View a markdown version of this page

CreateDeployment - AWS Network Security Manager

CreateDeployment

Creates a deployment. A deployment applies one or more policies to the accounts and resources selected by a scope. Use isPublished to create the deployment in published (ACTIVE) or draft (DRAFT) state. The response includes coverage information and any warnings about the deployment.

Request Syntax

POST /deployments HTTP/1.1 Content-type: application/json { "associatedPolicyList": [ { "policyIdentifier": "string" } ], "associatedScopeList": [ { "scopeIdentifier": "string" } ], "clientToken": "string", "deploymentConfiguration": { "enableCrossAccountVisibility": boolean }, "deploymentDescription": "string", "deploymentName": "string", "isPublished": boolean, "tags": { "string" : "string" } }

URI Request Parameters

The request does not use any URI parameters.

Request Body

The request accepts the following data in JSON format.

associatedPolicyList

The policies associated with the deployment.

Type: Array of PolicyReference objects

Array Members: Minimum number of 1 item. Maximum number of 2 items.

Required: Yes

associatedScopeList

The scope associated with the deployment. A deployment has exactly one scope.

Type: Array of ScopeReference objects

Array Members: Fixed number of 1 item.

Required: Yes

clientToken

A unique, case-sensitive token that you provide to ensure that the operation completes no more than one time. If you retry a request with the same client token and the same parameters, the service returns the result of the original successful request.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 64.

Pattern: [\x21-\x7E]+

Required: No

deploymentConfiguration

The configuration settings for the deployment.

Type: DeploymentConfiguration object

Required: Yes

deploymentDescription

A description of the deployment.

Type: String

Length Constraints: Minimum length of 0. Maximum length of 256.

Pattern: [a-zA-Z0-9 _.:/=+\-@]*

Required: No

deploymentName

The name of the deployment.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 128.

Pattern: [a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*

Required: Yes

isPublished

Specifies whether to publish the resource. When true, the resource is saved in published (ACTIVE) state. When false, it is saved as a draft (DRAFT). Default: true.

Type: Boolean

Required: No

tags

The tags to add to the resource when it is created.

Type: String to string map

Map Entries: Minimum number of 0 items. Maximum number of 200 items.

Key Length Constraints: Minimum length of 1. Maximum length of 128.

Key Pattern: ([\p{L}\p{Z}\p{N}_.:/=+\-@]*)

Value Length Constraints: Minimum length of 0. Maximum length of 256.

Required: No

Response Syntax

HTTP/1.1 201 Content-type: application/json { "associatedPolicyList": [ { "policyArn": "string" } ], "associatedScopeList": [ { "scopeArn": "string" } ], "deploymentArn": "string", "deploymentConfiguration": { "enableCrossAccountVisibility": boolean }, "deploymentCoverage": [ { "firewallType": "string", "inScopeResourceTypes": [ "string" ], "policyArns": [ "string" ] } ], "deploymentDescription": "string", "deploymentId": "string", "deploymentName": "string", "hasPublishedVersion": boolean, "isSnapshot": boolean, "status": "string", "updatedAt": "string", "updateToken": "string", "version": "string", "warnings": [ { "code": "string", "message": "string", "policyArn": "string" } ] }

Response Elements

If the action is successful, the service sends back an HTTP 201 response.

The following data is returned in JSON format by the service.

associatedPolicyList

The policies associated with the deployment.

Type: Array of AssociatedPolicy objects

Array Members: Minimum number of 1 item. Maximum number of 2 items.

associatedScopeList

The scope associated with the deployment. A deployment has exactly one scope.

Type: Array of AssociatedScope objects

Array Members: Fixed number of 1 item.

deploymentArn

The Amazon Resource Name (ARN) of the deployment.

Type: String

Length Constraints: Minimum length of 20. Maximum length of 1010.

Pattern: arn(:[a-z0-9]+([.-][a-z0-9]+)*){2}(:([a-z0-9]+([.-][a-z0-9]+)*)?){2}:(.+)

deploymentConfiguration

The configuration settings for the deployment.

Type: DeploymentConfiguration object

deploymentCoverage

The coverage information for the deployment. For each firewall type, it shows which policies have that firewall type and which in-scope resource types the firewall type protects.

Type: Array of DeploymentCoverageEntry objects

Array Members: Minimum number of 0 items. Maximum number of 10 items.

deploymentDescription

A description of the deployment.

Type: String

Length Constraints: Minimum length of 0. Maximum length of 256.

Pattern: [a-zA-Z0-9 _.:/=+\-@]*

deploymentId

The service-generated id of the deployment.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 64.

Pattern: [a-z0-9]{1,64}

deploymentName

The name of the deployment.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 128.

Pattern: [a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*

hasPublishedVersion

Specifies whether a published version of the resource exists.

Type: Boolean

isSnapshot

Specifies whether the resource is a snapshot of a published version.

Type: Boolean

status

The current status of the resource: DRAFT (unpublished, editable) or ACTIVE (published, in use).

Type: String

Valid Values: DRAFT | ACTIVE | DISABLED

updatedAt

The time when the resource was last updated.

Type: Timestamp

updateToken

A token used for optimistic concurrency control. Each read and write returns an updateToken. Provide the most recent value on your next update to detect and prevent conflicting concurrent modifications.

Type: String

Length Constraints: Fixed length of 36.

Pattern: ([0-9a-f]{8})-([0-9a-f]{4}-){3}([0-9a-f]{12})

version

The version of the resource.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 10.

Pattern: [1-9][0-9]*

warnings

Warnings about potential issues, such as a policy that has no applicable resources in the deployment's scope.

Type: Array of DeploymentWarningEntry objects

Array Members: Minimum number of 0 items. Maximum number of 100 items.

Errors

For information about the errors that are common to all actions, see Common Error Types.

AccessDeniedException

You do not have sufficient permissions to perform this action.

HTTP Status Code: 403

ConflictException

The request conflicts with the current state of the resource. For example, the resource was modified concurrently, or it is in a state that does not allow the requested operation.

resourceId

The ID of the resource that is in conflict with the request.

resourceType

The type of the resource that is in conflict with the request.

HTTP Status Code: 409

InternalServerException

The request processing failed because of an internal error in the service. This is a retryable error.

HTTP Status Code: 500

ServiceQuotaExceededException

The request would exceed a service quota.

quotaCode

The code that identifies the service quota that was exceeded.

resourceId

The ID of the resource associated with the quota that was exceeded.

resourceType

The type of the resource associated with the quota that was exceeded.

serviceCode

The code for the AWS service that owns the quota that was exceeded.

HTTP Status Code: 402

ServiceUnavailableException

The service is temporarily unavailable. This is a retryable error.

retryAfterSeconds

The number of seconds to wait before retrying the request.

HTTP Status Code: 503

TagPolicyViolationException

The request violates a tag policy that is in effect for the account or organization.

HTTP Status Code: 400

ThrottlingException

The request was denied because of request throttling. Reduce your request rate and try again.

retryAfterSeconds

The number of seconds to wait before retrying the request.

HTTP Status Code: 429

ValidationException

The request failed validation. For details, see the reason and fieldList members of the response.

fieldList

The list of request fields that failed validation, if any.

reason

The reason that the request failed validation.

HTTP Status Code: 400

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: