Skip to content

KeyProps

Properties for defining a Key.

See https://www.alibabacloud.com/help/ros/developer-reference/aliyun-kms-key

Initializer

import ros_cdk_kms
ros_cdk_kms.KeyProps(
  deletion_protection: typing.Union[bool, IResolvable] = None,
  description: typing.Union[str, IResolvable] = None,
  dkms_instance_id: typing.Union[str, IResolvable] = None,
  enable: typing.Union[bool, IResolvable] = None,
  enable_automatic_rotation: typing.Union[bool, IResolvable] = None,
  key_spec: typing.Union[str, IResolvable] = None,
  key_usage: typing.Union[str, IResolvable] = None,
  pending_window_in_days: typing.Union[typing.Union[int, float], IResolvable] = None,
  policy: typing.Union[IResolvable, typing.Mapping[typing.Any]] = None,
  protection_level: typing.Union[str, IResolvable] = None,
  rotation_interval: typing.Union[str, IResolvable] = None,
  tags: typing.List[TagsProperty] = None
)

Properties

Name Type Description
deletion_protection typing.Union[bool, ros_cdk_core.IResolvable] Property deletionProtection: Specifies whether to enable the release protection feature for the key.
description typing.Union[str, ros_cdk_core.IResolvable] Property description: The description of the CMK.
dkms_instance_id typing.Union[str, ros_cdk_core.IResolvable] Property dkmsInstanceId: The ID of the KMS instance.
enable typing.Union[bool, ros_cdk_core.IResolvable] Property enable: Specifies whether the key is enabled.
enable_automatic_rotation typing.Union[bool, ros_cdk_core.IResolvable] Property enableAutomaticRotation: Whether to enable automatic key rotation.
key_spec typing.Union[str, ros_cdk_core.IResolvable] Property keySpec: Key type.
key_usage typing.Union[str, ros_cdk_core.IResolvable] Property keyUsage: The usage of the CMK.
pending_window_in_days typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable] Property pendingWindowInDays: The waiting period, specified in number of days.
policy typing.Union[ros_cdk_core.IResolvable, typing.Mapping[typing.Any]] Property policy: The policy of key.
protection_level typing.Union[str, ros_cdk_core.IResolvable] Property protectionLevel: You do not need to specify this parameter.
rotation_interval typing.Union[str, ros_cdk_core.IResolvable] Property rotationInterval: The automatic rotation period.
tags typing.List[TagsProperty] Property tags: Tags to attach to key.

deletion_protectionOptional

deletion_protection: typing.Union[bool, IResolvable]
  • Type: typing.Union[bool, ros_cdk_core.IResolvable]

Property deletionProtection: Specifies whether to enable the release protection feature for the key.

Default is false.


descriptionOptional

description: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property description: The description of the CMK.

Length constraints: Minimum length of 0 characters. Maximum length of 8192 characters.


dkms_instance_idOptional

dkms_instance_id: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property dkmsInstanceId: The ID of the KMS instance.

This parameter is required when you create a key for a KMS instance. This parameter is not required when you create a default key (master key).


enableOptional

enable: typing.Union[bool, IResolvable]
  • Type: typing.Union[bool, ros_cdk_core.IResolvable]

Property enable: Specifies whether the key is enabled.

Defaults to true.


enable_automatic_rotationOptional

enable_automatic_rotation: typing.Union[bool, IResolvable]
  • Type: typing.Union[bool, ros_cdk_core.IResolvable]

Property enableAutomaticRotation: Whether to enable automatic key rotation.

Valid value: true/false (default)


key_specOptional

key_spec: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property keySpec: Key type.

Valid value: Aliyun_AES_256/Aliyun_SM4/RSA_2048/EC_P256/EC_P256K/EC_SM2


key_usageOptional

key_usage: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property keyUsage: The usage of the CMK.

Valid values: ENCRYPT/DECRYPT: encrypts or decrypts data. SIGN/VERIFY: generates or verifies a digital signature. If the CMK supports signature verification, the default value is SIGN/VERIFY. If the CMK does not support signature verification, the default value is ENCRYPT/DECRYPT.


pending_window_in_daysOptional

pending_window_in_days: typing.Union[typing.Union[int, float], IResolvable]
  • Type: typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable]

Property pendingWindowInDays: The waiting period, specified in number of days.

During this period, you can cancel the CMK in PendingDeletion status. After the waiting period expires, you cannot cancel the deletion. The value must be between 7 and 366. Default value is 30.


policyOptional

policy: typing.Union[IResolvable, typing.Mapping[typing.Any]]
  • Type: typing.Union[ros_cdk_core.IResolvable, typing.Mapping[typing.Any]]

Property policy: The policy of key.


protection_levelOptional

protection_level: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property protectionLevel: You do not need to specify this parameter.

KMS automatically sets an appropriate protection level for your key. The protection level of the key. Valid values:

  • SOFTWARE
  • HSM
  • If you specify DKMSInstanceId, this parameter is ignored. If the instance is a software key management instance, the protection level is SOFTWARE. If the instance is a hardware key management instance, the protection level is HSM.
  • If you do not specify DKMSInstanceId, leave this parameter empty. KMS sets the protection level. If a managed HSM is available in the region, KMS sets this parameter to HSM. Otherwise, KMS sets this parameter to SOFTWARE. For more information, see Managed HSM overview.

rotation_intervalOptional

rotation_interval: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property rotationInterval: The automatic rotation period.

The format is integer[unit]. integer indicates the length of the period. unit indicates the unit of time. Valid units: d (day), h (hour), m (minute), and s (second). For example, both 7d and 604800s represent a period of 7 days.

  • If the key is a default key, the value is 365d.
  • If the key is a software-protected key, the value can be from 7d to 365d.
  • If the key is a hardware-protected key, automatic rotation is not supported.

This parameter is required if you set EnableAutomaticRotation to true.


tagsOptional

tags: typing.List[TagsProperty]

Property tags: Tags to attach to key.

Max support 20 tags to add during create key. Each tag with two properties Key and Value, and Key is required.