update_virtual_node
(**kwargs)¶Updates an existing virtual node in a specified service mesh.
See also: AWS API Documentation
Request Syntax
response = client.update_virtual_node(
clientToken='string',
meshName='string',
meshOwner='string',
spec={
'backendDefaults': {
'clientPolicy': {
'tls': {
'certificate': {
'file': {
'certificateChain': 'string',
'privateKey': 'string'
},
'sds': {
'secretName': 'string'
}
},
'enforce': True|False,
'ports': [
123,
],
'validation': {
'subjectAlternativeNames': {
'match': {
'exact': [
'string',
]
}
},
'trust': {
'acm': {
'certificateAuthorityArns': [
'string',
]
},
'file': {
'certificateChain': 'string'
},
'sds': {
'secretName': 'string'
}
}
}
}
}
},
'backends': [
{
'virtualService': {
'clientPolicy': {
'tls': {
'certificate': {
'file': {
'certificateChain': 'string',
'privateKey': 'string'
},
'sds': {
'secretName': 'string'
}
},
'enforce': True|False,
'ports': [
123,
],
'validation': {
'subjectAlternativeNames': {
'match': {
'exact': [
'string',
]
}
},
'trust': {
'acm': {
'certificateAuthorityArns': [
'string',
]
},
'file': {
'certificateChain': 'string'
},
'sds': {
'secretName': 'string'
}
}
}
}
},
'virtualServiceName': 'string'
}
},
],
'listeners': [
{
'connectionPool': {
'grpc': {
'maxRequests': 123
},
'http': {
'maxConnections': 123,
'maxPendingRequests': 123
},
'http2': {
'maxRequests': 123
},
'tcp': {
'maxConnections': 123
}
},
'healthCheck': {
'healthyThreshold': 123,
'intervalMillis': 123,
'path': 'string',
'port': 123,
'protocol': 'http'|'tcp'|'http2'|'grpc',
'timeoutMillis': 123,
'unhealthyThreshold': 123
},
'outlierDetection': {
'baseEjectionDuration': {
'unit': 's'|'ms',
'value': 123
},
'interval': {
'unit': 's'|'ms',
'value': 123
},
'maxEjectionPercent': 123,
'maxServerErrors': 123
},
'portMapping': {
'port': 123,
'protocol': 'http'|'tcp'|'http2'|'grpc'
},
'timeout': {
'grpc': {
'idle': {
'unit': 's'|'ms',
'value': 123
},
'perRequest': {
'unit': 's'|'ms',
'value': 123
}
},
'http': {
'idle': {
'unit': 's'|'ms',
'value': 123
},
'perRequest': {
'unit': 's'|'ms',
'value': 123
}
},
'http2': {
'idle': {
'unit': 's'|'ms',
'value': 123
},
'perRequest': {
'unit': 's'|'ms',
'value': 123
}
},
'tcp': {
'idle': {
'unit': 's'|'ms',
'value': 123
}
}
},
'tls': {
'certificate': {
'acm': {
'certificateArn': 'string'
},
'file': {
'certificateChain': 'string',
'privateKey': 'string'
},
'sds': {
'secretName': 'string'
}
},
'mode': 'STRICT'|'PERMISSIVE'|'DISABLED',
'validation': {
'subjectAlternativeNames': {
'match': {
'exact': [
'string',
]
}
},
'trust': {
'file': {
'certificateChain': 'string'
},
'sds': {
'secretName': 'string'
}
}
}
}
},
],
'logging': {
'accessLog': {
'file': {
'format': {
'json': [
{
'key': 'string',
'value': 'string'
},
],
'text': 'string'
},
'path': 'string'
}
}
},
'serviceDiscovery': {
'awsCloudMap': {
'attributes': [
{
'key': 'string',
'value': 'string'
},
],
'ipPreference': 'IPv6_PREFERRED'|'IPv4_PREFERRED'|'IPv4_ONLY'|'IPv6_ONLY',
'namespaceName': 'string',
'serviceName': 'string'
},
'dns': {
'hostname': 'string',
'ipPreference': 'IPv6_PREFERRED'|'IPv4_PREFERRED'|'IPv4_ONLY'|'IPv6_ONLY',
'responseType': 'LOADBALANCER'|'ENDPOINTS'
}
}
},
virtualNodeName='string'
)
Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. Up to 36 letters, numbers, hyphens, and underscores are allowed.
