%% WARNING: DO NOT EDIT, AUTO-GENERATED CODE! %% See https://github.com/aws-beam/aws-codegen for more details. %% @doc AWS Secrets Manager API Reference %% %% AWS Secrets Manager provides a service to enable you to store, manage, and %% retrieve, secrets. %% %% This guide provides descriptions of the Secrets Manager API. For more %% information about using this service, see the AWS %% Secrets Manager User Guide. %% %% API Version %% %% This version of the Secrets Manager API Reference documents the Secrets %% Manager API version 2017-10-17. %% %% As an alternative to using the API, you can use one of the AWS %% SDKs, which consist of libraries and sample code for various programming %% languages and platforms such as Java, Ruby, .NET, iOS, and Android. The %% SDKs provide a convenient way to create programmatic access to AWS Secrets %% Manager. For example, the SDKs provide cryptographically signing requests, %% managing errors, and retrying requests automatically. For more information %% about the AWS SDKs, including downloading and installing them, see Tools for Amazon Web Services. %% %% We recommend you use the AWS SDKs to make programmatic API calls %% to Secrets Manager. However, you also can use the Secrets Manager HTTP %% Query API to make direct calls to the Secrets Manager web service. To %% learn more about the Secrets Manager HTTP Query API, see Making %% Query Requests in the AWS Secrets Manager User Guide. %% %% Secrets Manager API supports GET and POST requests for all actions, and %% doesn't require you to use GET for some actions and POST for others. %% However, GET requests are subject to the limitation size of a URL. %% Therefore, for operations that require larger sizes, use a POST request. %% %% Support and Feedback for AWS Secrets Manager %% %% We welcome your feedback. Send your comments to awssecretsmanager-feedback@amazon.com, %% or post your feedback and questions in the AWS Secrets %% Manager Discussion Forum. For more information about the AWS %% Discussion Forums, see Forums Help. %% %% How examples are presented %% %% The JSON that AWS Secrets Manager expects as your request parameters and %% the service returns as a response to HTTP query requests contain single, %% long strings without line breaks or white space formatting. The JSON shown %% in the examples displays the code formatted with both line breaks and %% white space to improve readability. When example input parameters can also %% cause long strings extending beyond the screen, you can insert line breaks %% to enhance readability. You should always submit the input as a single %% JSON text string. %% %% Logging API Requests %% %% AWS Secrets Manager supports AWS CloudTrail, a service that records AWS %% API calls for your AWS account and delivers log files to an Amazon S3 %% bucket. By using information that's collected by AWS CloudTrail, you can %% determine the requests successfully made to Secrets Manager, who made the %% request, when it was made, and so on. For more about AWS Secrets Manager %% and support for AWS CloudTrail, see Logging %% AWS Secrets Manager Events with AWS CloudTrail in the AWS Secrets %% Manager User Guide. To learn more about CloudTrail, including enabling %% it and find your log files, see the AWS %% CloudTrail User Guide. -module(aws_secrets_manager). -export([cancel_rotate_secret/2, cancel_rotate_secret/3, create_secret/2, create_secret/3, delete_resource_policy/2, delete_resource_policy/3, delete_secret/2, delete_secret/3, describe_secret/2, describe_secret/3, get_random_password/2, get_random_password/3, get_resource_policy/2, get_resource_policy/3, get_secret_value/2, get_secret_value/3, list_secret_version_ids/2, list_secret_version_ids/3, list_secrets/2, list_secrets/3, put_resource_policy/2, put_resource_policy/3, put_secret_value/2, put_secret_value/3, restore_secret/2, restore_secret/3, rotate_secret/2, rotate_secret/3, tag_resource/2, tag_resource/3, untag_resource/2, untag_resource/3, update_secret/2, update_secret/3, update_secret_version_stage/2, update_secret_version_stage/3, validate_resource_policy/2, validate_resource_policy/3]). -include_lib("hackney/include/hackney_lib.hrl"). %%==================================================================== %% API %%==================================================================== %% @doc Disables automatic scheduled rotation and cancels the rotation of a %% secret if currently in progress. %% %% To re-enable scheduled rotation, call RotateSecret with %% AutomaticallyRotateAfterDays set to a value greater than 0. %% This immediately rotates your secret and then enables the automatic %% schedule. %% %% If you cancel a rotation while in progress, it can leave the %% VersionStage labels in an unexpected state. Depending on the %% step of the rotation in progress, you might need to remove the staging %% label AWSPENDING from the partially created version, %% specified by the VersionId response value. You should also %% evaluate the partially rotated new version to see if it should be deleted, %% which you can do by removing all staging labels from the new version %% VersionStage field. %% %% To successfully start a rotation, the staging label %% AWSPENDING must be in one of the following states: %% %% If the staging label AWSPENDING attached to a %% different version than the version with AWSCURRENT then the %% attempt to rotate fails. