

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# 在启用 FHIR HealthLake 的数据存储上创建 SMART
<a name="reference-smart-on-fhir-create-data-store"></a>

要将 SMART on FHIR 框架与一起使用 HealthLake，请使用`CreateFHIRDatastore`请求中指定的`IdentityProviderConfiguration`参数创建 HealthLake 数据存储。在`IdentityProviderConfiguration`参数中指定以下信息：
+ 将[AuthorizationStrategy](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)等于设置为`SMART_ON_FHIR_V1`。
+ 设置[IdpLambdaArn](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)等于 AWS Lambda 您创建的 ARN，以便使用授权服务器管理令牌解码。
+ 将授权服务器中指定的[元数据](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)元素定义为 JSON 块。这些元数据元素将在探索文档中返回。
+ *可选*：启用[FineGrainedAuthorizationEnabled](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)。指定使用`True`提供的 Fine Grained 授权 HealthLake

**注意**  
创建数据存储后，您可以使用更改其身份提供商配置，包括`AuthorizationStrategy`、`IdpLambdaArn``Metadata`、和`FineGrainedAuthorizationEnabled`值。`UpdateFHIRDatastore`更新身份提供商配置会完全取代它，因此请包括您要保留的所有字段；您省略的任何字段都将被清除。身份提供商更新立即生效，不会将数据存储移动到`UPDATING`状态。有关更多信息，请参阅 [更新 HealthLake 数据存储](managing-data-stores-update.md)。

您可以使用 AWS Command Line Interface (AWS CLI) 或通过 AWS 支持的 SDK 之一在启用 FHIR 的数据存储上创建 SMART。 HealthLake 控制台不支持在启用 FHIR HealthLake 的数据存储上创建 SMART。

## 使用 AWS CLI 在启用 FHIR HealthLake 的数据存储上创建 SMART
<a name="create-smart-ds-request"></a>

您可以使用以下代码示例，使用在启用 FHIR HealthLake 的数据存储上创建 SMART。 AWS CLI在启用 FHIR HealthLake 的数据存储上创建 SMART 时，必须指定[`identity-provider-configuration`](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)参数。

在`identity-provider-configuration`参数中，您可以*选择通过设置`FineGrainedAuthorizationEnabled`等于来*启用细粒度授权。`True`要了解有关细粒度授权的更多信息，请参阅[在启用 SMART on FHIR 的数据存储中使用细粒度授权 HealthLake](reference-smart-on-fhir-fine-grained-authorization.md)。下面的示例包含一个特殊字符`\`，用于表示换行符或作为转义字符。这是为了清楚起见。

```
aws healthlake create-fhir-datastore \
  --region us-east-1 \
  --datastore-name "your-data-store-name" \
  --datastore-type-version R4 \
  --preload-data-config PreloadDataType="SYNTHEA" \
  --sse-configuration '{ "KmsEncryptionConfig": { \
    "CmkType": "customer-managed-kms-key1",
    "KmsKeyId": "arn:aws:kms:us-east-1:your-account-id:key/your-key-id" } }' \
  --identity-provider-configuration  \
      '{"AuthorizationStrategy": "SMART_ON_FHIR_V1", \
      "FineGrainedAuthorizationEnabled": boolean-false-by-default, \
      "IdpLambdaArn": "arn:aws:lambda:your-region:your-account-id:function:your-lambda-name", \
      "Metadata": "{\"issuer\":\"https://ehr.example.com\",\"jwks_uri\":\"https://ehr.example.com/.well-known/jwks.json\",\"authorization_endpoint\":\"https://ehr.example.com/auth/authorize\",\"token_endpoint\":\"https://ehr.token.com/auth/token\",\"token_endpoint_auth_methods_supported\":[\"client_secret_basic\",\"foo\"],\"grant_types_supported\":[\"client_credentials\",\"foo\"],\"registration_endpoint\":\"https://ehr.example.com/auth/register\",\"scopes_supported\":[\"openid\",\"profile\",\"launch\"],\"response_types_supported\":[\"code\"],\"management_endpoint\":\"https://ehr.example.com/user/manage\",\"introspection_endpoint\":\"https://ehr.example.com/user/introspect\",\"revocation_endpoint\":\"https://ehr.example.com/user/revoke\",\"code_challenge_methods_supported\":[\"S256\"],\"capabilities\":[\"launch-ehr\",\"sso-openid-connect\",\"client-public\"]}"}'
```

成功后，您将获得以下 JSON 响应：

```
{
  "DatastoreArn": "arn:aws:healthlake:your-region:111122223333:datastore/fhir/your-datastore-id",
  "DatastoreEndpoint": "https://healthlake.{{region}}.amazonaws.com/datastore/{{datastoreId}}/r4/",
  "DatastoreId": "your-data-store-id",
  "DatastoreStatus": "data-store-creation-status"
}
```