This field is autopopulated if not provided.
[REQUIRED]
The name of the service mesh that the virtual node resides in.
[REQUIRED]
The new virtual node specification to apply. This overwrites the existing data.
A reference to an object that represents the defaults for backends.
A reference to an object that represents a client policy.
A reference to an object that represents a Transport Layer Security (TLS) client policy.
A reference to an object that represents a client's TLS certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: file
, sds
.
An object that represents a local file certificate. The certificate must meet specific requirements and you must have proxy authorization enabled. For more information, see Transport Layer Security (TLS).
The certificate chain for the certificate.
The private key for a certificate stored on the file system of the virtual node that the proxy is running on.
A reference to an object that represents a client's TLS Secret Discovery Service certificate.
A reference to an object that represents the name of the secret requested from the Secret Discovery Service provider representing Transport Layer Security (TLS) materials like a certificate or certificate chain.
Whether the policy is enforced. The default is True
, if a value isn't specified.
One or more ports that the policy is enforced for.
A reference to an object that represents a TLS validation context.
A reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context. If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration. Since SPIRE vended certificates have a SPIFFE ID as a name, you must set the SAN since the name doesn't match the service discovery name.
An object that represents the criteria for determining a SANs match.
The values sent must match the specified values exactly.
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: acm
, file
, sds
.
A reference to an object that represents a Transport Layer Security (TLS) validation context trust for an Certificate Manager certificate.
One or more ACM Amazon Resource Name (ARN)s.
An object that represents a Transport Layer Security (TLS) validation context trust for a local file.
The certificate trust chain for a certificate stored on the file system of the virtual node that the proxy is running on.
A reference to an object that represents a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
A reference to an object that represents the name of the secret for a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
The backends that the virtual node is expected to send outbound traffic to.
An object that represents the backends that a virtual node is expected to send outbound traffic to.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: virtualService
.
Specifies a virtual service to use as a backend.
A reference to an object that represents the client policy for a backend.
A reference to an object that represents a Transport Layer Security (TLS) client policy.
A reference to an object that represents a client's TLS certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: file
, sds
.
An object that represents a local file certificate. The certificate must meet specific requirements and you must have proxy authorization enabled. For more information, see Transport Layer Security (TLS).
The certificate chain for the certificate.
The private key for a certificate stored on the file system of the virtual node that the proxy is running on.
A reference to an object that represents a client's TLS Secret Discovery Service certificate.
A reference to an object that represents the name of the secret requested from the Secret Discovery Service provider representing Transport Layer Security (TLS) materials like a certificate or certificate chain.
Whether the policy is enforced. The default is True
, if a value isn't specified.
One or more ports that the policy is enforced for.
A reference to an object that represents a TLS validation context.
A reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context. If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration. Since SPIRE vended certificates have a SPIFFE ID as a name, you must set the SAN since the name doesn't match the service discovery name.
An object that represents the criteria for determining a SANs match.
The values sent must match the specified values exactly.
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: acm
, file
, sds
.
A reference to an object that represents a Transport Layer Security (TLS) validation context trust for an Certificate Manager certificate.
One or more ACM Amazon Resource Name (ARN)s.
An object that represents a Transport Layer Security (TLS) validation context trust for a local file.
The certificate trust chain for a certificate stored on the file system of the virtual node that the proxy is running on.
A reference to an object that represents a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
A reference to an object that represents the name of the secret for a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
The name of the virtual service that is acting as a virtual node backend.
The listener that the virtual node is expected to receive inbound traffic from. You can specify one listener.
An object that represents a listener for a virtual node.
The connection pool information for the listener.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: grpc
, http
, http2
, tcp
.
An object that represents a type of connection pool.
Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster.
An object that represents a type of connection pool.
Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster.
Number of overflowing requests after max_connections
Envoy will queue to upstream cluster.
An object that represents a type of connection pool.
Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster.
An object that represents a type of connection pool.
Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster.
The health check information for the listener.