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% cancel_rotate_secret(Client, Input) when is_map(Client), is_map(Input) -> cancel_rotate_secret(Client, Input, []). cancel_rotate_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CancelRotateSecret">>, Input, Options). %% @doc Creates a new secret. A secret in Secrets Manager consists of both %% the protected secret data and the important information needed to manage %% the secret. %% %% Secrets Manager stores the encrypted secret data in one of a collection of %% "versions" associated with the secret. Each version contains a copy of the %% encrypted secret data. Each version is associated with one or more %% "staging labels" that identify where the version is in the rotation cycle. %% The SecretVersionsToStages field of the secret contains the %% mapping of staging labels to the active versions of the secret. Versions %% without a staging label are considered deprecated and not included in the %% list. %% %% You provide the secret data to be encrypted by putting text in either the %% SecretString parameter or binary data in the %% SecretBinary parameter, but not both. If you include %% SecretString or SecretBinary then Secrets %% Manager also creates an initial secret version and automatically attaches %% the staging label AWSCURRENT to the new version. %% %% %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% create_secret(Client, Input) when is_map(Client), is_map(Input) -> create_secret(Client, Input, []). create_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateSecret">>, Input, Options). %% @doc Deletes the resource-based permission policy attached to the secret. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% delete_resource_policy(Client, Input) when is_map(Client), is_map(Input) -> delete_resource_policy(Client, Input, []). delete_resource_policy(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteResourcePolicy">>, Input, Options). %% @doc Deletes an entire secret and all of its versions. You can optionally %% include a recovery window during which you can restore the secret. If you %% don't specify a recovery window value, the operation defaults to 30 days. %% Secrets Manager attaches a DeletionDate stamp to the secret %% that specifies the end of the recovery window. At the end of the recovery %% window, Secrets Manager deletes the secret permanently. %% %% At any time before recovery window ends, you can use RestoreSecret %% to remove the DeletionDate and cancel the deletion of the %% secret. %% %% You cannot access the encrypted secret information in any secret that is %% scheduled for deletion. If you need to access that information, you must %% cancel the deletion with RestoreSecret and then retrieve the %% information. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% delete_secret(Client, Input) when is_map(Client), is_map(Input) -> delete_secret(Client, Input, []). delete_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteSecret">>, Input, Options). %% @doc Retrieves the details of a secret. It does not include the encrypted %% fields. Secrets Manager only returns fields populated with a value in the %% response. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% describe_secret(Client, Input) when is_map(Client), is_map(Input) -> describe_secret(Client, Input, []). describe_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DescribeSecret">>, Input, Options). %% @doc Generates a random password of the specified complexity. This %% operation is intended for use in the Lambda rotation function. Per best %% practice, we recommend that you specify the maximum length and include %% every character type that the system you are generating a password for can %% support. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% get_random_password(Client, Input) when is_map(Client), is_map(Input) -> get_random_password(Client, Input, []). get_random_password(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetRandomPassword">>, Input, Options). %% @doc Retrieves the JSON text of the resource-based policy document %% attached to the specified secret. The JSON request string input and %% response output displays formatted code with white space and line breaks %% for better readability. Submit your input as a single line JSON string. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% get_resource_policy(Client, Input) when is_map(Client), is_map(Input) -> get_resource_policy(Client, Input, []). get_resource_policy(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetResourcePolicy">>, Input, Options). %% @doc Retrieves the contents of the encrypted fields %% SecretString or SecretBinary from the specified %% version of a secret, whichever contains content. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% get_secret_value(Client, Input) when is_map(Client), is_map(Input) -> get_secret_value(Client, Input, []). get_secret_value(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetSecretValue">>, Input, Options). %% @doc Lists all of the versions attached to the specified secret. The %% output does not include the SecretString or %% SecretBinary fields. By default, the list includes only %% versions that have at least one staging label in VersionStage %% attached. %% %% Always check the NextToken response parameter when %% calling any of the List* operations. These operations can %% occasionally return an empty or shorter than expected list of results even %% when there more results become available. When this happens, the %% NextToken response parameter contains a value to pass to the %% next call to the same API to request the next part of the list. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% list_secret_version_ids(Client, Input) when is_map(Client), is_map(Input) -> list_secret_version_ids(Client, Input, []). list_secret_version_ids(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListSecretVersionIds">>, Input, Options). %% @doc Lists all of the secrets that are stored by Secrets Manager in the %% AWS account. To list the versions currently stored for a specific secret, %% use ListSecretVersionIds. The encrypted fields %% SecretString and SecretBinary are not included %% in the output. To get that information, call the GetSecretValue %% operation. %% %% Always check the NextToken response parameter when %% calling any of the List* operations. These operations can %% occasionally return an empty or shorter than expected list of results even %% when there more results become available. When this happens, the %% NextToken response parameter contains a value to pass to the %% next call to the same API to request the next part of the list. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% list_secrets(Client, Input) when is_map(Client), is_map(Input) -> list_secrets(Client, Input, []). list_secrets(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListSecrets">>, Input, Options). %% @doc Attaches the contents of the specified resource-based permission %% policy to a secret. A resource-based policy is optional. Alternatively, %% you can use IAM identity-based policies that specify the secret's Amazon %% Resource Name (ARN) in the policy statement's Resources %% element. You can also use a combination of both identity-based and %% resource-based policies. The affected users and roles receive the %% permissions that are permitted by all of the relevant policies. For more %% information, see Using %% Resource-Based Policies for AWS Secrets Manager. For the complete %% description of the AWS policy syntax and grammar, see IAM %% JSON Policy Reference in the IAM User Guide. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% put_resource_policy(Client, Input) when is_map(Client), is_map(Input) -> put_resource_policy(Client, Input, []). put_resource_policy(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"PutResourcePolicy">>, Input, Options). %% @doc Stores a new encrypted secret value in the specified secret. To do %% this, the operation creates a new version and attaches it to the secret. %% The version can contain a new SecretString value or a new %% SecretBinary value. You can also specify the staging labels %% that are initially attached to the new version. %% %% The Secrets Manager console uses only the SecretString %% field. To add binary data to a secret with the SecretBinary %% field you must use the AWS CLI or one of the AWS SDKs. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% put_secret_value(Client, Input) when is_map(Client), is_map(Input) -> put_secret_value(Client, Input, []). put_secret_value(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"PutSecretValue">>, Input, Options). %% @doc Cancels the scheduled deletion of a secret by removing the %% DeletedDate time stamp. This makes the secret accessible to %% query once again. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% restore_secret(Client, Input) when is_map(Client), is_map(Input) -> restore_secret(Client, Input, []). restore_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"RestoreSecret">>, Input, Options). %% @doc Configures and starts the asynchronous process of rotating this %% secret. If you include the configuration parameters, the operation sets %% those values for the secret and then immediately starts a rotation. If you %% do not include the configuration parameters, the operation starts a %% rotation with the values already stored in the secret. After the rotation %% completes, the protected service and its clients all use the new version %% of the secret. %% %% This required configuration information includes the ARN of an AWS Lambda %% function and the time between scheduled rotations. The Lambda rotation %% function creates a new version of the secret and creates or updates the %% credentials on the protected service to match. After testing the new %% credentials, the function marks the new secret with the staging label %% AWSCURRENT so that your clients all immediately begin to use %% the new version. For more information about rotating secrets and how to %% configure a Lambda function to rotate the secrets for your protected %% service, see Rotating %% Secrets in AWS Secrets Manager in the AWS Secrets Manager User %% Guide. %% %% Secrets Manager schedules the next rotation when the previous one %% completes. Secrets Manager schedules the date by adding the rotation %% interval (number of days) to the actual date of the last rotation. The %% service chooses the hour within that 24-hour date window randomly. The %% minute is also chosen somewhat randomly, but weighted towards the top of %% the hour and influenced by a variety of factors that help distribute load. %% %% The rotation function must end with the versions of the secret in one of %% two states: %% %% If the AWSPENDING staging label is present but %% not attached to the same version as AWSCURRENT then any later %% invocation of RotateSecret assumes that a previous rotation %% request is still in progress and returns an error. