555beb.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "GuardDuty AWS Organizations policy integration. GetDetector and GetMemberDetectors now show whether a GuardDuty policy manages a feature." +} \ No newline at end of file diff --git a/clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-596a89194d6346d0a1186fc0bef1a5f6.json b/clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-596a89194d6346d0a1186fc0bef1a5f6.json new file mode 100644 index 00000000..73248810 --- /dev/null +++ b/clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-596a89194d6346d0a1186fc0bef1a5f6.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "AWS Lambda now provides configurable control over S3 direct access, allowing you to explicitly enable or disable how functions stream file reads directly from S3 buckets. This gives you flexibility to tune data access behavior based on your workload requirements, independent of memory size." +} \ No newline at end of file diff --git a/clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-f794a103fce243158d8bcafa869869e5.json b/clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-f794a103fce243158d8bcafa869869e5.json new file mode 100644 index 00000000..a4ef31fb --- /dev/null +++ b/clients/aws-sdk-lambda/.changes/next-release/aws-sdk-lambda-api-change-f794a103fce243158d8bcafa869869e5.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Updates documentation for lambda function timeout." +} \ No newline at end of file diff --git a/clients/aws-sdk-sns/.changes/next-release/aws-sdk-sns-api-change-993e36a068354088acc6b75e39d22e7b.json b/clients/aws-sdk-sns/.changes/next-release/aws-sdk-sns-api-change-993e36a068354088acc6b75e39d22e7b.json new file mode 100644 index 00000000..883dae3b --- /dev/null +++ b/clients/aws-sdk-sns/.changes/next-release/aws-sdk-sns-api-change-993e36a068354088acc6b75e39d22e7b.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "SNS API reference documentation update." +} \ No newline at end of file diff --git a/clients/aws-sdk-sts/.changes/next-release/aws-sdk-sts-api-change-9c5f55dd8b2f4de29489b349e16696f2.json b/clients/aws-sdk-sts/.changes/next-release/aws-sdk-sts-api-change-9c5f55dd8b2f4de29489b349e16696f2.json new file mode 100644 index 00000000..0ff3e72b --- /dev/null +++ b/clients/aws-sdk-sts/.changes/next-release/aws-sdk-sts-api-change-9c5f55dd8b2f4de29489b349e16696f2.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Increases the maximum session token size to 4,096 bytes and removes the packed policy size limit. Adds SessionTokenSize and SessionTokenUtilization fields and a new MinimumSessionTokenSize parameter. PackedPolicySize is deprecated." +} \ No newline at end of file diff --git a/codegen/aws-models/api-gateway.json b/codegen/aws-models/api-gateway.json index d9c9c188..41bc8d4c 100644 --- a/codegen/aws-models/api-gateway.json +++ b/codegen/aws-models/api-gateway.json @@ -11296,6 +11296,18 @@ "smithy.api#enumValue": "SecurityPolicy_TLS13_1_2_FIPS_PFS_PQ_2025_09" } }, + "SecurityPolicy_TLS13_1_2_Ext2_PQ_2025_09": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SecurityPolicy_TLS13_1_2_Ext2_PQ_2025_09" + } + }, + "SecurityPolicy_TLS13_1_2_Ext2_FIPS_PQ_2025_09": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SecurityPolicy_TLS13_1_2_Ext2_FIPS_PQ_2025_09" + } + }, "SecurityPolicy_TLS13_1_2_PQ_2025_09": { "target": "smithy.api#Unit", "traits": { diff --git a/codegen/aws-models/bedrock-agent-runtime.json b/codegen/aws-models/bedrock-agent-runtime.json index e39b7003..9028c0d9 100644 --- a/codegen/aws-models/bedrock-agent-runtime.json +++ b/codegen/aws-models/bedrock-agent-runtime.json @@ -738,7 +738,7 @@ "smithy.api#default": 5, "smithy.api#documentation": "

The maximum number of agent iterations for retrieval.

", "smithy.api#range": { - "min": 2 + "min": 0 } } } @@ -6443,6 +6443,12 @@ "traits": { "smithy.api#documentation": "

The Bedrock foundation model configuration.

" } + }, + "mantleFoundationModelConfiguration": { + "target": "com.amazonaws.bedrockagentruntime#MantleFoundationModelConfiguration", + "traits": { + "smithy.api#documentation": "

The Mantle foundation model configuration.

" + } } }, "traits": { @@ -6457,6 +6463,12 @@ "traits": { "smithy.api#enumValue": "BEDROCK_FOUNDATION_MODEL" } + }, + "MANTLE_FOUNDATION_MODEL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "MANTLE_FOUNDATION_MODEL" + } } }, "traits": { @@ -10981,6 +10993,51 @@ "smithy.api#documentation": "

The type of reranking configuration for managed search.

" } }, + "com.amazonaws.bedrockagentruntime#MantleFoundationModelConfiguration": { + "type": "structure", + "members": { + "modelConfiguration": { + "target": "com.amazonaws.bedrockagentruntime#MantleFoundationModelModelConfiguration", + "traits": { + "smithy.api#documentation": "

The model configuration containing the model ARN and project ID.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

Configuration for a Mantle foundation model.

" + } + }, + "com.amazonaws.bedrockagentruntime#MantleFoundationModelModelConfiguration": { + "type": "structure", + "members": { + "modelArn": { + "target": "com.amazonaws.bedrockagentruntime#BedrockModelArn", + "traits": { + "smithy.api#documentation": "

The ARN of the Mantle foundation model.

", + "smithy.api#required": {} + } + }, + "projectId": { + "target": "com.amazonaws.bedrockagentruntime#MantleProjectId", + "traits": { + "smithy.api#documentation": "

The Amazon Bedrock project ID used for billing and usage attribution. If you don't specify a value, the service uses the default project.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

Model configuration for a Mantle foundation model.

" + } + }, + "com.amazonaws.bedrockagentruntime#MantleProjectId": { + "type": "string", + "traits": { + "smithy.api#length": { + "max": 128 + }, + "smithy.api#pattern": "^(proj_[a-zA-Z0-9]+|default)$" + } + }, "com.amazonaws.bedrockagentruntime#MaxResults": { "type": "integer", "traits": { diff --git a/codegen/aws-models/bedrock-agent.json b/codegen/aws-models/bedrock-agent.json index 60f270b5..928acd54 100644 --- a/codegen/aws-models/bedrock-agent.json +++ b/codegen/aws-models/bedrock-agent.json @@ -1538,12 +1538,24 @@ "type": "service", "version": "2023-06-05", "operations": [ + { + "target": "com.amazonaws.bedrockagent#CreateVpcConfiguration" + }, { "target": "com.amazonaws.bedrockagent#DeleteResourcePolicy" }, + { + "target": "com.amazonaws.bedrockagent#DeleteVpcConfiguration" + }, { "target": "com.amazonaws.bedrockagent#GetResourcePolicy" }, + { + "target": "com.amazonaws.bedrockagent#GetVpcConfiguration" + }, + { + "target": "com.amazonaws.bedrockagent#ListVpcConfigurations" + }, { "target": "com.amazonaws.bedrockagent#PutResourcePolicy" }, @@ -1616,7 +1628,7 @@ ], "maxAge": 86400 }, - "smithy.api#documentation": "

Describes the API operations for creating and managing Amazon Bedrock agents.

", + "smithy.api#documentation": "

Amazon Bedrock Agents (now Amazon Bedrock Agents Classic) is no longer open to new customers. For capabilities similar to Bedrock Agents Classic, explore Amazon Bedrock AgentCore. Existing customers can continue to use the service as normal. For more information, see Amazon Bedrock Agents Classic availability change.

Describes the API operations for creating and managing Amazon Bedrock agents.

", "smithy.api#title": "Agents for Amazon Bedrock", "smithy.rules#endpointBdd": { "version": "1.1", @@ -2691,7 +2703,7 @@ "audioExtractionStatus": { "target": "com.amazonaws.bedrockagent#EnabledOrDisabledState", "traits": { - "smithy.api#documentation": "Whether audio extraction is enabled or disabled.", + "smithy.api#documentation": "

Whether audio extraction is enabled or disabled.

", "smithy.api#required": {} } } @@ -2800,13 +2812,27 @@ "audio": { "target": "com.amazonaws.bedrockagent#AudioConfigurations", "traits": { - "smithy.api#documentation": "

Configuration settings for processing audio content in multimodal knowledge bases.

" + "smithy.api#deprecated": { + "message": "Use Managed Knowledge Base's modelConfiguration field. https://docs.aws.amazon.com/bedrock/latest/userguide/kb-build-managed.html", + "since": "2026-09-01" + }, + "smithy.api#documentation": "

Configuration settings for processing audio content in multimodal knowledge bases.

This field is deprecated. Use modelConfiguration instead.

" } }, "video": { "target": "com.amazonaws.bedrockagent#VideoConfigurations", "traits": { - "smithy.api#documentation": "

Configuration settings for processing video content in multimodal knowledge bases.

" + "smithy.api#deprecated": { + "message": "Use Managed Knowledge Base's modelConfiguration field. https://docs.aws.amazon.com/bedrock/latest/userguide/kb-build-managed.html", + "since": "2026-09-01" + }, + "smithy.api#documentation": "

Configuration settings for processing video content in multimodal knowledge bases.

This field is deprecated. Use modelConfiguration instead.

" + } + }, + "modelConfiguration": { + "target": "smithy.api#Document", + "traits": { + "smithy.api#documentation": "

Model-specific configuration for the embedding model, provided as a JSON object. Use this field to specify settings that apply to the embedding model that you selected, such as how audio and video files are divided into segments.

The fields that this object accepts depend on the embedding model. For the settings that each model accepts, see the documentation for that model.

For an example of a CreateKnowledgeBase request that uses this field to configure a multimodal embedding model, see the Examples section of CreateKnowledgeBase.

" } } }, @@ -3382,7 +3408,7 @@ } ], "traits": { - "smithy.api#documentation": "

Creates an agent that orchestrates interactions between foundation models, data sources, software applications, user conversations, and APIs to carry out tasks to help customers.

", + "smithy.api#documentation": "

Amazon Bedrock Agents (now Amazon Bedrock Agents Classic) is no longer open to new customers. For capabilities similar to Bedrock Agents Classic, explore Amazon Bedrock AgentCore. Existing customers can continue to use the service as normal. For more information, see Amazon Bedrock Agents Classic availability change.

Creates an agent that orchestrates interactions between foundation models, data sources, software applications, user conversations, and APIs to carry out tasks to help customers.

", "smithy.api#http": { "code": 202, "method": "PUT", @@ -4801,6 +4827,161 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagent#CreateVpcConfiguration": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagent#CreateVpcConfigurationRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagent#CreateVpcConfigurationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagent#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagent#ConflictException" + }, + { + "target": "com.amazonaws.bedrockagent#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagent#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagent#ServiceQuotaExceededException" + }, + { + "target": "com.amazonaws.bedrockagent#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagent#ValidationException" + } + ], + "traits": { + "smithy.api#documentation": "

Creates a VPC configuration that lets a knowledge base connect to a resource in your private VPC. This operation is asynchronous: it returns a vpcConfigurationId with status CREATING. Poll GetVpcConfiguration until the status becomes CREATED or CREATE_FAILED.

", + "smithy.api#http": { + "code": 202, + "method": "POST", + "uri": "/knowledgebases/{knowledgeBaseId}/vpcconfigurations/" + }, + "smithy.api#idempotent": {}, + "smithy.api#tags": [ + "console" + ] + } + }, + "com.amazonaws.bedrockagent#CreateVpcConfigurationRequest": { + "type": "structure", + "members": { + "knowledgeBaseId": { + "target": "com.amazonaws.bedrockagent#Id", + "traits": { + "smithy.api#documentation": "

The unique identifier of the knowledge base to associate this VPC configuration with.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "clientToken": { + "target": "com.amazonaws.bedrockagent#ClientToken", + "traits": { + "smithy.api#documentation": "

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, the service ignores the request but does not return an error.

", + "smithy.api#idempotencyToken": {} + } + }, + "vpcId": { + "target": "com.amazonaws.bedrockagent#VpcId", + "traits": { + "smithy.api#documentation": "

The identifier of the VPC that the knowledge base connects through to reach the resource.

", + "smithy.api#required": {} + } + }, + "subnetIds": { + "target": "com.amazonaws.bedrockagent#SubnetIdList", + "traits": { + "smithy.api#documentation": "

The subnets, in the VPC identified by vpcId, that the knowledge base uses to connect to the resource.

", + "smithy.api#required": {} + } + }, + "resourceTarget": { + "target": "com.amazonaws.bedrockagent#ResourceTarget", + "traits": { + "smithy.api#documentation": "

The private IPv4 address or DNS name of the resource you want the knowledge base to reach. The target must be privately reachable from inside your VPC, such as an internal load balancer or a private IP. The following are not supported:

", + "smithy.api#required": {} + } + }, + "port": { + "target": "com.amazonaws.bedrockagent#Port", + "traits": { + "smithy.api#documentation": "

The port on which to reach the resource.

", + "smithy.api#required": {} + } + }, + "protocol": { + "target": "com.amazonaws.bedrockagent#VpcProtocol", + "traits": { + "smithy.api#documentation": "

The protocol used to connect to the resource. Specify HTTP for plaintext or HTTPS for TLS. When you specify HTTPS, you must also provide tlsServerName.

", + "smithy.api#required": {} + } + }, + "resolutionMode": { + "target": "com.amazonaws.bedrockagent#VpcResolutionMode", + "traits": { + "smithy.api#documentation": "

Controls how a domain-name resourceTarget is resolved. This applies only when the target is a domain name; it has no effect for IP-address targets, which have no name to resolve. In all cases the resolved address must be reachable from inside your VPC. Valid values:

", + "smithy.api#required": {} + } + }, + "hostHeader": { + "target": "com.amazonaws.bedrockagent#HostHeader", + "traits": { + "smithy.api#documentation": "

An optional HTTP Host header value to send when invoking the resource. Set this only if your resource (or an upstream router or ingress) routes by the Host header and that host differs from the target. This setting is independent of tlsServerName.

" + } + }, + "tlsServerName": { + "target": "com.amazonaws.bedrockagent#TlsServerName", + "traits": { + "smithy.api#documentation": "

The expected TLS server name. The service matches this value against the Subject Alternative Names on your resource's TLS certificate during invocation. This field is required when protocol is HTTPS. Set it to a hostname on your certificate, such as app.internal.example.com. You can use a single leftmost wildcard, such as *.example.com. The value must be a hostname without a port.

" + } + }, + "name": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationName", + "traits": { + "smithy.api#documentation": "

An optional human-readable name for the VPC configuration. If you don't specify a name, the VPC configuration has no name.

" + } + }, + "description": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationDescription", + "traits": { + "smithy.api#documentation": "

An optional description of the VPC configuration. If you don't specify a description, the VPC configuration has no description.

" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagent#CreateVpcConfigurationResponse": { + "type": "structure", + "members": { + "vpcConfigurationId": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the VPC configuration that was created.

", + "smithy.api#required": {} + } + }, + "status": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatus", + "traits": { + "smithy.api#documentation": "

The current status of the VPC configuration. Immediately after creation this is CREATING.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagent#CreationMode": { "type": "enum", "members": { @@ -5004,6 +5185,13 @@ "smithy.api#documentation": "

Details about a cyclic connection detected in the flow.

" } }, + "com.amazonaws.bedrockagent#DailySchedule": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#documentation": "

A daily sync. The run time is system-chosen (off-peak) and not configurable.

" + } + }, "com.amazonaws.bedrockagent#Data": { "type": "string", "traits": { @@ -5344,6 +5532,86 @@ "smithy.api#timestampFormat": "date-time" } }, + "com.amazonaws.bedrockagent#DayOfMonth": { + "type": "union", + "members": { + "dayNumber": { + "target": "com.amazonaws.bedrockagent#DayOfMonthNumber", + "traits": { + "smithy.api#documentation": "

A specific day of the month, from 1 to 28. Values are capped at 28, so a monthly sync runs in every month, including February.

" + } + }, + "lastDayOfMonth": { + "target": "com.amazonaws.bedrockagent#LastDayOfMonth", + "traits": { + "smithy.api#documentation": "

Set this option to run the monthly sync on the last calendar day of each month.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

The day of the month on which a monthly sync runs. Specify exactly one of dayNumber or lastDayOfMonth.

" + } + }, + "com.amazonaws.bedrockagent#DayOfMonthNumber": { + "type": "integer", + "traits": { + "smithy.api#documentation": "

A specific day of the month, from 1 to 28.

", + "smithy.api#range": { + "min": 1, + "max": 28 + } + } + }, + "com.amazonaws.bedrockagent#DayOfWeek": { + "type": "enum", + "members": { + "SUNDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SUNDAY" + } + }, + "MONDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "MONDAY" + } + }, + "TUESDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "TUESDAY" + } + }, + "WEDNESDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "WEDNESDAY" + } + }, + "THURSDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "THURSDAY" + } + }, + "FRIDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "FRIDAY" + } + }, + "SATURDAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SATURDAY" + } + } + }, + "traits": { + "smithy.api#documentation": "

The day of the week on which a weekly sync runs. Valid values are the standard English day names, for example, MONDAY or TUESDAY.

" + } + }, "com.amazonaws.bedrockagent#DeleteAgent": { "type": "operation", "input": { @@ -6407,66 +6675,13 @@ "smithy.api#output": {} } }, - "com.amazonaws.bedrockagent#DeletionProtectionConfiguration": { - "type": "structure", - "members": { - "deletionProtectionStatus": { - "target": "com.amazonaws.bedrockagent#EnabledOrDisabledState", - "traits": { - "smithy.api#documentation": "

Enable or disable deletion protection for the connector.

", - "smithy.api#required": {} - } - }, - "deletionProtectionThreshold": { - "target": "smithy.api#Integer", - "traits": { - "smithy.api#default": 15, - "smithy.api#documentation": "

The threshold is the maximum percentage of documents that a sync job can delete from your index. If a sync would delete more than this percentage, the sync skips its delete phase, leaving your indexed documents in place. Not supported for the Custom connector.

", - "smithy.api#range": { - "min": 0, - "max": 100 - } - } - } - }, - "traits": { - "smithy.api#documentation": "

Configuration for deletion protection.

" - } - }, - "com.amazonaws.bedrockagent#Description": { - "type": "string", - "traits": { - "smithy.api#length": { - "min": 1, - "max": 200 - } - } - }, - "com.amazonaws.bedrockagent#DescriptionString": { - "type": "string", - "traits": { - "smithy.api#length": { - "min": 1, - "max": 200 - } - } - }, - "com.amazonaws.bedrockagent#Dimensions": { - "type": "integer", - "traits": { - "smithy.api#range": { - "min": 0, - "max": 4096 - } - } - }, - "com.amazonaws.bedrockagent#DisassociateAgentCollaborator": { + "com.amazonaws.bedrockagent#DeleteVpcConfiguration": { "type": "operation", "input": { - "target": "com.amazonaws.bedrockagent#DisassociateAgentCollaboratorRequest" + "target": "com.amazonaws.bedrockagent#DeleteVpcConfigurationRequest" }, "output": { - "target": "com.amazonaws.bedrockagent#DisassociateAgentCollaboratorResponse" + "target": "com.amazonaws.bedrockagent#DeleteVpcConfigurationResponse" }, "errors": [ { @@ -6489,11 +6704,11 @@ } ], "traits": { - "smithy.api#documentation": "

Disassociates an agent collaborator.

", + "smithy.api#documentation": "

Deletes a VPC configuration. This operation is asynchronous: it returns status DELETING. Poll GetVpcConfiguration until it returns a ResourceNotFoundException, indicating the configuration is deleted. Delete requests are idempotent and safe to retry.

", "smithy.api#http": { - "code": 204, + "code": 202, "method": "DELETE", - "uri": "/agents/{agentId}/agentversions/{agentVersion}/agentcollaborators/{collaboratorId}/" + "uri": "/knowledgebases/{knowledgeBaseId}/vpcconfigurations/{vpcConfigurationId}" }, "smithy.api#idempotent": {}, "smithy.api#tags": [ @@ -6501,27 +6716,167 @@ ] } }, - "com.amazonaws.bedrockagent#DisassociateAgentCollaboratorRequest": { + "com.amazonaws.bedrockagent#DeleteVpcConfigurationRequest": { "type": "structure", "members": { - "agentId": { + "knowledgeBaseId": { "target": "com.amazonaws.bedrockagent#Id", "traits": { - "smithy.api#documentation": "

An agent ID.

", + "smithy.api#documentation": "

The unique identifier of the knowledge base that owns the VPC configuration.

", "smithy.api#httpLabel": {}, "smithy.api#required": {} } }, - "agentVersion": { - "target": "com.amazonaws.bedrockagent#DraftVersion", + "vpcConfigurationId": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationId", "traits": { - "smithy.api#documentation": "

The agent's version.

", + "smithy.api#documentation": "

The unique identifier of the VPC configuration to delete.

", "smithy.api#httpLabel": {}, "smithy.api#required": {} } - }, - "collaboratorId": { - "target": "com.amazonaws.bedrockagent#Id", + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagent#DeleteVpcConfigurationResponse": { + "type": "structure", + "members": { + "vpcConfigurationId": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the VPC configuration being deleted.

", + "smithy.api#required": {} + } + }, + "status": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatus", + "traits": { + "smithy.api#documentation": "

The current status of the VPC configuration. Immediately after a delete request this is DELETING.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.bedrockagent#DeletionProtectionConfiguration": { + "type": "structure", + "members": { + "deletionProtectionStatus": { + "target": "com.amazonaws.bedrockagent#EnabledOrDisabledState", + "traits": { + "smithy.api#documentation": "

Enable or disable deletion protection for the connector.

", + "smithy.api#required": {} + } + }, + "deletionProtectionThreshold": { + "target": "smithy.api#Integer", + "traits": { + "smithy.api#default": 15, + "smithy.api#documentation": "

The threshold is the maximum percentage of documents that a sync job can delete from your index. If a sync would delete more than this percentage, the sync skips its delete phase, leaving your indexed documents in place. Not supported for the Custom connector.

", + "smithy.api#range": { + "min": 0, + "max": 100 + } + } + } + }, + "traits": { + "smithy.api#documentation": "

Configuration for deletion protection.

" + } + }, + "com.amazonaws.bedrockagent#Description": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 200 + } + } + }, + "com.amazonaws.bedrockagent#DescriptionString": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 200 + } + } + }, + "com.amazonaws.bedrockagent#Dimensions": { + "type": "integer", + "traits": { + "smithy.api#range": { + "min": 0, + "max": 4096 + } + } + }, + "com.amazonaws.bedrockagent#DisassociateAgentCollaborator": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagent#DisassociateAgentCollaboratorRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagent#DisassociateAgentCollaboratorResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagent#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagent#ConflictException" + }, + { + "target": "com.amazonaws.bedrockagent#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagent#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagent#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagent#ValidationException" + } + ], + "traits": { + "smithy.api#documentation": "

Disassociates an agent collaborator.

", + "smithy.api#http": { + "code": 204, + "method": "DELETE", + "uri": "/agents/{agentId}/agentversions/{agentVersion}/agentcollaborators/{collaboratorId}/" + }, + "smithy.api#idempotent": {}, + "smithy.api#tags": [ + "console" + ] + } + }, + "com.amazonaws.bedrockagent#DisassociateAgentCollaboratorRequest": { + "type": "structure", + "members": { + "agentId": { + "target": "com.amazonaws.bedrockagent#Id", + "traits": { + "smithy.api#documentation": "

An agent ID.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "agentVersion": { + "target": "com.amazonaws.bedrockagent#DraftVersion", + "traits": { + "smithy.api#documentation": "

The agent's version.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "collaboratorId": { + "target": "com.amazonaws.bedrockagent#Id", "traits": { "smithy.api#documentation": "

The collaborator's ID.

", "smithy.api#httpLabel": {}, @@ -10261,6 +10616,83 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagent#GetVpcConfiguration": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagent#GetVpcConfigurationRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagent#GetVpcConfigurationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagent#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagent#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagent#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagent#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagent#ValidationException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns the details and current status of a single VPC configuration. Use this operation to poll for the outcome of an asynchronous create or delete.

", + "smithy.api#http": { + "code": 200, + "method": "GET", + "uri": "/knowledgebases/{knowledgeBaseId}/vpcconfigurations/{vpcConfigurationId}" + }, + "smithy.api#readonly": {}, + "smithy.api#tags": [ + "console" + ] + } + }, + "com.amazonaws.bedrockagent#GetVpcConfigurationRequest": { + "type": "structure", + "members": { + "knowledgeBaseId": { + "target": "com.amazonaws.bedrockagent#Id", + "traits": { + "smithy.api#documentation": "

The unique identifier of the knowledge base that owns the VPC configuration.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "vpcConfigurationId": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the VPC configuration to retrieve.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagent#GetVpcConfigurationResponse": { + "type": "structure", + "members": { + "vpcConfiguration": { + "target": "com.amazonaws.bedrockagent#VpcConfiguration", + "traits": { + "smithy.api#documentation": "

The VPC configuration, including its connection settings, resolution mode, and current lifecycle status.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagent#GraphArn": { "type": "string", "traits": { @@ -10364,6 +10796,16 @@ } } }, + "com.amazonaws.bedrockagent#HostHeader": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 255 + }, + "smithy.api#pattern": "^[A-Za-z0-9._:\\[\\]-]{1,255}$" + } + }, "com.amazonaws.bedrockagent#HttpsUrl": { "type": "string", "traits": { @@ -10382,7 +10824,7 @@ "imageExtractionStatus": { "target": "com.amazonaws.bedrockagent#EnabledOrDisabledState", "traits": { - "smithy.api#documentation": "Whether image extraction is enabled or disabled.", + "smithy.api#documentation": "

Whether image extraction is enabled or disabled.

", "smithy.api#required": {} } } @@ -11309,7 +11751,10 @@ } }, "managedKnowledgeBaseConfiguration": { - "target": "com.amazonaws.bedrockagent#ManagedKnowledgeBaseConfiguration" + "target": "com.amazonaws.bedrockagent#ManagedKnowledgeBaseConfiguration", + "traits": { + "smithy.api#documentation": "

Contains configuration details for a knowledge base that uses a vector store fully managed by Amazon Bedrock. Specify this object when the knowledge base type is MANAGED.

" + } }, "kendraKnowledgeBaseConfiguration": { "target": "com.amazonaws.bedrockagent#KendraKnowledgeBaseConfiguration", @@ -11831,6 +12276,13 @@ "smithy.api#documentation": "

Contains configurations for a Lambda function node in the flow. You specify the Lambda function to invoke and the inputs into the function. The output is the response that is defined in the Lambda function. For more information, see Node types in a flow in the Amazon Bedrock User Guide.

" } }, + "com.amazonaws.bedrockagent#LastDayOfMonth": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#documentation": "

The option to run the monthly sync on the last calendar day of each month.

" + } + }, "com.amazonaws.bedrockagent#LexFlowNodeConfiguration": { "type": "structure", "members": { @@ -13253,30 +13705,136 @@ "smithy.api#output": {} } }, - "com.amazonaws.bedrockagent#LoopControllerFlowNodeConfiguration": { - "type": "structure", - "members": { - "continueCondition": { - "target": "com.amazonaws.bedrockagent#FlowCondition", - "traits": { - "smithy.api#documentation": "

Specifies the condition that determines when the flow exits the DoWhile loop. The loop executes until this condition evaluates to true.

", - "smithy.api#required": {} - } + "com.amazonaws.bedrockagent#ListVpcConfigurations": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagent#ListVpcConfigurationsRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagent#ListVpcConfigurationsResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagent#AccessDeniedException" }, - "maxIterations": { - "target": "smithy.api#Integer", - "traits": { - "smithy.api#default": 10, - "smithy.api#documentation": "

Specifies the maximum number of times the DoWhile loop can iterate before the flow exits the loop.

", - "smithy.api#range": { - "min": 1, - "max": 1000 - } - } + { + "target": "com.amazonaws.bedrockagent#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagent#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagent#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagent#ValidationException" } - }, + ], "traits": { - "smithy.api#documentation": "

Contains configurations for the controller node of a DoWhile loop in the flow.

" + "smithy.api#documentation": "

Returns a paginated list of the VPC configurations for a knowledge base. You can optionally filter by status. Use the nextToken parameter to retrieve additional results.

", + "smithy.api#http": { + "code": 200, + "method": "GET", + "uri": "/knowledgebases/{knowledgeBaseId}/vpcconfigurations/" + }, + "smithy.api#paginated": { + "inputToken": "nextToken", + "outputToken": "nextToken", + "pageSize": "maxResults", + "items": "items" + }, + "smithy.api#readonly": {}, + "smithy.api#tags": [ + "console" + ] + } + }, + "com.amazonaws.bedrockagent#ListVpcConfigurationsRequest": { + "type": "structure", + "members": { + "knowledgeBaseId": { + "target": "com.amazonaws.bedrockagent#Id", + "traits": { + "smithy.api#documentation": "

The unique identifier of the knowledge base whose VPC configurations you want to list.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "statusFilter": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatus", + "traits": { + "smithy.api#documentation": "

The status to filter the results by. Only VPC configurations with the specified status are returned.

", + "smithy.api#httpQuery": "status" + } + }, + "maxResults": { + "target": "com.amazonaws.bedrockagent#MaxResults", + "traits": { + "smithy.api#documentation": "

The maximum number of results to return in the response. If more results are available, the response returns a nextToken.

", + "smithy.api#httpQuery": "maxResults", + "smithy.api#range": { + "min": 1, + "max": 100 + } + } + }, + "nextToken": { + "target": "com.amazonaws.bedrockagent#NextToken", + "traits": { + "smithy.api#documentation": "

A pagination token to retrieve the next page of results, returned in a previous response when more results are available.

", + "smithy.api#httpQuery": "nextToken" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagent#ListVpcConfigurationsResponse": { + "type": "structure", + "members": { + "items": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationSummaryList", + "traits": { + "smithy.api#documentation": "

A list of VPC configuration summaries.

", + "smithy.api#required": {} + } + }, + "nextToken": { + "target": "com.amazonaws.bedrockagent#NextToken", + "traits": { + "smithy.api#documentation": "

A pagination token to retrieve the next page of results, present when the total number of results exceeds the maximum number of results.

" + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.bedrockagent#LoopControllerFlowNodeConfiguration": { + "type": "structure", + "members": { + "continueCondition": { + "target": "com.amazonaws.bedrockagent#FlowCondition", + "traits": { + "smithy.api#documentation": "

Specifies the condition that determines when the flow exits the DoWhile loop. The loop executes until this condition evaluates to true.

", + "smithy.api#required": {} + } + }, + "maxIterations": { + "target": "smithy.api#Integer", + "traits": { + "smithy.api#default": 10, + "smithy.api#documentation": "

Specifies the maximum number of times the DoWhile loop can iterate before the flow exits the loop.

", + "smithy.api#range": { + "min": 1, + "max": 1000 + } + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains configurations for the controller node of a DoWhile loop in the flow.

" } }, "com.amazonaws.bedrockagent#LoopFlowNodeConfiguration": { @@ -13392,7 +13950,10 @@ "type": "structure", "members": { "embeddingModelType": { - "target": "com.amazonaws.bedrockagent#EmbeddingModelType" + "target": "com.amazonaws.bedrockagent#EmbeddingModelType", + "traits": { + "smithy.api#documentation": "

Choose CUSTOM to provide your own Bedrock embedding model ARN. Choose MANAGED to use a service-managed embedding model.

" + } }, "embeddingModelArn": { "target": "com.amazonaws.bedrockagent#BedrockEmbeddingModelArn", @@ -13401,10 +13962,22 @@ } }, "embeddingModelConfiguration": { - "target": "com.amazonaws.bedrockagent#EmbeddingModelConfiguration" + "target": "com.amazonaws.bedrockagent#EmbeddingModelConfiguration", + "traits": { + "smithy.api#documentation": "

The configuration details for the embeddings model. Not required when choosing the MANAGED embeddingModelType.

" + } }, "serverSideEncryptionConfiguration": { - "target": "com.amazonaws.bedrockagent#ServerSideEncryptionConfiguration" + "target": "com.amazonaws.bedrockagent#ServerSideEncryptionConfiguration", + "traits": { + "smithy.api#documentation": "

Contains the configuration for server-side encryption for your managed knowledge base.

" + } + }, + "supplementalDataStorageConfiguration": { + "target": "com.amazonaws.bedrockagent#SupplementalDataStorageConfiguration", + "traits": { + "smithy.api#documentation": "

Use this object to specify the Amazon S3 location that the knowledge base uses to process and ingest multimodal content. This field is required when you use a native multimodal embedding model.

" + } } }, "traits": { @@ -13431,6 +14004,12 @@ "traits": { "smithy.api#documentation": "

Connector-specific parameters. For more information, see Connect a data source.

" } + }, + "syncSchedule": { + "target": "com.amazonaws.bedrockagent#SyncSchedule", + "traits": { + "smithy.api#documentation": "

The recurring schedule on which the connector automatically syncs this data source. If not specified, the data source is not synced automatically and you start each sync yourself. Not supported for the Custom connector.

" + } } }, "traits": { @@ -14041,6 +14620,21 @@ "smithy.api#pattern": "^.*$" } }, + "com.amazonaws.bedrockagent#MonthlySchedule": { + "type": "structure", + "members": { + "dayOfMonth": { + "target": "com.amazonaws.bedrockagent#DayOfMonth", + "traits": { + "smithy.api#documentation": "

The day of the month on which the monthly sync runs.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

A monthly sync on a specified day of the month.

" + } + }, "com.amazonaws.bedrockagent#MultipleLoopControllerNodesFlowValidationDetails": { "type": "structure", "members": { @@ -14447,7 +15041,7 @@ "parsingStrategy": { "target": "com.amazonaws.bedrockagent#ParsingStrategy", "traits": { - "smithy.api#documentation": "

The parsing strategy for the data source. Only SMART_PARSING can be selected for managed knowledge bases. For more information, see Customize ingestion for managed knowledge bases.

", + "smithy.api#documentation": "

The parsing strategy for the data source.

For managed knowledge bases, the strategy that you can select depends on the embedding model that your knowledge base uses:

For more information, see Customize ingestion for managed knowledge bases.

", "smithy.api#required": {} } }, @@ -14523,6 +15117,12 @@ "traits": { "smithy.api#enumValue": "SMART_PARSING" } + }, + "MULTI_MODAL_EMBEDDINGS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "MULTI_MODAL_EMBEDDINGS" + } } } }, @@ -14694,6 +15294,15 @@ "smithy.api#pattern": "^.*$" } }, + "com.amazonaws.bedrockagent#Port": { + "type": "integer", + "traits": { + "smithy.api#range": { + "min": 1, + "max": 65535 + } + } + }, "com.amazonaws.bedrockagent#PrepareAgent": { "type": "operation", "input": { @@ -16416,6 +17025,15 @@ "smithy.api#pattern": "^[\\u0009\\u000A\\u000D\\u0020-\\u00FF]+$" } }, + "com.amazonaws.bedrockagent#ResourceTarget": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 255 + } + } + }, "com.amazonaws.bedrockagent#RetrievalFlowNodeConfiguration": { "type": "structure", "members": { @@ -17382,6 +18000,28 @@ "smithy.api#sensitive": {} } }, + "com.amazonaws.bedrockagent#SubnetId": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 64 + }, + "smithy.api#pattern": "^subnet-[a-zA-Z0-9]+$" + } + }, + "com.amazonaws.bedrockagent#SubnetIdList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagent#SubnetId" + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 6 + } + } + }, "com.amazonaws.bedrockagent#SupplementalDataStorageConfiguration": { "type": "structure", "members": { @@ -17452,6 +18092,32 @@ } } }, + "com.amazonaws.bedrockagent#SyncSchedule": { + "type": "union", + "members": { + "daily": { + "target": "com.amazonaws.bedrockagent#DailySchedule", + "traits": { + "smithy.api#documentation": "

A daily sync that runs once a day at a system-chosen off-peak time. The run time is not configurable.

" + } + }, + "weekly": { + "target": "com.amazonaws.bedrockagent#WeeklySchedule", + "traits": { + "smithy.api#documentation": "

A weekly sync that runs once a week on the specified day of the week.

" + } + }, + "monthly": { + "target": "com.amazonaws.bedrockagent#MonthlySchedule", + "traits": { + "smithy.api#documentation": "

A monthly sync that runs once a month on the specified day of the month.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

The recurring schedule on which a managed knowledge base connector automatically syncs its data source. Specify exactly one of daily, weekly, or monthly.

" + } + }, "com.amazonaws.bedrockagent#SystemContentBlock": { "type": "union", "members": { @@ -17685,6 +18351,16 @@ "smithy.api#httpError": 429 } }, + "com.amazonaws.bedrockagent#TlsServerName": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 253 + }, + "smithy.api#pattern": "^(\\*\\.)?([A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)*[A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?$" + } + }, "com.amazonaws.bedrockagent#Tool": { "type": "union", "members": { @@ -17806,7 +18482,7 @@ "strict": { "target": "smithy.api#Boolean", "traits": { - "smithy.api#documentation": "Whether to enforce strict JSON schema adherence for the tool input" + "smithy.api#documentation": "

Whether the tool schema is strictly enforced.

" } } }, @@ -19894,7 +20570,7 @@ "videoExtractionStatus": { "target": "com.amazonaws.bedrockagent#EnabledOrDisabledState", "traits": { - "smithy.api#documentation": "Whether video extraction is enabled or disabled.", + "smithy.api#documentation": "

Whether video extraction is enabled or disabled.

", "smithy.api#required": {} } } @@ -19922,6 +20598,341 @@ "smithy.api#documentation": "

Configuration for segmenting video content during multimodal knowledge base ingestion. Determines how video files are divided into chunks for processing.

" } }, + "com.amazonaws.bedrockagent#VpcConfiguration": { + "type": "structure", + "members": { + "vpcConfigurationId": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the VPC configuration.

", + "smithy.api#required": {} + } + }, + "status": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatus", + "traits": { + "smithy.api#documentation": "

The current lifecycle status of the VPC configuration.

", + "smithy.api#required": {} + } + }, + "statusMessage": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatusMessage", + "traits": { + "smithy.api#documentation": "

Additional detail about the current status, such as the cause of a CREATE_FAILED or DELETE_FAILED status.

" + } + }, + "vpcId": { + "target": "com.amazonaws.bedrockagent#VpcId", + "traits": { + "smithy.api#documentation": "

The identifier of the VPC that the knowledge base connects through to reach the resource.

", + "smithy.api#required": {} + } + }, + "subnetIds": { + "target": "com.amazonaws.bedrockagent#SubnetIdList", + "traits": { + "smithy.api#documentation": "

The subnets that the knowledge base uses to connect to the resource.

", + "smithy.api#required": {} + } + }, + "resourceTarget": { + "target": "com.amazonaws.bedrockagent#ResourceTarget", + "traits": { + "smithy.api#documentation": "

The private IPv4 address or DNS name of the resource.

", + "smithy.api#required": {} + } + }, + "port": { + "target": "com.amazonaws.bedrockagent#Port", + "traits": { + "smithy.api#documentation": "

The port on which the resource is reached.

", + "smithy.api#required": {} + } + }, + "protocol": { + "target": "com.amazonaws.bedrockagent#VpcProtocol", + "traits": { + "smithy.api#documentation": "

The protocol used to connect to the resource.

", + "smithy.api#required": {} + } + }, + "resolutionMode": { + "target": "com.amazonaws.bedrockagent#VpcResolutionMode", + "traits": { + "smithy.api#documentation": "

Specifies how the resource target is resolved.

", + "smithy.api#required": {} + } + }, + "hostHeader": { + "target": "com.amazonaws.bedrockagent#HostHeader", + "traits": { + "smithy.api#documentation": "

The HTTP Host header value sent when invoking the resource, if configured.

" + } + }, + "tlsServerName": { + "target": "com.amazonaws.bedrockagent#TlsServerName", + "traits": { + "smithy.api#documentation": "

The expected TLS server name that the service matches against the Subject Alternative Names on the resource's TLS certificate. Present when protocol is HTTPS.

" + } + }, + "name": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationName", + "traits": { + "smithy.api#documentation": "

The human-readable name of the VPC configuration, if provided.

" + } + }, + "description": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationDescription", + "traits": { + "smithy.api#documentation": "

The description of the VPC configuration, if provided.

" + } + }, + "createdAt": { + "target": "com.amazonaws.bedrockagent#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The time at which the VPC configuration was created.

", + "smithy.api#required": {} + } + }, + "updatedAt": { + "target": "com.amazonaws.bedrockagent#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The time at which the VPC configuration was last updated.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains the details of a VPC configuration, including its connection settings, resolution mode, and current lifecycle status.

" + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationDescription": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 0, + "max": 512 + }, + "smithy.api#pattern": "^[^\\p{C}]*$" + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationId": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 32, + "max": 32 + }, + "smithy.api#pattern": "^[a-z0-9](?:[a-z0-9-]{30}[a-z0-9])$" + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationName": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 128 + }, + "smithy.api#pattern": "^[a-zA-Z0-9]([a-zA-Z0-9 _-]*[a-zA-Z0-9])?$" + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationStatus": { + "type": "enum", + "members": { + "CREATING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CREATING" + } + }, + "CREATED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CREATED" + } + }, + "DELETING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DELETING" + } + }, + "CREATE_FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CREATE_FAILED" + } + }, + "DELETE_FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DELETE_FAILED" + } + } + }, + "traits": { + "smithy.api#documentation": "

The lifecycle status of a VPC configuration. Valid values:

" + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationStatusMessage": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 2048 + } + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationSummary": { + "type": "structure", + "members": { + "vpcConfigurationId": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the VPC configuration.

", + "smithy.api#required": {} + } + }, + "status": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatus", + "traits": { + "smithy.api#documentation": "

The current lifecycle status of the VPC configuration.

", + "smithy.api#required": {} + } + }, + "statusMessage": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationStatusMessage", + "traits": { + "smithy.api#documentation": "

Additional detail about the current status, such as the cause of a failure.

" + } + }, + "vpcId": { + "target": "com.amazonaws.bedrockagent#VpcId", + "traits": { + "smithy.api#documentation": "

The identifier of the VPC that the knowledge base connects through to reach the resource.

", + "smithy.api#required": {} + } + }, + "resourceTarget": { + "target": "com.amazonaws.bedrockagent#ResourceTarget", + "traits": { + "smithy.api#documentation": "

The private IPv4 address or DNS name of the resource.

", + "smithy.api#required": {} + } + }, + "port": { + "target": "com.amazonaws.bedrockagent#Port", + "traits": { + "smithy.api#documentation": "

The port on which the resource is reached.

", + "smithy.api#required": {} + } + }, + "protocol": { + "target": "com.amazonaws.bedrockagent#VpcProtocol", + "traits": { + "smithy.api#documentation": "

The protocol used to connect to the resource.

", + "smithy.api#required": {} + } + }, + "resolutionMode": { + "target": "com.amazonaws.bedrockagent#VpcResolutionMode", + "traits": { + "smithy.api#documentation": "

Specifies how the resource target is resolved.

", + "smithy.api#required": {} + } + }, + "hostHeader": { + "target": "com.amazonaws.bedrockagent#HostHeader", + "traits": { + "smithy.api#documentation": "

The HTTP Host header value sent when invoking the resource, if configured.

" + } + }, + "tlsServerName": { + "target": "com.amazonaws.bedrockagent#TlsServerName", + "traits": { + "smithy.api#documentation": "

The expected TLS server name that the service matches against the Subject Alternative Names on the resource's TLS certificate. Present when protocol is HTTPS.

" + } + }, + "name": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationName", + "traits": { + "smithy.api#documentation": "

The human-readable name of the VPC configuration, if provided.

" + } + }, + "description": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationDescription", + "traits": { + "smithy.api#documentation": "

The description of the VPC configuration, if provided.

" + } + }, + "createdAt": { + "target": "com.amazonaws.bedrockagent#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The time at which the VPC configuration was created.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

A summary of a VPC configuration returned by ListVpcConfigurations.

" + } + }, + "com.amazonaws.bedrockagent#VpcConfigurationSummaryList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagent#VpcConfigurationSummary" + } + }, + "com.amazonaws.bedrockagent#VpcId": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 64 + }, + "smithy.api#pattern": "^vpc-[a-zA-Z0-9]+$" + } + }, + "com.amazonaws.bedrockagent#VpcProtocol": { + "type": "enum", + "members": { + "HTTP": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "HTTP" + } + }, + "HTTPS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "HTTPS" + } + } + }, + "traits": { + "smithy.api#documentation": "

The protocol used to connect to the resource. Valid values:

" + } + }, + "com.amazonaws.bedrockagent#VpcResolutionMode": { + "type": "enum", + "members": { + "PUBLIC": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "PUBLIC" + } + }, + "IN_VPC": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "IN_VPC" + } + } + }, + "traits": { + "smithy.api#documentation": "

Controls how a domain-name resource target is resolved. This applies only when the target is a domain name; it has no effect for IP-address targets. In all cases the resolved address must be reachable from inside the VPC. Valid values:

" + } + }, "com.amazonaws.bedrockagent#WebCrawlerConfiguration": { "type": "structure", "members": { @@ -20046,6 +21057,21 @@ "smithy.api#documentation": "

The configuration of the URL/URLs for the web content that you want to crawl. You should be authorized to crawl the URLs.

" } }, + "com.amazonaws.bedrockagent#WeeklySchedule": { + "type": "structure", + "members": { + "dayOfWeek": { + "target": "com.amazonaws.bedrockagent#DayOfWeek", + "traits": { + "smithy.api#documentation": "

The day of the week on which the weekly sync runs.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

A weekly sync on a specified day of the week.

" + } + }, "com.amazonaws.bedrockagent#WorkgroupArn": { "type": "string", "traits": { diff --git a/codegen/aws-models/bedrock-agentcore-control.json b/codegen/aws-models/bedrock-agentcore-control.json index 86ccd461..cf0db60a 100644 --- a/codegen/aws-models/bedrock-agentcore-control.json +++ b/codegen/aws-models/bedrock-agentcore-control.json @@ -595,6 +595,12 @@ "traits": { "smithy.api#enumValue": "DELETING" } + }, + "DELETE_FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DELETE_FAILED" + } } } }, @@ -654,6 +660,12 @@ "traits": { "smithy.api#enumValue": "DELETING" } + }, + "DELETE_FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DELETE_FAILED" + } } } }, @@ -742,6 +754,9 @@ } } }, + "com.amazonaws.bedrockagentcorecontrol#AllowedAudienceType": { + "type": "string" + }, "com.amazonaws.bedrockagentcorecontrol#AllowedClient": { "type": "string" }, @@ -934,6 +949,9 @@ { "target": "com.amazonaws.bedrockagentcorecontrol#ConfigurationBundle" }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortal" + }, { "target": "com.amazonaws.bedrockagentcorecontrol#Dataset" }, @@ -3259,6 +3277,44 @@ "smithy.api#documentation": "

A certificate to install in the browser or code interpreter.

" } }, + "com.amazonaws.bedrockagentcorecontrol#CertificateBucketOwnerAccountId": { + "type": "string", + "traits": { + "smithy.api#pattern": "^[0-9]{12}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#CertificateConfiguration": { + "type": "union", + "members": { + "s3": { + "target": "com.amazonaws.bedrockagentcorecontrol#S3CertificateConfiguration", + "traits": { + "smithy.api#documentation": "

The Amazon S3 location of the PEM-encoded private CA certificate.

" + } + }, + "secretsManager": { + "target": "com.amazonaws.bedrockagentcorecontrol#SecretsManagerCertificateConfiguration", + "traits": { + "smithy.api#documentation": "

The Amazon Web Services Secrets Manager location of the PEM-encoded private CA certificate.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

A reference to a private certificate authority (CA) certificate that the gateway uses to verify TLS connections to the target endpoint. Use this when the target presents a certificate issued by a private CA that is not trusted by default. Specify exactly one certificate source. The configuration is a reference only and never contains the certificate content.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfiguration" + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 1 + } + } + }, "com.amazonaws.bedrockagentcorecontrol#CertificateLocation": { "type": "union", "members": { @@ -3273,6 +3329,18 @@ "smithy.api#documentation": "

The location from which to retrieve a certificate.

" } }, + "com.amazonaws.bedrockagentcorecontrol#CertificateS3Uri": { + "type": "string", + "traits": { + "smithy.api#pattern": "^s3://.{1,2043}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#CertificateSecretArn": { + "type": "string", + "traits": { + "smithy.api#pattern": "^arn:aws(-[^:]+)?:secretsmanager:[a-z0-9-]+:[0-9]{12}:secret:.+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#Certificates": { "type": "list", "member": { @@ -3382,12 +3450,22 @@ "logGroupNames": { "target": "com.amazonaws.bedrockagentcorecontrol#LogGroupNamesList", "traits": { + "smithy.api#addedDefault": {}, + "smithy.api#default": [], "smithy.api#documentation": "

The list of CloudWatch log group names to monitor for agent traces.

", + "smithy.api#length": { + "max": 10 + } + } + }, + "logGroupNamePrefixes": { + "target": "com.amazonaws.bedrockagentcorecontrol#LogGroupNamePrefixList", + "traits": { + "smithy.api#documentation": "

The list of CloudWatch log group name prefixes to monitor for agent traces. Specify this instead of logGroupNames to match log groups by prefix. Specify either logGroupNames or logGroupNamePrefixes, not both. One of the two is required.

", "smithy.api#length": { "min": 1, "max": 5 - }, - "smithy.api#required": {} + } } }, "serviceNames": { @@ -3410,10 +3488,24 @@ "type": "structure", "members": { "logGroupName": { - "target": "com.amazonaws.bedrockagentcorecontrol#LogGroupName", + "target": "com.amazonaws.bedrockagentcorecontrol#OptionalLogGroupName", "traits": { - "smithy.api#documentation": "

The name of the CloudWatch log group where evaluation results will be written. The log group will be created if it doesn't exist.

", - "smithy.api#required": {} + "smithy.api#addedDefault": {}, + "smithy.api#default": "", + "smithy.api#documentation": "

The name of the CloudWatch log group where evaluation results will be written. An existing log group is used as-is; otherwise the service creates it, which requires the evaluation execution role to grant logs:CreateLogGroup on the log group. Don't specify this value when resultDestination is SOURCE_LOG_GROUP. The name can't be under the service-reserved /aws/bedrock-agentcore/evaluations/ namespace, apart from this configuration's own service-managed default group.

" + } + }, + "metricsNamespace": { + "target": "com.amazonaws.bedrockagentcorecontrol#MetricsNamespace", + "traits": { + "smithy.api#documentation": "

The CloudWatch metrics namespace where evaluation result metrics are published. If you omit this value, the service publishes metrics to Bedrock-AgentCore/Evaluations. This value can't begin with AWS/.

" + } + }, + "resultDestination": { + "target": "com.amazonaws.bedrockagentcorecontrol#ResultDestination", + "traits": { + "smithy.api#default": "DEDICATED_LOG_GROUP", + "smithy.api#documentation": "

The destination where evaluation results are written. Valid values:

" } } }, @@ -3830,6 +3922,50 @@ "smithy.api#documentation": "

Coinbase CDP configuration output with secret ARNs.

" } }, + "com.amazonaws.bedrockagentcorecontrol#CoinbaseCdpRotationTargets": { + "type": "structure", + "members": { + "secrets": { + "target": "com.amazonaws.bedrockagentcorecontrol#CoinbaseCdpSecrets", + "traits": { + "smithy.api#documentation": "

The secrets to rotate. Specify at least one value. Each secret that you specify is rotated independently.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

Specifies the service-managed Coinbase CDP secrets to rotate.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#CoinbaseCdpSecret": { + "type": "enum", + "members": { + "API_KEY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "API_KEY" + } + }, + "WALLET_SECRET": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "WALLET_SECRET" + } + } + } + }, + "com.amazonaws.bedrockagentcorecontrol#CoinbaseCdpSecrets": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcorecontrol#CoinbaseCdpSecret" + }, + "traits": { + "smithy.api#length": { + "min": 1 + }, + "smithy.api#uniqueItems": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#ComponentConfiguration": { "type": "structure", "members": { @@ -4003,6 +4139,9 @@ "com.amazonaws.bedrockagentcorecontrol#ConfigurationBundleArn": { "type": "string", "traits": { + "aws.api#arnReference": { + "type": "AWS::BedrockAgentCore::ConfigurationBundle" + }, "smithy.api#pattern": "^arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:configuration-bundle/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}$" } }, @@ -4386,6 +4525,311 @@ "smithy.api#pattern": "^(?:0|[1-9]\\d*)\\.(?:0|[1-9]\\d*)\\.(?:0|[1-9]\\d*)$" } }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortal": { + "type": "resource", + "identifiers": { + "consentPortalId": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdentifier" + } + }, + "properties": { + "sources": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources" + }, + "consentPortalArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalArnType" + }, + "createdAt": { + "target": "smithy.api#Timestamp" + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType" + }, + "executionRoleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType" + }, + "idpConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig" + }, + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType" + }, + "portalUrl": { + "target": "com.amazonaws.bedrockagentcorecontrol#PortalUrlType" + }, + "status": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalStatus" + }, + "statusReason": { + "target": "com.amazonaws.bedrockagentcorecontrol#StatusReasonType" + }, + "updatedAt": { + "target": "smithy.api#Timestamp" + } + }, + "create": { + "target": "com.amazonaws.bedrockagentcorecontrol#CreateConsentPortal" + }, + "read": { + "target": "com.amazonaws.bedrockagentcorecontrol#GetConsentPortal" + }, + "update": { + "target": "com.amazonaws.bedrockagentcorecontrol#UpdateConsentPortal" + }, + "delete": { + "target": "com.amazonaws.bedrockagentcorecontrol#DeleteConsentPortal" + }, + "collectionOperations": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#ListConsentPortals" + } + ] + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalArnType": { + "type": "string", + "traits": { + "aws.api#arnReference": { + "type": "AWS::BedrockAgentCore::ConsentPortal" + }, + "smithy.api#pattern": "^arn:aws[^:]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:consent-portal/[a-zA-Z0-9\\-_]{1,50}-[A-Za-z0-9]{10}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType": { + "type": "string", + "traits": { + "smithy.api#length": { + "max": 512 + } + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdType": { + "type": "string", + "traits": { + "smithy.api#pattern": "^[a-zA-Z0-9\\-_]{1,50}-[A-Za-z0-9]{10}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdentifier": { + "type": "string", + "traits": { + "smithy.api#pattern": "^[a-zA-Z0-9\\-_]{1,50}-[A-Za-z0-9]{10}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig": { + "type": "structure", + "members": { + "credentialProviderArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#OAuth2CredentialProviderArn", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the OAuth2 credential provider used to authenticate end users to the consent portal.

", + "smithy.api#required": {} + } + }, + "scopes": { + "target": "com.amazonaws.bedrockagentcorecontrol#AllowedScopesType", + "traits": { + "smithy.api#documentation": "

The OAuth2 scopes that the consent portal requests when authenticating end users.

", + "smithy.api#required": {} + } + }, + "audience": { + "target": "com.amazonaws.bedrockagentcorecontrol#AllowedAudienceType", + "traits": { + "smithy.api#documentation": "

The audience value that the consent portal includes when requesting tokens from the identity provider.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

The identity provider configuration used to authenticate end users to the consent portal.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 50 + }, + "smithy.api#pattern": "^[a-zA-Z0-9_-]{1,50}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSource": { + "type": "structure", + "members": { + "identifier": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSourceIdentifierType", + "traits": { + "smithy.api#documentation": "

The identifier of the source resource. For an agentcore-gateway source, this is the gateway ID or its Amazon Resource Name (ARN).

", + "smithy.api#required": {} + } + }, + "type": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSourceType", + "traits": { + "smithy.api#documentation": "

The type of the source resource.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

A resource served by the consent portal.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSourceIdentifierType": { + "type": "string", + "traits": { + "smithy.api#pattern": "^([0-9a-z][-]?){1,100}-[0-9a-z]{10}$|^arn:aws(-[a-z-]+)?:bedrock-agentcore:[a-z0-9-]{1,20}:[0-9]{12}:gateway/([0-9a-z][-]?){1,48}-[a-z0-9]{10}$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSourceType": { + "type": "enum", + "members": { + "AGENTCORE_GATEWAY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "agentcore-gateway" + } + } + }, + "traits": { + "smithy.api#documentation": "

The type of a consent portal source. Currently, we only support type agentcore-gateway.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSource" + }, + "traits": { + "smithy.api#documentation": "

The list of resources served by the consent portal.

", + "smithy.api#length": { + "min": 1, + "max": 1 + } + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalStatus": { + "type": "enum", + "members": { + "CREATING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CREATING" + } + }, + "ACTIVE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "ACTIVE" + } + }, + "UPDATING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "UPDATING" + } + }, + "UPDATE_FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "UPDATE_FAILED" + } + }, + "DELETING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DELETING" + } + }, + "FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "FAILED" + } + } + }, + "traits": { + "smithy.api#documentation": "

The lifecycle status of a consent portal.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSummaries": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSummary" + }, + "traits": { + "smithy.api#documentation": "

A list of consent portal summaries.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSummary": { + "type": "structure", + "members": { + "sources": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources", + "traits": { + "smithy.api#documentation": "

The resources served by the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalId": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdType", + "traits": { + "smithy.api#documentation": "

The unique identifier of the consent portal.

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + }, + "createdAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was created.

", + "smithy.api#required": {} + } + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType", + "traits": { + "smithy.api#documentation": "

The description of the consent portal.

" + } + }, + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType", + "traits": { + "smithy.api#documentation": "

The name of the consent portal.

", + "smithy.api#required": {} + } + }, + "portalUrl": { + "target": "com.amazonaws.bedrockagentcorecontrol#PortalUrlType", + "traits": { + "smithy.api#documentation": "

The URL used to access the consent portal.

" + } + }, + "status": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalStatus", + "traits": { + "smithy.api#documentation": "

The current status of the consent portal.

", + "smithy.api#required": {} + } + }, + "updatedAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was last updated.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

Summary information about a consent portal.

" + } + }, "com.amazonaws.bedrockagentcorecontrol#ConsolidationConfiguration": { "type": "union", "members": { @@ -4421,7 +4865,7 @@ "rawText": { "target": "com.amazonaws.bedrockagentcorecontrol#NaturalLanguage", "traits": { - "smithy.api#documentation": "

The raw text content containing natural language descriptions of desired policy behavior. This text is processed by AI to generate corresponding Cedar policy statements that match the described intent.

" + "smithy.api#documentation": "

The raw text content containing natural language descriptions of desired policy behavior. This text is processed by AI to generate corresponding Dogwood policy statements that match the described intent.

" } } }, @@ -4754,6 +5198,12 @@ "traits": { "smithy.api#documentation": "

A map of tag keys and values to assign to the agent runtime. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

" } + }, + "platformVersion": { + "target": "com.amazonaws.bedrockagentcorecontrol#PlatformVersion", + "traits": { + "smithy.api#documentation": "

The version of the runtime platform to use for the AgentCore Runtime.

" + } } }, "traits": { @@ -5611,6 +6061,189 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagentcorecontrol#CreateConsentPortal": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcorecontrol#CreateConsentPortalRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagentcorecontrol#CreateConsentPortalResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ConflictException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ServiceQuotaExceededException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#UnauthorizedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ValidationException" + } + ], + "traits": { + "aws.api#controlPlane": {}, + "smithy.api#documentation": "

Creates a new consent portal.

", + "smithy.api#http": { + "code": 202, + "uri": "/identities/CreateConsentPortal", + "method": "POST" + } + } + }, + "com.amazonaws.bedrockagentcorecontrol#CreateConsentPortalRequest": { + "type": "structure", + "members": { + "executionRoleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the IAM role that the consent portal assumes to access the resources defined in its sources.

", + "smithy.api#required": {} + } + }, + "idpConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig", + "traits": { + "smithy.api#documentation": "

The identity provider configuration that the consent portal uses to authenticate end users.

", + "smithy.api#required": {} + } + }, + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType", + "traits": { + "smithy.api#documentation": "

The name of the consent portal. The name must be unique within your account.

", + "smithy.api#required": {} + } + }, + "sources": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources", + "traits": { + "smithy.api#documentation": "

The resources served by the consent portal. Currently, we only support type agentcore-gateway.

", + "smithy.api#required": {} + } + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType", + "traits": { + "smithy.api#documentation": "

The description of the consent portal.

" + } + }, + "tags": { + "target": "com.amazonaws.bedrockagentcorecontrol#TagsMap", + "traits": { + "smithy.api#documentation": "

A map of tag keys and values to assign to the consent portal. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

", + "smithy.api#notProperty": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#CreateConsentPortalResponse": { + "type": "structure", + "members": { + "sources": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources", + "traits": { + "smithy.api#documentation": "

The resources served by the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalId": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdType", + "traits": { + "smithy.api#documentation": "

The unique identifier of the consent portal.

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + }, + "createdAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was created.

", + "smithy.api#required": {} + } + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType", + "traits": { + "smithy.api#documentation": "

The description of the consent portal.

" + } + }, + "executionRoleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the IAM role that the consent portal assumes to access the resources defined in its sources.

", + "smithy.api#required": {} + } + }, + "idpConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig", + "traits": { + "smithy.api#documentation": "

The identity provider configuration that the consent portal uses to authenticate end users.

", + "smithy.api#required": {} + } + }, + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType", + "traits": { + "smithy.api#documentation": "

The name of the consent portal.

", + "smithy.api#required": {} + } + }, + "portalUrl": { + "target": "com.amazonaws.bedrockagentcorecontrol#PortalUrlType", + "traits": { + "smithy.api#documentation": "

The URL used to access the consent portal.

" + } + }, + "status": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalStatus", + "traits": { + "smithy.api#documentation": "

The current status of the consent portal.

", + "smithy.api#required": {} + } + }, + "statusReason": { + "target": "com.amazonaws.bedrockagentcorecontrol#StatusReasonType", + "traits": { + "smithy.api#documentation": "

A message that provides additional information about the current status of the consent portal.

" + } + }, + "updatedAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was last updated.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#CreateDataset": { "type": "operation", "input": { @@ -6660,6 +7293,12 @@ "traits": { "smithy.api#documentation": "

The private endpoint configuration for the gateway target. Use this to connect the gateway to private resources in your VPC.

" } + }, + "certificateConfigurations": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList", + "traits": { + "smithy.api#documentation": "

The private certificate authority (CA) configurations for the gateway target. Use this to have the gateway trust a private CA when it establishes TLS connections to the target endpoint. Provide each certificate by reference to an Amazon S3 object or an Amazon Web Services Secrets Manager secret. You can specify only one certificate authority configuration in this list.

" + } } }, "traits": { @@ -6772,6 +7411,12 @@ "traits": { "smithy.api#documentation": "

The protocol type of the created gateway target.

" } + }, + "certificateConfigurations": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList", + "traits": { + "smithy.api#documentation": "

The private certificate authority (CA) configurations for the gateway target.

" + } } }, "traits": { @@ -7007,6 +7652,12 @@ "smithy.api#documentation": "

The truncation configuration for managing conversation context when it exceeds model limits.

" } }, + "hooks": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHooks", + "traits": { + "smithy.api#documentation": "

The lifecycle hooks to run at defined points in the agent loop.

" + } + }, "maxIterations": { "target": "smithy.api#Integer", "traits": { @@ -7434,6 +8085,9 @@ "smithy.api#documentation": "

Configuration for periodic batch evaluation clustering of insight results.

" } }, + "outputConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#OutputConfig" + }, "evaluationExecutionRoleArn": { "target": "com.amazonaws.bedrockagentcorecontrol#RoleArn", "traits": { @@ -8006,7 +8660,7 @@ } ], "traits": { - "smithy.api#documentation": "

Creates a policy within the AgentCore Policy system. Policies provide real-time, deterministic control over agentic interactions with AgentCore Gateway. Using the Cedar policy language, you can define fine-grained policies that specify which interactions with Gateway tools are permitted based on input parameters and OAuth claims, ensuring agents operate within defined boundaries and business rules. The policy is validated during creation against the Cedar schema generated from the Gateway's tools' input schemas, which defines the available tools, their parameters, and expected data types. This is an asynchronous operation. Use the GetPolicy operation to poll the status field to track completion.

If the new policy is a temporal policy, creating it invalidates the policy engine's active temporal sessions. For more information about temporal policy sessions, see session-based temporal policies. The policy engine returns an HTTP 409 ConflictException to in-flight sessions. To resume, you must start a new session with a new session ID.

", + "smithy.api#documentation": "

Creates a policy within the AgentCore Policy system. Policies provide real-time, deterministic control over agentic interactions with AgentCore Gateway. Using Cedar or Dogwood, you can define fine-grained policies that specify which interactions with Gateway tools are permitted based on input parameters and OAuth claims, ensuring agents operate within defined boundaries and business rules. The policy is validated during creation against the Cedar schema generated from the Gateway's tools' input schemas, which defines the available tools, their parameters, and expected data types. This is an asynchronous operation. Use the GetPolicy operation to poll the status field to track completion.

If the new policy is a temporal policy, creating it invalidates the policy engine's active temporal sessions. For more information about temporal policy sessions, see session-based temporal policies. The policy engine returns an HTTP 409 ConflictException to in-flight sessions. To resume, you must start a new session with a new session ID.

", "smithy.api#http": { "method": "POST", "uri": "/policy-engines/{policyEngineId}/policies", @@ -8173,7 +8827,7 @@ "definition": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyDefinition", "traits": { - "smithy.api#documentation": "

The Cedar policy statement that defines the access control rules. This contains the actual policy logic written in Cedar policy language, specifying effect (permit or forbid), principals, actions, resources, and conditions for agent behavior control.

", + "smithy.api#documentation": "

The Cedar or Dogwood policy statement that defines the access control rules. This contains the actual policy logic written in Cedar or Dogwood, specifying effect (permit or forbid), principals, actions, resources, and conditions for agent behavior control.

", "smithy.api#required": {} } }, @@ -8284,7 +8938,7 @@ "definition": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyDefinition", "traits": { - "smithy.api#documentation": "

The Cedar policy statement that was created. This is the validated policy definition that will be used for agent behavior control and access decisions.

", + "smithy.api#documentation": "

The Cedar or Dogwood policy statement that was created. This is the validated policy definition that will be used for agent behavior control and access decisions.

", "smithy.api#required": {} } }, @@ -8913,6 +9567,20 @@ } } }, + "com.amazonaws.bedrockagentcorecontrol#CredentialRotationConfig": { + "type": "union", + "members": { + "coinbaseCDP": { + "target": "com.amazonaws.bedrockagentcorecontrol#CoinbaseCdpRotationTargets", + "traits": { + "smithy.api#documentation": "

The credentials to rotate for a Coinbase CDP payment connector.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

Specifies the service-managed credentials to rotate. Provide the member that matches the payment connector's type.

" + } + }, "com.amazonaws.bedrockagentcorecontrol#CredentialsProviderConfiguration": { "type": "union", "members": { @@ -9532,6 +10200,9 @@ "com.amazonaws.bedrockagentcorecontrol#DatasetArn": { "type": "string", "traits": { + "aws.api#arnReference": { + "type": "AWS::BedrockAgentCore::Dataset" + }, "smithy.api#pattern": "^arn:aws(-[a-z]+)*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:dataset/[a-zA-Z0-9_-]{1,110}$" } }, @@ -10548,6 +11219,14 @@ "com.amazonaws.bedrockagentcorecontrol#DeleteConfigurationBundleResponse": { "type": "structure", "members": { + "bundleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConfigurationBundleArn", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the deleted configuration bundle.

", + "smithy.api#required": {} + } + }, "bundleId": { "target": "com.amazonaws.bedrockagentcorecontrol#ConfigurationBundleId", "traits": { @@ -10567,6 +11246,71 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagentcorecontrol#DeleteConsentPortal": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcorecontrol#DeleteConsentPortalRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagentcorecontrol#DeleteConsentPortalResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ConflictException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#UnauthorizedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ValidationException" + } + ], + "traits": { + "aws.api#controlPlane": {}, + "smithy.api#documentation": "

Deletes a consent portal.

", + "smithy.api#http": { + "code": 204, + "uri": "/identities/DeleteConsentPortal", + "method": "POST" + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#DeleteConsentPortalRequest": { + "type": "structure", + "members": { + "consentPortalIdentifier": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdentifier", + "traits": { + "smithy.api#documentation": "

The identifier of the consent portal. You can specify either the consent portal ID or its Amazon Resource Name (ARN).

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#DeleteConsentPortalResponse": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#DeleteDataset": { "type": "operation", "input": { @@ -13508,7 +14252,7 @@ "traits": { "smithy.api#length": { "min": 0, - "max": 10 + "max": 25 } } }, @@ -13754,6 +14498,12 @@ } } }, + "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType": { + "type": "string", + "traits": { + "smithy.api#pattern": "^arn:aws(-[a-z-]+)?:iam::[0-9]{12}:role/[a-zA-Z0-9+=,.@\\-_/]+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#ExtractionConfig": { "type": "union", "members": { @@ -14239,7 +14989,7 @@ "min": 1, "max": 170 }, - "smithy.api#pattern": "^arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:policy-engine\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9_]{10}$" + "smithy.api#pattern": "^arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:policy-engine\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9_]{10}$" } }, "com.amazonaws.bedrockagentcorecontrol#GatewayPolicyEngineConfiguration": { @@ -14248,7 +14998,7 @@ "arn": { "target": "com.amazonaws.bedrockagentcorecontrol#GatewayPolicyEngineArn", "traits": { - "smithy.api#documentation": "

The ARN of the policy engine. The policy engine contains Cedar policies that define fine-grained authorization rules specifying who can perform what actions on which resources as agents interact through the gateway.

", + "smithy.api#documentation": "

The ARN of the policy engine. The policy engine contains Cedar or Dogwood policies that define fine-grained authorization rules specifying who can perform what actions on which resources as agents interact through the gateway.

", "smithy.api#required": {} } }, @@ -14879,6 +15629,12 @@ "traits": { "smithy.api#documentation": "

The protocol type of the gateway target.

" } + }, + "certificateConfigurations": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList", + "traits": { + "smithy.api#documentation": "

The private certificate authority (CA) configurations for the gateway target.

" + } } }, "traits": { @@ -15255,6 +16011,12 @@ "traits": { "smithy.api#documentation": "

The capacity provider configuration for the AgentCore Runtime.