The number of consecutive successful health checks that must occur before declaring listener healthy.
The time period in milliseconds between each health check execution.
The destination path for the health check request. This value is only used if the specified protocol is HTTP or HTTP/2. For any other protocol, this value is ignored.
The destination port for the health check request. This port must match the port defined in the PortMapping for the listener.
The protocol for the health check request. If you specify grpc
, then your service must conform to the GRPC Health Checking Protocol.
The amount of time to wait when receiving a response from the health check, in milliseconds.
The number of consecutive failed health checks that must occur before declaring a virtual node unhealthy.
The outlier detection information for the listener.
The base amount of time for which a host is ejected.
A unit of time.
A number of time units.
The time interval between ejection sweep analysis.
A unit of time.
A number of time units.
Maximum percentage of hosts in load balancing pool for upstream service that can be ejected. Will eject at least one host regardless of the value.
Number of consecutive 5xx
errors required for ejection.
The port mapping information for the listener.
The port used for the port mapping.
The protocol used for the port mapping. Specify one protocol.
An object that represents timeouts for different protocols.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: grpc
, http
, http2
, tcp
.
An object that represents types of timeouts.
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
A unit of time.
A number of time units.
An object that represents a per request timeout. The default value is 15 seconds. If you set a higher timeout, then make sure that the higher value is set for each App Mesh resource in a conversation. For example, if a virtual node backend uses a virtual router provider to route to another virtual node, then the timeout should be greater than 15 seconds for the source and destination virtual node and the route.
A unit of time.
A number of time units.
An object that represents types of timeouts.
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
A unit of time.
A number of time units.
An object that represents a per request timeout. The default value is 15 seconds. If you set a higher timeout, then make sure that the higher value is set for each App Mesh resource in a conversation. For example, if a virtual node backend uses a virtual router provider to route to another virtual node, then the timeout should be greater than 15 seconds for the source and destination virtual node and the route.
A unit of time.
A number of time units.
An object that represents types of timeouts.
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
A unit of time.
A number of time units.
An object that represents a per request timeout. The default value is 15 seconds. If you set a higher timeout, then make sure that the higher value is set for each App Mesh resource in a conversation. For example, if a virtual node backend uses a virtual router provider to route to another virtual node, then the timeout should be greater than 15 seconds for the source and destination virtual node and the route.
A unit of time.
A number of time units.
An object that represents types of timeouts.
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
A unit of time.
A number of time units.
A reference to an object that represents the Transport Layer Security (TLS) properties for a listener.
A reference to an object that represents a listener's Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: acm
, file
, sds
.
A reference to an object that represents an Certificate Manager certificate.
The Amazon Resource Name (ARN) for the certificate. The certificate must meet specific requirements and you must have proxy authorization enabled. For more information, see Transport Layer Security (TLS).
A reference to an object that represents a local file certificate.
The certificate chain for the certificate.
The private key for a certificate stored on the file system of the virtual node that the proxy is running on.
A reference to an object that represents a listener's Secret Discovery Service certificate.
A reference to an object that represents the name of the secret requested from the Secret Discovery Service provider representing Transport Layer Security (TLS) materials like a certificate or certificate chain.
Specify one of the following modes.
A reference to an object that represents a listener's Transport Layer Security (TLS) validation context.
A reference to an object that represents the SANs for a listener's Transport Layer Security (TLS) validation context.
An object that represents the criteria for determining a SANs match.
The values sent must match the specified values exactly.
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: file
, sds
.
An object that represents a Transport Layer Security (TLS) validation context trust for a local file.
The certificate trust chain for a certificate stored on the file system of the virtual node that the proxy is running on.
A reference to an object that represents a listener's Transport Layer Security (TLS) Secret Discovery Service validation context trust.
A reference to an object that represents the name of the secret for a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
The inbound and outbound access logging information for the virtual node.
The access log configuration for a virtual node.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: file
.
The file object to send virtual node access logs to.
The specified format for the logs. The format is either json_format
or text_format
.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: json
, text
.
An object that represents the key value pairs for the JSON.
The specified key for the JSON.
The specified value for the JSON.
