Key
- Implements: IKey
This class encapsulates and extends the ROS resource type ALIYUN::KMS::Key.
Initializers
import ros_cdk_kms
ros_cdk_kms.Key(
scope: Construct,
id: str,
deletion_protection: typing.Union[bool, IResolvable] = None,
description: typing.Union[str, IResolvable] = None,
dkms_instance_id: typing.Union[str, IResolvable] = None,
enable: typing.Union[bool, IResolvable] = None,
enable_automatic_rotation: typing.Union[bool, IResolvable] = None,
key_spec: typing.Union[str, IResolvable] = None,
key_usage: typing.Union[str, IResolvable] = None,
pending_window_in_days: typing.Union[typing.Union[int, float], IResolvable] = None,
policy: typing.Union[IResolvable, typing.Mapping[typing.Any]] = None,
protection_level: typing.Union[str, IResolvable] = None,
rotation_interval: typing.Union[str, IResolvable] = None,
tags: typing.List[TagsProperty] = None,
enable_resource_property_constraint: bool = None
)
| Name | Type | Description |
|---|---|---|
scope | ros_cdk_core.Construct | No description. |
id | str | No description. |
deletion_protection | typing.Union[bool, ros_cdk_core.IResolvable] | Property deletionProtection: Specifies whether to enable the release protection feature for the key. |
description | typing.Union[str, ros_cdk_core.IResolvable] | Property description: The description of the CMK. |
dkms_instance_id | typing.Union[str, ros_cdk_core.IResolvable] | Property dkmsInstanceId: The ID of the KMS instance. |
enable | typing.Union[bool, ros_cdk_core.IResolvable] | Property enable: Specifies whether the key is enabled. |
enable_automatic_rotation | typing.Union[bool, ros_cdk_core.IResolvable] | Property enableAutomaticRotation: Whether to enable automatic key rotation. |
key_spec | typing.Union[str, ros_cdk_core.IResolvable] | Property keySpec: Key type. |
key_usage | typing.Union[str, ros_cdk_core.IResolvable] | Property keyUsage: The usage of the CMK. |
pending_window_in_days | typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable] | Property pendingWindowInDays: The waiting period, specified in number of days. |
policy | typing.Union[ros_cdk_core.IResolvable, typing.Mapping[typing.Any]] | Property policy: The policy of key. |
protection_level | typing.Union[str, ros_cdk_core.IResolvable] | Property protectionLevel: You do not need to specify this parameter. |
rotation_interval | typing.Union[str, ros_cdk_core.IResolvable] | Property rotationInterval: The automatic rotation period. |
tags | typing.List[TagsProperty] | Property tags: Tags to attach to key. |
enable_resource_property_constraint | bool | No description. |
scopeRequired
- Type: ros_cdk_core.Construct
idRequired
- Type: str
deletion_protectionOptional
- Type: typing.Union[bool, ros_cdk_core.IResolvable]
Property deletionProtection: Specifies whether to enable the release protection feature for the key.
Default is false.
descriptionOptional
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Property description: The description of the CMK.
Length constraints: Minimum length of 0 characters. Maximum length of 8192 characters.
dkms_instance_idOptional
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Property dkmsInstanceId: The ID of the KMS instance.
This parameter is required when you create a key for a KMS instance. This parameter is not required when you create a default key (master key).
enableOptional
- Type: typing.Union[bool, ros_cdk_core.IResolvable]
Property enable: Specifies whether the key is enabled.
Defaults to true.
enable_automatic_rotationOptional
- Type: typing.Union[bool, ros_cdk_core.IResolvable]
Property enableAutomaticRotation: Whether to enable automatic key rotation.
Valid value: true/false (default)
key_specOptional
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Property keySpec: Key type.
Valid value: Aliyun_AES_256/Aliyun_SM4/RSA_2048/EC_P256/EC_P256K/EC_SM2
key_usageOptional
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Property keyUsage: The usage of the CMK.
Valid values: ENCRYPT/DECRYPT: encrypts or decrypts data. SIGN/VERIFY: generates or verifies a digital signature. If the CMK supports signature verification, the default value is SIGN/VERIFY. If the CMK does not support signature verification, the default value is ENCRYPT/DECRYPT.
pending_window_in_daysOptional
- Type: typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable]
Property pendingWindowInDays: The waiting period, specified in number of days.
During this period, you can cancel the CMK in PendingDeletion status. After the waiting period expires, you cannot cancel the deletion. The value must be between 7 and 366. Default value is 30.
policyOptional
- Type: typing.Union[ros_cdk_core.IResolvable, typing.Mapping[typing.Any]]
Property policy: The policy of key.
protection_levelOptional
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Property protectionLevel: You do not need to specify this parameter.