" } + }, + "platformVersion": { + "target": "com.amazonaws.bedrockagentcorecontrol#PlatformVersion", + "traits": { + "smithy.api#documentation": "

The version of the runtime platform used by the AgentCore Runtime.

" + } } }, "traits": { @@ -16187,6 +16949,150 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagentcorecontrol#GetConsentPortal": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcorecontrol#GetConsentPortalRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagentcorecontrol#GetConsentPortalResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#UnauthorizedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ValidationException" + } + ], + "traits": { + "aws.api#controlPlane": {}, + "smithy.api#documentation": "

Retrieves information about a consent portal.

", + "smithy.api#http": { + "uri": "/identities/GetConsentPortal", + "method": "POST" + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#GetConsentPortalRequest": { + "type": "structure", + "members": { + "consentPortalIdentifier": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdentifier", + "traits": { + "smithy.api#documentation": "

The identifier of the consent portal. You can specify either the consent portal ID or its Amazon Resource Name (ARN).

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#GetConsentPortalResponse": { + "type": "structure", + "members": { + "sources": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources", + "traits": { + "smithy.api#documentation": "

The resources served by the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalId": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdType", + "traits": { + "smithy.api#documentation": "

The unique identifier of the consent portal.

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + }, + "createdAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was created.

", + "smithy.api#required": {} + } + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType", + "traits": { + "smithy.api#documentation": "

The description of the consent portal.

" + } + }, + "executionRoleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the IAM role that the consent portal assumes to access the resources defined in its sources.

", + "smithy.api#required": {} + } + }, + "idpConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig", + "traits": { + "smithy.api#documentation": "

The identity provider configuration that the consent portal uses to authenticate end users.

", + "smithy.api#required": {} + } + }, + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType", + "traits": { + "smithy.api#documentation": "

The name of the consent portal.

", + "smithy.api#required": {} + } + }, + "portalUrl": { + "target": "com.amazonaws.bedrockagentcorecontrol#PortalUrlType", + "traits": { + "smithy.api#documentation": "

The URL used to access the consent portal.

" + } + }, + "status": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalStatus", + "traits": { + "smithy.api#documentation": "

The current status of the consent portal.

", + "smithy.api#required": {} + } + }, + "statusReason": { + "target": "com.amazonaws.bedrockagentcorecontrol#StatusReasonType", + "traits": { + "smithy.api#documentation": "

A message that provides additional information about the current status of the consent portal.

" + } + }, + "updatedAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was last updated.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#GetDataset": { "type": "operation", "input": { @@ -17129,6 +18035,12 @@ "traits": { "smithy.api#documentation": "

The protocol type of the gateway target.

" } + }, + "certificateConfigurations": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList", + "traits": { + "smithy.api#documentation": "

The private certificate authority (CA) configurations for the gateway target.

" + } } }, "traits": { @@ -17793,6 +18705,12 @@ "smithy.api#required": {} } }, + "provisionMode": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorProvisionMode", + "traits": { + "smithy.api#documentation": "

Specifies how the payment connector was provisioned. Payment connectors that were created before this field was available return MANUAL.

" + } + }, "credentialProviderConfigurations": { "target": "com.amazonaws.bedrockagentcorecontrol#CredentialsProviderConfigurations", "traits": { @@ -17826,6 +18744,12 @@ "traits": { "smithy.api#documentation": "

The URL that the user must open to complete OAuth consent. This field is only present when the payment connector status is PENDING_AUTHENTICATION.

" } + }, + "credentialsUpdatedAt": { + "target": "com.amazonaws.bedrockagentcorecontrol#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The timestamp when the payment connector's current service-managed credentials took effect. It is first set when the credentials are provisioned and is updated by each rotation. This field is present only for payment connectors with a provisionMode of QUICK_CREATE.

" + } } }, "traits": { @@ -18536,7 +19460,7 @@ } ], "traits": { - "smithy.api#documentation": "

Retrieves information about a policy generation request within the AgentCore Policy system. Policy generation converts natural language descriptions into Cedar policy statements using AI-powered translation, enabling non-technical users to create policies.

", + "smithy.api#documentation": "

Retrieves information about a policy generation request within the AgentCore Policy system. Policy generation converts natural language descriptions into Dogwood policy statements using AI-powered translation, enabling non-technical users to create policies.

", "smithy.api#http": { "method": "GET", "uri": "/policy-engines/{policyEngineId}/policy-generations/{policyGenerationId}" @@ -18934,7 +19858,7 @@ "definition": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyDefinition", "traits": { - "smithy.api#documentation": "

The Cedar policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

", + "smithy.api#documentation": "

The Cedar or Dogwood policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

", "smithy.api#required": {} } }, @@ -19869,6 +20793,12 @@ "smithy.api#documentation": "

AgentCore Memory instance configuration for short and long term memory.

" } }, + "hooks": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHooks", + "traits": { + "smithy.api#documentation": "

The lifecycle hooks configured for the harness.

" + } + }, "maxIterations": { "target": "smithy.api#Integer", "traits": { @@ -19898,6 +20828,50 @@ "smithy.api#documentation": "

Representation of a harness.

" } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessAfterInvocationHook": { + "type": "structure", + "members": { + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookName", + "traits": { + "smithy.api#documentation": "

The name of the hook.

", + "smithy.api#required": {} + } + }, + "target": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookTarget", + "traits": { + "smithy.api#documentation": "

The target that receives the hook event.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for a hook that runs after an invocation completes.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessAfterToolCallHook": { + "type": "structure", + "members": { + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookName", + "traits": { + "smithy.api#documentation": "

The name of the hook.

", + "smithy.api#required": {} + } + }, + "target": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookTarget", + "traits": { + "smithy.api#documentation": "

The target that receives the hook event.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for a hook that runs after a tool call completes.

" + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessAgentCoreBrowserConfig": { "type": "structure", "members": { @@ -20191,6 +21165,50 @@ "smithy.api#documentation": "

Configuration for an Amazon Bedrock model provider.

" } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessBeforeInvocationHook": { + "type": "structure", + "members": { + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookName", + "traits": { + "smithy.api#documentation": "

The name of the hook.

", + "smithy.api#required": {} + } + }, + "target": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookTarget", + "traits": { + "smithy.api#documentation": "

The target that receives the hook event.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for a hook that runs before an invocation begins.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessBeforeToolCallHook": { + "type": "structure", + "members": { + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookName", + "traits": { + "smithy.api#documentation": "

The name of the hook.

", + "smithy.api#required": {} + } + }, + "target": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookTarget", + "traits": { + "smithy.api#documentation": "

The target that receives the hook event.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for a hook that runs before the agent calls a tool.

" + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessBrowserArn": { "type": "string", "traits": { @@ -20426,6 +21444,17 @@ "smithy.api#documentation": "

The environment provider request configuration.

" } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessEventBridgeBusArn": { + "type": "string", + "traits": { + "smithy.api#documentation": "

The ARN of an Amazon EventBridge event bus.

", + "smithy.api#length": { + "min": 20, + "max": 2048 + }, + "smithy.api#pattern": "^arn:aws(-[^:]+)?:events:[a-z0-9-]+:[0-9]{12}:event-bus/.+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessGatewayOutboundAuth": { "type": "union", "members": { @@ -20504,6 +21533,173 @@ "smithy.api#documentation": "

Configuration for a Google Gemini model provider. Requires an API key stored in AgentCore Identity.

" } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHook": { + "type": "union", + "members": { + "beforeInvocation": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessBeforeInvocationHook", + "traits": { + "smithy.api#documentation": "

A hook that runs before an invocation begins.

" + } + }, + "afterInvocation": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessAfterInvocationHook", + "traits": { + "smithy.api#documentation": "

A hook that runs after an invocation completes.

" + } + }, + "beforeToolCall": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessBeforeToolCallHook", + "traits": { + "smithy.api#documentation": "

A hook that runs before the agent calls a tool.

" + } + }, + "afterToolCall": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessAfterToolCallHook", + "traits": { + "smithy.api#documentation": "

A hook that runs after a tool call completes.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

A lifecycle hook configuration. Specify one hook type.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHookEventBridgeTarget": { + "type": "structure", + "members": { + "arn": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessEventBridgeBusArn", + "traits": { + "smithy.api#documentation": "

The ARN of the Amazon EventBridge event bus to send hook events to.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for an Amazon EventBridge hook target.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHookFailureMode": { + "type": "enum", + "members": { + "ALLOW": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

Specifies that the current action continues when the hook target fails.

", + "smithy.api#enumValue": "allow" + } + }, + "DENY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

Specifies that the service denies the current action when the hook target fails.

", + "smithy.api#enumValue": "deny" + } + } + }, + "traits": { + "smithy.api#documentation": "

The behavior when a synchronous hook target fails.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHookLambdaTarget": { + "type": "structure", + "members": { + "arn": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessLambdaFunctionArn", + "traits": { + "smithy.api#documentation": "

The ARN of the Lambda function to invoke.

", + "smithy.api#required": {} + } + }, + "timeoutSeconds": { + "target": "smithy.api#Integer", + "traits": { + "smithy.api#default": 60, + "smithy.api#documentation": "

The maximum number of seconds to wait for the Lambda function response. The default is 60 seconds.

", + "smithy.api#range": { + "min": 1, + "max": 900 + } + } + }, + "failureMode": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookFailureMode", + "traits": { + "smithy.api#default": "deny", + "smithy.api#documentation": "

The behavior when the Lambda function times out, returns an error, or returns an invalid response. The default is DENY.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for an AWS Lambda hook target.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHookName": { + "type": "string", + "traits": { + "smithy.api#documentation": "

The name of a lifecycle hook.

", + "smithy.api#length": { + "min": 1, + "max": 64 + }, + "smithy.api#pattern": "^[a-zA-Z0-9_-]+$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHookSnsTarget": { + "type": "structure", + "members": { + "arn": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessSnsTopicArn", + "traits": { + "smithy.api#documentation": "

The ARN of the Amazon SNS topic to publish hook events to.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The configuration for an Amazon SNS hook target.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHookTarget": { + "type": "union", + "members": { + "lambda": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookLambdaTarget", + "traits": { + "smithy.api#documentation": "

A Lambda hook target that invokes an AWS Lambda function synchronously and waits for its response.

" + } + }, + "sns": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookSnsTarget", + "traits": { + "smithy.api#documentation": "

An Amazon SNS hook target that publishes the hook event without waiting for a response.

" + } + }, + "eventBridge": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHookEventBridgeTarget", + "traits": { + "smithy.api#documentation": "

An Amazon EventBridge hook target that sends the hook event without waiting for a response.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

The target that receives lifecycle hook events. Specify one target type.

" + } + }, + "com.amazonaws.bedrockagentcorecontrol#HarnessHooks": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHook" + }, + "traits": { + "smithy.api#documentation": "

The lifecycle hooks configured to run at defined points in the agent loop.

", + "smithy.api#length": { + "max": 20 + }, + "smithy.api#uniqueItems": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessId": { "type": "string", "traits": { @@ -20542,6 +21738,17 @@ "smithy.api#sensitive": {} } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessLambdaFunctionArn": { + "type": "string", + "traits": { + "smithy.api#documentation": "

The ARN of an AWS Lambda function.

", + "smithy.api#length": { + "min": 20, + "max": 2048 + }, + "smithy.api#pattern": "^arn:aws(-[^:]+)?:lambda:[a-z0-9-]+:[0-9]{12}:function:.+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessLiteLlmApiBase": { "type": "string", "traits": { @@ -20745,6 +21952,16 @@ "smithy.api#pattern": "^[a-zA-Z][a-zA-Z0-9_]{0,39}$" } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessOpenAiApiBase": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 16383 + }, + "smithy.api#sensitive": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessOpenAiApiFormat": { "type": "enum", "members": { @@ -20781,6 +21998,12 @@ "smithy.api#required": {} } }, + "apiBase": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessOpenAiApiBase", + "traits": { + "smithy.api#documentation": "

Optional custom endpoint URL for an OpenAI-compatible endpoint.

" + } + }, "maxTokens": { "target": "com.amazonaws.bedrockagentcorecontrol#MaxTokens", "traits": { @@ -21028,6 +22251,17 @@ "smithy.api#documentation": "

Configuration for sliding window truncation strategy.

" } }, + "com.amazonaws.bedrockagentcorecontrol#HarnessSnsTopicArn": { + "type": "string", + "traits": { + "smithy.api#documentation": "

The ARN of an Amazon SNS topic.

", + "smithy.api#length": { + "min": 20, + "max": 2048 + }, + "smithy.api#pattern": "^arn:aws(-[^:]+)?:sns:[a-z0-9-]+:[0-9]{12}:.+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#HarnessStatus": { "type": "enum", "members": { @@ -23708,6 +24942,92 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagentcorecontrol#ListConsentPortals": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcorecontrol#ListConsentPortalsRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagentcorecontrol#ListConsentPortalsResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#UnauthorizedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ValidationException" + } + ], + "traits": { + "aws.api#controlPlane": {}, + "smithy.api#documentation": "

Lists all of the consent portals in your account.

", + "smithy.api#http": { + "uri": "/identities/ListConsentPortals", + "method": "POST" + }, + "smithy.api#paginated": { + "inputToken": "nextToken", + "outputToken": "nextToken", + "pageSize": "maxResults", + "items": "consentPortals" + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#ListConsentPortalsRequest": { + "type": "structure", + "members": { + "maxResults": { + "target": "smithy.api#Integer", + "traits": { + "smithy.api#documentation": "

The maximum number of consent portals to return in a single call.

", + "smithy.api#range": { + "min": 1, + "max": 100 + } + } + }, + "nextToken": { + "target": "smithy.api#String", + "traits": { + "smithy.api#documentation": "

A token to retrieve the next page of results. Use the value returned in a previous response to request the next page.

" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#ListConsentPortalsResponse": { + "type": "structure", + "members": { + "consentPortals": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSummaries", + "traits": { + "smithy.api#documentation": "

The list of consent portals.

", + "smithy.api#required": {} + } + }, + "nextToken": { + "target": "smithy.api#String", + "traits": { + "smithy.api#documentation": "

The token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#ListDatasetExamples": { "type": "operation", "input": { @@ -25540,7 +26860,7 @@ } ], "traits": { - "smithy.api#documentation": "

Retrieves a list of generated policy assets from a policy generation request within the AgentCore Policy system. This operation returns the actual Cedar policies and related artifacts produced by the AI-powered policy generation process, allowing users to review and select from multiple generated policy options.

", + "smithy.api#documentation": "

Retrieves a list of generated policy assets from a policy generation request within the AgentCore Policy system. This operation returns the actual Dogwood policies and related artifacts produced by the AI-powered policy generation process, allowing users to review and select from multiple generated policy options.

", "smithy.api#http": { "method": "GET", "uri": "/policy-engines/{policyEngineId}/policy-generations/{policyGenerationId}/assets" @@ -25603,7 +26923,7 @@ "policyGenerationAssets": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyGenerationAssets", "traits": { - "smithy.api#documentation": "

An array of generated policy assets including Cedar policies and related artifacts from the AI-powered policy generation process. Each asset represents a different policy option or variation generated from the original natural language input.

" + "smithy.api#documentation": "

An array of generated policy assets including Dogwood policies and related artifacts from the AI-powered policy generation process. Each asset represents a different policy option or variation generated from the original natural language input.

" } }, "nextToken": { @@ -26372,6 +27692,30 @@ "smithy.api#pattern": "^[.\\-_/#A-Za-z0-9]+$" } }, + "com.amazonaws.bedrockagentcorecontrol#LogGroupNamePrefix": { + "type": "string", + "traits": { + "smithy.api#documentation": "Prefix of a CloudWatch Logs log group name.", + "smithy.api#length": { + "min": 1, + "max": 512 + }, + "smithy.api#pattern": "^[.\\-_/#A-Za-z0-9]+$" + } + }, + "com.amazonaws.bedrockagentcorecontrol#LogGroupNamePrefixList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcorecontrol#LogGroupNamePrefix" + }, + "traits": { + "smithy.api#documentation": "List of CloudWatch Logs log group name prefixes to source trace data from.", + "smithy.api#length": { + "min": 1, + "max": 5 + } + } + }, "com.amazonaws.bedrockagentcorecontrol#LogGroupNamesList": { "type": "list", "member": { @@ -26410,6 +27754,12 @@ "traits": { "smithy.api#documentation": "

The streaming configuration for the MCP gateway. This configuration controls whether response streaming is enabled for the gateway.

" } + }, + "disableMcpListToolsPagination": { + "target": "smithy.api#Boolean", + "traits": { + "smithy.api#documentation": "

Specifies whether pagination is disabled for the Model Context Protocol (MCP) tools/list operation. When set to true, the gateway returns the complete list of tools in a single response without a pagination cursor. When set to false or omitted, the gateway returns tools in paginated responses.

" + } } }, "traits": { @@ -26666,7 +28016,7 @@ "mcpToolSchema": { "target": "com.amazonaws.bedrockagentcorecontrol#McpToolSchemaConfiguration", "traits": { - "smithy.api#documentation": "

The tool schema configuration for the MCP server target. Supported only when the credential provider is configured with an authorization code grant type. Dynamic tool discovery/synchronization will be disabled when target is configured with mcpToolSchema.

" + "smithy.api#documentation": "

A static tool list for the MCP server target. It is supported for all credential providers. Dynamic tool discovery/synchronization will be disabled when a target is configured with mcpToolSchema.

" } }, "listingMode": { @@ -27389,6 +28739,17 @@ } } }, + "com.amazonaws.bedrockagentcorecontrol#MetricsNamespace": { + "type": "string", + "traits": { + "smithy.api#documentation": "CloudWatch metrics namespace for evaluation result metrics.", + "smithy.api#length": { + "min": 1, + "max": 255 + }, + "smithy.api#pattern": "^[a-zA-Z0-9._#/:-]+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#MicrosoftOauth2ProviderConfigInput": { "type": "structure", "members": { @@ -28033,6 +29394,15 @@ "smithy.api#documentation": "

OAuth2-specific authorization data, including the authorization URL and user identifier for the authorization session.

" } }, + "com.amazonaws.bedrockagentcorecontrol#OAuth2CredentialProviderArn": { + "type": "string", + "traits": { + "aws.api#arnReference": { + "type": "AWS::BedrockAgentCore::OAuth2CredentialProvider" + }, + "smithy.api#pattern": "^arn:(aws|aws-cn|aws-us-gov|aws-iso|aws-iso-b|aws-iso-e|aws-iso-f|aws-eusc):bedrock-agentcore:[a-z0-9-]{1,32}:[0-9]{12}:token-vault/[a-zA-Z0-9_-]{1,64}/oauth2credentialprovider/[a-zA-Z0-9_-]{1,128}$" + } + }, "com.amazonaws.bedrockagentcorecontrol#OAuthCredentialProvider": { "type": "structure", "members": { @@ -28757,6 +30127,13 @@ "smithy.api#documentation": "

The operating system and CPU architecture for capacity provider instances.

" } }, + "com.amazonaws.bedrockagentcorecontrol#OptionalLogGroupName": { + "type": "string", + "traits": { + "smithy.api#documentation": "A log group name that may also be empty. The empty string is the @default of members that\nwere relaxed from @required, and carries the meaning \"no log group\" for that member.", + "smithy.api#pattern": "^$|^[.\\-_/#A-Za-z0-9]+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#OutputConfig": { "type": "structure", "members": { @@ -28966,7 +30343,12 @@ }, "list": { "target": "com.amazonaws.bedrockagentcorecontrol#ListPaymentConnectors" - } + }, + "operations": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#RotatePaymentConnectorCredentials" + } + ] }, "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorStatus": { "type": "enum", @@ -29075,6 +30457,12 @@ "smithy.api#required": {} } }, + "provisionMode": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorProvisionMode", + "traits": { + "smithy.api#documentation": "

Specifies how the payment connector was provisioned. Payment connectors that were created before this field was available return MANUAL.

" + } + }, "status": { "target": "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorStatus", "traits": { @@ -29552,6 +30940,16 @@ "smithy.api#documentation": "

The permissions configuration for a capacity provider. This specifies the IAM role that AgentCore uses to manage the Amazon EC2 instances for the capacity provider on your behalf.

" } }, + "com.amazonaws.bedrockagentcorecontrol#PlatformVersion": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 128 + }, + "smithy.api#pattern": "^[^\\s]+$" + } + }, "com.amazonaws.bedrockagentcorecontrol#Policies": { "type": "list", "member": { @@ -29626,7 +31024,7 @@ "definition": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyDefinition", "traits": { - "smithy.api#documentation": "

The Cedar policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

", + "smithy.api#documentation": "

The Cedar or Dogwood policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

", "smithy.api#required": {} } }, @@ -29645,7 +31043,7 @@ } }, "traits": { - "smithy.api#documentation": "

Represents a complete policy resource within the AgentCore Policy system. Policies are ARN-able resources that contain Cedar policy statements and associated metadata for controlling agent behavior and access decisions. Each policy belongs to a policy engine and defines fine-grained authorization rules that are evaluated in real-time as agents interact with tools through Gateway. Policies use the Cedar policy language to specify who (principals based on OAuth claims like username, role, or scope) can perform what actions (tool calls) on which resources (Gateways), with optional conditions for attribute-based access control. Multiple policies can apply to a single request, with Cedar's forbid-wins semantics ensuring that security restrictions are never accidentally overridden.

", + "smithy.api#documentation": "

Represents a complete policy resource within the AgentCore Policy system. Policies are ARN-able resources that contain Cedar or Dogwood policy statements and associated metadata for controlling agent behavior and access decisions. Each policy belongs to a policy engine and defines fine-grained authorization rules that are evaluated in real-time as agents interact with tools through Gateway. Policies use Cedar or Dogwood to specify who (principals based on OAuth claims like username, role, or scope) can perform what actions (tool calls) on which resources (Gateways), with optional conditions for attribute-based access control. Multiple policies can apply to a single request, with forbid-wins semantics ensuring that security restrictions are never accidentally overridden.

", "smithy.api#references": [ { "resource": "com.amazonaws.bedrockagentcorecontrol#PolicyEngineResource" @@ -29678,13 +31076,13 @@ "policyGeneration": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyGenerationDetails", "traits": { - "smithy.api#documentation": "

The generated policy asset information within the policy definition structure. This contains information identifying a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Cedar policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" + "smithy.api#documentation": "

The generated policy asset information within the policy definition structure. This contains information identifying a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Dogwood policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" } }, "policy": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyStatement", "traits": { - "smithy.api#documentation": "

An AgentCore policy statement that defines the access control rules. The statement can be a Cedar policy or a guardrails definition.

" + "smithy.api#documentation": "

The Dogwood policy statement that defines the access control rules. This policy definition can include Dogwood policies and supports temporal conditions and information providers such as guardrails.

" } } }, @@ -30018,7 +31416,7 @@ } }, "traits": { - "smithy.api#documentation": "

Represents a policy generation request within the AgentCore Policy system. Tracks the AI-powered conversion of natural language descriptions into Cedar policy statements, enabling users to author policies by describing authorization requirements in plain English. The generation process analyzes the natural language input along with the Gateway's tool context and Cedar schema to produce one or more validated policy options. Each generation request tracks the status of the conversion process and maintains findings about the generated policies, including validation results and potential issues. Generated policy assets remain available for one week after successful generation, allowing time to review and create policies from the generated options.

", + "smithy.api#documentation": "

Represents a policy generation request within the AgentCore Policy system. Tracks the AI-powered conversion of natural language descriptions into Dogwood policy statements, enabling users to author policies by describing authorization requirements in plain English. The generation process analyzes the natural language input along with the Gateway's tool context and Cedar schema to produce one or more validated policy options. Each generation request tracks the status of the conversion process and maintains findings about the generated policies, including validation results and potential issues. Generated policy assets remain available for one week after successful generation, allowing time to review and create policies from the generated options.

", "smithy.api#references": [ { "resource": "com.amazonaws.bedrockagentcorecontrol#PolicyEngineResource" @@ -30055,7 +31453,7 @@ "rawTextFragment": { "target": "com.amazonaws.bedrockagentcorecontrol#NaturalLanguage", "traits": { - "smithy.api#documentation": "

The portion of the original natural language input that this generated policy asset addresses. This helps users understand which part of their policy description was translated into this specific Cedar policy statement, enabling better policy selection and refinement. When a single natural language input describes multiple authorization requirements, the generation process creates separate policy assets for each requirement, with each asset's rawTextFragment showing which requirement it addresses. Use this mapping to verify that all parts of your natural language input were correctly translated into Cedar policies.

", + "smithy.api#documentation": "

The portion of the original natural language input that this generated policy asset addresses. This helps users understand which part of their policy description was translated into this specific Dogwood policy statement, enabling better policy selection and refinement. When a single natural language input describes multiple authorization requirements, the generation process creates separate policy assets for each requirement, with each asset's rawTextFragment showing which requirement it addresses. Use this mapping to verify that all parts of your natural language input were correctly translated into Dogwood policies.

", "smithy.api#required": {} } }, @@ -30068,7 +31466,7 @@ } }, "traits": { - "smithy.api#documentation": "

Represents a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Cedar policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" + "smithy.api#documentation": "

Represents a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Dogwood policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" } }, "com.amazonaws.bedrockagentcorecontrol#PolicyGenerationAssets": { @@ -30096,7 +31494,7 @@ } }, "traits": { - "smithy.api#documentation": "

Represents the information identifying a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Cedar policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" + "smithy.api#documentation": "

Represents the information identifying a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Dogwood policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" } }, "com.amazonaws.bedrockagentcorecontrol#PolicyGenerationName": { @@ -30316,13 +31714,13 @@ "statement": { "target": "com.amazonaws.bedrockagentcorecontrol#Statement", "traits": { - "smithy.api#documentation": "

The body of the AgentCore policy statement. Contains the policy logic, which can be a Cedar policy or a guardrails definition.

", + "smithy.api#documentation": "

The body of the AgentCore Cedar or Dogwood policy statement. Contains the policy logic, which can be a Cedar policy, a temporal policy, or a guardrails definition.

", "smithy.api#required": {} } } }, "traits": { - "smithy.api#documentation": "

An AgentCore policy statement, which supports plain Cedar policies as well as guardrails definitions.

" + "smithy.api#documentation": "

An AgentCore Cedar or Dogwood policy statement, which supports plain Cedar policies, temporal policies, and guardrails definitions.

" } }, "com.amazonaws.bedrockagentcorecontrol#PolicyStatus": { @@ -30479,6 +31877,15 @@ "smithy.api#default": "FAIL_ON_ANY_FINDINGS" } }, + "com.amazonaws.bedrockagentcorecontrol#PortalUrlType": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 2000 + } + } + }, "com.amazonaws.bedrockagentcorecontrol#PrincipalMatchOperator": { "type": "enum", "members": { @@ -31671,6 +33078,26 @@ "target": "com.amazonaws.bedrockagentcorecontrol#RestApiMethod" } }, + "com.amazonaws.bedrockagentcorecontrol#ResultDestination": { + "type": "enum", + "members": { + "DEDICATED_LOG_GROUP": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DEDICATED_LOG_GROUP" + } + }, + "SOURCE_LOG_GROUP": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SOURCE_LOG_GROUP" + } + } + }, + "traits": { + "smithy.api#documentation": "Where evaluation results are written: dedicated results log group (default) or the source log group." + } + }, "com.amazonaws.bedrockagentcorecontrol#RetryableConflictException": { "type": "structure", "members": { @@ -31751,6 +33178,118 @@ "smithy.api#documentation": "

The configuration for the root volume of a capacity provider instance. Specify the amount of free space to guarantee on the root volume. The device name and delete-on-termination settings are fixed and cannot be changed.

" } }, + "com.amazonaws.bedrockagentcorecontrol#RotatePaymentConnectorCredentials": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcorecontrol#RotatePaymentConnectorCredentialsRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagentcorecontrol#RotatePaymentConnectorCredentialsResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ConflictException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ValidationException" + } + ], + "traits": { + "smithy.api#documentation": "

Replaces the service-managed credentials of a payment connector with newly issued credentials.

Use this operation only for payment connectors with a provisionMode of QUICK_CREATE. For payment connectors with a provisionMode of MANUAL, call UpdatePaymentCredentialProvider instead after rotating credentials with the payment provider directly.

The rotation finishes before the response is returned, and only one rotation runs at a time for a given payment connector. When it succeeds, the new credential is in effect and the payment connector stays in the READY state. When it fails, an error is returned, the payment connector and its existing credential are left unchanged, and you can retry the request.

Rotation replaces the credential on the connector's credential provider, so every payment connector that uses that provider is affected. Replace any copy of the previous credential that you use outside AgentCore.

", + "smithy.api#http": { + "code": 202, + "method": "POST", + "uri": "/payments/managers/{paymentManagerId}/connectors/{paymentConnectorId}/rotate-credentials" + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#RotatePaymentConnectorCredentialsRequest": { + "type": "structure", + "members": { + "paymentManagerId": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentManagerId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the parent payment manager.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "paymentConnectorId": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the payment connector whose credentials you want to rotate.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "credentialsToRotate": { + "target": "com.amazonaws.bedrockagentcorecontrol#CredentialRotationConfig", + "traits": { + "smithy.api#documentation": "

The credentials to rotate. Specify the member that matches the payment connector's type. Each credential that you select is rotated independently.

", + "smithy.api#required": {} + } + }, + "clientToken": { + "target": "com.amazonaws.bedrockagentcorecontrol#ClientToken", + "traits": { + "smithy.api#documentation": "

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "smithy.api#idempotencyToken": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#RotatePaymentConnectorCredentialsResponse": { + "type": "structure", + "members": { + "paymentConnectorId": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the payment connector.

", + "smithy.api#required": {} + } + }, + "paymentManagerId": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentManagerId", + "traits": { + "smithy.api#documentation": "

The unique identifier of the parent payment manager.

", + "smithy.api#required": {} + } + }, + "lastUpdatedAt": { + "target": "com.amazonaws.bedrockagentcorecontrol#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The timestamp when the payment connector was last updated, which is when the rotation completed.

", + "smithy.api#required": {} + } + }, + "status": { + "target": "com.amazonaws.bedrockagentcorecontrol#PaymentConnectorStatus", + "traits": { + "smithy.api#documentation": "

The current status of the payment connector, which is READY after a successful rotation.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#RouteToTargetAction": { "type": "union", "members": { @@ -31880,6 +33419,27 @@ "smithy.api#pattern": "^s3://.{1,2043}$" } }, + "com.amazonaws.bedrockagentcorecontrol#S3CertificateConfiguration": { + "type": "structure", + "members": { + "uri": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateS3Uri", + "traits": { + "smithy.api#documentation": "

The URI of the Amazon S3 object that contains the PEM-encoded certificate.

", + "smithy.api#required": {} + } + }, + "bucketOwnerAccountId": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateBucketOwnerAccountId", + "traits": { + "smithy.api#documentation": "

The account ID of the Amazon S3 bucket owner. This ID is used for cross-account access to the bucket.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

A reference to a PEM-encoded private CA certificate stored as an Amazon S3 object.

" + } + }, "com.amazonaws.bedrockagentcorecontrol#S3Configuration": { "type": "structure", "members": { @@ -32337,6 +33897,21 @@ } } }, + "com.amazonaws.bedrockagentcorecontrol#SecretsManagerCertificateConfiguration": { + "type": "structure", + "members": { + "secretArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateSecretArn", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the Amazon Web Services Secrets Manager secret that contains the PEM-encoded certificate.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

A reference to a PEM-encoded private CA certificate stored in an Amazon Web Services Secrets Manager secret.

" + } + }, "com.amazonaws.bedrockagentcorecontrol#SecretsManagerLocation": { "type": "structure", "members": { @@ -33011,7 +34586,7 @@ } ], "traits": { - "smithy.api#documentation": "

Initiates the AI-powered generation of Cedar policies from natural language descriptions within the AgentCore Policy system. This feature enables both technical and non-technical users to create policies by describing their authorization requirements in plain English, which is then automatically translated into formal Cedar policy statements. The generation process analyzes the natural language input along with the Gateway's tool context to produce validated policy options. Generated policy assets are automatically deleted after 7 days, so you should review and create policies from the generated assets within this timeframe. Once created, policies are permanent and not subject to this expiration. Generated policies should be reviewed and tested in log-only mode before deploying to production. Use this when you want to describe policy intent naturally rather than learning Cedar syntax, though generated policies may require refinement for complex scenarios.

", + "smithy.api#documentation": "

Initiates the AI-powered generation of Dogwood policies from natural language descriptions within the AgentCore Policy system. This feature enables both technical and non-technical users to create policies by describing their authorization requirements in plain English, which is then automatically translated into formal Dogwood policy statements. The generation process analyzes the natural language input along with the Gateway's tool context to produce validated policy options. Generated policy assets are automatically deleted after 7 days, so you should review and create policies from the generated assets within this timeframe. Once created, policies are permanent and not subject to this expiration. Generated policies should be reviewed and tested in log-only mode before deploying to production. Use this when you want to describe policy intent naturally rather than learning Dogwood syntax, though generated policies may require refinement for complex scenarios.

", "smithy.api#http": { "method": "POST", "uri": "/policy-engines/{policyEngineId}/policy-generations", @@ -33040,7 +34615,7 @@ "content": { "target": "com.amazonaws.bedrockagentcorecontrol#Content", "traits": { - "smithy.api#documentation": "

The natural language description of the desired policy behavior. This content is processed by AI to generate corresponding Cedar policy statements that match the described intent.

", + "smithy.api#documentation": "

The natural language description of the desired policy behavior. This content is processed by AI to generate corresponding Dogwood policy statements that match the described intent.

", "smithy.api#required": {} } }, @@ -33303,6 +34878,15 @@ } } }, + "com.amazonaws.bedrockagentcorecontrol#StatusReasonType": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 1024 + } + } + }, "com.amazonaws.bedrockagentcorecontrol#StatusReasons": { "type": "list", "member": { @@ -35338,6 +36922,12 @@ "smithy.api#documentation": "

The updated capacity provider configuration for the AgentCore Runtime.

" } }, + "platformVersion": { + "target": "com.amazonaws.bedrockagentcorecontrol#PlatformVersion", + "traits": { + "smithy.api#documentation": "

The updated version of the runtime platform to use for the AgentCore Runtime.

" + } + }, "clientToken": { "target": "com.amazonaws.bedrockagentcorecontrol#ClientToken", "traits": { @@ -35744,7 +37334,8 @@ "parentVersionIds": { "target": "com.amazonaws.bedrockagentcorecontrol#ConfigurationBundleVersionList", "traits": { - "smithy.api#documentation": "

A list of parent version identifiers for lineage tracking. Regular commits have a single parent. Merge commits have two parents: the target branch parent and the source branch parent. If the branch already exists, the first parent must be the latest version on that branch.

" + "smithy.api#documentation": "

A list of parent version identifiers for lineage tracking. Regular commits have a single parent. Merge commits have two parents: the target branch parent and the source branch parent. If the branch already exists, the first parent must be the latest version on that branch.