The file path to write access logs to. You can use /dev/stdout
to send access logs to standard out and configure your Envoy container to use a log driver, such as awslogs
, to export the access logs to a log storage service such as Amazon CloudWatch Logs. You can also specify a path in the Envoy container's file system to write the files to disk.
<note> <p>The Envoy process must have write permissions to the path that you specify here. Otherwise, Envoy fails to bootstrap properly.</p> </note>
The service discovery information for the virtual node. If your virtual node does not expect ingress traffic, you can omit this parameter. If you specify a listener
, then you must specify service discovery information.
Note
This is a Tagged Union structure. Only one of the following top level keys can be set: awsCloudMap
, dns
.
Specifies any Cloud Map information for the virtual node.
A string map that contains attributes with values that you can use to filter instances by any custom attribute that you specified when you registered the instance. Only instances that match all of the specified key/value pairs will be returned.
An object that represents the Cloud Map attribute information for your virtual node.
Note
Cloud Map is not available in the eu-south-1 Region.
The name of an Cloud Map service instance attribute key. Any Cloud Map service instance that contains the specified key and value is returned.
The value of an Cloud Map service instance attribute key. Any Cloud Map service instance that contains the specified key and value is returned.
The preferred IP version that this virtual node uses. Setting the IP preference on the virtual node only overrides the IP preference set for the mesh on this specific node.
The name of the Cloud Map namespace to use.
The name of the Cloud Map service to use.
Specifies the DNS information for the virtual node.
Specifies the DNS service discovery hostname for the virtual node.
The preferred IP version that this virtual node uses. Setting the IP preference on the virtual node only overrides the IP preference set for the mesh on this specific node.
Specifies the DNS response type for the virtual node.
[REQUIRED]
The name of the virtual node to update.
dict
Response Syntax
{
'virtualNode': {
'meshName': 'string',
'metadata': {
'arn': 'string',
'createdAt': datetime(2015, 1, 1),
'lastUpdatedAt': datetime(2015, 1, 1),
'meshOwner': 'string',
'resourceOwner': 'string',
'uid': 'string',
'version': 123
},
'spec': {
'backendDefaults': {
'clientPolicy': {
'tls': {
'certificate': {
'file': {
'certificateChain': 'string',
'privateKey': 'string'
},
'sds': {
'secretName': 'string'
}
},
'enforce': True|False,
'ports': [
123,
],
'validation': {
'subjectAlternativeNames': {
'match': {
'exact': [
'string',
]
}
},
'trust': {
'acm': {
'certificateAuthorityArns': [
'string',
]
},
'file': {
'certificateChain': 'string'
},
'sds': {
'secretName': 'string'
}
}
}
}
}
},
'backends': [
{
'virtualService': {
'clientPolicy': {
'tls': {
'certificate': {
'file': {
'certificateChain': 'string',
'privateKey': 'string'
},
'sds': {
'secretName': 'string'
}
},
'enforce': True|False,
'ports': [
123,
],
'validation': {
'subjectAlternativeNames': {
'match': {
'exact': [
'string',
]
}
},
'trust': {
'acm': {
'certificateAuthorityArns': [
'string',
]
},
'file': {
'certificateChain': 'string'
},
'sds': {
'secretName': 'string'
}
}
}
}
},
'virtualServiceName': 'string'
}
},
],
'listeners': [
{
'connectionPool': {
'grpc': {
'maxRequests': 123
},
'http': {
'maxConnections': 123,
'maxPendingRequests': 123
},
'http2': {
'maxRequests': 123
},
'tcp': {
'maxConnections': 123
}
},
'healthCheck': {
'healthyThreshold': 123,
'intervalMillis': 123,
'path': 'string',
'port': 123,
'protocol': 'http'|'tcp'|'http2'|'grpc',
'timeoutMillis': 123,
'unhealthyThreshold': 123
},
'outlierDetection': {
'baseEjectionDuration': {
'unit': 's'|'ms',
'value': 123
},
'interval': {
'unit': 's'|'ms',
'value': 123
},
'maxEjectionPercent': 123,
'maxServerErrors': 123
},
'portMapping': {
'port': 123,
'protocol': 'http'|'tcp'|'http2'|'grpc'
},
'timeout': {
