Class: Aws::BedrockAgentCoreControl::Types::Policy
- Inherits:
-
Struct
- Object
- Struct
- Aws::BedrockAgentCoreControl::Types::Policy
- Defined in:
- gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb
Overview
Represents a complete policy resource within the AgentCore Policy system. Policies are ARN-able resources that contain Cedar or Dogwood policy statements and associated metadata for controlling agent behavior and access decisions. Each policy belongs to a policy engine and defines fine-grained authorization rules that are evaluated in real-time as agents interact with tools through Gateway. Policies use Cedar or Dogwood to specify who (principals based on OAuth claims like username, role, or scope) can perform what actions (tool calls) on which resources (Gateways), with optional conditions for attribute-based access control. Multiple policies can apply to a single request, with forbid-wins semantics ensuring that security restrictions are never accidentally overridden.
Constant Summary collapse
- SENSITIVE =
[:description]
Instance Attribute Summary collapse
-
#created_at ⇒ Time
The timestamp when the policy was originally created.
-
#definition ⇒ Types::PolicyDefinition
The Cedar or Dogwood policy statement that defines the access control rules.
-
#description ⇒ String
A human-readable description of the policy's purpose and functionality.
-
#enforcement_mode ⇒ String
The current enforcement mode of the policy.
-
#name ⇒ String
The customer-assigned immutable name for the policy.
-
#policy_arn ⇒ String
The Amazon Resource Name (ARN) of the policy.
-
#policy_engine_id ⇒ String
The identifier of the policy engine that manages this policy.
-
#policy_id ⇒ String
The unique identifier for the policy.
-
#status ⇒ String
The current status of the policy.
-
#status_reasons ⇒ Array<String>
Additional information about the policy status.
-
#updated_at ⇒ Time
The timestamp when the policy was last modified.
Instance Attribute Details
#created_at ⇒ Time
The timestamp when the policy was originally created. This is automatically set by the service and used for auditing and lifecycle management.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#definition ⇒ Types::PolicyDefinition
The Cedar or Dogwood policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#description ⇒ String
A human-readable description of the policy's purpose and functionality. Limited to 4,096 characters, this helps administrators understand and manage the policy.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#enforcement_mode ⇒ String
The current enforcement mode of the policy.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#name ⇒ String
The customer-assigned immutable name for the policy. This human-readable identifier must be unique within the account and cannot exceed 48 characters.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#policy_arn ⇒ String
The Amazon Resource Name (ARN) of the policy. This globally unique identifier can be used for cross-service references and IAM policy statements.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#policy_engine_id ⇒ String
The identifier of the policy engine that manages this policy. This establishes the policy engine context for policy evaluation and management.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#policy_id ⇒ String
The unique identifier for the policy. This system-generated identifier consists of the user name plus a 10-character generated suffix and serves as the primary key for policy operations.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#status ⇒ String
The current status of the policy.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#status_reasons ⇒ Array<String>
Additional information about the policy status. This provides details about any failures or the current state of the policy lifecycle.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |
#updated_at ⇒ Time
The timestamp when the policy was last modified. This tracks the most recent changes to the policy configuration or metadata.
17627 17628 17629 17630 17631 17632 17633 17634 17635 17636 17637 17638 17639 17640 17641 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 17627 class Policy < Struct.new( :policy_id, :name, :policy_engine_id, :created_at, :updated_at, :policy_arn, :status, :enforcement_mode, :definition, :description, :status_reasons) SENSITIVE = [:description] include Aws::Structure end |