This is the new AWS CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::SageMaker::FeatureGroup OnlineStoreSecurityConfig
The security configuration for OnlineStore.
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "KmsKeyId" :String}
YAML
KmsKeyId:String
Properties
KmsKeyId-
The AWS Key Management Service (KMS) key ARN that SageMaker Feature Store uses to encrypt the Amazon S3 objects at rest using Amazon S3 server-side encryption.
The caller (either user or IAM role) of
CreateFeatureGroupmust have below permissions to theOnlineStoreKmsKeyId:-
"kms:Encrypt" -
"kms:Decrypt" -
"kms:DescribeKey" -
"kms:CreateGrant" -
"kms:RetireGrant" -
"kms:ReEncryptFrom" -
"kms:ReEncryptTo" -
"kms:GenerateDataKey" -
"kms:ListAliases" -
"kms:ListGrants" -
"kms:RevokeGrant"
The caller (either user or IAM role) to all DataPlane operations (
PutRecord,GetRecord,DeleteRecord) must have the following permissions to theKmsKeyId:-
"kms:Decrypt"
Required: No
Type: String
Maximum:
2048Update requires: Replacement
-