'grpc': {
'idle': {
'unit': 's'|'ms',
'value': 123
},
'perRequest': {
'unit': 's'|'ms',
'value': 123
}
},
'http': {
'idle': {
'unit': 's'|'ms',
'value': 123
},
'perRequest': {
'unit': 's'|'ms',
'value': 123
}
},
'http2': {
'idle': {
'unit': 's'|'ms',
'value': 123
},
'perRequest': {
'unit': 's'|'ms',
'value': 123
}
},
'tcp': {
'idle': {
'unit': 's'|'ms',
'value': 123
}
}
},
'tls': {
'certificate': {
'acm': {
'certificateArn': 'string'
},
'file': {
'certificateChain': 'string',
'privateKey': 'string'
},
'sds': {
'secretName': 'string'
}
},
'mode': 'STRICT'|'PERMISSIVE'|'DISABLED',
'validation': {
'subjectAlternativeNames': {
'match': {
'exact': [
'string',
]
}
},
'trust': {
'file': {
'certificateChain': 'string'
},
'sds': {
'secretName': 'string'
}
}
}
}
},
],
'logging': {
'accessLog': {
'file': {
'format': {
'json': [
{
'key': 'string',
'value': 'string'
},
],
'text': 'string'
},
'path': 'string'
}
}
},
'serviceDiscovery': {
'awsCloudMap': {
'attributes': [
{
'key': 'string',
'value': 'string'
},
],
'ipPreference': 'IPv6_PREFERRED'|'IPv4_PREFERRED'|'IPv4_ONLY'|'IPv6_ONLY',
'namespaceName': 'string',
'serviceName': 'string'
},
'dns': {
'hostname': 'string',
'ipPreference': 'IPv6_PREFERRED'|'IPv4_PREFERRED'|'IPv4_ONLY'|'IPv6_ONLY',
'responseType': 'LOADBALANCER'|'ENDPOINTS'
}
}
},
'status': {
'status': 'ACTIVE'|'INACTIVE'|'DELETED'
},
'virtualNodeName': 'string'
}
}
Response Structure
(dict) --
virtualNode (dict) --
A full description of the virtual node that was updated.
meshName (string) --
The name of the service mesh that the virtual node resides in.
metadata (dict) --
The associated metadata for the virtual node.
arn (string) --
The full Amazon Resource Name (ARN) for the resource.
createdAt (datetime) --
The Unix epoch timestamp in seconds for when the resource was created.
lastUpdatedAt (datetime) --
The Unix epoch timestamp in seconds for when the resource was last updated.
meshOwner (string) --
The Amazon Web Services IAM account ID of the service mesh owner. If the account ID is not your own, then it's the ID of the account that shared the mesh with your account. For more information about mesh sharing, see Working with shared meshes.
resourceOwner (string) --
The Amazon Web Services IAM account ID of the resource owner. If the account ID is not your own, then it's the ID of the mesh owner or of another account that the mesh is shared with. For more information about mesh sharing, see Working with shared meshes.
uid (string) --
The unique identifier for the resource.
version (integer) --
The version of the resource. Resources are created at version 1, and this version is incremented each time that they're updated.
spec (dict) --
The specifications of the virtual node.
backendDefaults (dict) --
A reference to an object that represents the defaults for backends.
clientPolicy (dict) --
A reference to an object that represents a client policy.
tls (dict) --
A reference to an object that represents a Transport Layer Security (TLS) client policy.
certificate (dict) --
A reference to an object that represents a client's TLS certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: file
, sds
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
file (dict) --
An object that represents a local file certificate. The certificate must meet specific requirements and you must have proxy authorization enabled. For more information, see Transport Layer Security (TLS).
certificateChain (string) --
The certificate chain for the certificate.
privateKey (string) --
The private key for a certificate stored on the file system of the virtual node that the proxy is running on.
sds (dict) --
A reference to an object that represents a client's TLS Secret Discovery Service certificate.
secretName (string) --
A reference to an object that represents the name of the secret requested from the Secret Discovery Service provider representing Transport Layer Security (TLS) materials like a certificate or certificate chain.
enforce (boolean) --
Whether the policy is enforced. The default is True
, if a value isn't specified.