", + "smithy.api#required": {} } }, "branchName": { @@ -35760,7 +37351,8 @@ "smithy.api#length": { "min": 1, "max": 500 - } + }, + "smithy.api#required": {} } }, "createdBy": { @@ -35816,6 +37408,172 @@ "smithy.api#output": {} } }, + "com.amazonaws.bedrockagentcorecontrol#UpdateConsentPortal": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcorecontrol#UpdateConsentPortalRequest" + }, + "output": { + "target": "com.amazonaws.bedrockagentcorecontrol#UpdateConsentPortalResponse" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcorecontrol#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ConflictException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#InternalServerException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#UnauthorizedException" + }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ValidationException" + } + ], + "traits": { + "aws.api#controlPlane": {}, + "smithy.api#documentation": "

Updates an existing consent portal.

", + "smithy.api#http": { + "code": 202, + "uri": "/identities/UpdateConsentPortal", + "method": "POST" + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#UpdateConsentPortalRequest": { + "type": "structure", + "members": { + "consentPortalIdentifier": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdentifier", + "traits": { + "smithy.api#documentation": "

The identifier of the consent portal. You can specify either the consent portal ID or its Amazon Resource Name (ARN).

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + }, + "executionRoleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the IAM role that the consent portal assumes to access the resources defined in its sources.

" + } + }, + "idpConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig", + "traits": { + "smithy.api#documentation": "

The identity provider configuration that the consent portal uses to authenticate end users.

" + } + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType", + "traits": { + "smithy.api#documentation": "

The description of the consent portal.

" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcorecontrol#UpdateConsentPortalResponse": { + "type": "structure", + "members": { + "sources": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalSources", + "traits": { + "smithy.api#documentation": "

The resources served by the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the consent portal.

", + "smithy.api#required": {} + } + }, + "consentPortalId": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdType", + "traits": { + "smithy.api#documentation": "

The unique identifier of the consent portal.

", + "smithy.api#required": {}, + "smithy.api#resourceIdentifier": "consentPortalId" + } + }, + "createdAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was created.

", + "smithy.api#required": {} + } + }, + "description": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalDescriptionType", + "traits": { + "smithy.api#documentation": "

The description of the consent portal.

" + } + }, + "executionRoleArn": { + "target": "com.amazonaws.bedrockagentcorecontrol#ExecutionRoleArnType", + "traits": { + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the IAM role that the consent portal assumes to access the resources defined in its sources.

", + "smithy.api#required": {} + } + }, + "idpConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalIdpConfig", + "traits": { + "smithy.api#documentation": "

The identity provider configuration that the consent portal uses to authenticate end users.

", + "smithy.api#required": {} + } + }, + "name": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalNameType", + "traits": { + "smithy.api#documentation": "

The name of the consent portal.

", + "smithy.api#required": {} + } + }, + "portalUrl": { + "target": "com.amazonaws.bedrockagentcorecontrol#PortalUrlType", + "traits": { + "smithy.api#documentation": "

The URL used to access the consent portal.

" + } + }, + "status": { + "target": "com.amazonaws.bedrockagentcorecontrol#ConsentPortalStatus", + "traits": { + "smithy.api#documentation": "

The current status of the consent portal.

", + "smithy.api#required": {} + } + }, + "statusReason": { + "target": "com.amazonaws.bedrockagentcorecontrol#StatusReasonType", + "traits": { + "smithy.api#documentation": "

A message that provides additional information about the current status of the consent portal.

" + } + }, + "updatedAt": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp for when the consent portal was last updated.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.bedrockagentcorecontrol#UpdateDataset": { "type": "operation", "input": { @@ -36833,6 +38591,12 @@ "traits": { "smithy.api#documentation": "

The private endpoint configuration for the gateway target. Use this to connect the gateway to private resources in your VPC.

" } + }, + "certificateConfigurations": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList", + "traits": { + "smithy.api#documentation": "

The private certificate authority (CA) configurations for the gateway target. Use this to have the gateway trust a private CA when it establishes TLS connections to the target endpoint. Provide each certificate by reference to an Amazon S3 object or an Amazon Web Services Secrets Manager secret. You can specify only one certificate authority configuration in this list. To remove a previously configured certificate authority, omit this field on update.

" + } } }, "traits": { @@ -36944,6 +38708,12 @@ "traits": { "smithy.api#documentation": "

The protocol type of the updated gateway target.

" } + }, + "certificateConfigurations": { + "target": "com.amazonaws.bedrockagentcorecontrol#CertificateConfigurationList", + "traits": { + "smithy.api#documentation": "

The private certificate authority (CA) configurations for the gateway target.

" + } } }, "traits": { @@ -36971,6 +38741,9 @@ { "target": "com.amazonaws.bedrockagentcorecontrol#ResourceNotFoundException" }, + { + "target": "com.amazonaws.bedrockagentcorecontrol#ServiceQuotaExceededException" + }, { "target": "com.amazonaws.bedrockagentcorecontrol#ThrottlingException" }, @@ -37174,6 +38947,12 @@ "smithy.api#documentation": "

The truncation configuration for managing conversation context. If not specified, the existing value is retained.

" } }, + "hooks": { + "target": "com.amazonaws.bedrockagentcorecontrol#HarnessHooks", + "traits": { + "smithy.api#documentation": "

The lifecycle hooks to run at defined points in the agent loop. If specified, this replaces all existing hooks. If not specified, the existing hooks are retained.

" + } + }, "maxIterations": { "target": "smithy.api#Integer", "traits": { @@ -37597,6 +39376,9 @@ "smithy.api#documentation": "

The updated clustering configuration for periodic batch evaluation.

" } }, + "outputConfig": { + "target": "com.amazonaws.bedrockagentcorecontrol#OutputConfig" + }, "evaluationExecutionRoleArn": { "target": "com.amazonaws.bedrockagentcorecontrol#RoleArn", "traits": { @@ -38306,7 +40088,7 @@ "definition": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyDefinition", "traits": { - "smithy.api#documentation": "

The new Cedar policy statement that defines the access control rules. This replaces the existing policy definition with new logic while maintaining the policy's identity.

" + "smithy.api#documentation": "

The new Cedar or Dogwood policy statement that defines the access control rules. This replaces the existing policy definition with new logic while maintaining the policy's identity.

" } }, "validationMode": { @@ -38395,7 +40177,7 @@ "definition": { "target": "com.amazonaws.bedrockagentcorecontrol#PolicyDefinition", "traits": { - "smithy.api#documentation": "

The updated Cedar policy statement.

", + "smithy.api#documentation": "

The updated Cedar or Dogwood policy statement.

", "smithy.api#required": {} } }, diff --git a/codegen/aws-models/bedrock-agentcore.json b/codegen/aws-models/bedrock-agentcore.json index e53a5553..deca2bc9 100644 --- a/codegen/aws-models/bedrock-agentcore.json +++ b/codegen/aws-models/bedrock-agentcore.json @@ -2575,6 +2575,12 @@ "traits": { "smithy.api#documentation": "

The time range filter for selecting sessions to evaluate.

" } + }, + "sessionTraceIds": { + "target": "com.amazonaws.bedrockagentcore#SessionTraceIdsList", + "traits": { + "smithy.api#documentation": "

A list of session and trace ID pairs that restrict evaluation to specific traces within a session. If specified, only the listed traces are evaluated instead of the entire session.

" + } } }, "traits": { @@ -2706,14 +2712,24 @@ } }, "logGroupNames": { - "target": "com.amazonaws.bedrockagentcore#EvaluationStringList", + "target": "com.amazonaws.bedrockagentcore#LogGroupNameList", + "traits": { + "smithy.api#addedDefault": {}, + "smithy.api#default": [], + "smithy.api#documentation": "

The list of CloudWatch log group names to read agent traces from. Maximum of 10 log groups.

", + "smithy.api#length": { + "max": 10 + } + } + }, + "logGroupNamePrefixes": { + "target": "com.amazonaws.bedrockagentcore#LogGroupNamePrefixList", "traits": { - "smithy.api#documentation": "

The list of CloudWatch log group names to read agent traces from. Maximum of 5 log groups.

", + "smithy.api#documentation": "

The list of CloudWatch log group name prefixes to read agent traces from. Specify this instead of logGroupNames to match log groups by prefix. Maximum of 5 prefixes. Specify either logGroupNames or logGroupNamePrefixes, not both. One of the two is required.

", "smithy.api#length": { "min": 1, "max": 5 - }, - "smithy.api#required": {} + } } }, "filterConfig": { @@ -2779,17 +2795,32 @@ "type": "structure", "members": { "logGroupName": { - "target": "smithy.api#String", + "target": "com.amazonaws.bedrockagentcore#OptionalLogGroupName", "traits": { - "smithy.api#documentation": "

The name of the CloudWatch log group where evaluation results will be written.

", - "smithy.api#required": {} + "smithy.api#addedDefault": {}, + "smithy.api#default": "", + "smithy.api#documentation": "

The name of the CloudWatch log group where evaluation results will be written. This value doesn't apply when resultDestination is SOURCE_LOG_GROUP, because results are written back to the trace source log group. The name can't be under the service-reserved /aws/bedrock-agentcore/evaluations/ namespace, apart from the service-managed default group.

" } }, "logStreamName": { - "target": "smithy.api#String", + "target": "com.amazonaws.bedrockagentcore#LogStreamName", "traits": { - "smithy.api#documentation": "

The name of the CloudWatch log stream where evaluation results will be written.

", - "smithy.api#required": {} + "smithy.api#addedDefault": {}, + "smithy.api#default": "", + "smithy.api#documentation": "

The name of the CloudWatch log stream where evaluation results will be written.

" + } + }, + "metricsNamespace": { + "target": "com.amazonaws.bedrockagentcore#MetricsNamespace", + "traits": { + "smithy.api#documentation": "

The CloudWatch metrics namespace where evaluation result metrics are published. If you omit this value, the service publishes metrics to Bedrock-AgentCore/Evaluations. This value can't begin with AWS/.

" + } + }, + "resultDestination": { + "target": "com.amazonaws.bedrockagentcore#ResultDestination", + "traits": { + "smithy.api#default": "DEDICATED_LOG_GROUP", + "smithy.api#documentation": "

The destination where evaluation results are written. Valid values:

" } } }, @@ -3364,6 +3395,20 @@ "smithy.api#documentation": "

An event that contains incremental output from a command execution. This event streams standard output and standard error content as it becomes available during command execution.

" } }, + "com.amazonaws.bedrockagentcore#ContentSource": { + "type": "union", + "members": { + "inline": { + "target": "com.amazonaws.bedrockagentcore#InlineMemoryContent", + "traits": { + "smithy.api#documentation": "

The content included directly in the request.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

The source of the content to ingest. Only inline content is supported.

" + } + }, "com.amazonaws.bedrockagentcore#ContentStartEvent": { "type": "structure", "members": {}, @@ -8684,6 +8729,112 @@ "smithy.api#documentation": "

Configuration for a Google Gemini model provider. Requires an API key stored in AgentCore Identity.

" } }, + "com.amazonaws.bedrockagentcore#HarnessHookDecision": { + "type": "enum", + "members": { + "ALLOW": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "allow" + } + }, + "DENY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "deny" + } + } + } + }, + "com.amazonaws.bedrockagentcore#HarnessHookEvent": { + "type": "structure", + "members": { + "hookEventId": { + "target": "com.amazonaws.bedrockagentcore#HarnessHookEventId", + "traits": { + "smithy.api#documentation": "

The unique identifier for this hook event.

", + "smithy.api#required": {} + } + }, + "name": { + "target": "com.amazonaws.bedrockagentcore#HarnessHookName", + "traits": { + "smithy.api#documentation": "

The name of the hook that ran.

", + "smithy.api#required": {} + } + }, + "type": { + "target": "com.amazonaws.bedrockagentcore#HarnessHookEventType", + "traits": { + "smithy.api#documentation": "

The type of lifecycle hook event.

", + "smithy.api#required": {} + } + }, + "decision": { + "target": "com.amazonaws.bedrockagentcore#HarnessHookDecision", + "traits": { + "smithy.api#documentation": "

The decision applied to the hook event. This field is present only for blocking Lambda targets.

" + } + }, + "reason": { + "target": "smithy.api#String", + "traits": { + "smithy.api#documentation": "

The optional reason for the applied decision.

", + "smithy.api#length": { + "max": 1024 + } + } + } + }, + "traits": { + "smithy.api#documentation": "

A lifecycle hook event emitted in the invocation stream for visibility into hook decisions.

" + } + }, + "com.amazonaws.bedrockagentcore#HarnessHookEventId": { + "type": "string", + "traits": { + "smithy.api#pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" + } + }, + "com.amazonaws.bedrockagentcore#HarnessHookEventType": { + "type": "enum", + "members": { + "BEFORE_TOOL_CALL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "before_tool_call" + } + }, + "AFTER_TOOL_CALL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "after_tool_call" + } + }, + "BEFORE_INVOCATION": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "before_invocation" + } + }, + "AFTER_INVOCATION": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "after_invocation" + } + } + } + }, + "com.amazonaws.bedrockagentcore#HarnessHookName": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 64 + }, + "smithy.api#pattern": "^[a-zA-Z0-9_-]+$" + } + }, "com.amazonaws.bedrockagentcore#HarnessInlineFunctionConfig": { "type": "structure", "members": { @@ -8889,6 +9040,16 @@ "smithy.api#documentation": "

Specification of which model to use.

" } }, + "com.amazonaws.bedrockagentcore#HarnessOpenAiApiBase": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 16383 + }, + "smithy.api#sensitive": {} + } + }, "com.amazonaws.bedrockagentcore#HarnessOpenAiApiFormat": { "type": "enum", "members": { @@ -8925,6 +9086,12 @@ "smithy.api#required": {} } }, + "apiBase": { + "target": "com.amazonaws.bedrockagentcore#HarnessOpenAiApiBase", + "traits": { + "smithy.api#documentation": "

Optional custom endpoint URL for an OpenAI-compatible endpoint.

" + } + }, "maxTokens": { "target": "com.amazonaws.bedrockagentcore#MaxTokens", "traits": { @@ -9291,6 +9458,12 @@ "traits": { "smithy.api#enumValue": "timeout_exceeded" } + }, + "HOOK_STOPPED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "hook_stopped" + } } } }, @@ -9829,6 +10002,153 @@ } } }, + "com.amazonaws.bedrockagentcore#IngestData": { + "type": "operation", + "input": { + "target": "com.amazonaws.bedrockagentcore#IngestDataInput" + }, + "output": { + "target": "com.amazonaws.bedrockagentcore#IngestDataOutput" + }, + "errors": [ + { + "target": "com.amazonaws.bedrockagentcore#AccessDeniedException" + }, + { + "target": "com.amazonaws.bedrockagentcore#ResourceNotFoundException" + }, + { + "target": "com.amazonaws.bedrockagentcore#ServiceException" + }, + { + "target": "com.amazonaws.bedrockagentcore#ServiceQuotaExceededException" + }, + { + "target": "com.amazonaws.bedrockagentcore#ThrottledException" + }, + { + "target": "com.amazonaws.bedrockagentcore#ValidationException" + } + ], + "traits": { + "smithy.api#documentation": "

Submits content directly for ingestion to generate long-term memory records in a AgentCore Memory resource.

To use this operation, you must have the bedrock-agentcore:IngestData permission.

", + "smithy.api#http": { + "code": 202, + "method": "POST", + "uri": "/memories/{memoryId}/ingest" + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.bedrockagentcore#IngestDataInput": { + "type": "structure", + "members": { + "memoryId": { + "target": "com.amazonaws.bedrockagentcore#MemoryId", + "traits": { + "smithy.api#documentation": "

The identifier of the AgentCore Memory resource to ingest content into.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "source": { + "target": "com.amazonaws.bedrockagentcore#ContentSource", + "traits": { + "smithy.api#documentation": "

The content to ingest. Only inline content is supported.

", + "smithy.api#required": {} + } + }, + "contentTimestamp": { + "target": "smithy.api#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp of when the content occurred.

", + "smithy.api#required": {} + } + }, + "actorId": { + "target": "com.amazonaws.bedrockagentcore#ActorId", + "traits": { + "smithy.api#documentation": "

The identifier of the actor associated with this content. An actor represents an entity that participates in sessions and generates content.

", + "smithy.api#required": {} + } + }, + "sessionId": { + "target": "com.amazonaws.bedrockagentcore#SessionId", + "traits": { + "smithy.api#documentation": "

The identifier of the session that the content belongs to. If not provided, a session identifier is generated and returned in the response.

" + } + }, + "extractionConfig": { + "target": "com.amazonaws.bedrockagentcore#ExtractionConfig", + "traits": { + "smithy.api#documentation": "

The extraction configuration for long-term memory records. Use this parameter to specify namespace variable keys and their values for namespace substitution during extraction.

" + } + }, + "metadata": { + "target": "com.amazonaws.bedrockagentcore#MetadataMap", + "traits": { + "smithy.api#documentation": "

The key-value metadata to attach to the content.

" + } + }, + "clientToken": { + "target": "smithy.api#String", + "traits": { + "smithy.api#documentation": "

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, AgentCore ignores the request, but does not return an error.

", + "smithy.api#idempotencyToken": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.bedrockagentcore#IngestDataOutput": { + "type": "structure", + "members": { + "sessionId": { + "target": "com.amazonaws.bedrockagentcore#SessionId", + "traits": { + "smithy.api#documentation": "

The identifier of the session that the service ingested the content into. This value echoes the session identifier from the request, or the identifier that the service generated when you did not provide one.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.bedrockagentcore#IngestPayloadList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcore#IngestPayloadType" + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 100 + } + } + }, + "com.amazonaws.bedrockagentcore#IngestPayloadType": { + "type": "union", + "members": { + "conversational": { + "target": "com.amazonaws.bedrockagentcore#Conversational", + "traits": { + "smithy.api#documentation": "

The conversational content for this payload item.

" + } + }, + "json": { + "target": "com.amazonaws.bedrockagentcore#MemoryJsonData", + "traits": { + "smithy.api#documentation": "

The JSON content for this payload item.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

A single content payload item to ingest. A payload item contains either conversational or JSON content.

" + } + }, "com.amazonaws.bedrockagentcore#InlineContent": { "type": "string", "traits": { @@ -9867,6 +10187,21 @@ "smithy.api#documentation": "

Inline ground truth data containing assertions, expected trajectories, and per-turn expected responses.

" } }, + "com.amazonaws.bedrockagentcore#InlineMemoryContent": { + "type": "structure", + "members": { + "payload": { + "target": "com.amazonaws.bedrockagentcore#IngestPayloadList", + "traits": { + "smithy.api#documentation": "

The list of content payload items to ingest.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

The content included directly in the request as one or more payload items.

" + } + }, "com.amazonaws.bedrockagentcore#InputContentBlock": { "type": "structure", "members": { @@ -11234,6 +11569,12 @@ "traits": { "smithy.api#documentation": "

An error returned by the runtime container during agent execution.

" } + }, + "hookEvent": { + "target": "com.amazonaws.bedrockagentcore#HarnessHookEvent", + "traits": { + "smithy.api#documentation": "

A lifecycle hook event emitted when a configured hook runs.

" + } } }, "traits": { @@ -12802,6 +13143,52 @@ "target": "smithy.api#String" } }, + "com.amazonaws.bedrockagentcore#LogGroupName": { + "type": "string", + "traits": { + "smithy.api#pattern": "^[.\\-_/#A-Za-z0-9]+$" + } + }, + "com.amazonaws.bedrockagentcore#LogGroupNameList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcore#LogGroupName" + }, + "traits": { + "smithy.api#documentation": "Length is constrained per member, because members relaxed from @required carry @default([])." + } + }, + "com.amazonaws.bedrockagentcore#LogGroupNamePrefix": { + "type": "string", + "traits": { + "smithy.api#documentation": "Prefix of a CloudWatch Logs log group name.", + "smithy.api#length": { + "min": 1, + "max": 512 + }, + "smithy.api#pattern": "^[.\\-_/#A-Za-z0-9]+$" + } + }, + "com.amazonaws.bedrockagentcore#LogGroupNamePrefixList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcore#LogGroupNamePrefix" + }, + "traits": { + "smithy.api#documentation": "List of CloudWatch Logs log group name prefixes to source trace data from.", + "smithy.api#length": { + "min": 1, + "max": 5 + } + } + }, + "com.amazonaws.bedrockagentcore#LogStreamName": { + "type": "string", + "traits": { + "smithy.api#documentation": "A log stream name. The pattern is CloudWatch Logs' own log stream name pattern, which already\nadmits the empty string; empty is the @default of members relaxed from @required and means\n\"no log stream\". No @length is applied, because CloudWatch's min of 1 would reject that default.", + "smithy.api#pattern": "^[^:*]*$" + } + }, "com.amazonaws.bedrockagentcore#MaxLenString": { "type": "string", "traits": { @@ -13448,6 +13835,9 @@ { "target": "com.amazonaws.bedrockagentcore#GetMemoryRecord" }, + { + "target": "com.amazonaws.bedrockagentcore#IngestData" + }, { "target": "com.amazonaws.bedrockagentcore#ListActors" }, @@ -13559,6 +13949,17 @@ "smithy.api#documentation": "

Value associated with the eventMetadata key.

" } }, + "com.amazonaws.bedrockagentcore#MetricsNamespace": { + "type": "string", + "traits": { + "smithy.api#documentation": "CloudWatch metrics namespace for evaluation result metrics.", + "smithy.api#length": { + "min": 1, + "max": 255 + }, + "smithy.api#pattern": "^[a-zA-Z0-9._#/:-]+$" + } + }, "com.amazonaws.bedrockagentcore#MimeType": { "type": "string", "traits": { @@ -14278,6 +14679,13 @@ } } }, + "com.amazonaws.bedrockagentcore#OptionalLogGroupName": { + "type": "string", + "traits": { + "smithy.api#documentation": "A log group name that may also be empty. The empty string is the @default of members that\nwere relaxed from @required, and carries the meaning \"no log group\" for that member.", + "smithy.api#pattern": "^$|^[.\\-_/#A-Za-z0-9]+$" + } + }, "com.amazonaws.bedrockagentcore#OutputConfig": { "type": "union", "members": { @@ -15983,6 +16391,26 @@ "smithy.api#streaming": {} } }, + "com.amazonaws.bedrockagentcore#ResultDestination": { + "type": "enum", + "members": { + "DEDICATED_LOG_GROUP": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DEDICATED_LOG_GROUP" + } + }, + "SOURCE_LOG_GROUP": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SOURCE_LOG_GROUP" + } + } + }, + "traits": { + "smithy.api#documentation": "Where evaluation results are written: dedicated results log group (default) or the source log group." + } + }, "com.amazonaws.bedrockagentcore#RetrieveMemoryRecords": { "type": "operation", "input": { @@ -16953,6 +17381,40 @@ "target": "com.amazonaws.bedrockagentcore#SessionSummary" } }, + "com.amazonaws.bedrockagentcore#SessionTraceIds": { + "type": "structure", + "members": { + "sessionId": { + "target": "smithy.api#String", + "traits": { + "smithy.api#documentation": "

The unique identifier of the session that contains the traces to evaluate.

", + "smithy.api#required": {} + } + }, + "traceIds": { + "target": "com.amazonaws.bedrockagentcore#TraceIdList", + "traits": { + "smithy.api#documentation": "

The list of trace IDs within the session to evaluate.

", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

A pairing of a session with the specific trace IDs to evaluate within that session. Use this to evaluate individual traces rather than an entire session.

" + } + }, + "com.amazonaws.bedrockagentcore#SessionTraceIdsList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcore#SessionTraceIds" + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 500 + } + } + }, "com.amazonaws.bedrockagentcore#SessionType": { "type": "string", "traits": { @@ -17166,6 +17628,9 @@ "traits": { "smithy.api#documentation": "

The description of the batch evaluation.

" } + }, + "outputConfig": { + "target": "com.amazonaws.bedrockagentcore#OutputConfig" } }, "traits": { @@ -19298,6 +19763,18 @@ } } }, + "com.amazonaws.bedrockagentcore#TraceIdList": { + "type": "list", + "member": { + "target": "com.amazonaws.bedrockagentcore#TraceId" + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 100 + } + } + }, "com.amazonaws.bedrockagentcore#TraceIds": { "type": "list", "member": { diff --git a/codegen/aws-models/bedrock.json b/codegen/aws-models/bedrock.json index e0725b87..d951e361 100644 --- a/codegen/aws-models/bedrock.json +++ b/codegen/aws-models/bedrock.json @@ -3368,7 +3368,7 @@ "min": 1, "max": 64 }, - "smithy.api#pattern": "^[A-Za-z][A-Za-z0-9_]*$", + "smithy.api#pattern": "^\\p{L}[\\p{L}\\p{M}0-9_]*( [\\p{L}\\p{M}0-9_]+)*$", "smithy.api#sensitive": {} } }, @@ -3434,7 +3434,7 @@ "min": 1, "max": 64 }, - "smithy.api#pattern": "^[A-Za-z][A-Za-z0-9_]*$" + "smithy.api#pattern": "^\\p{L}[\\p{L}\\p{M}0-9_]*( [\\p{L}\\p{M}0-9_]+)*$" } }, "com.amazonaws.bedrock#AutomatedReasoningPolicyDefinitionTypeValuePair": { @@ -3529,7 +3529,7 @@ "min": 1, "max": 64 }, - "smithy.api#pattern": "^[A-Za-z][A-Za-z0-9_]*$", + "smithy.api#pattern": "^\\p{L}[\\p{L}\\p{M}0-9_]*( [\\p{L}\\p{M}0-9_]+)*$", "smithy.api#sensitive": {} } }, @@ -8256,6 +8256,12 @@ "smithy.api#enumValue": "none" } }, + "AWS_REVIEW": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "aws_review" + } + }, "PROVIDER_DATA_SHARE": { "target": "smithy.api#Unit", "traits": { @@ -8270,7 +8276,7 @@ } }, "traits": { - "smithy.api#documentation": "

The data retention mode for the account. Valid values are:

" + "smithy.api#documentation": "

The data retention mode for the account. Valid values are:

" } }, "com.amazonaws.bedrock#DataRetentionResource": { diff --git a/codegen/aws-models/cloudtrail.json b/codegen/aws-models/cloudtrail.json index 14e1d9e7..b83a3dca 100644 --- a/codegen/aws-models/cloudtrail.json +++ b/codegen/aws-models/cloudtrail.json @@ -420,7 +420,7 @@ } ], "traits": { - "smithy.api#documentation": "

Cancels a query if the query is not in a terminated state, such as\n CANCELLED, FAILED, TIMED_OUT, or\n FINISHED. You must specify an ARN value for EventDataStore.\n The ID of the query that you want to cancel is also required. When you run\n CancelQuery, the query status might show as CANCELLED even if\n the operation is not yet finished.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Cancels a query if the query is not in a terminated state, such as\n CANCELLED, FAILED, TIMED_OUT, or\n FINISHED. You must specify an ARN value for EventDataStore.\n The ID of the query that you want to cancel is also required. When you run\n CancelQuery, the query status might show as CANCELLED even if\n the operation is not yet finished.

", "smithy.api#idempotent": {} } }, @@ -2263,7 +2263,7 @@ } ], "traits": { - "smithy.api#documentation": "

Creates a channel for CloudTrail to ingest events from a partner or external source. \n After you create a channel, a CloudTrail Lake event data store can log events \n from the partner or source that you specify.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Creates a channel for CloudTrail to ingest events from a partner or external source. \n After you create a channel, a CloudTrail Lake event data store can log events \n from the partner or source that you specify.

" } }, "com.amazonaws.cloudtrail#CreateChannelRequest": { @@ -2368,7 +2368,7 @@ } ], "traits": { - "smithy.api#documentation": "

\nCreates a custom dashboard or the Highlights dashboard.\n

\n \n

\n CloudTrail runs queries to populate the dashboard's widgets during a manual or scheduled refresh. CloudTrail must be granted permissions to run the StartQuery operation on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to each event data store. For more information, \n see Example: Allow CloudTrail to run queries to populate a dashboard in the CloudTrail User Guide.\n

\n

\n To set a refresh schedule, CloudTrail must be granted permissions to run the StartDashboardRefresh operation to refresh the dashboard on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to the dashboard. For more information, \n see \n Resource-based policy example for a dashboard in the CloudTrail User Guide.\n

\n

For more information about dashboards, see CloudTrail Lake dashboards in the CloudTrail User Guide.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\nCreates a custom dashboard or the Highlights dashboard.\n

\n \n

\n CloudTrail runs queries to populate the dashboard's widgets during a manual or scheduled refresh. CloudTrail must be granted permissions to run the StartQuery operation on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to each event data store. For more information, \n see Example: Allow CloudTrail to run queries to populate a dashboard in the CloudTrail User Guide.\n

\n

\n To set a refresh schedule, CloudTrail must be granted permissions to run the StartDashboardRefresh operation to refresh the dashboard on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to the dashboard. For more information, \n see \n Resource-based policy example for a dashboard in the CloudTrail User Guide.\n

\n

For more information about dashboards, see CloudTrail Lake dashboards in the CloudTrail User Guide.

", "smithy.api#idempotent": {} } }, @@ -2523,7 +2523,7 @@ } ], "traits": { - "smithy.api#documentation": "

Creates a new event data store.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Creates a new event data store.

" } }, "com.amazonaws.cloudtrail#CreateEventDataStoreRequest": { @@ -2821,7 +2821,7 @@ "IncludeGlobalServiceEvents": { "target": "com.amazonaws.cloudtrail#Boolean", "traits": { - "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the\n log files.

" + "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the\n log files. Setting this value to true only delivers global service events to\n the trail if the trail is multi-Region or if the trail's home Region is the partition leader\n Region (for example, us-east-1).

" } }, "IsMultiRegionTrail": { @@ -2862,6 +2862,12 @@ }, "TagsList": { "target": "com.amazonaws.cloudtrail#TagsList" + }, + "RecursiveLogging": { + "target": "com.amazonaws.cloudtrail#Boolean", + "traits": { + "smithy.api#documentation": "

Specifies whether recursive logging is enabled for the trail. If you set\n RecursiveLogging to false, CloudTrail suppresses\n events generated by CloudTrail when it delivers log files to your trail's\n destinations, including Amazon S3 and CloudWatch Logs. The default value is\n true.

" + } } }, "traits": { @@ -2906,7 +2912,7 @@ "IncludeGlobalServiceEvents": { "target": "com.amazonaws.cloudtrail#Boolean", "traits": { - "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the\n log files.

" + "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the\n log files. Setting this value to true only delivers global service events to\n the trail if the trail is multi-Region or if the trail's home Region is the partition leader\n Region (for example, us-east-1).

" } }, "IsMultiRegionTrail": { @@ -2950,6 +2956,12 @@ "traits": { "smithy.api#documentation": "

Specifies whether the trail is an organization trail.

" } + }, + "RecursiveLogging": { + "target": "com.amazonaws.cloudtrail#Boolean", + "traits": { + "smithy.api#documentation": "

Specifies whether recursive logging is enabled for the trail.

" + } } }, "traits": { @@ -3129,7 +3141,7 @@ } ], "traits": { - "smithy.api#documentation": "

Deletes a channel.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Deletes a channel.

" } }, "com.amazonaws.cloudtrail#DeleteChannelRequest": { @@ -3174,7 +3186,7 @@ } ], "traits": { - "smithy.api#documentation": "

\nDeletes the specified dashboard. You cannot delete a dashboard that has termination protection enabled.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\nDeletes the specified dashboard. You cannot delete a dashboard that has termination protection enabled.\n

", "smithy.api#idempotent": {} } }, @@ -3253,7 +3265,7 @@ } ], "traits": { - "smithy.api#documentation": "

Disables the event data store specified by EventDataStore, which accepts an\n event data store ARN. After you run DeleteEventDataStore, the event data store\n enters a PENDING_DELETION state, and is automatically deleted after a wait\n period of seven days. TerminationProtectionEnabled must be set to\n False on the event data store and the FederationStatus must be DISABLED. \n You cannot delete an event data store if TerminationProtectionEnabled \n is True or the FederationStatus is ENABLED.

\n

After you run DeleteEventDataStore on an event data store, you cannot run\n ListQueries, DescribeQuery, or GetQueryResults on\n queries that are using an event data store in a PENDING_DELETION state. An\n event data store in the PENDING_DELETION state does not incur costs.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Disables the event data store specified by EventDataStore, which accepts an\n event data store ARN. After you run DeleteEventDataStore, the event data store\n enters a PENDING_DELETION state, and is automatically deleted after a wait\n period of seven days. TerminationProtectionEnabled must be set to\n False on the event data store and the FederationStatus must be DISABLED. \n You cannot delete an event data store if TerminationProtectionEnabled \n is True or the FederationStatus is ENABLED.

\n

After you run DeleteEventDataStore on an event data store, you cannot run\n ListQueries, DescribeQuery, or GetQueryResults on\n queries that are using an event data store in a PENDING_DELETION state. An\n event data store in the PENDING_DELETION state does not incur costs.

" } }, "com.amazonaws.cloudtrail#DeleteEventDataStoreRequest": { @@ -3584,7 +3596,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns metadata about a query, including query run time in milliseconds, number of\n events scanned and matched, and query status. If the query results were delivered to an S3 bucket, \n the response also provides the S3 URI and the delivery status.

\n

You must specify either QueryId or QueryAlias. Specifying the QueryAlias parameter \n returns information about the last query run for the alias. You can provide \n RefreshId along with QueryAlias to view the query results \n of a dashboard query for the specified RefreshId.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns metadata about a query, including query run time in milliseconds, number of\n events scanned and matched, and query status. If the query results were delivered to an S3 bucket, \n the response also provides the S3 URI and the delivery status.

\n

You must specify either QueryId or QueryAlias. Specifying the QueryAlias parameter \n returns information about the last query run for the alias. You can provide \n RefreshId along with QueryAlias to view the query results \n of a dashboard query for the specified RefreshId.

", "smithy.api#idempotent": {} } }, @@ -3874,7 +3886,7 @@ } ], "traits": { - "smithy.api#documentation": "

\n Disables Lake query federation on the specified event data store. When you disable federation, CloudTrail disables \n the integration with Glue, Lake Formation, and Amazon Athena. \n After disabling Lake query federation, you can no longer query your event data in Amazon Athena.

\n

No CloudTrail Lake data is deleted when you disable federation and you can continue to run queries in CloudTrail Lake.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\n Disables Lake query federation on the specified event data store. When you disable federation, CloudTrail disables \n the integration with Glue, Lake Formation, and Amazon Athena. \n After disabling Lake query federation, you can no longer query your event data in Amazon Athena.

\n

No CloudTrail Lake data is deleted when you disable federation and you can continue to run queries in CloudTrail Lake.

" } }, "com.amazonaws.cloudtrail#DisableFederationRequest": { @@ -3971,7 +3983,7 @@ } ], "traits": { - "smithy.api#documentation": "

\n Enables Lake query federation on the specified event data store. Federating an event data store lets you view the metadata associated with the event data store in the Glue \n Data Catalog and run \n SQL queries against your event data using Amazon Athena. The table metadata stored in the Glue Data Catalog \n lets the Athena query engine know how to find, read, and process the data that you want to query.

\n

When you enable Lake query federation, CloudTrail\n creates a managed database named aws:cloudtrail (if the database doesn't already exist) and a managed federated table in\n the Glue Data Catalog. The event data store ID is used for the table name. CloudTrail registers the role ARN and event data store in\n Lake Formation, the service responsible for allowing fine-grained access control \n of the federated resources in the Glue Data Catalog.

\n

For more information about Lake query federation, see Federate an event data store.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\n Enables Lake query federation on the specified event data store. Federating an event data store lets you view the metadata associated with the event data store in the Glue \n Data Catalog and run \n SQL queries against your event data using Amazon Athena. The table metadata stored in the Glue Data Catalog \n lets the Athena query engine know how to find, read, and process the data that you want to query.

