openapi: 3.0.0 info: version: '2017-03-31' x-release: v4 title: 'AWS Glue #X Amz Target=AWSGlue.BatchCreatePartition #X Amz Target=AWSGlue.BatchCreatePartition #X Amz Target=AWSGlue.GetDataCatalogEncryptionSettings API' description: Glue

Defines the public endpoint for the Glue service.

x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: glue x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/glue-2017-03-31.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://glue.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS Glue multi-region endpoint - url: https://glue.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS Glue multi-region endpoint - url: http://glue.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS Glue endpoint for China (Beijing) and China (Ningxia) - url: https://glue.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS Glue endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=AWSGlue.GetDataCatalogEncryptionSettings' paths: /#X-Amz-Target=AWSGlue.GetDataCatalogEncryptionSettings: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: GetDataCatalogEncryptionSettings description: Retrieves the security configuration for a specified catalog. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetDataCatalogEncryptionSettingsResponse' examples: GetDataCatalogEncryptionSettings200Example: summary: Default GetDataCatalogEncryptionSettings 200 response x-microcks-default: true value: JobRunId: jr_abc123 State: SUCCEEDED '480': description: InternalServiceException content: application/json: schema: $ref: '#/components/schemas/InternalServiceException' examples: GetDataCatalogEncryptionSettings480Example: summary: Default GetDataCatalogEncryptionSettings 480 response x-microcks-default: true value: JobRunId: jr_abc123 State: SUCCEEDED '481': description: InvalidInputException content: application/json: schema: $ref: '#/components/schemas/InvalidInputException' examples: GetDataCatalogEncryptionSettings481Example: summary: Default GetDataCatalogEncryptionSettings 481 response x-microcks-default: true value: JobRunId: jr_abc123 State: SUCCEEDED '482': description: OperationTimeoutException content: application/json: schema: $ref: '#/components/schemas/OperationTimeoutException' examples: GetDataCatalogEncryptionSettings482Example: summary: Default GetDataCatalogEncryptionSettings 482 response x-microcks-default: true value: JobRunId: jr_abc123 State: SUCCEEDED requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetDataCatalogEncryptionSettingsRequest' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - AWSGlue.GetDataCatalogEncryptionSettings summary: Amazon Glue Get Data Catalog Encryption Settings x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=AWSGlue.GetDataCatalogEncryptionSettings' components: schemas: InternalServiceException: {} GetDataCatalogEncryptionSettingsResponse: type: object properties: DataCatalogEncryptionSettings: allOf: - $ref: '#/components/schemas/DataCatalogEncryptionSettings' - description: The requested security configuration. Boolean: type: boolean DataCatalogEncryptionSettings: type: object properties: EncryptionAtRest: allOf: - $ref: '#/components/schemas/EncryptionAtRest' - description: Specifies the encryption-at-rest configuration for the Data Catalog. ConnectionPasswordEncryption: allOf: - $ref: '#/components/schemas/ConnectionPasswordEncryption' - description: When connection password protection is enabled, the Data Catalog uses a customer-provided key to encrypt the password as part of CreateConnection or UpdateConnection and store it in the ENCRYPTED_PASSWORD field in the connection properties. You can enable catalog encryption or only password encryption. description: Contains configuration information for maintaining Data Catalog security. OperationTimeoutException: {} EncryptionAtRest: type: object required: - CatalogEncryptionMode properties: CatalogEncryptionMode: allOf: - $ref: '#/components/schemas/CatalogEncryptionMode' - description: The encryption-at-rest mode for encrypting Data Catalog data. SseAwsKmsKeyId: allOf: - $ref: '#/components/schemas/NameString' - description: The ID of the KMS key to use for encryption at rest. description: Specifies the encryption-at-rest configuration for the Data Catalog. GetDataCatalogEncryptionSettingsRequest: type: object title: GetDataCatalogEncryptionSettingsRequest properties: CatalogId: allOf: - $ref: '#/components/schemas/CatalogIdString' - description: The ID of the Data Catalog to retrieve the security configuration for. If none is provided, the Amazon Web Services account ID is used by default. CatalogIdString: type: string minLength: 1 maxLength: 255 x-pattern: '[\u0020-\uD7FF\uE000-\uFFFD\uD800\uDC00-\uDBFF\uDFFF\t]*' CatalogEncryptionMode: type: string enum: - DISABLED - SSE-KMS NameString: type: string minLength: 1 maxLength: 255 x-pattern: '[\u0020-\uD7FF\uE000-\uFFFD\uD800\uDC00-\uDBFF\uDFFF\t]*' InvalidInputException: {} ConnectionPasswordEncryption: type: object required: - ReturnConnectionPasswordEncrypted properties: ReturnConnectionPasswordEncrypted: allOf: - $ref: '#/components/schemas/Boolean' - description: 'When the ReturnConnectionPasswordEncrypted flag is set to "true", passwords remain encrypted in the responses of GetConnection and GetConnections. This encryption takes effect independently from catalog encryption. ' AwsKmsKeyId: allOf: - $ref: '#/components/schemas/NameString' - description:

An KMS key that is used to encrypt the connection password.

If connection password protection is enabled, the caller of CreateConnection and UpdateConnection needs at least kms:Encrypt permission on the specified KMS key, to encrypt passwords before storing them in the Data Catalog.

You can set the decrypt permission to enable or restrict access on the password key according to your security requirements.

description:

The data structure used by the Data Catalog to encrypt the password as part of CreateConnection or UpdateConnection and store it in the ENCRYPTED_PASSWORD field in the connection properties. You can enable catalog encryption or only password encryption.

When a CreationConnection request arrives containing a password, the Data Catalog first encrypts the password using your KMS key. It then encrypts the whole connection object again if catalog encryption is also enabled.

This encryption requires that you set KMS key permissions to enable or restrict access on the password key according to your security requirements. For example, you might want only administrators to have decrypt permission on the password key.

parameters: X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/glue/ x-hasEquivalentPaths: true