Class NetworkConfiguration

java.lang.Object
software.amazon.awssdk.services.identitystore.model.NetworkConfiguration
All Implemented Interfaces:
Serializable, SdkPojo, ToCopyableBuilder<NetworkConfiguration.Builder,NetworkConfiguration>

@Generated("software.amazon.awssdk:codegen") public final class NetworkConfiguration extends Object implements SdkPojo, Serializable, ToCopyableBuilder<NetworkConfiguration.Builder,NetworkConfiguration>

The network configuration that controls how an identity store can be accessed. You provide this object in a request.

See Also:
  • Method Details

    • vpceAccessRequired

      public final Boolean vpceAccessRequired()

      Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to true, requests must originate from a VPC endpoint.

      This value must be set to either true or false when you provide NetworkConfiguration in a request.

      Returns:
      Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to true, requests must originate from a VPC endpoint.

      This value must be set to either true or false when you provide NetworkConfiguration in a request.

    • hasApiRestrictSourceVpcs

      public final boolean hasApiRestrictSourceVpcs()
      For responses, this returns true if the service returned a value for the ApiRestrictSourceVpcs property. This DOES NOT check that the value is non-empty (for which, you should check the isEmpty() method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified.
    • apiRestrictSourceVpcs

      public final List<String> apiRestrictSourceVpcs()

      A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in ApiAllowSourceIps if you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set by VpceAccessRequired still applies.

      Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.

      This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the hasApiRestrictSourceVpcs() method.

      Returns:
      A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in ApiAllowSourceIps if you specified one. If you don't specify a value, access isn't restricted to specific VPCs, but the VPC endpoint requirement set by VpceAccessRequired still applies.
    • hasApiAllowSourceIps

      public final boolean hasApiAllowSourceIps()
      For responses, this returns true if the service returned a value for the ApiAllowSourceIps property. This DOES NOT check that the value is non-empty (for which, you should check the isEmpty() method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified.
    • apiAllowSourceIps

      public final List<String> apiAllowSourceIps()

      A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by VpceAccessRequired, and even if it doesn't originate from a VPC in ApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.

      Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.

      This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the hasApiAllowSourceIps() method.

      Returns:
      A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store's other API network controls: it's permitted even if it doesn't come through a VPC endpoint required by VpceAccessRequired, and even if it doesn't originate from a VPC in ApiRestrictSourceVpcs. If you don't specify a value, no such IP address exception applies.
    • hasScimAllowSourceIps

      public final boolean hasScimAllowSourceIps()
      For responses, this returns true if the service returned a value for the ScimAllowSourceIps property. This DOES NOT check that the value is non-empty (for which, you should check the isEmpty() method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified.
    • scimAllowSourceIps

      public final List<String> scimAllowSourceIps()

      A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by VpceAccessRequired.

      For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set VpceAccessRequired to true and set this value to 0.0.0.0/0.

      Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.

      This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the hasScimAllowSourceIps() method.

      Returns:
      A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If you don't specify a value, SCIM requests remain subject to the identity store's other network controls, such as the VPC endpoint requirement set by VpceAccessRequired.

      For example, to allow SCIM traffic from the public internet while still requiring the identity store API operations to be accessed through a VPC endpoint, set VpceAccessRequired to true and set this value to 0.0.0.0/0.

    • toBuilder

      public NetworkConfiguration.Builder toBuilder()
      Description copied from interface: ToCopyableBuilder
      Take this object and create a builder that contains all of the current property values of this object.
      Specified by:
      toBuilder in interface ToCopyableBuilder<NetworkConfiguration.Builder,NetworkConfiguration>
      Returns:
      a builder for type T
    • builder

      public static NetworkConfiguration.Builder builder()
    • serializableBuilderClass

      public static Class<? extends NetworkConfiguration.Builder> serializableBuilderClass()
    • hashCode

      public final int hashCode()
      Overrides:
      hashCode in class Object
    • equals

      public final boolean equals(Object obj)
      Overrides:
      equals in class Object
    • equalsBySdkFields

      public final boolean equalsBySdkFields(Object obj)
      Description copied from interface: SdkPojo
      Indicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in an SdkPojo class, and is generated based on a service model.

      If an SdkPojo class does not have any inherited fields, equalsBySdkFields and equals are essentially the same.

      Specified by:
      equalsBySdkFields in interface SdkPojo
      Parameters:
      obj - the object to be compared with
      Returns:
      true if the other object equals to this object by sdk fields, false otherwise.
    • toString

      public final String toString()
      Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be redacted from this string using a placeholder value.
      Overrides:
      toString in class Object
    • getValueForField

      public final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz)
    • sdkFields

      public final List<SdkField<?>> sdkFields()
      Specified by:
      sdkFields in interface SdkPojo
      Returns:
      List of SdkField in this POJO. May be empty list but should never be null.
    • sdkFieldNameToField

      public final Map<String,SdkField<?>> sdkFieldNameToField()
      Specified by:
      sdkFieldNameToField in interface SdkPojo
      Returns:
      The mapping between the field name and its corresponding field.