\n

When you enable Lake query federation, CloudTrail\n creates a managed database named aws:cloudtrail (if the database doesn't already exist) and a managed federated table in\n the Glue Data Catalog. The event data store ID is used for the table name. CloudTrail registers the role ARN and event data store in\n Lake Formation, the service responsible for allowing fine-grained access control \n of the federated resources in the Glue Data Catalog.

\n

For more information about Lake query federation, see Federate an event data store.

" } }, "com.amazonaws.cloudtrail#EnableFederationRequest": { @@ -4594,7 +4606,7 @@ } ], "traits": { - "smithy.api#documentation": "

\n Generates a query from a natural language prompt. This operation uses generative artificial intelligence\n (generative AI) to produce a ready-to-use SQL query from the prompt.\n

\n

The prompt can be a question or a statement about the event data\n in your event data store. For example, you can enter prompts like \"What are my\n top errors in the past month?\" and “Give me a list of users that used SNS.”

\n

The prompt must be in English. For information about limitations, permissions, and supported Regions, see \n Create CloudTrail Lake queries from natural language prompts \n in the CloudTrail user guide.

\n \n

Do not include any personally identifying, confidential, or sensitive information\n in your prompts.

\n

This feature uses generative AI large language models (LLMs); we recommend double-checking the\n LLM response.

\n
", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\n Generates a query from a natural language prompt. This operation uses generative artificial intelligence\n (generative AI) to produce a ready-to-use SQL query from the prompt.\n

\n

The prompt can be a question or a statement about the event data\n in your event data store. For example, you can enter prompts like \"What are my\n top errors in the past month?\" and “Give me a list of users that used SNS.”

\n

The prompt must be in English. For information about limitations, permissions, and supported Regions, see \n Create CloudTrail Lake queries from natural language prompts \n in the CloudTrail user guide.

\n \n

Do not include any personally identifying, confidential, or sensitive information\n in your prompts.

\n

This feature uses generative AI large language models (LLMs); we recommend double-checking the\n LLM response.

\n
", "smithy.api#idempotent": {} } }, @@ -4689,7 +4701,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns information about a specific channel.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns information about a specific channel.\n

", "smithy.api#idempotent": {} } }, @@ -4769,7 +4781,7 @@ } ], "traits": { - "smithy.api#documentation": "

\nReturns the specified dashboard.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\nReturns the specified dashboard.\n

", "smithy.api#idempotent": {} } }, @@ -4994,7 +5006,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns information about an event data store specified as either an ARN or the ID\n portion of the ARN.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns information about an event data store specified as either an ARN or the ID\n portion of the ARN.

", "smithy.api#idempotent": {} } }, @@ -5208,7 +5220,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns information about a specific import.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns information about a specific import.

" } }, "com.amazonaws.cloudtrail#GetImportRequest": { @@ -5429,7 +5441,7 @@ } ], "traits": { - "smithy.api#documentation": "

Gets event data results of a query. You must specify the QueryID value\n returned by the StartQuery operation.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Gets event data results of a query. You must specify the QueryID value\n returned by the StartQuery operation.

", "smithy.api#paginated": { "inputToken": "NextToken", "outputToken": "NextToken" @@ -6929,7 +6941,7 @@ } ], "traits": { - "smithy.api#documentation": "

Lists the channels in the current account, and their source names. \n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Lists the channels in the current account, and their source names. \n

", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -7001,7 +7013,7 @@ } ], "traits": { - "smithy.api#documentation": "

\n Returns information about all dashboards in the account, in the current Region.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\n Returns information about all dashboards in the account, in the current Region.\n

", "smithy.api#idempotent": {} } }, @@ -7092,7 +7104,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns information about all event data stores in the account, in the current\n Region.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns information about all event data stores in the account, in the current\n Region.

", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -7173,7 +7185,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns a list of failures for the specified import.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns a list of failures for the specified import.

", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -7265,7 +7277,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns information on all imports, or a select set of imports by\n ImportStatus or Destination.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns information on all imports, or a select set of imports by\n ImportStatus or Destination.

", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -7356,7 +7368,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns Insights events generated on a trail that logs data events. You can list Insights events that occurred in a Region within the last 90 days.

\n

ListInsightsData supports the following Dimensions for Insights events:

\n \n

All dimensions are optional. The default number of results returned is 50, with a\n maximum of 50 possible. The response includes a token that you can use to get the next page\n of results.

\n

The rate of ListInsightsData requests is limited to two per second, per account, per Region. If\n this limit is exceeded, a throttling error occurs.

", + "smithy.api#documentation": "

Returns Insights events generated on a trail that logs data events. You can list Insights events that occurred in a Region within the last 90 days.

\n

ListInsightsData supports the following Dimensions for Insights events:

\n \n

All dimensions are optional. The default number of results returned is 50, with a\n maximum of 50 possible. The response includes a token that you can use to get the next page\n of results.

\n

The rate of ListInsightsData requests is limited to two per second, per account, per Region. If\n this limit is exceeded, a throttling error occurs.

\n \n

For data event Insights on organization trails, only the management account and delegated\n administrator accounts can call ListInsightsData. For these callers, the API returns\n Insights events only for the caller's own account. Member accounts cannot call this API on\n organization trails.

\n
", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -7528,7 +7540,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns Insights metrics data for trails that have enabled Insights. The request must include the EventSource, \n EventName, and InsightType parameters.

\n

If the InsightType is set to ApiErrorRateInsight, the request must also include the ErrorCode parameter.

\n

The following are the available time periods for ListInsightsMetricData. Each cutoff is inclusive.

\n \n

To use ListInsightsMetricData operation, you must have the following permissions:

\n ", + "smithy.api#documentation": "

Returns Insights metrics data for trails that have enabled Insights. The request must include the EventSource, \n EventName, and InsightType parameters.

\n

If the InsightType is set to ApiErrorRateInsight, the request must also include the ErrorCode parameter.

\n

The following are the available time periods for ListInsightsMetricData. Each cutoff is inclusive.

\n \n

To use ListInsightsMetricData operation, you must have the following permissions:

\n \n \n

For data event Insights on organization trails, only the management account and delegated\n administrator accounts can call ListInsightsMetricData. For these callers, the API returns\n Insights metrics only for the caller's own account. Member accounts cannot call this API on\n organization trails.

\n
", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -7794,7 +7806,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns a list of queries and query statuses for the past seven days. You must specify\n an ARN value for EventDataStore. Optionally, to shorten the list of results,\n you can specify a time range, formatted as timestamps, by adding StartTime and\n EndTime parameters, and a QueryStatus value. Valid values for\n QueryStatus include QUEUED, RUNNING,\n FINISHED, FAILED, TIMED_OUT, or\n CANCELLED.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Returns a list of queries and query statuses for the past seven days. You must specify\n an ARN value for EventDataStore. Optionally, to shorten the list of results,\n you can specify a time range, formatted as timestamps, by adding StartTime and\n EndTime parameters, and a QueryStatus value. Valid values for\n QueryStatus include QUEUED, RUNNING,\n FINISHED, FAILED, TIMED_OUT, or\n CANCELLED.

", "smithy.api#idempotent": {}, "smithy.api#paginated": { "inputToken": "NextToken", @@ -8863,6 +8875,9 @@ { "target": "com.amazonaws.cloudtrail#CloudTrailARNInvalidException" }, + { + "target": "com.amazonaws.cloudtrail#ConflictException" + }, { "target": "com.amazonaws.cloudtrail#InsufficientEncryptionPolicyException" }, @@ -9870,7 +9885,7 @@ } ], "traits": { - "smithy.api#documentation": "

Restores a deleted event data store specified by EventDataStore, which\n accepts an event data store ARN. You can only restore a deleted event data store within the\n seven-day wait period after deletion. Restoring an event data store can take several\n minutes, depending on the size of the event data store.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Restores a deleted event data store specified by EventDataStore, which\n accepts an event data store ARN. You can only restore a deleted event data store within the\n seven-day wait period after deletion. Restoring an event data store can take several\n minutes, depending on the size of the event data store.

" } }, "com.amazonaws.cloudtrail#RestoreEventDataStoreRequest": { @@ -10061,7 +10076,7 @@ } ], "traits": { - "smithy.api#documentation": "

\n Searches sample queries and returns a list of sample queries that are sorted by relevance. \n To search for sample queries, provide a natural language SearchPhrase in English.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\n Searches sample queries and returns a list of sample queries that are sorted by relevance. \n To search for sample queries, provide a natural language SearchPhrase in English.\n

", "smithy.api#idempotent": {} } }, @@ -10289,7 +10304,7 @@ } ], "traits": { - "smithy.api#documentation": "

\nStarts a refresh of the specified dashboard.\n

\n

\n Each time a dashboard is refreshed, CloudTrail runs queries to populate the dashboard's widgets. CloudTrail must be granted permissions to run the StartQuery operation on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to each event data store. For more information, \n see Example: Allow CloudTrail to run queries to populate a dashboard in the CloudTrail User Guide.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\nStarts a refresh of the specified dashboard.\n

\n

\n Each time a dashboard is refreshed, CloudTrail runs queries to populate the dashboard's widgets. CloudTrail must be granted permissions to run the StartQuery operation on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to each event data store. For more information, \n see Example: Allow CloudTrail to run queries to populate a dashboard in the CloudTrail User Guide.\n

", "smithy.api#idempotent": {} } }, @@ -10372,7 +10387,7 @@ } ], "traits": { - "smithy.api#documentation": "

Starts the ingestion of live events on an event data store specified as either an ARN or the ID portion of the ARN. To start ingestion, the event data store Status must be STOPPED_INGESTION \n and the eventCategory must be Management, Data, NetworkActivity, or ConfigurationItem.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Starts the ingestion of live events on an event data store specified as either an ARN or the ID portion of the ARN. To start ingestion, the event data store Status must be STOPPED_INGESTION \n and the eventCategory must be Management, Data, NetworkActivity, or ConfigurationItem.

" } }, "com.amazonaws.cloudtrail#StartEventDataStoreIngestionRequest": { @@ -10444,7 +10459,7 @@ } ], "traits": { - "smithy.api#documentation": "

Starts an import of logged trail events from a source S3 bucket to a destination event\n data store. By default, CloudTrail only imports events contained in the S3 bucket's\n CloudTrail prefix and the prefixes inside the CloudTrail prefix, and does not check prefixes for other Amazon Web Services\n services. If you want to import CloudTrail events contained in another prefix, you\n must include the prefix in the S3LocationUri. For more considerations about\n importing trail events, see Considerations for copying trail events in the CloudTrail User Guide.

\n

When you start a new import, the Destinations and\n ImportSource parameters are required. Before starting a new import, disable\n any access control lists (ACLs) attached to the source S3 bucket. For more information\n about disabling ACLs, see Controlling ownership of\n objects and disabling ACLs for your bucket.

\n

When you retry an import, the ImportID parameter is required.

\n \n

If the destination event data store is for an organization, you must use the\n management account to import trail events. You cannot use the delegated administrator\n account for the organization.

\n
" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Starts an import of logged trail events from a source S3 bucket to a destination event\n data store. By default, CloudTrail only imports events contained in the S3 bucket's\n CloudTrail prefix and the prefixes inside the CloudTrail prefix, and does not check prefixes for other Amazon Web Services\n services. If you want to import CloudTrail events contained in another prefix, you\n must include the prefix in the S3LocationUri. For more considerations about\n importing trail events, see Considerations for copying trail events in the CloudTrail User Guide.

\n

When you start a new import, the Destinations and\n ImportSource parameters are required. Before starting a new import, disable\n any access control lists (ACLs) attached to the source S3 bucket. For more information\n about disabling ACLs, see Controlling ownership of\n objects and disabling ACLs for your bucket.

\n

When you retry an import, the ImportID parameter is required.

\n \n

If the destination event data store is for an organization, you must use the\n management account to import trail events. You cannot use the delegated administrator\n account for the organization.

\n
" } }, "com.amazonaws.cloudtrail#StartImportRequest": { @@ -10666,7 +10681,7 @@ } ], "traits": { - "smithy.api#documentation": "

Starts a CloudTrail Lake query. Use the QueryStatement\n parameter to provide your SQL query, enclosed in single quotation marks. Use the optional\n DeliveryS3Uri parameter to deliver the query results to an S3\n bucket.

\n

\n StartQuery requires you specify either the QueryStatement parameter, or a QueryAlias and any QueryParameters. In the current release, \n the QueryAlias and QueryParameters parameters are used only for the queries that populate the CloudTrail Lake dashboards.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Starts a CloudTrail Lake query. Use the QueryStatement\n parameter to provide your SQL query, enclosed in single quotation marks. Use the optional\n DeliveryS3Uri parameter to deliver the query results to an S3\n bucket.

\n

\n StartQuery requires you specify either the QueryStatement parameter, or a QueryAlias and any QueryParameters. In the current release, \n the QueryAlias and QueryParameters parameters are used only for the queries that populate the CloudTrail Lake dashboards.

", "smithy.api#idempotent": {} } }, @@ -10772,7 +10787,7 @@ } ], "traits": { - "smithy.api#documentation": "

Stops the ingestion of live events on an event data store specified as either an ARN or the ID portion of the ARN. To stop ingestion, the event data store Status must be ENABLED \n and the eventCategory must be Management, Data, NetworkActivity, or ConfigurationItem.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Stops the ingestion of live events on an event data store specified as either an ARN or the ID portion of the ARN. To stop ingestion, the event data store Status must be ENABLED \n and the eventCategory must be Management, Data, NetworkActivity, or ConfigurationItem.

" } }, "com.amazonaws.cloudtrail#StopEventDataStoreIngestionRequest": { @@ -10820,7 +10835,7 @@ } ], "traits": { - "smithy.api#documentation": "

Stops a specified import.

" + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Stops a specified import.

" } }, "com.amazonaws.cloudtrail#StopImportRequest": { @@ -11157,7 +11172,7 @@ "IncludeGlobalServiceEvents": { "target": "com.amazonaws.cloudtrail#Boolean", "traits": { - "smithy.api#documentation": "

Set to True to include Amazon Web Services API calls\n from Amazon Web Services global services such as IAM. Otherwise, False.

" + "smithy.api#documentation": "

Set to True to include Amazon Web Services API calls\n from Amazon Web Services global services such as IAM. Otherwise, False. Setting this value to true only delivers\n global service events to the trail if the trail is multi-Region or if the trail's home\n Region is the partition leader Region (for example, us-east-1).

" } }, "IsMultiRegionTrail": { @@ -11219,6 +11234,12 @@ "traits": { "smithy.api#documentation": "

Specifies whether the trail is an organization trail.

" } + }, + "RecursiveLogging": { + "target": "com.amazonaws.cloudtrail#Boolean", + "traits": { + "smithy.api#documentation": "

Specifies whether recursive logging is enabled for the trail. If you set\n RecursiveLogging to false, CloudTrail suppresses\n events generated by CloudTrail when it delivers log files to your trail's\n destinations, including Amazon S3 and CloudWatch Logs. The default value is\n true.

" + } } }, "traits": { @@ -11417,7 +11438,7 @@ } ], "traits": { - "smithy.api#documentation": "

Updates a channel specified by a required channel ARN or UUID.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Updates a channel specified by a required channel ARN or UUID.

", "smithy.api#idempotent": {} } }, @@ -11515,7 +11536,7 @@ } ], "traits": { - "smithy.api#documentation": "

\nUpdates the specified dashboard.\n

\n

\n To set a refresh schedule, CloudTrail must be granted permissions to run the StartDashboardRefresh operation to refresh the dashboard on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to the dashboard. For more information, \n see \n Resource-based policy example for a dashboard in the CloudTrail User Guide.\n

\n

\n CloudTrail runs queries to populate the dashboard's widgets during a manual or scheduled refresh. CloudTrail must be granted permissions to run the StartQuery operation on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to each event data store. For more information, \n see Example: Allow CloudTrail to run queries to populate a dashboard in the CloudTrail User Guide.\n

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

\nUpdates the specified dashboard.\n

\n

\n To set a refresh schedule, CloudTrail must be granted permissions to run the StartDashboardRefresh operation to refresh the dashboard on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to the dashboard. For more information, \n see \n Resource-based policy example for a dashboard in the CloudTrail User Guide.\n

\n

\n CloudTrail runs queries to populate the dashboard's widgets during a manual or scheduled refresh. CloudTrail must be granted permissions to run the StartQuery operation on your behalf. To provide permissions, run the PutResourcePolicy operation to attach a resource-based policy to each event data store. For more information, \n see Example: Allow CloudTrail to run queries to populate a dashboard in the CloudTrail User Guide.\n

", "smithy.api#idempotent": {} } }, @@ -11685,7 +11706,7 @@ } ], "traits": { - "smithy.api#documentation": "

Updates an event data store. The required EventDataStore value is an ARN or\n the ID portion of the ARN. Other parameters are optional, but at least one optional\n parameter must be specified, or CloudTrail throws an error.\n RetentionPeriod is in days, and valid values are integers between 7 and\n 3653 if the BillingMode is set to EXTENDABLE_RETENTION_PRICING, or between 7 and 2557 if BillingMode is set to FIXED_RETENTION_PRICING. By default, TerminationProtection is enabled.

\n

For event data stores for CloudTrail events, AdvancedEventSelectors\n includes or excludes management, data, or network activity events in your event data store. For more\n information about AdvancedEventSelectors, see AdvancedEventSelectors.

\n

For event data stores for CloudTrail Insights events, Config configuration items, Audit Manager evidence, or non-Amazon Web Services events,\n AdvancedEventSelectors includes events of that type in your event data store.

", + "smithy.api#documentation": "\n

CloudTrail Lake will no longer be open to new customers starting May 31, 2026. If you would like to use CloudTrail Lake, sign up prior to that date. Existing customers can continue to use the service as normal. For more information, see CloudTrail Lake availability change.

\n
\n

Updates an event data store. The required EventDataStore value is an ARN or\n the ID portion of the ARN. Other parameters are optional, but at least one optional\n parameter must be specified, or CloudTrail throws an error.\n RetentionPeriod is in days, and valid values are integers between 7 and\n 3653 if the BillingMode is set to EXTENDABLE_RETENTION_PRICING, or between 7 and 2557 if BillingMode is set to FIXED_RETENTION_PRICING. By default, TerminationProtection is enabled.

\n

For event data stores for CloudTrail events, AdvancedEventSelectors\n includes or excludes management, data, or network activity events in your event data store. For more\n information about AdvancedEventSelectors, see AdvancedEventSelectors.

\n

For event data stores for CloudTrail Insights events, Config configuration items, Audit Manager evidence, or non-Amazon Web Services events,\n AdvancedEventSelectors includes events of that type in your event data store.

", "smithy.api#idempotent": {} } }, @@ -11989,7 +12010,7 @@ "IncludeGlobalServiceEvents": { "target": "com.amazonaws.cloudtrail#Boolean", "traits": { - "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the log files.

" + "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the log files. Setting this value to true only delivers\n global service events to the trail if the trail is multi-Region or if the trail's home\n Region is the partition leader Region (for example, us-east-1).

" } }, "IsMultiRegionTrail": { @@ -12027,6 +12048,12 @@ "traits": { "smithy.api#documentation": "

Specifies whether the trail is applied to all accounts in an organization in Organizations, or only for the current Amazon Web Services account. The default is false,\n and cannot be true unless the call is made on behalf of an Amazon Web Services account that\n is the management account for an organization in Organizations. If the trail is not an organization trail and this is set to\n true, the trail will be created in all Amazon Web Services accounts that\n belong to the organization. If the trail is an organization trail and this is set to\n false, the trail will remain in the current Amazon Web Services account but\n be deleted from all member accounts in the organization.

\n \n

Only the management account for the organization can convert an organization trail to a non-organization trail, or convert a non-organization trail to \n an organization trail.

\n
" } + }, + "RecursiveLogging": { + "target": "com.amazonaws.cloudtrail#Boolean", + "traits": { + "smithy.api#documentation": "

Specifies whether recursive logging is enabled for the trail. If you set\n RecursiveLogging to false, CloudTrail suppresses\n events generated by CloudTrail when it delivers log files to your trail's\n destinations, including Amazon S3 and CloudWatch Logs. The default value is\n true.

" + } } }, "traits": { @@ -12071,7 +12098,7 @@ "IncludeGlobalServiceEvents": { "target": "com.amazonaws.cloudtrail#Boolean", "traits": { - "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the log files.

" + "smithy.api#documentation": "

Specifies whether the trail is publishing events from global services such as IAM to the log files. Setting this value to true only delivers\n global service events to the trail if the trail is multi-Region or if the trail's home\n Region is the partition leader Region (for example, us-east-1).

" } }, "IsMultiRegionTrail": { @@ -12115,6 +12142,12 @@ "traits": { "smithy.api#documentation": "

Specifies whether the trail is an organization trail.

" } + }, + "RecursiveLogging": { + "target": "com.amazonaws.cloudtrail#Boolean", + "traits": { + "smithy.api#documentation": "

Specifies whether recursive logging is enabled for the trail.

" + } } }, "traits": { diff --git a/codegen/aws-models/connecthealth.json b/codegen/aws-models/connecthealth.json index 0ac15140..08f71c02 100644 --- a/codegen/aws-models/connecthealth.json +++ b/codegen/aws-models/connecthealth.json @@ -2338,6 +2338,12 @@ "traits": { "smithy.api#enumValue": "en-US" } + }, + "MULTI": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "multi" + } } } }, @@ -2905,13 +2911,6 @@ "smithy.api#pattern": "[a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}" } }, - "com.amazonaws.connecthealth#SensitiveAlphanumericString": { - "type": "string", - "traits": { - "smithy.api#pattern": "^[a-zA-Z0-9]+$", - "smithy.api#sensitive": {} - } - }, "com.amazonaws.connecthealth#SensitiveIsoDateString": { "type": "string", "traits": { @@ -2933,6 +2932,13 @@ "smithy.api#sensitive": {} } }, + "com.amazonaws.connecthealth#SensitiveSectionHeaderString": { + "type": "string", + "traits": { + "smithy.api#pattern": "^[a-zA-Z0-9_]+$", + "smithy.api#sensitive": {} + } + }, "com.amazonaws.connecthealth#ServiceQuotaExceededException": { "type": "structure", "members": { @@ -3476,7 +3482,7 @@ "type": "structure", "members": { "sectionHeader": { - "target": "com.amazonaws.connecthealth#SensitiveAlphanumericString", + "target": "com.amazonaws.connecthealth#SensitiveSectionHeaderString", "traits": { "smithy.api#documentation": "

The header for this section of the template

", "smithy.api#required": {} diff --git a/codegen/aws-models/dynamodb.json b/codegen/aws-models/dynamodb.json index c1ba160f..8e6049a6 100644 --- a/codegen/aws-models/dynamodb.json +++ b/codegen/aws-models/dynamodb.json @@ -4698,8 +4698,8 @@ "authSchemes": [ { "signingRegion": "us-east-1", - "name": "sigv4", - "signingName": "dynamodb" + "signingName": "dynamodb", + "name": "sigv4" } ] }, @@ -5290,8 +5290,8 @@ "authSchemes": [ { "signingRegion": "us-east-1", - "name": "sigv4", - "signingName": "dynamodb" + "signingName": "dynamodb", + "name": "sigv4" } ] }, @@ -22431,6 +22431,12 @@ "traits": { "smithy.api#documentation": "

Optional object containing the parameters specific to an incremental export.

" } + }, + "FilterSpecification": { + "target": "com.amazonaws.dynamodb#FilterSpecification", + "traits": { + "smithy.api#documentation": "

The filter criteria applied to the export. When present, only items that match the\n specified key conditions and filter expressions are included in the export\n output.

" + } } }, "traits": { @@ -22642,6 +22648,12 @@ "traits": { "smithy.api#documentation": "

Optional object containing the parameters specific to an incremental export.

" } + }, + "FilterSpecification": { + "target": "com.amazonaws.dynamodb#FilterSpecification", + "traits": { + "smithy.api#documentation": "

The criteria used to filter which items are included in the point-in-time export.\n When you specify this parameter, only items that match the key conditions and filter\n expressions are exported.

" + } } }, "traits": { @@ -22761,6 +22773,44 @@ "target": "com.amazonaws.dynamodb#Condition" } }, + "com.amazonaws.dynamodb#FilterSpecification": { + "type": "structure", + "members": { + "FilterExpression": { + "target": "com.amazonaws.dynamodb#ConditionExpression", + "traits": { + "smithy.api#documentation": "

A condition that filters which items are included in the export. This parameter\n uses the same syntax as FilterExpression in Query and\n Scan. If you don't provide KeyConditionExpression, this\n expression can also reference key attributes. If you don't specify this parameter,\n all items are included in the export.

" + } + }, + "ProjectionExpression": { + "target": "com.amazonaws.dynamodb#ProjectionExpression", + "traits": { + "smithy.api#documentation": "

The attributes you want to retrieve for items included in the export. Separate\n attribute names in the expression with commas. If you don't specify this parameter,\n all attributes are returned.

" + } + }, + "KeyConditionExpression": { + "target": "com.amazonaws.dynamodb#KeyExpression", + "traits": { + "smithy.api#documentation": "

A condition expression that filters items by key values. The expression must test\n equality on a single partition key value and can optionally compare a sort key value.\n This parameter uses the same syntax as KeyConditionExpression in\n Query. When you provide this parameter, FilterExpression\n can only reference non-key attributes. If you don't specify this parameter, all items\n are eligible for export.

" + } + }, + "ExpressionAttributeNames": { + "target": "com.amazonaws.dynamodb#ExpressionAttributeNameMap", + "traits": { + "smithy.api#documentation": "

One or more substitution tokens for attribute names in an expression. For more\n information, see Expression Attribute Names in the Amazon DynamoDB Developer Guide.

" + } + }, + "ExpressionAttributeValues": { + "target": "com.amazonaws.dynamodb#ExpressionAttributeValueMap", + "traits": { + "smithy.api#documentation": "

One or more values that can be substituted in an expression. For more information,\n see Expression Attribute Values in the Amazon DynamoDB Developer Guide.

" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains the filter criteria used to limit which items are included in an export.\n If you don't include this parameter, all items and attributes are exported.

" + } + }, "com.amazonaws.dynamodb#Get": { "type": "structure", "members": { diff --git a/codegen/aws-models/guardduty.json b/codegen/aws-models/guardduty.json index 1e282a2b..1a39b9a6 100644 --- a/codegen/aws-models/guardduty.json +++ b/codegen/aws-models/guardduty.json @@ -496,6 +496,58 @@ "smithy.api#documentation": "

Contains information about actions.

" } }, + "com.amazonaws.guardduty#Activities": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#Activity" + }, + "traits": { + "smithy.api#documentation": "

A list of activities that were observed for a signal.

", + "smithy.api#length": { + "min": 0, + "max": 100 + } + } + }, + "com.amazonaws.guardduty#Activity": { + "type": "structure", + "members": { + "Type": { + "target": "com.amazonaws.guardduty#ActivityType", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The type of the observed activity.

", + "smithy.api#jsonName": "type", + "smithy.api#required": {} + } + }, + "Api": { + "target": "com.amazonaws.guardduty#ApiCall", + "traits": { + "smithy.api#documentation": "

Contains information about the API call that was observed, when the activity type is API_CALL.

", + "smithy.api#jsonName": "api" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains information about an activity, such as an API call, that was observed for a signal.

" + } + }, + "com.amazonaws.guardduty#ActivityType": { + "type": "enum", + "members": { + "API_CALL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

The observed activity is an API call.

", + "smithy.api#enumValue": "API_CALL" + } + } + }, + "traits": { + "smithy.api#documentation": "

The type of an observed activity.

" + } + }, "com.amazonaws.guardduty#Actor": { "type": "structure", "members": { @@ -857,6 +909,58 @@ "target": "com.amazonaws.guardduty#AnomalyObject" } }, + "com.amazonaws.guardduty#ApiCall": { + "type": "structure", + "members": { + "Operation": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The name of the API operation that was invoked.

", + "smithy.api#jsonName": "operation", + "smithy.api#length": { + "min": 0, + "max": 512 + } + } + }, + "Service": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The service that the API operation was invoked against.

", + "smithy.api#jsonName": "service", + "smithy.api#length": { + "min": 0, + "max": 512 + } + } + }, + "Error": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The error code that was returned, if the API call failed.

", + "smithy.api#jsonName": "error", + "smithy.api#length": { + "min": 0, + "max": 512 + } + } + }, + "UserAgent": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

User agent in the request to the API operation

", + "smithy.api#jsonName": "userAgent", + "smithy.api#length": { + "min": 0, + "max": 1024 + } + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains information about an API call that was observed as part of an activity.

" + } + }, "com.amazonaws.guardduty#ArchiveFindings": { "type": "operation", "input": { @@ -914,6 +1018,186 @@ "smithy.api#output": {} } }, + "com.amazonaws.guardduty#AssociationDetail": { + "type": "structure", + "members": { + "AssociationId": { + "target": "com.amazonaws.guardduty#AssociationId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the association.

", + "smithy.api#jsonName": "associationId", + "smithy.api#required": {} + } + }, + "Arn": { + "target": "com.amazonaws.guardduty#DetectionRuleArn", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the association.

", + "smithy.api#jsonName": "arn", + "smithy.api#required": {} + } + }, + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#jsonName": "ruleId", + "smithy.api#required": {} + } + }, + "AccountId": { + "target": "com.amazonaws.guardduty#AccountId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Web Services account ID associated with this rule association.

", + "smithy.api#jsonName": "accountId", + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The rule execution mode. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} + } + }, + "CreatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the association was created.

", + "smithy.api#jsonName": "createdAt", + "smithy.api#required": {} + } + }, + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the association was last updated.

", + "smithy.api#jsonName": "updatedAt", + "smithy.api#required": {} + } + }, + "ExpiresAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp when the association expires.

", + "smithy.api#jsonName": "expiresAt" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains the full details of a custom detection rule association.

" + } + }, + "com.amazonaws.guardduty#AssociationId": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 64 + }, + "smithy.api#pattern": "^[a-zA-Z0-9_-]{1,64}$" + } + }, + "com.amazonaws.guardduty#AssociationMode": { + "type": "enum", + "members": { + "LIVE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "LIVE" + } + }, + "DRY_RUN": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DRY_RUN" + } + } + } + }, + "com.amazonaws.guardduty#AssociationSummary": { + "type": "structure", + "members": { + "AssociationId": { + "target": "com.amazonaws.guardduty#AssociationId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the association.

", + "smithy.api#jsonName": "associationId", + "smithy.api#required": {} + } + }, + "Arn": { + "target": "com.amazonaws.guardduty#DetectionRuleArn", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the association.

", + "smithy.api#jsonName": "arn", + "smithy.api#required": {} + } + }, + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#jsonName": "ruleId", + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The rule execution mode. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} + } + }, + "CreatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the association was created.

", + "smithy.api#jsonName": "createdAt", + "smithy.api#required": {} + } + }, + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the association was last updated.

", + "smithy.api#jsonName": "updatedAt", + "smithy.api#required": {} + } + }, + "ExpiresAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp when the association expires.

", + "smithy.api#jsonName": "expiresAt" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains summary information about a custom detection rule association.

" + } + }, + "com.amazonaws.guardduty#AssociationSummaryList": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#AssociationSummary" + } + }, "com.amazonaws.guardduty#AutoEnableMembers": { "type": "enum", "members": { @@ -1173,6 +1457,40 @@ "smithy.api#documentation": "

Contains information about the Bedrock guardrail that was involved in a finding.

" } }, + "com.amazonaws.guardduty#BedrockGuardrailResource": { + "type": "structure", + "members": { + "Version": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The version of the Amazon Bedrock guardrail. Valid values are a numeric version, DRAFT, or ENFORCED.

", + "smithy.api#jsonName": "version", + "smithy.api#length": { + "min": 1, + "max": 8 + }, + "smithy.api#pattern": "^(([1-9][0-9]{0,7})|(DRAFT)|(ENFORCED))$" + } + }, + "GuardrailAction": { + "target": "com.amazonaws.guardduty#GuardrailAction", + "traits": { + "smithy.api#documentation": "

Indicates whether the guardrail intervened during the model invocation.

", + "smithy.api#jsonName": "guardrailAction" + } + }, + "GuardrailSource": { + "target": "com.amazonaws.guardduty#GuardrailSource", + "traits": { + "smithy.api#documentation": "

Indicates whether the guardrail was applied on the input or output of the model invocation.

", + "smithy.api#jsonName": "guardrailSource" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains details about an Amazon Bedrock guardrail evaluated during a model invocation.

" + } + }, "com.amazonaws.guardduty#BedrockGuardrails": { "type": "list", "member": { @@ -2440,48 +2758,229 @@ } } }, - "com.amazonaws.guardduty#CreateDetector": { + "com.amazonaws.guardduty#CreateCustomDetectionRuleAssociation": { "type": "operation", "input": { - "target": "com.amazonaws.guardduty#CreateDetectorRequest" + "target": "com.amazonaws.guardduty#CreateCustomDetectionRuleAssociationRequest" }, "output": { - "target": "com.amazonaws.guardduty#CreateDetectorResponse" + "target": "com.amazonaws.guardduty#CreateCustomDetectionRuleAssociationResponse" }, "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, { "target": "com.amazonaws.guardduty#BadRequestException" }, + { + "target": "com.amazonaws.guardduty#ConflictException" + }, { "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" } ], "traits": { - "smithy.api#documentation": "

Creates a single GuardDuty detector. A detector is a resource that represents the GuardDuty service. To start using GuardDuty, you must create a detector in each Region where you enable the service. You can have only one detector per account per Region. All data sources are enabled in a new detector by default.

Specifying both EKS Runtime Monitoring (EKS_RUNTIME_MONITORING) and Runtime Monitoring (RUNTIME_MONITORING) will cause an error. You can add only one of these two features because Runtime Monitoring already includes the threat detection for Amazon EKS resources. For more information, see Runtime Monitoring.

There might be regional differences because some data sources might not be available in all the Amazon Web Services Regions where GuardDuty is presently supported. For more information, see Regions and endpoints.

", + "smithy.api#documentation": "

Enables a custom detection rule for your account by creating an association. You specify the rule and the mode in which it operates.

", "smithy.api#http": { "method": "POST", - "uri": "/detector", + "uri": "/custom-detection-rule/association", "code": 200 } } }, - "com.amazonaws.guardduty#CreateDetectorRequest": { + "com.amazonaws.guardduty#CreateCustomDetectionRuleAssociationRequest": { "type": "structure", "members": { - "Enable": { - "target": "com.amazonaws.guardduty#Boolean", + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", "traits": { "smithy.api#clientOptional": {}, - "smithy.api#documentation": "

A Boolean value that specifies whether the detector is to be enabled.

", - "smithy.api#jsonName": "enable", + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#jsonName": "ruleId", "smithy.api#required": {} } }, - "ClientToken": { - "target": "com.amazonaws.guardduty#ClientToken", + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", "traits": { - "smithy.api#documentation": "

The idempotency token for the create request.

", - "smithy.api#idempotencyToken": {}, + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The rule execution mode. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} + } + }, + "ClientToken": { + "target": "com.amazonaws.guardduty#ClientToken", + "traits": { + "smithy.api#documentation": "

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. Maximum 64 characters.

