CloudHSMV2 / Client / delete_cluster



Deletes the specified AWS CloudHSM cluster. Before you can delete a cluster, you must delete all HSMs in the cluster. To see if the cluster contains any HSMs, use DescribeClusters. To delete an HSM, use DeleteHsm.

See also: AWS API Documentation

Request Syntax

response = client.delete_cluster(

ClusterId (string) –


The identifier (ID) of the cluster that you are deleting. To find the cluster ID, use DescribeClusters.

Return type:



Response Syntax

    'Cluster': {
        'BackupPolicy': 'DEFAULT',
        'BackupRetentionPolicy': {
            'Type': 'DAYS',
            'Value': 'string'
        'ClusterId': 'string',
        'CreateTimestamp': datetime(2015, 1, 1),
        'Hsms': [
                'AvailabilityZone': 'string',
                'ClusterId': 'string',
                'SubnetId': 'string',
                'EniId': 'string',
                'EniIp': 'string',
                'HsmId': 'string',
                'StateMessage': 'string'
        'HsmType': 'string',
        'PreCoPassword': 'string',
        'SecurityGroup': 'string',
        'SourceBackupId': 'string',
        'StateMessage': 'string',
        'SubnetMapping': {
            'string': 'string'
        'VpcId': 'string',
        'Certificates': {
            'ClusterCsr': 'string',
            'HsmCertificate': 'string',
            'AwsHardwareCertificate': 'string',
            'ManufacturerHardwareCertificate': 'string',
            'ClusterCertificate': 'string'
        'TagList': [
                'Key': 'string',
                'Value': 'string'

Response Structure

  • (dict) –

    • Cluster (dict) –

      Information about the cluster that was deleted.

      • BackupPolicy (string) –

        The cluster’s backup policy.

      • BackupRetentionPolicy (dict) –

        A policy that defines how the service retains backups.

        • Type (string) –

          The type of backup retention policy. For the DAYS type, the value is the number of days to retain backups.

        • Value (string) –

          Use a value between 7 - 379.

      • ClusterId (string) –

        The cluster’s identifier (ID).

      • CreateTimestamp (datetime) –

        The date and time when the cluster was created.

      • Hsms (list) –

        Contains information about the HSMs in the cluster.

        • (dict) –

          Contains information about a hardware security module (HSM) in an AWS CloudHSM cluster.

          • AvailabilityZone (string) –

            The Availability Zone that contains the HSM.

          • ClusterId (string) –

            The identifier (ID) of the cluster that contains the HSM.

          • SubnetId (string) –

            The subnet that contains the HSM’s elastic network interface (ENI).

          • EniId (string) –

            The identifier (ID) of the HSM’s elastic network interface (ENI).

          • EniIp (string) –

            The IP address of the HSM’s elastic network interface (ENI).

          • HsmId (string) –

            The HSM’s identifier (ID).

          • State (string) –

            The HSM’s state.

          • StateMessage (string) –

            A description of the HSM’s state.

      • HsmType (string) –

        The type of HSM that the cluster contains.

      • PreCoPassword (string) –

        The default password for the cluster’s Pre-Crypto Officer (PRECO) user.

      • SecurityGroup (string) –

        The identifier (ID) of the cluster’s security group.

      • SourceBackupId (string) –

        The identifier (ID) of the backup used to create the cluster. This value exists only when the cluster was created from a backup.

      • State (string) –

        The cluster’s state.

      • StateMessage (string) –

        A description of the cluster’s state.

      • SubnetMapping (dict) –

        A map from availability zone to the cluster’s subnet in that availability zone.

        • (string) –

          • (string) –

      • VpcId (string) –

        The identifier (ID) of the virtual private cloud (VPC) that contains the cluster.

      • Certificates (dict) –

        Contains one or more certificates or a certificate signing request (CSR).

        • ClusterCsr (string) –

          The cluster’s certificate signing request (CSR). The CSR exists only when the cluster’s state is UNINITIALIZED.

        • HsmCertificate (string) –

          The HSM certificate issued (signed) by the HSM hardware.

        • AwsHardwareCertificate (string) –

          The HSM hardware certificate issued (signed) by AWS CloudHSM.

        • ManufacturerHardwareCertificate (string) –

          The HSM hardware certificate issued (signed) by the hardware manufacturer.

        • ClusterCertificate (string) –

          The cluster certificate issued (signed) by the issuing certificate authority (CA) of the cluster’s owner.

      • TagList (list) –

        The list of tags for the cluster.

        • (dict) –

          Contains a tag. A tag is a key-value pair.

          • Key (string) –

            The key of the tag.

          • Value (string) –

            The value of the tag.


  • CloudHSMV2.Client.exceptions.CloudHsmAccessDeniedException

  • CloudHSMV2.Client.exceptions.CloudHsmInternalFailureException

  • CloudHSMV2.Client.exceptions.CloudHsmInvalidRequestException

  • CloudHSMV2.Client.exceptions.CloudHsmResourceNotFoundException

  • CloudHSMV2.Client.exceptions.CloudHsmServiceException

  • CloudHSMV2.Client.exceptions.CloudHsmTagException