Interface NetworkConfiguration.Builder

  • Method Details

    • vpceAccessRequired

      NetworkConfiguration.Builder vpceAccessRequired(Boolean vpceAccessRequired)

      Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to true, requests must originate from a VPC endpoint.

      This value must be set to either true or false when you provide NetworkConfiguration in a request.

      Parameters:
      vpceAccessRequired - Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to true, requests must originate from a VPC endpoint.

      This value must be set to either true or false when you provide NetworkConfiguration in a request.

      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • apiRestrictSourceVpcs

      NetworkConfiguration.Builder apiRestrictSourceVpcs(Collection<String> apiRestrictSourceVpcs)

      A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in ApiAllowSourceIps if you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set by VpceAccessRequired still applies.

      Parameters:
      apiRestrictSourceVpcs - A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in ApiAllowSourceIps if you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set by VpceAccessRequired still applies.
      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • apiRestrictSourceVpcs

      NetworkConfiguration.Builder apiRestrictSourceVpcs(String... apiRestrictSourceVpcs)

      A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in ApiAllowSourceIps if you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set by VpceAccessRequired still applies.

      Parameters:
      apiRestrictSourceVpcs - A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in ApiAllowSourceIps if you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set by VpceAccessRequired still applies.
      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • apiAllowSourceIps

      NetworkConfiguration.Builder apiAllowSourceIps(Collection<String> apiAllowSourceIps)

      A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by VpceAccessRequired, and even if it doesn't originate from a VPC in ApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.

      Parameters:
      apiAllowSourceIps - A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by VpceAccessRequired, and even if it doesn't originate from a VPC in ApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.
      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • apiAllowSourceIps

      NetworkConfiguration.Builder apiAllowSourceIps(String... apiAllowSourceIps)

      A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by VpceAccessRequired, and even if it doesn't originate from a VPC in ApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.

      Parameters:
      apiAllowSourceIps - A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by VpceAccessRequired, and even if it doesn't originate from a VPC in ApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.
      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • scimAllowSourceIps

      NetworkConfiguration.Builder scimAllowSourceIps(Collection<String> scimAllowSourceIps)

      A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by VpceAccessRequired.

      For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set VpceAccessRequired to true and set this value to 0.0.0.0/0.

      Parameters:
      scimAllowSourceIps - A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by VpceAccessRequired.

      For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set VpceAccessRequired to true and set this value to 0.0.0.0/0.

      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • scimAllowSourceIps

      NetworkConfiguration.Builder scimAllowSourceIps(String... scimAllowSourceIps)

      A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by VpceAccessRequired.

      For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set VpceAccessRequired to true and set this value to 0.0.0.0/0.

      Parameters:
      scimAllowSourceIps - A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by VpceAccessRequired.

      For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set VpceAccessRequired to true and set this value to 0.0.0.0/0.

      Returns:
      Returns a reference to this object so that method calls can be chained together.