", + "smithy.api#idempotencyToken": {}, + "smithy.api#jsonName": "clientToken" + } + }, + "Tags": { + "target": "com.amazonaws.guardduty#TagMap", + "traits": { + "smithy.api#documentation": "

The tags to be added to the new custom detection rule association resource.

", + "smithy.api#jsonName": "tags" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#CreateCustomDetectionRuleAssociationResponse": { + "type": "structure", + "members": { + "RuleAssociation": { + "target": "com.amazonaws.guardduty#AssociationDetail", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The details of the newly created custom detection rule association.

", + "smithy.api#jsonName": "ruleAssociation", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#CreateCustomDetectionRuleOrgConfiguration": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#CreateCustomDetectionRuleOrgConfigurationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#CreateCustomDetectionRuleOrgConfigurationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#ConflictException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Creates an organization-level configuration that enables a custom detection rule across your organization. This operation is available only to the delegated administrator account.

", + "smithy.api#http": { + "method": "POST", + "uri": "/custom-detection-rule/org-configuration", + "code": 200 + } + } + }, + "com.amazonaws.guardduty#CreateCustomDetectionRuleOrgConfigurationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#jsonName": "ruleId", + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} + } + }, + "IncludeAccountIds": { + "target": "com.amazonaws.guardduty#DetectionRuleAccountIds", + "traits": { + "smithy.api#documentation": "

The account IDs to include in the organization configuration. Mutually exclusive with ExcludeAccountIds.

", + "smithy.api#jsonName": "includeAccountIds" + } + }, + "ExcludeAccountIds": { + "target": "com.amazonaws.guardduty#DetectionRuleAccountIds", + "traits": { + "smithy.api#documentation": "

The account IDs to exclude from the organization configuration. Mutually exclusive with IncludeAccountIds.

", + "smithy.api#jsonName": "excludeAccountIds" + } + }, + "ClientToken": { + "target": "com.amazonaws.guardduty#ClientToken", + "traits": { + "smithy.api#documentation": "

A unique, case-sensitive identifier to ensure that the operation completes no more than one time.

", + "smithy.api#idempotencyToken": {}, + "smithy.api#jsonName": "clientToken" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#CreateCustomDetectionRuleOrgConfigurationResponse": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#CreateDetector": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#CreateDetectorRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#CreateDetectorResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + } + ], + "traits": { + "smithy.api#documentation": "

Creates a single GuardDuty detector. A detector is a resource that represents the GuardDuty service. To start using GuardDuty, you must create a detector in each Region where you enable the service. You can have only one detector per account per Region. All data sources are enabled in a new detector by default.

Specifying both EKS Runtime Monitoring (EKS_RUNTIME_MONITORING) and Runtime Monitoring (RUNTIME_MONITORING) will cause an error. You can add only one of these two features because Runtime Monitoring already includes the threat detection for Amazon EKS resources. For more information, see Runtime Monitoring.

There might be regional differences because some data sources might not be available in all the Amazon Web Services Regions where GuardDuty is presently supported. For more information, see Regions and endpoints.

", + "smithy.api#http": { + "method": "POST", + "uri": "/detector", + "code": 200 + } + } + }, + "com.amazonaws.guardduty#CreateDetectorRequest": { + "type": "structure", + "members": { + "Enable": { + "target": "com.amazonaws.guardduty#Boolean", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A Boolean value that specifies whether the detector is to be enabled.

", + "smithy.api#jsonName": "enable", + "smithy.api#required": {} + } + }, + "ClientToken": { + "target": "com.amazonaws.guardduty#ClientToken", + "traits": { + "smithy.api#documentation": "

The idempotency token for the create request.

", + "smithy.api#idempotencyToken": {}, "smithy.api#jsonName": "clientToken" } }, @@ -3959,6 +4458,136 @@ "smithy.api#documentation": "

Contains information on the server side encryption method used in the S3 bucket. See S3 Server-Side Encryption for more information.

" } }, + "com.amazonaws.guardduty#DeleteCustomDetectionRuleAssociation": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#DeleteCustomDetectionRuleAssociationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#DeleteCustomDetectionRuleAssociationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Disables a custom detection rule by deleting its association. This operation is idempotent.

", + "smithy.api#http": { + "method": "DELETE", + "uri": "/custom-detection-rule/rule/{RuleId}/association/{AssociationId}", + "code": 200 + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.guardduty#DeleteCustomDetectionRuleAssociationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "AssociationId": { + "target": "com.amazonaws.guardduty#AssociationId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the association to delete.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#DeleteCustomDetectionRuleAssociationResponse": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#DeleteCustomDetectionRuleOrgConfiguration": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#DeleteCustomDetectionRuleOrgConfigurationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#DeleteCustomDetectionRuleOrgConfigurationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#ConflictException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Deletes the organization-level configuration for a custom detection rule. This operation is available only to the delegated administrator account.

", + "smithy.api#http": { + "method": "DELETE", + "uri": "/custom-detection-rule/org-configuration/{RuleId}", + "code": 200 + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.guardduty#DeleteCustomDetectionRuleOrgConfigurationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The execution mode of the organization configuration to delete. Valid values: LIVE | DRY_RUN.

", + "smithy.api#httpQuery": "mode", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#DeleteCustomDetectionRuleOrgConfigurationResponse": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.guardduty#DeleteDetector": { "type": "operation", "input": { @@ -4947,249 +5576,617 @@ "smithy.api#documentation": "

Contains information about the detected behavior.

" } }, - "com.amazonaws.guardduty#DetectionSource": { - "type": "enum", - "members": { - "AMAZON": { - "target": "smithy.api#Unit", - "traits": { - "smithy.api#enumValue": "AMAZON" - } - }, - "BITDEFENDER": { - "target": "smithy.api#Unit", - "traits": { - "smithy.api#enumValue": "BITDEFENDER" - } + "com.amazonaws.guardduty#DetectionRuleAccountIds": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#AccountId" + }, + "traits": { + "smithy.api#length": { + "min": 0, + "max": 50000 } } }, - "com.amazonaws.guardduty#DetectorAdditionalConfiguration": { - "type": "structure", + "com.amazonaws.guardduty#DetectionRuleArn": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 1024 + }, + "smithy.api#pattern": "^arn:[a-zA-Z0-9\\-]+:[a-zA-Z0-9\\-]+:[a-zA-Z0-9\\-]*:([0-9]*|aws):.+$" + } + }, + "com.amazonaws.guardduty#DetectionRuleConfigurationStatus": { + "type": "enum", "members": { - "Name": { - "target": "com.amazonaws.guardduty#FeatureAdditionalConfiguration", + "ACTIVE": { + "target": "smithy.api#Unit", "traits": { - "smithy.api#documentation": "

Name of the additional configuration.

", - "smithy.api#jsonName": "name" + "smithy.api#enumValue": "ACTIVE" } }, - "Status": { - "target": "com.amazonaws.guardduty#FeatureStatus", + "PROCESSING": { + "target": "smithy.api#Unit", "traits": { - "smithy.api#documentation": "

Status of the additional configuration.

", - "smithy.api#jsonName": "status" + "smithy.api#enumValue": "PROCESSING" + } + }, + "FAILED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "FAILED" } } - }, + } + }, + "com.amazonaws.guardduty#DetectionRuleDataSource": { + "type": "enum", + "members": { + "CLOUDTRAIL_MANAGEMENT_EVENT": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CloudTrailManagementEvent" + } + } + } + }, + "com.amazonaws.guardduty#DetectionRuleDescription": { + "type": "string", "traits": { - "smithy.api#documentation": "

Information about the additional configuration for a feature in your GuardDuty account.

" + "smithy.api#length": { + "min": 1, + "max": 1024 + } } }, - "com.amazonaws.guardduty#DetectorAdditionalConfigurationResult": { + "com.amazonaws.guardduty#DetectionRuleFilter": { "type": "structure", "members": { "Name": { - "target": "com.amazonaws.guardduty#FeatureAdditionalConfiguration", + "target": "com.amazonaws.guardduty#FilterFieldName", "traits": { - "smithy.api#documentation": "

Name of the additional configuration.

", - "smithy.api#jsonName": "name" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The name of the field to filter by.

", + "smithy.api#jsonName": "name", + "smithy.api#required": {} } }, - "Status": { - "target": "com.amazonaws.guardduty#FeatureStatus", + "Values": { + "target": "com.amazonaws.guardduty#DetectionRuleFilterValues", "traits": { - "smithy.api#documentation": "

Status of the additional configuration.

", - "smithy.api#jsonName": "status" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The values to match against the specified filter name.

", + "smithy.api#jsonName": "values", + "smithy.api#required": {} } }, - "UpdatedAt": { - "target": "com.amazonaws.guardduty#Timestamp", + "Condition": { + "target": "com.amazonaws.guardduty#DetectionRuleFilterCondition", "traits": { - "smithy.api#documentation": "

The timestamp at which the additional configuration was last updated. This is in UTC format.

", - "smithy.api#jsonName": "updatedAt" + "smithy.api#documentation": "

The condition to apply to the filter. For example, EQUALS or CONTAINS.

", + "smithy.api#jsonName": "condition" } } }, "traits": { - "smithy.api#documentation": "

Information about the additional configuration.

" + "smithy.api#documentation": "

Contains filter criteria for listing custom detection rules or associations.

" } }, - "com.amazonaws.guardduty#DetectorAdditionalConfigurationResults": { + "com.amazonaws.guardduty#DetectionRuleFilterCondition": { + "type": "enum", + "members": { + "EQUALS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "EQUALS" + } + }, + "CONTAINS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CONTAINS" + } + } + } + }, + "com.amazonaws.guardduty#DetectionRuleFilterList": { "type": "list", "member": { - "target": "com.amazonaws.guardduty#DetectorAdditionalConfigurationResult" + "target": "com.amazonaws.guardduty#DetectionRuleFilter" + }, + "traits": { + "smithy.api#length": { + "min": 0, + "max": 100 + } } }, - "com.amazonaws.guardduty#DetectorAdditionalConfigurations": { + "com.amazonaws.guardduty#DetectionRuleFilterValue": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 255 + }, + "smithy.api#pattern": "^[a-zA-Z0-9 _.\\-:/]+$" + } + }, + "com.amazonaws.guardduty#DetectionRuleFilterValues": { "type": "list", "member": { - "target": "com.amazonaws.guardduty#DetectorAdditionalConfiguration" + "target": "com.amazonaws.guardduty#DetectionRuleFilterValue" + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 50 + } } }, - "com.amazonaws.guardduty#DetectorFeature": { - "type": "enum", + "com.amazonaws.guardduty#DetectionRuleMaxResults": { + "type": "integer", + "traits": { + "smithy.api#range": { + "min": 1, + "max": 100 + } + } + }, + "com.amazonaws.guardduty#DetectionRuleOrgConfiguration": { + "type": "structure", "members": { - "S3_DATA_EVENTS": { - "target": "smithy.api#Unit", + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", "traits": { - "smithy.api#enumValue": "S3_DATA_EVENTS" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#jsonName": "ruleId", + "smithy.api#required": {} } }, - "EKS_AUDIT_LOGS": { - "target": "smithy.api#Unit", + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", "traits": { - "smithy.api#enumValue": "EKS_AUDIT_LOGS" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} } }, - "EBS_MALWARE_PROTECTION": { - "target": "smithy.api#Unit", + "Status": { + "target": "com.amazonaws.guardduty#DetectionRuleConfigurationStatus", "traits": { - "smithy.api#enumValue": "EBS_MALWARE_PROTECTION" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The configuration status. Valid values: ACTIVE | PROCESSING | FAILED.

", + "smithy.api#jsonName": "status", + "smithy.api#required": {} } }, - "RDS_LOGIN_EVENTS": { - "target": "smithy.api#Unit", + "StatusReason": { + "target": "com.amazonaws.guardduty#String", "traits": { - "smithy.api#enumValue": "RDS_LOGIN_EVENTS" + "smithy.api#documentation": "

The reason for the current configuration status.

", + "smithy.api#jsonName": "statusReason" } }, - "LAMBDA_NETWORK_LOGS": { - "target": "smithy.api#Unit", + "IncludeAccountIds": { + "target": "com.amazonaws.guardduty#DetectionRuleAccountIds", "traits": { - "smithy.api#enumValue": "LAMBDA_NETWORK_LOGS" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A list of member account IDs included in the organization configuration. Mutually exclusive with ExcludeAccountIds.

", + "smithy.api#jsonName": "includeAccountIds", + "smithy.api#required": {} } }, - "EKS_RUNTIME_MONITORING": { - "target": "smithy.api#Unit", + "ExcludeAccountIds": { + "target": "com.amazonaws.guardduty#DetectionRuleAccountIds", "traits": { - "smithy.api#enumValue": "EKS_RUNTIME_MONITORING" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A list of member account IDs excluded from the organization configuration. Mutually exclusive with IncludeAccountIds.

", + "smithy.api#jsonName": "excludeAccountIds", + "smithy.api#required": {} } }, - "RUNTIME_MONITORING": { - "target": "smithy.api#Unit", + "CreatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#enumValue": "RUNTIME_MONITORING" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the organization configuration was created.

", + "smithy.api#jsonName": "createdAt", + "smithy.api#required": {} } }, - "AI_PROTECTION": { - "target": "smithy.api#Unit", + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#enumValue": "AI_PROTECTION" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the organization configuration was last updated.

", + "smithy.api#jsonName": "updatedAt", + "smithy.api#required": {} } }, - "AI_ANALYST": { - "target": "smithy.api#Unit", + "ExpiresAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#enumValue": "AI_ANALYST" + "smithy.api#documentation": "

The timestamp when the organization configuration expires.

", + "smithy.api#jsonName": "expiresAt" } } + }, + "traits": { + "smithy.api#documentation": "

Contains the organization-level configuration for a custom detection rule.

" } }, - "com.amazonaws.guardduty#DetectorFeatureConfiguration": { + "com.amazonaws.guardduty#DetectionRuleOrgConfigurationSummary": { "type": "structure", "members": { - "Name": { - "target": "com.amazonaws.guardduty#DetectorFeature", + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", "traits": { - "smithy.api#documentation": "

The name of the feature.

", - "smithy.api#jsonName": "name" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#jsonName": "ruleId", + "smithy.api#required": {} } }, - "Status": { - "target": "com.amazonaws.guardduty#FeatureStatus", + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", "traits": { - "smithy.api#documentation": "

The status of the feature.

", - "smithy.api#jsonName": "status" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The rule execution mode.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} } }, - "AdditionalConfiguration": { - "target": "com.amazonaws.guardduty#DetectorAdditionalConfigurations", + "Status": { + "target": "com.amazonaws.guardduty#DetectionRuleConfigurationStatus", "traits": { - "smithy.api#documentation": "

Additional configuration for a resource.

", - "smithy.api#jsonName": "additionalConfiguration" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The configuration status.

", + "smithy.api#jsonName": "status", + "smithy.api#required": {} } - } - }, - "traits": { - "smithy.api#documentation": "

Contains information about a GuardDuty feature.

Specifying both EKS Runtime Monitoring (EKS_RUNTIME_MONITORING) and Runtime Monitoring (RUNTIME_MONITORING) will cause an error. You can add only one of these two features because Runtime Monitoring already includes the threat detection for Amazon EKS resources. For more information, see Runtime Monitoring.

" - } - }, - "com.amazonaws.guardduty#DetectorFeatureConfigurationResult": { - "type": "structure", - "members": { - "Name": { - "target": "com.amazonaws.guardduty#DetectorFeatureResult", + }, + "StatusReason": { + "target": "com.amazonaws.guardduty#String", "traits": { - "smithy.api#documentation": "

Indicates the name of the feature that can be enabled for the detector.

", - "smithy.api#jsonName": "name" + "smithy.api#documentation": "

The reason for the current configuration status.

", + "smithy.api#jsonName": "statusReason" } }, - "Status": { - "target": "com.amazonaws.guardduty#FeatureStatus", + "CreatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#documentation": "

Indicates the status of the feature that is enabled for the detector.

", - "smithy.api#jsonName": "status" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the organization configuration was created.

", + "smithy.api#jsonName": "createdAt", + "smithy.api#required": {} } }, "UpdatedAt": { "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#documentation": "

The timestamp at which the feature object was updated.

", - "smithy.api#jsonName": "updatedAt" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the organization configuration was last updated.

", + "smithy.api#jsonName": "updatedAt", + "smithy.api#required": {} } }, - "AdditionalConfiguration": { - "target": "com.amazonaws.guardduty#DetectorAdditionalConfigurationResults", + "ExpiresAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#documentation": "

Additional configuration for a resource.

", - "smithy.api#jsonName": "additionalConfiguration" + "smithy.api#documentation": "

The timestamp when the organization configuration expires.

", + "smithy.api#jsonName": "expiresAt" } } }, "traits": { - "smithy.api#documentation": "

Contains information about a GuardDuty feature.

Specifying both EKS Runtime Monitoring (EKS_RUNTIME_MONITORING) and Runtime Monitoring (RUNTIME_MONITORING) will cause an error. You can add only one of these two features because Runtime Monitoring already includes the threat detection for Amazon EKS resources. For more information, see Runtime Monitoring.

" + "smithy.api#documentation": "

Contains summary information about an organization-level configuration for a custom detection rule.

" } }, - "com.amazonaws.guardduty#DetectorFeatureConfigurations": { + "com.amazonaws.guardduty#DetectionRuleOrgConfigurationSummaryList": { "type": "list", "member": { - "target": "com.amazonaws.guardduty#DetectorFeatureConfiguration" + "target": "com.amazonaws.guardduty#DetectionRuleOrgConfigurationSummary" } }, - "com.amazonaws.guardduty#DetectorFeatureConfigurationsResults": { - "type": "list", - "member": { - "target": "com.amazonaws.guardduty#DetectorFeatureConfigurationResult" + "com.amazonaws.guardduty#DetectionRuleServiceName": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 128 + } } }, - "com.amazonaws.guardduty#DetectorFeatureResult": { + "com.amazonaws.guardduty#DetectionRuleSeverity": { "type": "enum", "members": { - "FLOW_LOGS": { + "CRITICAL": { "target": "smithy.api#Unit", "traits": { - "smithy.api#enumValue": "FLOW_LOGS" + "smithy.api#enumValue": "CRITICAL" } }, - "CLOUD_TRAIL": { + "HIGH": { "target": "smithy.api#Unit", "traits": { - "smithy.api#enumValue": "CLOUD_TRAIL" + "smithy.api#enumValue": "HIGH" } }, - "DNS_LOGS": { + "MEDIUM": { "target": "smithy.api#Unit", "traits": { - "smithy.api#enumValue": "DNS_LOGS" + "smithy.api#enumValue": "MEDIUM" } }, - "S3_DATA_EVENTS": { + "LOW": { "target": "smithy.api#Unit", "traits": { - "smithy.api#enumValue": "S3_DATA_EVENTS" + "smithy.api#enumValue": "LOW" } - }, + } + } + }, + "com.amazonaws.guardduty#DetectionSource": { + "type": "enum", + "members": { + "AMAZON": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "AMAZON" + } + }, + "BITDEFENDER": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "BITDEFENDER" + } + } + } + }, + "com.amazonaws.guardduty#DetectorAdditionalConfiguration": { + "type": "structure", + "members": { + "Name": { + "target": "com.amazonaws.guardduty#FeatureAdditionalConfiguration", + "traits": { + "smithy.api#documentation": "

Name of the additional configuration.

", + "smithy.api#jsonName": "name" + } + }, + "Status": { + "target": "com.amazonaws.guardduty#FeatureStatus", + "traits": { + "smithy.api#documentation": "

Status of the additional configuration.

", + "smithy.api#jsonName": "status" + } + } + }, + "traits": { + "smithy.api#documentation": "

Information about the additional configuration for a feature in your GuardDuty account.

" + } + }, + "com.amazonaws.guardduty#DetectorAdditionalConfigurationResult": { + "type": "structure", + "members": { + "Name": { + "target": "com.amazonaws.guardduty#FeatureAdditionalConfiguration", + "traits": { + "smithy.api#documentation": "

Name of the additional configuration.

", + "smithy.api#jsonName": "name" + } + }, + "Status": { + "target": "com.amazonaws.guardduty#FeatureStatus", + "traits": { + "smithy.api#documentation": "

Status of the additional configuration.

", + "smithy.api#jsonName": "status" + } + }, + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp at which the additional configuration was last updated. This is in UTC format.

", + "smithy.api#jsonName": "updatedAt" + } + }, + "ManagedBy": { + "target": "com.amazonaws.guardduty#ManagedBy", + "traits": { + "smithy.api#documentation": "

Indicates what manages the additional configuration. A value of GUARDDUTY_POLICY means a GuardDuty policy manages the additional configuration.

", + "smithy.api#jsonName": "managedBy" + } + } + }, + "traits": { + "smithy.api#documentation": "

Information about the additional configuration.

" + } + }, + "com.amazonaws.guardduty#DetectorAdditionalConfigurationResults": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#DetectorAdditionalConfigurationResult" + } + }, + "com.amazonaws.guardduty#DetectorAdditionalConfigurations": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#DetectorAdditionalConfiguration" + } + }, + "com.amazonaws.guardduty#DetectorFeature": { + "type": "enum", + "members": { + "S3_DATA_EVENTS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "S3_DATA_EVENTS" + } + }, + "EKS_AUDIT_LOGS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "EKS_AUDIT_LOGS" + } + }, + "EBS_MALWARE_PROTECTION": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "EBS_MALWARE_PROTECTION" + } + }, + "RDS_LOGIN_EVENTS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "RDS_LOGIN_EVENTS" + } + }, + "LAMBDA_NETWORK_LOGS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "LAMBDA_NETWORK_LOGS" + } + }, + "EKS_RUNTIME_MONITORING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "EKS_RUNTIME_MONITORING" + } + }, + "RUNTIME_MONITORING": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "RUNTIME_MONITORING" + } + }, + "AI_PROTECTION": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "AI_PROTECTION" + } + }, + "AI_ANALYST": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "AI_ANALYST" + } + } + } + }, + "com.amazonaws.guardduty#DetectorFeatureConfiguration": { + "type": "structure", + "members": { + "Name": { + "target": "com.amazonaws.guardduty#DetectorFeature", + "traits": { + "smithy.api#documentation": "

The name of the feature.

", + "smithy.api#jsonName": "name" + } + }, + "Status": { + "target": "com.amazonaws.guardduty#FeatureStatus", + "traits": { + "smithy.api#documentation": "

The status of the feature.

", + "smithy.api#jsonName": "status" + } + }, + "AdditionalConfiguration": { + "target": "com.amazonaws.guardduty#DetectorAdditionalConfigurations", + "traits": { + "smithy.api#documentation": "

Additional configuration for a resource.

", + "smithy.api#jsonName": "additionalConfiguration" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains information about a GuardDuty feature.

Specifying both EKS Runtime Monitoring (EKS_RUNTIME_MONITORING) and Runtime Monitoring (RUNTIME_MONITORING) will cause an error. You can add only one of these two features because Runtime Monitoring already includes the threat detection for Amazon EKS resources. For more information, see Runtime Monitoring.

" + } + }, + "com.amazonaws.guardduty#DetectorFeatureConfigurationResult": { + "type": "structure", + "members": { + "Name": { + "target": "com.amazonaws.guardduty#DetectorFeatureResult", + "traits": { + "smithy.api#documentation": "

Indicates the name of the feature that can be enabled for the detector.

", + "smithy.api#jsonName": "name" + } + }, + "Status": { + "target": "com.amazonaws.guardduty#FeatureStatus", + "traits": { + "smithy.api#documentation": "

Indicates the status of the feature that is enabled for the detector.

", + "smithy.api#jsonName": "status" + } + }, + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp at which the feature object was updated.

", + "smithy.api#jsonName": "updatedAt" + } + }, + "AdditionalConfiguration": { + "target": "com.amazonaws.guardduty#DetectorAdditionalConfigurationResults", + "traits": { + "smithy.api#documentation": "

Additional configuration for a resource.

", + "smithy.api#jsonName": "additionalConfiguration" + } + }, + "ManagedBy": { + "target": "com.amazonaws.guardduty#ManagedBy", + "traits": { + "smithy.api#documentation": "

Indicates what manages the feature. A value of GUARDDUTY_POLICY means a GuardDuty policy manages the feature.

", + "smithy.api#jsonName": "managedBy" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains information about a GuardDuty feature.

Specifying both EKS Runtime Monitoring (EKS_RUNTIME_MONITORING) and Runtime Monitoring (RUNTIME_MONITORING) will cause an error. You can add only one of these two features because Runtime Monitoring already includes the threat detection for Amazon EKS resources. For more information, see Runtime Monitoring.

" + } + }, + "com.amazonaws.guardduty#DetectorFeatureConfigurations": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#DetectorFeatureConfiguration" + } + }, + "com.amazonaws.guardduty#DetectorFeatureConfigurationsResults": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#DetectorFeatureConfigurationResult" + } + }, + "com.amazonaws.guardduty#DetectorFeatureResult": { + "type": "enum", + "members": { + "FLOW_LOGS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "FLOW_LOGS" + } + }, + "CLOUD_TRAIL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CLOUD_TRAIL" + } + }, + "DNS_LOGS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DNS_LOGS" + } + }, + "S3_DATA_EVENTS": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "S3_DATA_EVENTS" + } + }, "EKS_AUDIT_LOGS": { "target": "smithy.api#Unit", "traits": { @@ -6580,10 +7577,57 @@ } } }, - "com.amazonaws.guardduty#FilterName": { - "type": "string", - "traits": { - "smithy.api#length": { + "com.amazonaws.guardduty#FilterFieldName": { + "type": "enum", + "members": { + "NAME": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "name" + } + }, + "DESCRIPTION": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "description" + } + }, + "DATA_SOURCE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "dataSource" + } + }, + "SEVERITY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "severity" + } + }, + "TACTIC": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "tactic" + } + }, + "TECHNIQUE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "technique" + } + }, + "SERVICE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "service" + } + } + } + }, + "com.amazonaws.guardduty#FilterName": { + "type": "string", + "traits": { + "smithy.api#length": { "min": 3, "max": 64 } @@ -6913,6 +7957,76 @@ "traits": { "smithy.api#enumValue": "EC2_IMAGE" } + }, + "BEDROCK_CUSTOM_MODEL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon Bedrock custom model fine-tuned by the customer.

", + "smithy.api#enumValue": "BEDROCK_CUSTOM_MODEL" + } + }, + "BEDROCK_IMPORTED_MODEL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon Bedrock imported model brought in from an external source.

", + "smithy.api#enumValue": "BEDROCK_IMPORTED_MODEL" + } + }, + "BEDROCK_PROVISIONED_MODEL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon Bedrock model with provisioned throughput.

", + "smithy.api#enumValue": "BEDROCK_PROVISIONED_MODEL" + } + }, + "BEDROCK_CUSTOM_MODEL_DEPLOYMENT": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

A deployment of an Amazon Bedrock custom model.

", + "smithy.api#enumValue": "BEDROCK_CUSTOM_MODEL_DEPLOYMENT" + } + }, + "BEDROCK_INFERENCE_PROFILE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon Bedrock inference profile that routes model invocations across Regions.

", + "smithy.api#enumValue": "BEDROCK_INFERENCE_PROFILE" + } + }, + "BEDROCK_APPLICATION_INFERENCE_PROFILE": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An application-scoped Amazon Bedrock inference profile used to track invocation usage.

", + "smithy.api#enumValue": "BEDROCK_APPLICATION_INFERENCE_PROFILE" + } + }, + "BEDROCK_PROMPT": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

A managed prompt stored in Amazon Bedrock Prompt Management.

", + "smithy.api#enumValue": "BEDROCK_PROMPT" + } + }, + "BEDROCK_PROMPT_ROUTER": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon Bedrock prompt router that selects a model per request.

", + "smithy.api#enumValue": "BEDROCK_PROMPT_ROUTER" + } + }, + "BEDROCK_GUARDRAIL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon Bedrock guardrail evaluated during a model invocation.

", + "smithy.api#enumValue": "BEDROCK_GUARDRAIL" + } + }, + "SAGEMAKER_ENDPOINT": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#documentation": "

An Amazon SageMaker inference endpoint.

", + "smithy.api#enumValue": "SAGEMAKER_ENDPOINT" + } } } }, @@ -7334,6 +8448,225 @@ "smithy.api#output": {} } }, + "com.amazonaws.guardduty#GetCustomDetectionRule": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns details for a custom detection rule in GuardDuty, including its detection logic.

", + "smithy.api#http": { + "method": "GET", + "uri": "/custom-detection-rule/rule/{RuleId}", + "code": 200 + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleAssociation": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleAssociationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleAssociationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns details for a custom detection rule association.

", + "smithy.api#http": { + "method": "GET", + "uri": "/custom-detection-rule/rule/{RuleId}/association/{AssociationId}", + "code": 200 + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleAssociationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "AssociationId": { + "target": "com.amazonaws.guardduty#AssociationId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the association.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleAssociationResponse": { + "type": "structure", + "members": { + "RuleAssociation": { + "target": "com.amazonaws.guardduty#AssociationDetail", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The details of the custom detection rule association.

", + "smithy.api#jsonName": "ruleAssociation", + "smithy.api#required": {} + } + }, + "Tags": { + "target": "com.amazonaws.guardduty#TagMap", + "traits": { + "smithy.api#documentation": "

The tags associated with the custom detection rule association resource.

", + "smithy.api#jsonName": "tags" + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleOrgConfiguration": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleOrgConfigurationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleOrgConfigurationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns the organization-level configuration for a custom detection rule.

", + "smithy.api#http": { + "method": "GET", + "uri": "/custom-detection-rule/org-configuration/{RuleId}", + "code": 200 + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleOrgConfigurationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The execution mode of the organization configuration to retrieve. Valid values: LIVE | DRY_RUN.

", + "smithy.api#httpQuery": "mode", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleOrgConfigurationResponse": { + "type": "structure", + "members": { + "Configuration": { + "target": "com.amazonaws.guardduty#DetectionRuleOrgConfiguration", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The details of the organization configuration.

", + "smithy.api#jsonName": "configuration", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#GetCustomDetectionRuleResponse": { + "type": "structure", + "members": { + "Rule": { + "target": "com.amazonaws.guardduty#RuleDetail", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The details of the custom detection rule.

", + "smithy.api#jsonName": "rule", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.guardduty#GetDetector": { "type": "operation", "input": { @@ -9272,6 +10605,12 @@ { "target": "com.amazonaws.guardduty#ArchiveFindings" }, + { + "target": "com.amazonaws.guardduty#CreateCustomDetectionRuleAssociation" + }, + { + "target": "com.amazonaws.guardduty#CreateCustomDetectionRuleOrgConfiguration" + }, { "target": "com.amazonaws.guardduty#CreateDetector" }, @@ -9308,6 +10647,12 @@ { "target": "com.amazonaws.guardduty#DeclineInvitations" }, + { + "target": "com.amazonaws.guardduty#DeleteCustomDetectionRuleAssociation" + }, + { + "target": "com.amazonaws.guardduty#DeleteCustomDetectionRuleOrgConfiguration" + }, { "target": "com.amazonaws.guardduty#DeleteDetector" }, @@ -9369,16 +10714,25 @@ "target": "com.amazonaws.guardduty#GetCoverageStatistics" }, { - "target": "com.amazonaws.guardduty#GetDetector" + "target": "com.amazonaws.guardduty#GetCustomDetectionRule" }, { - "target": "com.amazonaws.guardduty#GetFilter" + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleAssociation" }, { - "target": "com.amazonaws.guardduty#GetFindings" + "target": "com.amazonaws.guardduty#GetCustomDetectionRuleOrgConfiguration" }, { - "target": "com.amazonaws.guardduty#GetFindingsStatistics" + "target": "com.amazonaws.guardduty#GetDetector" + }, + { + "target": "com.amazonaws.guardduty#GetFilter" + }, + { + "target": "com.amazonaws.guardduty#GetFindings" + }, + { + "target": "com.amazonaws.guardduty#GetFindingsStatistics" }, { "target": "com.amazonaws.guardduty#GetInvestigation" @@ -9431,6 +10785,15 @@ { "target": "com.amazonaws.guardduty#ListCoverage" }, + { + "target": "com.amazonaws.guardduty#ListCustomDetectionRuleAssociations" + }, + { + "target": "com.amazonaws.guardduty#ListCustomDetectionRuleOrgConfigurations" + }, + { + "target": "com.amazonaws.guardduty#ListCustomDetectionRules" + }, { "target": "com.amazonaws.guardduty#ListDetectors" }, @@ -9497,6 +10860,12 @@ { "target": "com.amazonaws.guardduty#UntagResource" }, + { + "target": "com.amazonaws.guardduty#UpdateCustomDetectionRuleAssociation" + }, + { + "target": "com.amazonaws.guardduty#UpdateCustomDetectionRuleOrgConfiguration" + }, { "target": "com.amazonaws.guardduty#UpdateDetector" }, @@ -12647,6 +14016,277 @@ "smithy.api#output": {} } }, + "com.amazonaws.guardduty#ListCustomDetectionRuleAssociations": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#ListCustomDetectionRuleAssociationsRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#ListCustomDetectionRuleAssociationsResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns all custom detection rule associations for your account. You can filter by rule ID and mode.

", + "smithy.api#http": { + "method": "GET", + "uri": "/custom-detection-rule/association", + "code": 200 + }, + "smithy.api#paginated": { + "inputToken": "NextToken", + "outputToken": "NextToken", + "items": "RuleAssociations", + "pageSize": "MaxResults" + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRuleAssociationsRequest": { + "type": "structure", + "members": { + "MaxResults": { + "target": "com.amazonaws.guardduty#DetectionRuleMaxResults", + "traits": { + "smithy.api#documentation": "

The maximum number of results to return in a single page. Minimum value of 1, maximum value of 100.

", + "smithy.api#httpQuery": "maxResults" + } + }, + "NextToken": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

A pagination token from a previous response. Use this token to retrieve the next page of results.

", + "smithy.api#httpQuery": "nextToken" + } + }, + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule to filter associations by.

", + "smithy.api#httpQuery": "ruleId" + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#documentation": "

The rule execution mode to filter associations by.

", + "smithy.api#httpQuery": "mode" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRuleAssociationsResponse": { + "type": "structure", + "members": { + "RuleAssociations": { + "target": "com.amazonaws.guardduty#AssociationSummaryList", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A list of custom detection rule association summaries.

", + "smithy.api#jsonName": "ruleAssociations", + "smithy.api#required": {} + } + }, + "NextToken": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

A pagination token to retrieve the next page of results. If this field is empty, there are no additional results.

", + "smithy.api#jsonName": "nextToken" + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRuleOrgConfigurations": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#ListCustomDetectionRuleOrgConfigurationsRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#ListCustomDetectionRuleOrgConfigurationsResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns all organization-level configurations for custom detection rules. You can filter the results by status.

", + "smithy.api#http": { + "method": "GET", + "uri": "/custom-detection-rule/org-configuration", + "code": 200 + }, + "smithy.api#paginated": { + "inputToken": "NextToken", + "outputToken": "NextToken", + "items": "Configurations", + "pageSize": "MaxResults" + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRuleOrgConfigurationsRequest": { + "type": "structure", + "members": { + "MaxResults": { + "target": "com.amazonaws.guardduty#DetectionRuleMaxResults", + "traits": { + "smithy.api#documentation": "

The maximum number of results to return in a single page. Minimum value of 1, maximum value of 100.