KMS automatically sets an appropriate protection level for your key. The protection level of the key. Valid values:
- SOFTWARE
- HSM
- If you specify DKMSInstanceId, this parameter is ignored. If the instance is a software key management instance, the protection level is SOFTWARE. If the instance is a hardware key management instance, the protection level is HSM.
- If you do not specify DKMSInstanceId, leave this parameter empty. KMS sets the protection level. If a managed HSM is available in the region, KMS sets this parameter to HSM. Otherwise, KMS sets this parameter to SOFTWARE. For more information, see Managed HSM overview.
rotation_intervalOptional
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Property rotationInterval: The automatic rotation period.
The format is integer[unit]. integer indicates the length of the period. unit indicates the unit of time. Valid units: d (day), h (hour), m (minute), and s (second). For example, both 7d and 604800s represent a period of 7 days.
- If the key is a default key, the value is 365d.
- If the key is a software-protected key, the value can be from 7d to 365d.
- If the key is a hardware-protected key, automatic rotation is not supported.
This parameter is required if you set EnableAutomaticRotation to true.
tagsOptional
- Type: typing.List[TagsProperty]
Property tags: Tags to attach to key.
Max support 20 tags to add during create key. Each tag with two properties Key and Value, and Key is required.
enable_resource_property_constraintOptional
- Type: bool
Methods
| Name | Description |
|---|---|
to_string | Returns a string representation of this construct. |
synthesize | Allows this construct to emit artifacts into the cloud assembly during synthesis. |
add_condition | No description. |
add_count | No description. |
add_dependency | No description. |
add_resource_desc | No description. |
apply_removal_policy | No description. |
fetch_condition | No description. |
fetch_dependency | No description. |
fetch_resource_desc | No description. |
get_att | No description. |
set_metadata | No description. |
to_string
def to_string() -> str
Returns a string representation of this construct.
synthesize
def synthesize(
session: ISynthesisSession
) -> None
Allows this construct to emit artifacts into the cloud assembly during synthesis.
This method is usually implemented by framework-level constructs such as Stack and Asset as they participate in synthesizing the cloud assembly.
- Type: ros_cdk_core.ISynthesisSession
The synthesis session.
add_condition
def add_condition(
condition: RosCondition
) -> None
- Type: ros_cdk_core.RosCondition
add_count
def add_count(
count: typing.Union[typing.Union[int, float], IResolvable]
) -> None
- Type: typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable]
add_dependency
def add_dependency(
resource: Resource
) -> None
- Type: ros_cdk_core.Resource
add_resource_desc
def add_resource_desc(
desc: str
) -> None
- Type: str
apply_removal_policy
def apply_removal_policy(
policy: RemovalPolicy
) -> None
- Type: ros_cdk_core.RemovalPolicy
fetch_condition
def fetch_condition() -> RosCondition
fetch_dependency
def fetch_dependency() -> typing.List[str]
fetch_resource_desc
def fetch_resource_desc() -> str
get_att
def get_att(
name: str
) -> IResolvable
- Type: str
set_metadata
def set_metadata(
key: str,
value: typing.Any
) -> None
- Type: str
- Type: typing.Any
Static Functions
| Name | Description |
|---|---|
is_construct | Return whether the given object is a Construct. |
is_construct
import ros_cdk_kms
ros_cdk_kms.Key.is_construct(
x: typing.Any
)
Return whether the given object is a Construct.
- Type: typing.Any
Properties
| Name | Type | Description |
|---|---|---|
node | ros_cdk_core.ConstructNode | The construct tree node associated with this construct. |
env | ros_cdk_core.IResourceEnvironment | The environment this resource belongs to. |
ref | str | No description. |
stack | ros_cdk_core.Stack | The stack in which this resource is defined. |
resource | ros_cdk_core.RosResource | No description. |
attr_key_id | typing.Union[str, ros_cdk_core.IResolvable] | Attribute KeyId: The globally unique identifier for the CMK. |
props | KeyProps | No description. |
nodeRequired
node: ConstructNode
- Type: ros_cdk_core.ConstructNode
The construct tree node associated with this construct.
envRequired
env: IResourceEnvironment
- Type: ros_cdk_core.IResourceEnvironment
The environment this resource belongs to.
For resources that are created and managed by the CDK (generally, those created by creating new class instances like Role, Bucket, etc.), this is always the same as the environment of the stack they belong to; however, for imported resources (those obtained from static methods like fromRoleArn, fromBucketName, etc.), that might be different than the stack they were imported into.
refRequired
ref: str
- Type: str
stackRequired
stack: Stack
- Type: ros_cdk_core.Stack
The stack in which this resource is defined.
resourceOptional
resource: RosResource
- Type: ros_cdk_core.RosResource
attr_key_idRequired
attr_key_id: typing.Union[str, IResolvable]
- Type: typing.Union[str, ros_cdk_core.IResolvable]
Attribute KeyId: The globally unique identifier for the CMK.
propsRequired
props: KeyProps
- Type: KeyProps