ports (list) --
One or more ports that the policy is enforced for.
validation (dict) --
A reference to an object that represents a TLS validation context.
subjectAlternativeNames (dict) --
A reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context. If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration. Since SPIRE vended certificates have a SPIFFE ID as a name, you must set the SAN since the name doesn't match the service discovery name.
match (dict) --
An object that represents the criteria for determining a SANs match.
exact (list) --
The values sent must match the specified values exactly.
trust (dict) --
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: acm
, file
, sds
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
acm (dict) --
A reference to an object that represents a Transport Layer Security (TLS) validation context trust for an Certificate Manager certificate.
certificateAuthorityArns (list) --
One or more ACM Amazon Resource Name (ARN)s.
file (dict) --
An object that represents a Transport Layer Security (TLS) validation context trust for a local file.
certificateChain (string) --
The certificate trust chain for a certificate stored on the file system of the virtual node that the proxy is running on.
sds (dict) --
A reference to an object that represents a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
secretName (string) --
A reference to an object that represents the name of the secret for a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
backends (list) --
The backends that the virtual node is expected to send outbound traffic to.
(dict) --
An object that represents the backends that a virtual node is expected to send outbound traffic to.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: virtualService
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
virtualService (dict) --
Specifies a virtual service to use as a backend.
clientPolicy (dict) --
A reference to an object that represents the client policy for a backend.
tls (dict) --
A reference to an object that represents a Transport Layer Security (TLS) client policy.
certificate (dict) --
A reference to an object that represents a client's TLS certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: file
, sds
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
file (dict) --
An object that represents a local file certificate. The certificate must meet specific requirements and you must have proxy authorization enabled. For more information, see Transport Layer Security (TLS).
certificateChain (string) --
The certificate chain for the certificate.
privateKey (string) --
The private key for a certificate stored on the file system of the virtual node that the proxy is running on.
sds (dict) --
A reference to an object that represents a client's TLS Secret Discovery Service certificate.
secretName (string) --
A reference to an object that represents the name of the secret requested from the Secret Discovery Service provider representing Transport Layer Security (TLS) materials like a certificate or certificate chain.
enforce (boolean) --
Whether the policy is enforced. The default is True
, if a value isn't specified.
ports (list) --
One or more ports that the policy is enforced for.
validation (dict) --
A reference to an object that represents a TLS validation context.
subjectAlternativeNames (dict) --
A reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context. If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration. Since SPIRE vended certificates have a SPIFFE ID as a name, you must set the SAN since the name doesn't match the service discovery name.
match (dict) --
An object that represents the criteria for determining a SANs match.
exact (list) --
The values sent must match the specified values exactly.
trust (dict) --
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: acm
, file
, sds
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
acm (dict) --
A reference to an object that represents a Transport Layer Security (TLS) validation context trust for an Certificate Manager certificate.
certificateAuthorityArns (list) --
One or more ACM Amazon Resource Name (ARN)s.
file (dict) --
An object that represents a Transport Layer Security (TLS) validation context trust for a local file.
certificateChain (string) --
The certificate trust chain for a certificate stored on the file system of the virtual node that the proxy is running on.
sds (dict) --
A reference to an object that represents a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
secretName (string) --
A reference to an object that represents the name of the secret for a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
virtualServiceName (string) --
The name of the virtual service that is acting as a virtual node backend.
listeners (list) --
The listener that the virtual node is expected to receive inbound traffic from. You can specify one listener.
(dict) --
An object that represents a listener for a virtual node.
connectionPool (dict) --
The connection pool information for the listener.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: grpc
, http
, http2
, tcp
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
grpc (dict) --
An object that represents a type of connection pool.
maxRequests (integer) --
Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster.
http (dict) --
An object that represents a type of connection pool.
maxConnections (integer) --
Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster.
maxPendingRequests (integer) --
Number of overflowing requests after max_connections
Envoy will queue to upstream cluster.
http2 (dict) --
An object that represents a type of connection pool.
maxRequests (integer) --
Maximum number of inflight requests Envoy can concurrently support across hosts in upstream cluster.
tcp (dict) --
An object that represents a type of connection pool.