", + "smithy.api#httpQuery": "maxResults" + } + }, + "NextToken": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

A pagination token from a previous response. Use this token to retrieve the next page of results.

", + "smithy.api#httpQuery": "nextToken" + } + }, + "Status": { + "target": "com.amazonaws.guardduty#DetectionRuleConfigurationStatus", + "traits": { + "smithy.api#documentation": "

The configuration status to filter by.

", + "smithy.api#httpQuery": "status" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRuleOrgConfigurationsResponse": { + "type": "structure", + "members": { + "Configurations": { + "target": "com.amazonaws.guardduty#DetectionRuleOrgConfigurationSummaryList", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A list of organization configurations for custom detection rules.

", + "smithy.api#jsonName": "configurations", + "smithy.api#required": {} + } + }, + "NextToken": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

A pagination token to retrieve the next page of results. If this field is empty, there are no additional results.

", + "smithy.api#jsonName": "nextToken" + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRules": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#ListCustomDetectionRulesRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#ListCustomDetectionRulesResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + } + ], + "traits": { + "smithy.api#documentation": "

Returns all available custom detection rules in GuardDuty. You can filter the results by data source, severity, tactic, technique, and service.

", + "smithy.api#http": { + "method": "POST", + "uri": "/custom-detection-rule/rule", + "code": 200 + }, + "smithy.api#paginated": { + "inputToken": "NextToken", + "outputToken": "NextToken", + "items": "Rules", + "pageSize": "MaxResults" + }, + "smithy.api#readonly": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRulesRequest": { + "type": "structure", + "members": { + "MaxResults": { + "target": "com.amazonaws.guardduty#DetectionRuleMaxResults", + "traits": { + "smithy.api#documentation": "

The maximum number of results to return in a single page. Minimum value of 1, maximum value of 100.

", + "smithy.api#jsonName": "maxResults" + } + }, + "NextToken": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

A pagination token from a previous response. Use this token to retrieve the next page of results.

", + "smithy.api#jsonName": "nextToken" + } + }, + "Filters": { + "target": "com.amazonaws.guardduty#DetectionRuleFilterList", + "traits": { + "smithy.api#documentation": "

A list of filter criteria to apply when listing custom detection rules.

", + "smithy.api#jsonName": "filters" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#ListCustomDetectionRulesResponse": { + "type": "structure", + "members": { + "Rules": { + "target": "com.amazonaws.guardduty#RuleSummaryList", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A list of custom detection rule summaries.

", + "smithy.api#jsonName": "rules", + "smithy.api#required": {} + } + }, + "NextToken": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

A pagination token to retrieve the next page of results. If this field is empty, there are no additional results.

", + "smithy.api#jsonName": "nextToken" + } + } + }, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.guardduty#ListDetectors": { "type": "operation", "input": { @@ -14532,6 +16172,17 @@ "target": "com.amazonaws.guardduty#MalwareScan" } }, + "com.amazonaws.guardduty#ManagedBy": { + "type": "enum", + "members": { + "GUARDDUTY_POLICY": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "GUARDDUTY_POLICY" + } + } + } + }, "com.amazonaws.guardduty#ManagementType": { "type": "enum", "members": { @@ -14755,6 +16406,13 @@ "smithy.api#documentation": "

The timestamp at which the additional configuration was set for the member account. This is in UTC format.

", "smithy.api#jsonName": "updatedAt" } + }, + "ManagedBy": { + "target": "com.amazonaws.guardduty#ManagedBy", + "traits": { + "smithy.api#documentation": "

Indicates what manages the additional configuration. A value of GUARDDUTY_POLICY means a GuardDuty policy manages the additional configuration.

", + "smithy.api#jsonName": "managedBy" + } } }, "traits": { @@ -14880,6 +16538,13 @@ "smithy.api#documentation": "

Indicates the additional configuration of the feature that is configured for the member account.

", "smithy.api#jsonName": "additionalConfiguration" } + }, + "ManagedBy": { + "target": "com.amazonaws.guardduty#ManagedBy", + "traits": { + "smithy.api#documentation": "

Indicates what manages the feature. A value of GUARDDUTY_POLICY means a GuardDuty policy manages the feature.

", + "smithy.api#jsonName": "managedBy" + } } }, "traits": { @@ -14933,6 +16598,24 @@ } } }, + "com.amazonaws.guardduty#MitreTactic": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 255 + } + } + }, + "com.amazonaws.guardduty#MitreTechnique": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 255 + } + } + }, "com.amazonaws.guardduty#ModelDetail": { "type": "structure", "members": { @@ -16783,6 +18466,13 @@ "smithy.api#documentation": "

Details on whether the Amazon Web Services account of the remote API caller is related to your GuardDuty environment. If this value is True the API caller is affiliated to your account in some way. If it is False the API caller is from outside your environment.

", "smithy.api#jsonName": "affiliated" } + }, + "AwsServiceName": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

If the remote account belongs to an Amazon Web Services service, this field indicates which service the remote account belongs to.

", + "smithy.api#jsonName": "awsServiceName" + } } }, "traits": { @@ -17114,6 +18804,13 @@ "smithy.api#documentation": "

Contains detailed information about the CloudFormation stack associated with the activity that prompted GuardDuty to generate a finding.

", "smithy.api#jsonName": "cloudformationStack" } + }, + "BedrockGuardrail": { + "target": "com.amazonaws.guardduty#BedrockGuardrailResource", + "traits": { + "smithy.api#documentation": "

Contains detailed information about the Amazon Bedrock guardrail associated with the activity that prompted GuardDuty to generate a finding.

", + "smithy.api#jsonName": "bedrockGuardrail" + } } }, "traits": { @@ -17231,153 +18928,473 @@ } } }, - "com.amazonaws.guardduty#ResourceUids": { - "type": "list", - "member": { - "target": "com.amazonaws.guardduty#String" - }, - "traits": { - "smithy.api#length": { - "min": 0, - "max": 400 + "com.amazonaws.guardduty#ResourceUids": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#String" + }, + "traits": { + "smithy.api#length": { + "min": 0, + "max": 400 + } + } + }, + "com.amazonaws.guardduty#ResourceV2": { + "type": "structure", + "members": { + "Uid": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier of the resource.

", + "smithy.api#jsonName": "uid", + "smithy.api#required": {} + } + }, + "Name": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The name of the resource.

", + "smithy.api#jsonName": "name" + } + }, + "AccountId": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The Amazon Web Services account ID to which the resource belongs.

", + "smithy.api#jsonName": "accountId" + } + }, + "ResourceType": { + "target": "com.amazonaws.guardduty#FindingResourceType", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The type of the Amazon Web Services resource.

", + "smithy.api#jsonName": "resourceType", + "smithy.api#required": {} + } + }, + "Region": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The Amazon Web Services Region where the resource belongs.

", + "smithy.api#jsonName": "region" + } + }, + "Service": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The Amazon Web Services service of the resource.

", + "smithy.api#jsonName": "service" + } + }, + "CloudPartition": { + "target": "com.amazonaws.guardduty#String", + "traits": { + "smithy.api#documentation": "

The cloud partition within the Amazon Web Services Region to which the resource belongs.

", + "smithy.api#jsonName": "cloudPartition" + } + }, + "Tags": { + "target": "com.amazonaws.guardduty#Tags", + "traits": { + "smithy.api#documentation": "

Contains information about the tags associated with the resource.

", + "smithy.api#jsonName": "tags" + } + }, + "Data": { + "target": "com.amazonaws.guardduty#ResourceData", + "traits": { + "smithy.api#documentation": "

Contains information about the Amazon Web Services resource associated with the activity that prompted GuardDuty to generate a finding.

", + "smithy.api#jsonName": "data" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains information about the Amazon Web Services resource that is associated with the GuardDuty finding.

" + } + }, + "com.amazonaws.guardduty#Resources": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#ResourceV2" + }, + "traits": { + "smithy.api#length": { + "min": 0, + "max": 400 + } + } + }, + "com.amazonaws.guardduty#RiskDetails": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 0, + "max": 1024 + } + } + }, + "com.amazonaws.guardduty#RiskLevel": { + "type": "enum", + "members": { + "INFO": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "Info" + } + }, + "LOW": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "Low" + } + }, + "MEDIUM": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "Medium" + } + }, + "HIGH": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "High" + } + }, + "CRITICAL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "Critical" + } + } + }, + "traits": { + "smithy.api#length": { + "min": 1, + "max": 300 + } + } + }, + "com.amazonaws.guardduty#RuleDefinition": { + "type": "structure", + "members": { + "Expression": { + "target": "com.amazonaws.guardduty#RuleExpression", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The detection logic expression for the rule.

", + "smithy.api#jsonName": "expression", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains the detection logic for a custom detection rule.

" + } + }, + "com.amazonaws.guardduty#RuleDetail": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The unique identifier for the rule.

", + "smithy.api#jsonName": "ruleId", + "smithy.api#required": {} + } + }, + "Arn": { + "target": "com.amazonaws.guardduty#DetectionRuleArn", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the rule.

", + "smithy.api#jsonName": "arn", + "smithy.api#required": {} + } + }, + "Name": { + "target": "com.amazonaws.guardduty#RuleName", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The display name of the rule.

", + "smithy.api#jsonName": "name", + "smithy.api#required": {} + } + }, + "Description": { + "target": "com.amazonaws.guardduty#DetectionRuleDescription", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

A description of what the rule detects.

", + "smithy.api#jsonName": "description", + "smithy.api#required": {} + } + }, + "Severity": { + "target": "com.amazonaws.guardduty#DetectionRuleSeverity", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The severity level assigned to findings generated by this rule.

", + "smithy.api#jsonName": "severity", + "smithy.api#required": {} + } + }, + "DataSource": { + "target": "com.amazonaws.guardduty#DetectionRuleDataSource", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The data source that the rule analyzes.

", + "smithy.api#jsonName": "dataSource", + "smithy.api#required": {} + } + }, + "Tactic": { + "target": "com.amazonaws.guardduty#MitreTactic", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The MITRE ATT&CK tactic associated with the rule.

", + "smithy.api#jsonName": "tactic", + "smithy.api#required": {} + } + }, + "Technique": { + "target": "com.amazonaws.guardduty#MitreTechnique", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The MITRE ATT&CK technique associated with the rule.

", + "smithy.api#jsonName": "technique", + "smithy.api#required": {} + } + }, + "Service": { + "target": "com.amazonaws.guardduty#DetectionRuleServiceName", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Web Services service associated with the rule.

", + "smithy.api#jsonName": "service", + "smithy.api#required": {} + } + }, + "Definition": { + "target": "com.amazonaws.guardduty#RuleDefinition", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The detection logic definition for the rule.

", + "smithy.api#jsonName": "definition", + "smithy.api#required": {} + } + }, + "Language": { + "target": "com.amazonaws.guardduty#RuleLanguage", + "traits": { + "smithy.api#documentation": "

The language used for the detection logic expression.

", + "smithy.api#jsonName": "language" + } + }, + "Schema": { + "target": "com.amazonaws.guardduty#RuleSchema", + "traits": { + "smithy.api#documentation": "

The schema version used by the rule definition.

", + "smithy.api#jsonName": "schema" + } + }, + "CreatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the rule was created.

", + "smithy.api#jsonName": "createdAt", + "smithy.api#required": {} + } + }, + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", + "traits": { + "smithy.api#documentation": "

The timestamp when the rule was last updated.

", + "smithy.api#jsonName": "updatedAt" + } + } + }, + "traits": { + "smithy.api#documentation": "

Contains the full details of a custom detection rule, including its detection logic.

" + } + }, + "com.amazonaws.guardduty#RuleExpression": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 4096 + } + } + }, + "com.amazonaws.guardduty#RuleId": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 100 + }, + "smithy.api#pattern": "^[a-z0-9]+(-[a-z0-9]+)*$" + } + }, + "com.amazonaws.guardduty#RuleLanguage": { + "type": "enum", + "members": { + "SQL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "SQL" + } + } + } + }, + "com.amazonaws.guardduty#RuleName": { + "type": "string", + "traits": { + "smithy.api#length": { + "min": 1, + "max": 255 + } + } + }, + "com.amazonaws.guardduty#RuleSchema": { + "type": "enum", + "members": { + "CLOUD_TRAIL": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "CloudTrail" + } } } }, - "com.amazonaws.guardduty#ResourceV2": { + "com.amazonaws.guardduty#RuleSummary": { "type": "structure", "members": { - "Uid": { - "target": "com.amazonaws.guardduty#String", + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", "traits": { "smithy.api#clientOptional": {}, - "smithy.api#documentation": "

The unique identifier of the resource.

", - "smithy.api#jsonName": "uid", + "smithy.api#documentation": "

The unique identifier for the rule.

", + "smithy.api#jsonName": "ruleId", "smithy.api#required": {} } }, - "Name": { - "target": "com.amazonaws.guardduty#String", + "Arn": { + "target": "com.amazonaws.guardduty#DetectionRuleArn", "traits": { - "smithy.api#documentation": "

The name of the resource.

", - "smithy.api#jsonName": "name" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Resource Name (ARN) of the rule.

", + "smithy.api#jsonName": "arn", + "smithy.api#required": {} } }, - "AccountId": { - "target": "com.amazonaws.guardduty#String", + "Name": { + "target": "com.amazonaws.guardduty#RuleName", "traits": { - "smithy.api#documentation": "

The Amazon Web Services account ID to which the resource belongs.

", - "smithy.api#jsonName": "accountId" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The display name of the rule.

", + "smithy.api#jsonName": "name", + "smithy.api#required": {} } }, - "ResourceType": { - "target": "com.amazonaws.guardduty#FindingResourceType", + "Description": { + "target": "com.amazonaws.guardduty#DetectionRuleDescription", "traits": { "smithy.api#clientOptional": {}, - "smithy.api#documentation": "

The type of the Amazon Web Services resource.

", - "smithy.api#jsonName": "resourceType", + "smithy.api#documentation": "

A description of what the rule detects.

", + "smithy.api#jsonName": "description", "smithy.api#required": {} } }, - "Region": { - "target": "com.amazonaws.guardduty#String", + "Severity": { + "target": "com.amazonaws.guardduty#DetectionRuleSeverity", "traits": { - "smithy.api#documentation": "

The Amazon Web Services Region where the resource belongs.

", - "smithy.api#jsonName": "region" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The severity level assigned to findings generated by this rule.

", + "smithy.api#jsonName": "severity", + "smithy.api#required": {} } }, - "Service": { - "target": "com.amazonaws.guardduty#String", + "DataSource": { + "target": "com.amazonaws.guardduty#DetectionRuleDataSource", "traits": { - "smithy.api#documentation": "

The Amazon Web Services service of the resource.

", - "smithy.api#jsonName": "service" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The data source that the rule analyzes.

", + "smithy.api#jsonName": "dataSource", + "smithy.api#required": {} } }, - "CloudPartition": { - "target": "com.amazonaws.guardduty#String", + "Tactic": { + "target": "com.amazonaws.guardduty#MitreTactic", "traits": { - "smithy.api#documentation": "

The cloud partition within the Amazon Web Services Region to which the resource belongs.

", - "smithy.api#jsonName": "cloudPartition" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The MITRE ATT&CK tactic associated with the rule.

", + "smithy.api#jsonName": "tactic", + "smithy.api#required": {} } }, - "Tags": { - "target": "com.amazonaws.guardduty#Tags", + "Technique": { + "target": "com.amazonaws.guardduty#MitreTechnique", "traits": { - "smithy.api#documentation": "

Contains information about the tags associated with the resource.

", - "smithy.api#jsonName": "tags" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The MITRE ATT&CK technique associated with the rule.

", + "smithy.api#jsonName": "technique", + "smithy.api#required": {} } }, - "Data": { - "target": "com.amazonaws.guardduty#ResourceData", - "traits": { - "smithy.api#documentation": "

Contains information about the Amazon Web Services resource associated with the activity that prompted GuardDuty to generate a finding.

", - "smithy.api#jsonName": "data" - } - } - }, - "traits": { - "smithy.api#documentation": "

Contains information about the Amazon Web Services resource that is associated with the GuardDuty finding.

" - } - }, - "com.amazonaws.guardduty#Resources": { - "type": "list", - "member": { - "target": "com.amazonaws.guardduty#ResourceV2" - }, - "traits": { - "smithy.api#length": { - "min": 0, - "max": 400 - } - } - }, - "com.amazonaws.guardduty#RiskDetails": { - "type": "string", - "traits": { - "smithy.api#length": { - "min": 0, - "max": 1024 - } - } - }, - "com.amazonaws.guardduty#RiskLevel": { - "type": "enum", - "members": { - "INFO": { - "target": "smithy.api#Unit", + "Service": { + "target": "com.amazonaws.guardduty#DetectionRuleServiceName", "traits": { - "smithy.api#enumValue": "Info" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The Amazon Web Services service associated with the rule.

", + "smithy.api#jsonName": "service", + "smithy.api#required": {} } }, - "LOW": { - "target": "smithy.api#Unit", + "Language": { + "target": "com.amazonaws.guardduty#RuleLanguage", "traits": { - "smithy.api#enumValue": "Low" + "smithy.api#documentation": "

The language used for the detection logic expression.

", + "smithy.api#jsonName": "language" } }, - "MEDIUM": { - "target": "smithy.api#Unit", + "Schema": { + "target": "com.amazonaws.guardduty#RuleSchema", "traits": { - "smithy.api#enumValue": "Medium" + "smithy.api#documentation": "

The schema version used by the rule definition.

", + "smithy.api#jsonName": "schema" } }, - "HIGH": { - "target": "smithy.api#Unit", + "CreatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#enumValue": "High" + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The timestamp when the rule was created.

", + "smithy.api#jsonName": "createdAt", + "smithy.api#required": {} } }, - "CRITICAL": { - "target": "smithy.api#Unit", + "UpdatedAt": { + "target": "com.amazonaws.guardduty#Timestamp", "traits": { - "smithy.api#enumValue": "Critical" + "smithy.api#documentation": "

The timestamp when the rule was last updated.

", + "smithy.api#jsonName": "updatedAt" } } }, "traits": { - "smithy.api#length": { - "min": 1, - "max": 300 - } + "smithy.api#documentation": "

Contains summary information about a custom detection rule.

" + } + }, + "com.amazonaws.guardduty#RuleSummaryList": { + "type": "list", + "member": { + "target": "com.amazonaws.guardduty#RuleSummary" } }, "com.amazonaws.guardduty#RuntimeContext": { @@ -19223,6 +21240,13 @@ "smithy.api#documentation": "

Contains information about the indicators associated with the signals.

", "smithy.api#jsonName": "signalIndicators" } + }, + "Activities": { + "target": "com.amazonaws.guardduty#Activities", + "traits": { + "smithy.api#documentation": "

Contains information about the activities, such as API calls, that were observed for this signal.

", + "smithy.api#jsonName": "activities" + } } }, "traits": { @@ -20456,6 +22480,162 @@ "smithy.api#output": {} } }, + "com.amazonaws.guardduty#UpdateCustomDetectionRuleAssociation": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#UpdateCustomDetectionRuleAssociationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#UpdateCustomDetectionRuleAssociationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#ConflictException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Updates the mode of an existing custom detection rule association.

", + "smithy.api#http": { + "method": "PUT", + "uri": "/custom-detection-rule/rule/{RuleId}/association/{AssociationId}", + "code": 200 + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.guardduty#UpdateCustomDetectionRuleAssociationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "AssociationId": { + "target": "com.amazonaws.guardduty#AssociationId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the association to update.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The rule execution mode. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#UpdateCustomDetectionRuleAssociationResponse": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#output": {} + } + }, + "com.amazonaws.guardduty#UpdateCustomDetectionRuleOrgConfiguration": { + "type": "operation", + "input": { + "target": "com.amazonaws.guardduty#UpdateCustomDetectionRuleOrgConfigurationRequest" + }, + "output": { + "target": "com.amazonaws.guardduty#UpdateCustomDetectionRuleOrgConfigurationResponse" + }, + "errors": [ + { + "target": "com.amazonaws.guardduty#AccessDeniedException" + }, + { + "target": "com.amazonaws.guardduty#BadRequestException" + }, + { + "target": "com.amazonaws.guardduty#ConflictException" + }, + { + "target": "com.amazonaws.guardduty#InternalServerErrorException" + }, + { + "target": "com.amazonaws.guardduty#ResourceNotFoundException" + } + ], + "traits": { + "smithy.api#documentation": "

Updates the organization-level configuration for a custom detection rule, including the mode and include/exclude account lists.

", + "smithy.api#http": { + "method": "PUT", + "uri": "/custom-detection-rule/org-configuration/{RuleId}", + "code": 200 + }, + "smithy.api#idempotent": {} + } + }, + "com.amazonaws.guardduty#UpdateCustomDetectionRuleOrgConfigurationRequest": { + "type": "structure", + "members": { + "RuleId": { + "target": "com.amazonaws.guardduty#RuleId", + "traits": { + "smithy.api#documentation": "

The unique identifier for the custom detection rule.

", + "smithy.api#httpLabel": {}, + "smithy.api#required": {} + } + }, + "Mode": { + "target": "com.amazonaws.guardduty#AssociationMode", + "traits": { + "smithy.api#clientOptional": {}, + "smithy.api#documentation": "

The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

", + "smithy.api#jsonName": "mode", + "smithy.api#required": {} + } + }, + "IncludeAccountIds": { + "target": "com.amazonaws.guardduty#DetectionRuleAccountIds", + "traits": { + "smithy.api#documentation": "

The account IDs to include in the organization configuration. Mutually exclusive with ExcludeAccountIds.

", + "smithy.api#jsonName": "includeAccountIds" + } + }, + "ExcludeAccountIds": { + "target": "com.amazonaws.guardduty#DetectionRuleAccountIds", + "traits": { + "smithy.api#documentation": "

The account IDs to exclude from the organization configuration. Mutually exclusive with IncludeAccountIds.

", + "smithy.api#jsonName": "excludeAccountIds" + } + } + }, + "traits": { + "smithy.api#input": {} + } + }, + "com.amazonaws.guardduty#UpdateCustomDetectionRuleOrgConfigurationResponse": { + "type": "structure", + "members": {}, + "traits": { + "smithy.api#output": {} + } + }, "com.amazonaws.guardduty#UpdateDetector": { "type": "operation", "input": { diff --git a/codegen/aws-models/lambda.json b/codegen/aws-models/lambda.json index 5fc8d322..2e0fa8e5 100644 --- a/codegen/aws-models/lambda.json +++ b/codegen/aws-models/lambda.json @@ -5383,7 +5383,7 @@ "Timeout": { "target": "com.amazonaws.lambda#Timeout", "traits": { - "smithy.api#documentation": "

The amount of time (in seconds) that Lambda allows a function to run before stopping it. The default is 3 seconds. The maximum allowed value is 900 seconds. For more information, see Lambda execution environment.

", + "smithy.api#documentation": "

The amount of time (in seconds) that Lambda allows a function to run before stopping it. The default is 3 seconds, and the maximum allowed value is 900 seconds. For functions using Lambda Managed Instances, asynchronous invocations and event source mapping invocations (except Amazon MQ and Amazon DocumentDB) support a maximum allowed value of 5,400 seconds (90 minutes). For more information, see Lambda execution environment.

", "smithy.api#tags": [ "feature:public" ] @@ -6816,7 +6816,7 @@ }, "smithy.api#idempotent": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -6830,7 +6830,7 @@ "smithy.api#httpLabel": {}, "smithy.api#required": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -6840,7 +6840,7 @@ "smithy.api#documentation": "

The revision ID that the existing policy must match for the deletion to proceed. If the revision ID doesn't match, the operation fails with a PreconditionFailedException error. To retrieve the current revision ID, use the GetResourcePolicy operation.

", "smithy.api#httpQuery": "RevisionId", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } } @@ -6848,7 +6848,7 @@ "traits": { "smithy.api#input": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -6906,6 +6906,43 @@ ] } }, + "com.amazonaws.lambda#DirectS3Read": { + "type": "enum", + "members": { + "ENABLED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "ENABLED", + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } + }, + "DISABLED": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "DISABLED", + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } + }, + "AUTO": { + "target": "smithy.api#Unit", + "traits": { + "smithy.api#enumValue": "AUTO", + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } + } + }, + "traits": { + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } + }, "com.amazonaws.lambda#DocumentDBEventSourceConfig": { "type": "structure", "members": { @@ -6952,7 +6989,7 @@ "traits": { "smithy.api#documentation": "

The ARN of the Key Management Service (KMS) customer managed key that is used to encrypt your durable execution's payload data, including input, output, and error payloads.

", "smithy.api#tags": [ - "feature:dar-cmkms" + "feature:public" ] } }, @@ -9249,10 +9286,19 @@ "feature:public" ] } + }, + "S3FilesConfig": { + "target": "com.amazonaws.lambda#S3FilesConfig", + "traits": { + "smithy.api#documentation": "

The configuration for how your function accesses data on an Amazon S3 file system. Valid only when the file system access point ARN is an Amazon S3 Files access point. If you specify a different access point type (for example, Amazon Elastic File System), the operation returns an InvalidParameterException.

", + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } } }, "traits": { - "smithy.api#documentation": "

Details about the connection between a Lambda function and an Amazon EFS file system or an Amazon S3 Files file system.

", + "smithy.api#documentation": "

Details about the connection between a Lambda function and an Amazon EFS file system or an Amazon S3 file system.

", "smithy.api#tags": [ "feature:public" ] @@ -10033,7 +10079,7 @@ "FileSystemConfigs": { "target": "com.amazonaws.lambda#FileSystemConfigList", "traits": { - "smithy.api#documentation": "

Connection settings for an Amazon EFS file system or an Amazon S3 Files file system.

", + "smithy.api#documentation": "

Connection settings for an Amazon EFS file system or an Amazon S3 file system.

", "smithy.api#tags": [ "feature:public" ] @@ -13350,7 +13396,7 @@ "smithy.api#documentation": "

Retrieves the provisioned concurrency configuration for a function's alias or version.

", "smithy.api#examples": [ { - "documentation": "The following example displays details for the provisioned concurrency configuration for the BLUE alias of the specified function.", + "documentation": "The following example returns details for the provisioned concurrency configuration for the BLUE alias of the specified function.", "input": { "FunctionName": "my-function", "Qualifier": "BLUE" @@ -13362,10 +13408,10 @@ "RequestedProvisionedConcurrentExecutions": 100, "Status": "READY" }, - "title": "To view a provisioned concurrency configuration" + "title": "To get a provisioned concurrency configuration" }, { - "documentation": "The following example returns details for the provisioned concurrency configuration for the BLUE alias of the specified function.", + "documentation": "The following example displays details for the provisioned concurrency configuration for the BLUE alias of the specified function.", "input": { "FunctionName": "my-function", "Qualifier": "BLUE" @@ -13377,7 +13423,7 @@ "RequestedProvisionedConcurrentExecutions": 100, "Status": "READY" }, - "title": "To get a provisioned concurrency configuration" + "title": "To view a provisioned concurrency configuration" } ], "smithy.api#http": { @@ -13532,7 +13578,7 @@ }, "smithy.api#readonly": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -13546,7 +13592,7 @@ "smithy.api#httpLabel": {}, "smithy.api#required": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } } @@ -13554,7 +13600,7 @@ "traits": { "smithy.api#input": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -13566,7 +13612,7 @@ "traits": { "smithy.api#documentation": "

The resource-based policy attached to the Lambda resource you specified.

", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -13575,7 +13621,7 @@ "traits": { "smithy.api#documentation": "

The revision ID of the policy. Pass this value as the RevisionId in a PutResourcePolicy or DeleteResourcePolicy request. Doing so ensures the operation acts on the expected version of the policy.

", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } } @@ -13583,7 +13629,7 @@ "traits": { "smithy.api#output": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -19074,7 +19120,7 @@ "min": 1, "max": 256 }, - "smithy.api#pattern": "^(arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:|(((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?))(function:)?([a-zA-Z0-9-_\\.]+)(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_]+))?$", + "smithy.api#pattern": "^(arn:(aws[a-zA-Z-]*)?:lambda:)?((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_\\.]+)(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_]+))?$", "smithy.api#tags": [ "feature:public" ] @@ -19914,7 +19960,7 @@ }, "smithy.api#pattern": "^arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_]+(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_])+)?$", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -21493,7 +21539,7 @@ }, "smithy.api#idempotent": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -21507,7 +21553,7 @@ "smithy.api#httpLabel": {}, "smithy.api#required": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -21517,7 +21563,7 @@ "smithy.api#documentation": "

The policy document you want to add to your Lambda resource. This is formatted as a JSON string.

For more information, see Working with resource-based policies in Lambda in the Lambda Developer Guide.

", "smithy.api#required": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -21526,7 +21572,7 @@ "traits": { "smithy.api#documentation": "

The revision ID that the existing policy must match for the replacement to proceed. If the revision ID doesn't match, the operation fails with a PreconditionFailedException error. To retrieve the current revision ID, use the GetResourcePolicy operation.

", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } } @@ -21534,7 +21580,7 @@ "traits": { "smithy.api#input": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -21546,7 +21592,7 @@ "traits": { "smithy.api#documentation": "

The resource-based policy that Lambda adds to the resource.

", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -21555,7 +21601,7 @@ "traits": { "smithy.api#documentation": "

The revision ID of the policy that Lambda adds to your Lambda resource.

", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } } @@ -21563,7 +21609,7 @@ "traits": { "smithy.api#output": {}, "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -22268,7 +22314,7 @@ }, "smithy.api#pattern": "^[\\s\\S]+$", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -22359,7 +22405,7 @@ }, "smithy.api#pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$", "smithy.api#tags": [ - "feature:rbp" + "feature:public" ] } }, @@ -22816,7 +22862,7 @@ "traits": { "smithy.api#enumValue": "java8.al2023", "smithy.api#tags": [ - "feature:java-al2023" + "feature:public" ] } }, @@ -22825,7 +22871,7 @@ "traits": { "smithy.api#enumValue": "java11.al2023", "smithy.api#tags": [ - "feature:java-al2023" + "feature:public" ] } }, @@ -22834,7 +22880,7 @@ "traits": { "smithy.api#enumValue": "java17.al2023", "smithy.api#tags": [ - "feature:java-al2023" + "feature:public" ] } } @@ -22929,6 +22975,26 @@ ] } }, + "com.amazonaws.lambda#S3FilesConfig": { + "type": "structure", + "members": { + "DirectS3Read": { + "target": "com.amazonaws.lambda#DirectS3Read", + "traits": { + "smithy.api#documentation": "

Specifies if a function reads from the file system for the lowest latency, or through Amazon S3 Files feature \"direct Amazon S3 bucket reads\" for the highest throughput. Valid values:

To use direct reads, you must grant the execution role the s3:GetObject and s3:GetObjectVersion permissions. If a direct read fails, Lambda automatically falls back to reading through the file system.

", + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } + } + }, + "traits": { + "smithy.api#documentation": "

Setting controls how your function accesses data from an Amazon S3 file system.

", + "smithy.api#tags": [ + "feature:s3files-rbp" + ] + } + }, "com.amazonaws.lambda#S3FilesMountConnectivityException": { "type": "structure", "members": { @@ -26666,7 +26732,7 @@ "Timeout": { "target": "com.amazonaws.lambda#Timeout", "traits": { - "smithy.api#documentation": "

The amount of time (in seconds) that Lambda allows a function to run before stopping it. The default is 3 seconds. The maximum allowed value is 900 seconds. For more information, see Lambda execution environment.

", + "smithy.api#documentation": "

The amount of time (in seconds) that Lambda allows a function to run before stopping it. The default is 3 seconds, and the maximum allowed value is 900 seconds. For functions using Lambda Managed Instances, asynchronous invocations and event source mapping invocations (except Amazon MQ and Amazon DocumentDB) support a maximum allowed value of 5,400 seconds (90 minutes). For more information, see Lambda execution environment.

", "smithy.api#tags": [ "feature:public" ] diff --git a/codegen/aws-models/sns.json b/codegen/aws-models/sns.json index f207a8c9..78fc6083 100644 --- a/codegen/aws-models/sns.json +++ b/codegen/aws-models/sns.json @@ -1974,7 +1974,7 @@ "Attributes": { "target": "com.amazonaws.sns#TopicAttributesMap", "traits": { - "smithy.api#documentation": "

A map of attributes with their corresponding values.

\n

The following lists names, descriptions, and values of the special request parameters\n that the CreateTopic action uses:

\n \n \n

The SuccessFeedbackRoleArn and FailureFeedbackRoleArn\n attributes are used to give Amazon SNS write access to use CloudWatch Logs on your\n behalf. The SuccessFeedbackSampleRate attribute is for specifying the\n sample rate percentage (0-100) of successfully delivered messages. After you\n configure the FailureFeedbackRoleArn attribute, then all failed message\n deliveries generate CloudWatch Logs.

\n
\n

The following attribute applies only to server-side\n encryption:

\n \n

The following attributes apply only to FIFO topics:

\n \n " + "smithy.api#documentation": "

A map of attributes with their corresponding values.

\n

The following lists names, descriptions, and values of the special request parameters\n that the CreateTopic action uses:

\n \n \n

The SuccessFeedbackRoleArn and FailureFeedbackRoleArn\n attributes are used to give Amazon SNS write access to use CloudWatch Logs on your\n behalf. The SuccessFeedbackSampleRate attribute is for specifying the\n sample rate percentage (0-100) of successfully delivered messages. After you\n configure the FailureFeedbackRoleArn attribute, then all failed message\n deliveries generate CloudWatch Logs.

\n
\n

The following attribute applies only to server-side\n encryption:

\n \n

The following attributes apply only to FIFO topics:

\n \n " } }, "Tags": { @@ -1986,7 +1986,7 @@ "DataProtectionPolicy": { "target": "com.amazonaws.sns#attributeValue", "traits": { - "smithy.api#documentation": "

The body of the policy document you want to use for this topic.

\n

You can only add one policy per topic.

\n

The policy must be in JSON string format.

\n

Length Constraints: Maximum length of 30,720.

" + "smithy.api#documentation": "\n

Amazon SNS message data protection is no longer available to new customers. \n For more information and guidance on alternatives, see\nAmazon SNS message data protection availability change.

\n
\n

The body of the policy document you want to use for this topic.

\n

You can only add one policy per topic.

\n

The policy must be in JSON string format.

\n

Length Constraints: Maximum length of 30,720.

" } } }, @@ -2304,7 +2304,7 @@ } ], "traits": { - "smithy.api#documentation": "

Retrieves the specified inline DataProtectionPolicy document that is\n stored in the specified Amazon SNS topic.

" + "smithy.api#documentation": "\n

Amazon SNS message data protection is no longer available to new customers. \n For more information and guidance on alternatives, see\nAmazon SNS message data protection availability change.

\n
\n

Retrieves the specified inline DataProtectionPolicy document that is\n stored in the specified Amazon SNS topic.