maxConnections (integer) --
Maximum number of outbound TCP connections Envoy can establish concurrently with all hosts in upstream cluster.
healthCheck (dict) --
The health check information for the listener.
healthyThreshold (integer) --
The number of consecutive successful health checks that must occur before declaring listener healthy.
intervalMillis (integer) --
The time period in milliseconds between each health check execution.
path (string) --
The destination path for the health check request. This value is only used if the specified protocol is HTTP or HTTP/2. For any other protocol, this value is ignored.
port (integer) --
The destination port for the health check request. This port must match the port defined in the PortMapping for the listener.
protocol (string) --
The protocol for the health check request. If you specify grpc
, then your service must conform to the GRPC Health Checking Protocol.
timeoutMillis (integer) --
The amount of time to wait when receiving a response from the health check, in milliseconds.
unhealthyThreshold (integer) --
The number of consecutive failed health checks that must occur before declaring a virtual node unhealthy.
outlierDetection (dict) --
The outlier detection information for the listener.
baseEjectionDuration (dict) --
The base amount of time for which a host is ejected.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
interval (dict) --
The time interval between ejection sweep analysis.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
maxEjectionPercent (integer) --
Maximum percentage of hosts in load balancing pool for upstream service that can be ejected. Will eject at least one host regardless of the value.
maxServerErrors (integer) --
Number of consecutive 5xx
errors required for ejection.
portMapping (dict) --
The port mapping information for the listener.
port (integer) --
The port used for the port mapping.
protocol (string) --
The protocol used for the port mapping. Specify one protocol.
timeout (dict) --
An object that represents timeouts for different protocols.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: grpc
, http
, http2
, tcp
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
grpc (dict) --
An object that represents types of timeouts.
idle (dict) --
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
perRequest (dict) --
An object that represents a per request timeout. The default value is 15 seconds. If you set a higher timeout, then make sure that the higher value is set for each App Mesh resource in a conversation. For example, if a virtual node backend uses a virtual router provider to route to another virtual node, then the timeout should be greater than 15 seconds for the source and destination virtual node and the route.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
http (dict) --
An object that represents types of timeouts.
idle (dict) --
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
perRequest (dict) --
An object that represents a per request timeout. The default value is 15 seconds. If you set a higher timeout, then make sure that the higher value is set for each App Mesh resource in a conversation. For example, if a virtual node backend uses a virtual router provider to route to another virtual node, then the timeout should be greater than 15 seconds for the source and destination virtual node and the route.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
http2 (dict) --
An object that represents types of timeouts.
idle (dict) --
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
perRequest (dict) --
An object that represents a per request timeout. The default value is 15 seconds. If you set a higher timeout, then make sure that the higher value is set for each App Mesh resource in a conversation. For example, if a virtual node backend uses a virtual router provider to route to another virtual node, then the timeout should be greater than 15 seconds for the source and destination virtual node and the route.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
tcp (dict) --
An object that represents types of timeouts.
idle (dict) --
An object that represents an idle timeout. An idle timeout bounds the amount of time that a connection may be idle. The default value is none.
unit (string) --
A unit of time.
value (integer) --
A number of time units.
tls (dict) --
A reference to an object that represents the Transport Layer Security (TLS) properties for a listener.
certificate (dict) --
A reference to an object that represents a listener's Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: acm
, file
, sds
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
acm (dict) --
A reference to an object that represents an Certificate Manager certificate.
certificateArn (string) --
The Amazon Resource Name (ARN) for the certificate. The certificate must meet specific requirements and you must have proxy authorization enabled. For more information, see Transport Layer Security (TLS).
file (dict) --
A reference to an object that represents a local file certificate.
certificateChain (string) --
The certificate chain for the certificate.
privateKey (string) --
The private key for a certificate stored on the file system of the virtual node that the proxy is running on.
sds (dict) --
A reference to an object that represents a listener's Secret Discovery Service certificate.
secretName (string) --
A reference to an object that represents the name of the secret requested from the Secret Discovery Service provider representing Transport Layer Security (TLS) materials like a certificate or certificate chain.
mode (string) --
Specify one of the following modes.
validation (dict) --
A reference to an object that represents a listener's Transport Layer Security (TLS) validation context.
subjectAlternativeNames (dict) --
A reference to an object that represents the SANs for a listener's Transport Layer Security (TLS) validation context.
match (dict) --
An object that represents the criteria for determining a SANs match.
exact (list) --
The values sent must match the specified values exactly.
trust (dict) --
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: file
, sds
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
file (dict) --
An object that represents a Transport Layer Security (TLS) validation context trust for a local file.
certificateChain (string) --
The certificate trust chain for a certificate stored on the file system of the virtual node that the proxy is running on.
sds (dict) --
A reference to an object that represents a listener's Transport Layer Security (TLS) Secret Discovery Service validation context trust.
secretName (string) --
A reference to an object that represents the name of the secret for a Transport Layer Security (TLS) Secret Discovery Service validation context trust.
logging (dict) --
The inbound and outbound access logging information for the virtual node.
accessLog (dict) --
The access log configuration for a virtual node.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: file
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
file (dict) --
The file object to send virtual node access logs to.
format (dict) --
The specified format for the logs. The format is either json_format
or text_format
.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: json
, text
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
json (list) --
(dict) --
An object that represents the key value pairs for the JSON.
key (string) --
The specified key for the JSON.
value (string) --
The specified value for the JSON.
text (string) --
path (string) --
The file path to write access logs to. You can use /dev/stdout
to send access logs to standard out and configure your Envoy container to use a log driver, such as awslogs
, to export the access logs to a log storage service such as Amazon CloudWatch Logs. You can also specify a path in the Envoy container's file system to write the files to disk.
<note> <p>The Envoy process must have write permissions to the path that you specify here. Otherwise, Envoy fails to bootstrap properly.</p> </note>
serviceDiscovery (dict) --
The service discovery information for the virtual node. If your virtual node does not expect ingress traffic, you can omit this parameter. If you specify a listener
, then you must specify service discovery information.
Note
This is a Tagged Union structure. Only one of the following top level keys will be set: awsCloudMap
, dns
. If a client receives an unknown member it will set SDK_UNKNOWN_MEMBER
as the top level key, which maps to the name or tag of the unknown member. The structure of SDK_UNKNOWN_MEMBER
is as follows:
'SDK_UNKNOWN_MEMBER': {'name': 'UnknownMemberName'}
awsCloudMap (dict) --
Specifies any Cloud Map information for the virtual node.
attributes (list) --
A string map that contains attributes with values that you can use to filter instances by any custom attribute that you specified when you registered the instance. Only instances that match all of the specified key/value pairs will be returned.
(dict) --
An object that represents the Cloud Map attribute information for your virtual node.
Note
Cloud Map is not available in the eu-south-1 Region.
key (string) --
The name of an Cloud Map service instance attribute key. Any Cloud Map service instance that contains the specified key and value is returned.
value (string) --
The value of an Cloud Map service instance attribute key. Any Cloud Map service instance that contains the specified key and value is returned.
ipPreference (string) --
The preferred IP version that this virtual node uses. Setting the IP preference on the virtual node only overrides the IP preference set for the mesh on this specific node.
namespaceName (string) --
The name of the Cloud Map namespace to use.
serviceName (string) --
The name of the Cloud Map service to use.
dns (dict) --
Specifies the DNS information for the virtual node.
hostname (string) --
Specifies the DNS service discovery hostname for the virtual node.
ipPreference (string) --
The preferred IP version that this virtual node uses. Setting the IP preference on the virtual node only overrides the IP preference set for the mesh on this specific node.
responseType (string) --
Specifies the DNS response type for the virtual node.
status (dict) --
The current status for the virtual node.
status (string) --
The current status of the virtual node.
virtualNodeName (string) --
The name of the virtual node.
Exceptions
AppMesh.Client.exceptions.NotFoundException
AppMesh.Client.exceptions.BadRequestException
AppMesh.Client.exceptions.ConflictException
AppMesh.Client.exceptions.TooManyRequestsException
AppMesh.Client.exceptions.ForbiddenException
AppMesh.Client.exceptions.ServiceUnavailableException
AppMesh.Client.exceptions.InternalServerErrorException
AppMesh.Client.exceptions.LimitExceededException