" } }, "com.amazonaws.sns#GetDataProtectionPolicyInput": { @@ -2660,7 +2660,7 @@ "Attributes": { "target": "com.amazonaws.sns#TopicAttributesMap", "traits": { - "smithy.api#documentation": "

A map of the topic's attributes. Attributes in this map include the following:

\n \n

The following attribute applies only to server-side-encryption:

\n \n

The following attributes apply only to FIFO topics:

\n " + "smithy.api#documentation": "

A map of the topic's attributes. Attributes in this map include the following:

\n \n

The following attribute applies only to server-side-encryption:

\n \n

The following attributes apply only to FIFO topics:

\n " } } }, @@ -3685,7 +3685,7 @@ } }, "traits": { - "smithy.api#documentation": "

The user-specified message attribute value. For string data types, the value attribute\n has the same restrictions on the content as the message body. For more information, see\n Publish.

\n

Name, type, and value must not be empty or null. In addition, the message body should\n not be empty or null. All parts of the message attribute, including name, type, and\n value, are included in the message size restriction, which is currently 256 KB (262,144\n bytes). For more information, see Amazon SNS message attributes and\n Publishing\n to a mobile phone in the Amazon SNS Developer Guide.\n

" + "smithy.api#documentation": "

The user-specified message attribute value. For string data types, the value attribute\n has the same restrictions on the content as the message body. For more information, see\n Publish.

\n

Name, type, and value must not be empty or null. In addition, the message body should\n not be empty or null. All parts of the message attribute, including name, type, and\n value, are included in the message size restriction, which is 256 KiB (262,144 bytes) by\n default and is determined by the topic's MaximumMessageSize attribute. For\n more information, see Large message payloads,\n Amazon SNS message attributes and\n Publishing\n to a mobile phone in the Amazon SNS Developer Guide.\n

" } }, "com.amazonaws.sns#NotFoundException": { @@ -4064,7 +4064,7 @@ } ], "traits": { - "smithy.api#documentation": "

Publishes up to 10 messages to the specified topic in a single batch. This is a batch\n version of the Publish API. If you try to send more than 10 messages in a\n single batch request, you will receive a TooManyEntriesInBatchRequest\n exception.

\n

For FIFO topics, multiple messages within a single batch are published in the order\n they are sent, and messages are deduplicated within the batch and across batches for\n five minutes.

\n

The result of publishing each message is reported individually in the response.\n Because the batch request can result in a combination of successful and unsuccessful\n actions, you should check for batch errors even when the call returns an HTTP status\n code of 200.

\n

The maximum allowed individual message size and the maximum total payload size (the sum\n of the individual lengths of all of the batched messages) are both 256 KB (262,144\n bytes).

\n \n

The PublishBatch API can send up to 10 messages at a time. If you\n attempt to send more than 10 messages in one request, you will encounter a\n TooManyEntriesInBatchRequest exception. In such cases, split your\n messages into multiple requests, each containing no more than 10 messages.

\n
\n

Some actions take lists of parameters. These lists are specified using the\n param.n notation. Values of n are integers starting from\n 1. For example, a parameter list with two elements\n looks like this:

\n

\n &AttributeName.1=first\n

\n

\n &AttributeName.2=second\n

\n

If you send a batch message to a topic, Amazon SNS publishes the batch message to each\n endpoint that is subscribed to the topic. The format of the batch message depends on the\n notification protocol for each subscribed endpoint.

\n

When a messageId is returned, the batch message is saved, and Amazon SNS\n immediately delivers the message to subscribers.

" + "smithy.api#documentation": "

Publishes up to 10 messages to the specified topic in a single batch. This is a batch\n version of the Publish API. If you try to send more than 10 messages in a\n single batch request, you will receive a TooManyEntriesInBatchRequest\n exception.

\n

For FIFO topics, multiple messages within a single batch are published in the order\n they are sent, and messages are deduplicated within the batch and across batches for\n five minutes.

\n

The result of publishing each message is reported individually in the response.\n Because the batch request can result in a combination of successful and unsuccessful\n actions, you should check for batch errors even when the call returns an HTTP status\n code of 200.

\n

By default, the maximum allowed individual message size and the maximum total payload\n size (the sum of the individual lengths of all of the batched messages) are both 256 KiB\n (262,144 bytes). To publish larger batches, set the topic's\n MaximumMessageSize attribute, which supports values up to 1 MiB\n (1,048,576 bytes). The combined size of all messages in the batch, including each\n message's body and attributes, must not exceed the topic's\n MaximumMessageSize.

\n

For more information, see Large message payloads in\n the Amazon SNS Developer Guide.\n

\n \n

The PublishBatch API can send up to 10 messages at a time. If you\n attempt to send more than 10 messages in one request, you will encounter a\n TooManyEntriesInBatchRequest exception. In such cases, split your\n messages into multiple requests, each containing no more than 10 messages.

\n
\n

Some actions take lists of parameters. These lists are specified using the\n param.n notation. Values of n are integers starting from\n 1. For example, a parameter list with two elements\n looks like this:

\n

\n &AttributeName.1=first\n

\n

\n &AttributeName.2=second\n

\n

If you send a batch message to a topic, Amazon SNS publishes the batch message to each\n endpoint that is subscribed to the topic. The format of the batch message depends on the\n notification protocol for each subscribed endpoint.

\n

When a messageId is returned, the batch message is saved, and Amazon SNS\n immediately delivers the message to subscribers.

" } }, "com.amazonaws.sns#PublishBatchInput": { @@ -4223,7 +4223,7 @@ "Message": { "target": "com.amazonaws.sns#message", "traits": { - "smithy.api#documentation": "

The message you want to send.

\n

If you are publishing to a topic and you want to send the same message to all\n transport protocols, include the text of the message as a String value. If you want to\n send different messages for each transport protocol, set the value of the\n MessageStructure parameter to json and use a JSON object\n for the Message parameter. \n

\n

\n

Constraints:

\n \n

JSON-specific constraints:

\n ", + "smithy.api#documentation": "

The message you want to send.

\n

If you are publishing to a topic and you want to send the same message to all\n transport protocols, include the text of the message as a String value. If you want to\n send different messages for each transport protocol, set the value of the\n MessageStructure parameter to json and use a JSON object\n for the Message parameter. \n

\n

\n

Constraints:

\n \n

JSON-specific constraints:

\n ", "smithy.api#required": {} } }, @@ -4310,7 +4310,7 @@ } ], "traits": { - "smithy.api#documentation": "

Adds or updates an inline policy document that is stored in the specified Amazon SNS\n topic.

" + "smithy.api#documentation": "\n

Amazon SNS message data protection is no longer available to new customers. \n For more information and guidance on alternatives, see\nAmazon SNS message data protection availability change.

\n
\n

Adds or updates an inline policy document that is stored in the specified Amazon SNS\n topic.

" } }, "com.amazonaws.sns#PutDataProtectionPolicyInput": { @@ -4741,7 +4741,7 @@ "AttributeName": { "target": "com.amazonaws.sns#attributeName", "traits": { - "smithy.api#documentation": "

A map of attributes with their corresponding values.

\n

The following lists the names, descriptions, and values of the special request\n parameters that the SetTopicAttributes action uses:

\n \n \n

The SuccessFeedbackRoleArn and FailureFeedbackRoleArn\n attributes are used to give Amazon SNS write access to use CloudWatch Logs on your\n behalf. The SuccessFeedbackSampleRate attribute is for specifying the\n sample rate percentage (0-100) of successfully delivered messages. After you\n configure the FailureFeedbackRoleArn attribute, then all failed message\n deliveries generate CloudWatch Logs.

\n
\n

The following attribute applies only to server-side-encryption:

\n \n

The following attribute applies only to FIFO topics:

\n \n ", + "smithy.api#documentation": "

A map of attributes with their corresponding values.

\n

The following lists the names, descriptions, and values of the special request\n parameters that the SetTopicAttributes action uses:

\n \n \n

The SuccessFeedbackRoleArn and FailureFeedbackRoleArn\n attributes are used to give Amazon SNS write access to use CloudWatch Logs on your\n behalf. The SuccessFeedbackSampleRate attribute is for specifying the\n sample rate percentage (0-100) of successfully delivered messages. After you\n configure the FailureFeedbackRoleArn attribute, then all failed message\n deliveries generate CloudWatch Logs.

\n
\n

The following attribute applies only to server-side-encryption:

\n \n

The following attribute applies only to FIFO topics:

\n \n ", "smithy.api#required": {} } }, diff --git a/codegen/aws-models/sts.json b/codegen/aws-models/sts.json index dcf278bd..fd1a3360 100644 --- a/codegen/aws-models/sts.json +++ b/codegen/aws-models/sts.json @@ -86,7 +86,7 @@ "aws.auth#sigv4", "aws.auth#sigv4a" ], - "smithy.api#documentation": "Security Token Service\n

Security Token Service (STS) enables you to request temporary, limited-privilege \n credentials for users. This guide provides descriptions of the STS API. For \n more information about using this service, see Temporary Security Credentials.

", + "smithy.api#documentation": "Security Token Service\n

Amazon Web Services provides Security Token Service (STS) as a web service that enables you to request temporary,\n limited-privilege credentials for users. This guide describes the STS API. For more\n information, see Temporary Security Credentials\n in the IAM User Guide.

\n \n

As an alternative to using the API, you can use one of the Amazon Web Services SDKs, which consist of\n libraries and sample code for various programming languages and platforms such as Java,\n Ruby, .NET, iOS, Android, and others. The SDKs provide a convenient way to create\n programmatic access to STS. For example, the SDKs can cryptographically sign requests,\n manage errors, and retry requests automatically. For information about the Amazon Web Services SDKs, see\n Tools to Build on Amazon Web Services.

\n
\n

For information about setting up signatures and authorization through the API, see Signing Amazon Web Services\n API Requests in the Amazon Web Services General Reference. For general information\n about the Query API, see Making Query Requests in the\n IAM User Guide. For information about using security tokens with\n other Amazon Web Services products, see Amazon Web Services Services\n That Work with IAM in the IAM User Guide.

\n

For information about STS endpoints, see STS Regions and\n endpoints in the IAM User Guide. For information about\n logging STS API calls, see Logging IAM and STS API calls\n with CloudTrail in the IAM User Guide.

", "smithy.api#title": "AWS Security Token Service", "smithy.api#xmlNamespace": { "uri": "https://sts.amazonaws.com/doc/2011-06-15/" @@ -2769,6 +2769,9 @@ "traits": { "smithy.api#documentation": "

A list of previously acquired trusted context assertions in the format of a JSON array.\n The trusted context assertion is signed and encrypted by Amazon Web Services STS.

\n

The following is an example of a ProvidedContext value that includes a\n single trusted context assertion and the ARN of the context provider from which the trusted\n context assertion was generated.

\n

\n [{\"ProviderArn\":\"arn:aws:iam::aws:contextProvider/IdentityCenter\",\"ContextAssertion\":\"trusted-context-assertion\"}]\n

" } + }, + "MinimumSessionTokenSize": { + "target": "com.amazonaws.sts#minimumSessionTokenSizeType" } }, "traits": { @@ -2793,6 +2796,10 @@ "PackedPolicySize": { "target": "com.amazonaws.sts#nonNegativeIntegerType", "traits": { + "smithy.api#deprecated": { + "since": "2026-06-17", + "message": "Deprecated. Replaced by SessionTokenUtilization." + }, "smithy.api#documentation": "

A percentage value that indicates the packed size of the session policies and session \n tags combined passed in the request. The request fails if the packed size is greater than 100 percent, \n which means the policies and tags exceeded the allowed space.

" } }, @@ -2801,6 +2808,12 @@ "traits": { "smithy.api#documentation": "

The source identity specified by the principal that is calling the\n AssumeRole operation.

\n

You can require users to specify a source identity when they assume a role. You do this\n by using the sts:SourceIdentity condition key in a role trust policy. You can\n use source identity information in CloudTrail logs to determine who took actions with a role.\n You can use the aws:SourceIdentity condition key to further control access to\n Amazon Web Services resources based on the value of source identity. For more information about using\n source identity, see Monitor and control\n actions taken with assumed roles in the\n IAM User Guide.

\n

The regex used to validate this parameter is a string of characters consisting of upper-\n and lower-case alphanumeric characters with no spaces. You can also include underscores or\n any of the following characters: =,.@-

" } + }, + "SessionTokenUtilization": { + "target": "com.amazonaws.sts#sessionTokenUtilizationType" + }, + "SessionTokenSize": { + "target": "com.amazonaws.sts#sessionTokenSizeType" } }, "traits": { @@ -2913,6 +2926,9 @@ "traits": { "smithy.api#documentation": "

The duration, in seconds, of the role session. Your role session lasts for the duration\n that you specify for the DurationSeconds parameter, or until the time\n specified in the SAML authentication response's SessionNotOnOrAfter value,\n whichever is shorter. You can provide a DurationSeconds value from 900 seconds\n (15 minutes) up to the maximum session duration setting for the role. This setting can have\n a value from 1 hour to 12 hours. If you specify a value higher than this setting, the\n operation fails. For example, if you specify a session duration of 12 hours, but your\n administrator set the maximum session duration to 6 hours, your operation fails. To learn\n how to view the maximum value for your role, see View the\n Maximum Session Duration Setting for a Role in the\n IAM User Guide.

\n

By default, the value is set to 3600 seconds.

\n \n

The DurationSeconds parameter is separate from the duration of a console\n session that you might request using the returned credentials. The request to the\n federation endpoint for a console sign-in token takes a SessionDuration\n parameter that specifies the maximum length of the console session. For more\n information, see Creating a URL\n that Enables Federated Users to Access the Amazon Web Services Management Console in the\n IAM User Guide.

\n
" } + }, + "MinimumSessionTokenSize": { + "target": "com.amazonaws.sts#minimumSessionTokenSizeType" } }, "traits": { @@ -2937,6 +2953,10 @@ "PackedPolicySize": { "target": "com.amazonaws.sts#nonNegativeIntegerType", "traits": { + "smithy.api#deprecated": { + "since": "2026-06-17", + "message": "Deprecated. Replaced by SessionTokenUtilization." + }, "smithy.api#documentation": "

A percentage value that indicates the packed size of the session policies and session \n tags combined passed in the request. The request fails if the packed size is greater than 100 percent, \n which means the policies and tags exceeded the allowed space.

" } }, @@ -2975,6 +2995,12 @@ "traits": { "smithy.api#documentation": "

The value in the SourceIdentity attribute in the SAML assertion. The source\n identity value persists across chained role\n sessions.

\n

You can require users to set a source identity value when they assume a role. You do\n this by using the sts:SourceIdentity condition key in a role trust policy.\n That way, actions that are taken with the role are associated with that user. After the\n source identity is set, the value cannot be changed. It is present in the request for all\n actions that are taken by the role and persists across chained role\n sessions. You can configure your SAML identity provider to use an attribute associated with\n your users, like user name or email, as the source identity when calling\n AssumeRoleWithSAML. You do this by adding an attribute to the SAML\n assertion. For more information about using source identity, see Monitor and control\n actions taken with assumed roles in the\n IAM User Guide.

\n

The regex used to validate this parameter is a string of characters \n consisting of upper- and lower-case alphanumeric characters with no spaces. You can \n also include underscores or any of the following characters: =,.@-

" } + }, + "SessionTokenUtilization": { + "target": "com.amazonaws.sts#sessionTokenUtilizationType" + }, + "SessionTokenSize": { + "target": "com.amazonaws.sts#sessionTokenSizeType" } }, "traits": { @@ -3096,6 +3122,9 @@ "traits": { "smithy.api#documentation": "

The duration, in seconds, of the role session. The value can range from 900 seconds (15\n minutes) up to the maximum session duration setting for the role. This setting can have a\n value from 1 hour to 12 hours. If you specify a value higher than this setting, the\n operation fails. For example, if you specify a session duration of 12 hours, but your\n administrator set the maximum session duration to 6 hours, your operation fails. To learn\n how to view the maximum value for your role, see View the\n Maximum Session Duration Setting for a Role in the\n IAM User Guide.

\n

By default, the value is set to 3600 seconds.

\n \n

The DurationSeconds parameter is separate from the duration of a console\n session that you might request using the returned credentials. The request to the\n federation endpoint for a console sign-in token takes a SessionDuration\n parameter that specifies the maximum length of the console session. For more\n information, see Creating a URL\n that Enables Federated Users to Access the Amazon Web Services Management Console in the\n IAM User Guide.

\n
" } + }, + "MinimumSessionTokenSize": { + "target": "com.amazonaws.sts#minimumSessionTokenSizeType" } }, "traits": { @@ -3126,6 +3155,10 @@ "PackedPolicySize": { "target": "com.amazonaws.sts#nonNegativeIntegerType", "traits": { + "smithy.api#deprecated": { + "since": "2026-06-17", + "message": "Deprecated. Replaced by SessionTokenUtilization." + }, "smithy.api#documentation": "

A percentage value that indicates the packed size of the session policies and session \n tags combined passed in the request. The request fails if the packed size is greater than 100 percent, \n which means the policies and tags exceeded the allowed space.

" } }, @@ -3146,6 +3179,12 @@ "traits": { "smithy.api#documentation": "

The value of the source identity that is returned in the JSON web token (JWT) from the\n identity provider.

\n

You can require users to set a source identity value when they assume a role. You do\n this by using the sts:SourceIdentity condition key in a role trust policy.\n That way, actions that are taken with the role are associated with that user. After the\n source identity is set, the value cannot be changed. It is present in the request for all\n actions that are taken by the role and persists across chained role\n sessions. You can configure your identity provider to use an attribute associated with your\n users, like user name or email, as the source identity when calling\n AssumeRoleWithWebIdentity. You do this by adding a claim to the JSON web\n token. To learn more about OIDC tokens and claims, see Using Tokens with User Pools in the Amazon Cognito Developer Guide.\n For more information about using source identity, see Monitor and control\n actions taken with assumed roles in the\n IAM User Guide.

\n

The regex used to validate this parameter is a string of characters \n consisting of upper- and lower-case alphanumeric characters with no spaces. You can \n also include underscores or any of the following characters: =,.@-

" } + }, + "SessionTokenUtilization": { + "target": "com.amazonaws.sts#sessionTokenUtilizationType" + }, + "SessionTokenSize": { + "target": "com.amazonaws.sts#sessionTokenSizeType" } }, "traits": { @@ -3217,6 +3256,9 @@ "traits": { "smithy.api#documentation": "

The duration, in seconds, of the privileged session. The value can range from 0 seconds\n up to the maximum session duration of 900 seconds (15 minutes). If you specify a value\n higher than this setting, the operation fails.

\n

By default, the value is set to 900 seconds.

" } + }, + "MinimumSessionTokenSize": { + "target": "com.amazonaws.sts#minimumSessionTokenSizeType" } }, "traits": { @@ -3237,6 +3279,12 @@ "traits": { "smithy.api#documentation": "

The source identity specified by the principal that is calling the\n AssumeRoot operation.

\n

You can use the aws:SourceIdentity condition key to control access based on\n the value of source identity. For more information about using source identity, see Monitor and control\n actions taken with assumed roles in the\n IAM User Guide.

\n

The regex used to validate this parameter is a string of characters consisting of upper-\n and lower-case alphanumeric characters with no spaces. You can also include underscores or\n any of the following characters: =,.@-

" } + }, + "SessionTokenUtilization": { + "target": "com.amazonaws.sts#sessionTokenUtilizationType" + }, + "SessionTokenSize": { + "target": "com.amazonaws.sts#sessionTokenSizeType" } }, "traits": { @@ -3582,6 +3630,10 @@ "PackedPolicySize": { "target": "com.amazonaws.sts#nonNegativeIntegerType", "traits": { + "smithy.api#deprecated": { + "since": "2026-06-17", + "message": "Deprecated. This field is not populated for GetDelegatedAccessToken." + }, "smithy.api#documentation": "

The percentage of the maximum policy size that is used by the session policy. The policy\n size is calculated as the sum of all the session policies and permission boundaries\n attached to the session. If the packed size exceeds 100%, the request fails.

" } }, @@ -3686,6 +3738,9 @@ "traits": { "smithy.api#documentation": "

A list of session tags. Each session tag consists of a key name and an associated value.\n For more information about session tags, see Passing Session Tags in STS in the\n IAM User Guide.

\n

This parameter is optional. You can pass up to 50 session tags. The plaintext session\n tag keys can’t exceed 128 characters and the values can’t exceed 256 characters. For these\n and additional limits, see IAM\n and STS Character Limits in the IAM User Guide.

\n \n

An Amazon Web Services conversion compresses the passed inline session policy, managed policy ARNs,\n and session tags into a packed binary format that has a separate limit. Your request can\n fail for this limit even if your plaintext meets the other requirements. The\n PackedPolicySize response element indicates by percentage how close the\n policies and tags for your request are to the upper size limit.

\n
\n

You can pass a session tag with the same key as a tag that is already attached to the\n user you are federating. When you do, session tags override a user tag with the same key.

\n

Tag key–value pairs are not case sensitive, but case is preserved. This means that you\n cannot have separate Department and department tag keys. Assume\n that the role has the Department=Marketing tag and you pass the\n department=engineering session tag. Department\n and department are not saved as separate tags, and the session tag passed in\n the request takes precedence over the role tag.

" } + }, + "MinimumSessionTokenSize": { + "target": "com.amazonaws.sts#minimumSessionTokenSizeType" } }, "traits": { @@ -3710,8 +3765,18 @@ "PackedPolicySize": { "target": "com.amazonaws.sts#nonNegativeIntegerType", "traits": { + "smithy.api#deprecated": { + "since": "2026-06-17", + "message": "Deprecated. Replaced by SessionTokenUtilization." + }, "smithy.api#documentation": "

A percentage value that indicates the packed size of the session policies and session \n tags combined passed in the request. The request fails if the packed size is greater than 100 percent, \n which means the policies and tags exceeded the allowed space.

" } + }, + "SessionTokenUtilization": { + "target": "com.amazonaws.sts#sessionTokenUtilizationType" + }, + "SessionTokenSize": { + "target": "com.amazonaws.sts#sessionTokenSizeType" } }, "traits": { @@ -3775,6 +3840,9 @@ "traits": { "smithy.api#documentation": "

The value provided by the MFA device, if MFA is required. If any policy requires the\n IAM user to submit an MFA code, specify this value. If MFA authentication\n is required, the user must provide a code when requesting a set of temporary security\n credentials. A user who fails to provide the code receives an \"access denied\" response when\n requesting resources that require MFA authentication.

\n

The format for this parameter, as described by its regex pattern, is a sequence of six\n numeric digits.

" } + }, + "MinimumSessionTokenSize": { + "target": "com.amazonaws.sts#minimumSessionTokenSizeType" } }, "traits": { @@ -3789,6 +3857,12 @@ "traits": { "smithy.api#documentation": "

The temporary security credentials, which include an access key ID, a secret access key,\n and a security (or session) token.

\n \n

The size of the security token that STS API operations return is not fixed. We\n strongly recommend that you make no assumptions about the maximum size.

\n
" } + }, + "SessionTokenUtilization": { + "target": "com.amazonaws.sts#sessionTokenUtilizationType" + }, + "SessionTokenSize": { + "target": "com.amazonaws.sts#sessionTokenSizeType" } }, "traits": { @@ -3816,7 +3890,7 @@ } ], "traits": { - "smithy.api#documentation": "

Returns a signed JSON Web Token (JWT) that represents the calling Amazon Web Services identity. \n The returned JWT can be used to authenticate with external services that support OIDC discovery. \n The token is signed by Amazon Web Services STS and can be publicly verified using the verification keys published at the issuer's JWKS endpoint.

" + "smithy.api#documentation": "

Returns a signed JSON Web Token (JWT) that represents the calling Amazon Web Services identity. \n The returned JWT can be used to authenticate with external services that support OIDC discovery. \n The token is signed by Amazon Web Services STS and can be publicly verified using the verification keys published at the issuer's JWKS endpoint.

\n \n

The GetWebIdentityToken API is not available on the STS Global endpoint.

\n
" } }, "com.amazonaws.sts#GetWebIdentityTokenRequest": { @@ -4292,6 +4366,16 @@ "com.amazonaws.sts#malformedPolicyDocumentMessage": { "type": "string" }, + "com.amazonaws.sts#minimumSessionTokenSizeType": { + "type": "integer", + "traits": { + "smithy.api#documentation": "The minimum size, in bytes, of the session token that STS issues for the request. STS increases\n the session token to at least this size, regardless of its actual content. The value must not\n exceed 4,096 bytes. When set to 0 or not specified, the session token size is unchanged.", + "smithy.api#range": { + "min": 0, + "max": 4096 + } + } + }, "com.amazonaws.sts#nonNegativeIntegerType": { "type": "integer", "traits": { @@ -4351,6 +4435,24 @@ "smithy.api#pattern": "^[\\u0009\\u000A\\u000D\\u0020-\\u00FF]+$" } }, + "com.amazonaws.sts#sessionTokenSizeType": { + "type": "integer", + "traits": { + "smithy.api#documentation": "The size, in bytes, of the session token returned in the Credentials for this response.", + "smithy.api#range": { + "min": 0 + } + } + }, + "com.amazonaws.sts#sessionTokenUtilizationType": { + "type": "integer", + "traits": { + "smithy.api#documentation": "The percentage (0-100) of the maximum allowed session token size that the returned session\n token consumes.", + "smithy.api#range": { + "min": 0 + } + } + }, "com.amazonaws.sts#sourceIdentityType": { "type": "string", "traits": { From 6af7bda11afd4964730d975d0e93feecc4354ec0 Mon Sep 17 00:00:00 2001 From: jonathan343 Date: Thu, 1 Oct 2026 13:18:38 -0400 Subject: [PATCH 2/4] Remove duplicate entry --- ...e-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json | 4 ---- 1 file changed, 4 deletions(-) delete mode 100644 clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json diff --git a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json b/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json deleted file mode 100644 index d72660e9..00000000 --- a/clients/aws-sdk-bedrock-agentcore-control/.changes/next-release/aws-sdk-bedrock-agentcore-control-api-change-b67e2191d0fb48b19ba4f91d3af999cd.json +++ /dev/null @@ -1,4 +0,0 @@ -{ - "type": "api-change", - "description": "Update Dataset schema to THIRDPARTYEVALUATIONV1." -} \ No newline at end of file From 6bba9911f8ac0cbc719fd0a843179f0445344c77 Mon Sep 17 00:00:00 2001 From: jonathan343 Date: Tue, 6 Oct 2026 22:48:20 -0400 Subject: [PATCH 3/4] Update to latest bedrock-agent model and add changelog entry --- ...ange-014756dbdebc4b7a99fc6fa845652a89.json | 4 + codegen/aws-models/bedrock-agent.json | 12 ++ update_codegen_models.py | 113 ++++++++++++++++++ 3 files changed, 129 insertions(+) create mode 100644 clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-014756dbdebc4b7a99fc6fa845652a89.json create mode 100755 update_codegen_models.py diff --git a/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-014756dbdebc4b7a99fc6fa845652a89.json b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-014756dbdebc4b7a99fc6fa845652a89.json new file mode 100644 index 00000000..3b341360 --- /dev/null +++ b/clients/aws-sdk-bedrock-agent/.changes/next-release/aws-sdk-bedrock-agent-api-change-014756dbdebc4b7a99fc6fa845652a89.json @@ -0,0 +1,4 @@ +{ + "type": "api-change", + "description": "Adds an optional textReadyAt field to ListIngestionJobs and GetIngestionJob for Managed Knowledge Bases data source sync jobs. The field denotes the timestamp at which all the documents in the scope of a sync job had their text content indexed and are available for retrieval." +} \ No newline at end of file diff --git a/codegen/aws-models/bedrock-agent.json b/codegen/aws-models/bedrock-agent.json index 928acd54..82c19114 100644 --- a/codegen/aws-models/bedrock-agent.json +++ b/codegen/aws-models/bedrock-agent.json @@ -11121,6 +11121,12 @@ "smithy.api#documentation": "

The time the data ingestion job was last updated.

If you stop a data ingestion job, the updatedAt time is the time the job was stopped.

", "smithy.api#required": {} } + }, + "textReadyAt": { + "target": "com.amazonaws.bedrockagent#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The time at which all text content in the data ingestion job finished extraction and became available to query.

This time isn't returned until text extraction is complete for all the documents in the job.

" + } } }, "traits": { @@ -11430,6 +11436,12 @@ "smithy.api#required": {} } }, + "textReadyAt": { + "target": "com.amazonaws.bedrockagent#DateTimestamp", + "traits": { + "smithy.api#documentation": "

The time at which all text content in the data ingestion job finished extraction and became available to query.

This time isn't returned until text extraction is complete for all the documents in the job.

" + } + }, "statistics": { "target": "com.amazonaws.bedrockagent#IngestionJobStatistics", "traits": { diff --git a/update_codegen_models.py b/update_codegen_models.py new file mode 100755 index 00000000..c8dd617c --- /dev/null +++ b/update_codegen_models.py @@ -0,0 +1,113 @@ +#!/usr/bin/env python3 +"""Update the selected codegen models from a local aws-models checkout.""" + +from __future__ import annotations + +import argparse +import shutil +import subprocess +from pathlib import Path + + +DEFAULT_AWS_MODELS_REPO = Path("~/dev/GitHub/aws-models").expanduser() +MODEL_DIRECTORY_OVERRIDES = { + "api-gateway": "apigateway", + "lex-runtime-v2": "runtime.lex.v2", + "secrets-manager": "secretsmanager" +} + + +def run_git(repository: Path, *arguments: str) -> str: + result = subprocess.run( + ["git", "-C", str(repository), *arguments], + check=True, + stdout=subprocess.PIPE, + text=True, + ) + return result.stdout.strip() + + +def update_aws_models(repository: Path) -> None: + if not (repository / ".git").exists(): + raise RuntimeError(f"{repository} is not a Git repository") + + tracked_changes = run_git( + repository, "status", "--porcelain", "--untracked-files=no" + ) + if tracked_changes: + raise RuntimeError( + f"{repository} has tracked changes; refusing to update it" + ) + + remotes = set(run_git(repository, "remote").splitlines()) + remote = "upstream" if "upstream" in remotes else "origin" + if remote not in remotes: + raise RuntimeError( + f"{repository} has neither an upstream nor an origin remote" + ) + + run_git(repository, "switch", "master") + run_git(repository, "pull", "--ff-only", remote, "master") + + +def copy_codegen_models(repository: Path, destination: Path) -> int: + destination_models = sorted(destination.glob("*.json")) + if not destination_models: + raise RuntimeError(f"no model files found in {destination}") + + copies: list[tuple[Path, Path]] = [] + for destination_model in destination_models: + service_name = destination_model.stem + source_directory = MODEL_DIRECTORY_OVERRIDES.get( + service_name, service_name + ) + source_model = repository / source_directory / "smithy" / "model.json" + if not source_model.is_file(): + raise RuntimeError( + f"no Smithy model found for {service_name}: {source_model}" + ) + copies.append((source_model, destination_model)) + + for source_model, destination_model in copies: + shutil.copyfile(source_model, destination_model) + print(f"Copied {source_model} -> {destination_model}") + + return len(copies) + + +def parse_args() -> argparse.Namespace: + parser = argparse.ArgumentParser( + description=( + "Update aws-models and copy Smithy models for the services already " + "present in codegen/aws-models." + ) + ) + parser.add_argument( + "--aws-models-repo", + type=Path, + default=DEFAULT_AWS_MODELS_REPO, + help=f"aws-models checkout (default: {DEFAULT_AWS_MODELS_REPO})", + ) + parser.add_argument( + "--skip-update", + action="store_true", + help="copy models without updating the aws-models checkout", + ) + return parser.parse_args() + + +def main() -> None: + args = parse_args() + aws_models_repo = args.aws_models_repo.expanduser().resolve() + repository_root = Path(__file__).resolve().parent + destination = repository_root / "codegen" / "aws-models" + + if not args.skip_update: + update_aws_models(aws_models_repo) + + count = copy_codegen_models(aws_models_repo, destination) + print(f"Updated {count} codegen models.") + + +if __name__ == "__main__": + main() From e869a6818d07fa6c4b3df9981db8fee695b1050e Mon Sep 17 00:00:00 2001 From: jonathan343 Date: Tue, 6 Oct 2026 23:02:35 -0400 Subject: [PATCH 4/4] Remove model sync script --- update_codegen_models.py | 113 --------------------------------------- 1 file changed, 113 deletions(-) delete mode 100755 update_codegen_models.py diff --git a/update_codegen_models.py b/update_codegen_models.py deleted file mode 100755 index c8dd617c..00000000 --- a/update_codegen_models.py +++ /dev/null @@ -1,113 +0,0 @@ -#!/usr/bin/env python3 -"""Update the selected codegen models from a local aws-models checkout.""" - -from __future__ import annotations - -import argparse -import shutil -import subprocess -from pathlib import Path - - -DEFAULT_AWS_MODELS_REPO = Path("~/dev/GitHub/aws-models").expanduser() -MODEL_DIRECTORY_OVERRIDES = { - "api-gateway": "apigateway", - "lex-runtime-v2": "runtime.lex.v2", - "secrets-manager": "secretsmanager" -} - - -def run_git(repository: Path, *arguments: str) -> str: - result = subprocess.run( - ["git", "-C", str(repository), *arguments], - check=True, - stdout=subprocess.PIPE, - text=True, - ) - return result.stdout.strip() - - -def update_aws_models(repository: Path) -> None: - if not (repository / ".git").exists(): - raise RuntimeError(f"{repository} is not a Git repository") - - tracked_changes = run_git( - repository, "status", "--porcelain", "--untracked-files=no" - ) - if tracked_changes: - raise RuntimeError( - f"{repository} has tracked changes; refusing to update it" - ) - - remotes = set(run_git(repository, "remote").splitlines()) - remote = "upstream" if "upstream" in remotes else "origin" - if remote not in remotes: - raise RuntimeError( - f"{repository} has neither an upstream nor an origin remote" - ) - - run_git(repository, "switch", "master") - run_git(repository, "pull", "--ff-only", remote, "master") - - -def copy_codegen_models(repository: Path, destination: Path) -> int: - destination_models = sorted(destination.glob("*.json")) - if not destination_models: - raise RuntimeError(f"no model files found in {destination}") - - copies: list[tuple[Path, Path]] = [] - for destination_model in destination_models: - service_name = destination_model.stem - source_directory = MODEL_DIRECTORY_OVERRIDES.get( - service_name, service_name - ) - source_model = repository / source_directory / "smithy" / "model.json" - if not source_model.is_file(): - raise RuntimeError( - f"no Smithy model found for {service_name}: {source_model}" - ) - copies.append((source_model, destination_model)) - - for source_model, destination_model in copies: - shutil.copyfile(source_model, destination_model) - print(f"Copied {source_model} -> {destination_model}") - - return len(copies) - - -def parse_args() -> argparse.Namespace: - parser = argparse.ArgumentParser( - description=( - "Update aws-models and copy Smithy models for the services already " - "present in codegen/aws-models." - ) - ) - parser.add_argument( - "--aws-models-repo", - type=Path, - default=DEFAULT_AWS_MODELS_REPO, - help=f"aws-models checkout (default: {DEFAULT_AWS_MODELS_REPO})", - ) - parser.add_argument( - "--skip-update", - action="store_true", - help="copy models without updating the aws-models checkout", - ) - return parser.parse_args() - - -def main() -> None: - args = parse_args() - aws_models_repo = args.aws_models_repo.expanduser().resolve() - repository_root = Path(__file__).resolve().parent - destination = repository_root / "codegen" / "aws-models" - - if not args.skip_update: - update_aws_models(aws_models_repo) - - count = copy_codegen_models(aws_models_repo, destination) - print(f"Updated {count} codegen models.") - - -if __name__ == "__main__": - main()