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% rotate_secret(Client, Input) when is_map(Client), is_map(Input) -> rotate_secret(Client, Input, []). rotate_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"RotateSecret">>, Input, Options). %% @doc Attaches one or more tags, each consisting of a key name and a value, %% to the specified secret. Tags are part of the secret's overall metadata, %% and are not associated with any specific version of the secret. This %% operation only appends tags to the existing list of tags. To remove tags, %% you must use UntagResource. %% %% The following basic restrictions apply to tags: %% %% If you use tags as part of your security strategy, %% then adding or removing a tag can change permissions. If successfully %% completing this operation would result in you losing your permissions for %% this secret, then the operation is blocked and returns an Access Denied %% error. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% tag_resource(Client, Input) when is_map(Client), is_map(Input) -> tag_resource(Client, Input, []). tag_resource(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"TagResource">>, Input, Options). %% @doc Removes one or more tags from the specified secret. %% %% This operation is idempotent. If a requested tag is not attached to the %% secret, no error is returned and the secret metadata is unchanged. %% %% If you use tags as part of your security strategy, then %% removing a tag can change permissions. If successfully completing this %% operation would result in you losing your permissions for this secret, %% then the operation is blocked and returns an Access Denied error. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% untag_resource(Client, Input) when is_map(Client), is_map(Input) -> untag_resource(Client, Input, []). untag_resource(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UntagResource">>, Input, Options). %% @doc Modifies many of the details of the specified secret. If you include %% a ClientRequestToken and either %% SecretString or SecretBinary then it also %% creates a new version attached to the secret. %% %% To modify the rotation configuration of a secret, use RotateSecret %% instead. %% %% The Secrets Manager console uses only the SecretString %% parameter and therefore limits you to encrypting and storing only a text %% string. To encrypt and store binary data as part of the version of a %% secret, you must use either the AWS CLI or one of the AWS SDKs. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% update_secret(Client, Input) when is_map(Client), is_map(Input) -> update_secret(Client, Input, []). update_secret(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateSecret">>, Input, Options). %% @doc Modifies the staging labels attached to a version of a secret. %% Staging labels are used to track a version as it progresses through the %% secret rotation process. You can attach a staging label to only one %% version of a secret at a time. If a staging label to be added is already %% attached to another version, then it is moved--removed from the other %% version first and then attached to this one. For more information about %% staging labels, see Staging %% Labels in the AWS Secrets Manager User Guide. %% %% The staging labels that you specify in the VersionStage %% parameter are added to the existing list of staging labels--they don't %% replace it. %% %% You can move the AWSCURRENT staging label to this version by %% including it in this call. %% %% Whenever you move AWSCURRENT, Secrets Manager %% automatically moves the label AWSPREVIOUS to the version that %% AWSCURRENT was removed from. %% %% If this action results in the last label being removed from a %% version, then the version is considered to be 'deprecated' and can be %% deleted by Secrets Manager. %% %% Minimum permissions %% %% To run this command, you must have the following permissions: %% %% Related operations %% %% update_secret_version_stage(Client, Input) when is_map(Client), is_map(Input) -> update_secret_version_stage(Client, Input, []). update_secret_version_stage(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateSecretVersionStage">>, Input, Options). %% @doc Validates the JSON text of the resource-based policy document %% attached to the specified secret. The JSON request string input and %% response output displays formatted code with white space and line breaks %% for better readability. Submit your input as a single line JSON string. A %% resource-based policy is optional. validate_resource_policy(Client, Input) when is_map(Client), is_map(Input) -> validate_resource_policy(Client, Input, []). validate_resource_policy(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ValidateResourcePolicy">>, Input, Options). %%==================================================================== %% Internal functions %%==================================================================== -spec request(aws_client:aws_client(), binary(), map(), list()) -> {ok, Result, {integer(), list(), hackney:client()}} | {error, Error, {integer(), list(), hackney:client()}} | {error, term()} when Result :: map() | undefined, Error :: {binary(), binary()}. request(Client, Action, Input, Options) -> Client1 = Client#{service => <<"secretsmanager">>}, Host = get_host(<<"secretsmanager">>, Client1), URL = get_url(Host, Client1), Headers = [ {<<"Host">>, Host}, {<<"Content-Type">>, <<"application/x-amz-json-1.1">>}, {<<"X-Amz-Target">>, << <<"secretsmanager.">>/binary, Action/binary>>} ], Payload = jsx:encode(Input), SignedHeaders = aws_request:sign_request(Client1, <<"POST">>, URL, Headers, Payload), Response = hackney:request(post, URL, SignedHeaders, Payload, Options), handle_response(Response). handle_response({ok, 200, ResponseHeaders, Client}) -> case hackney:body(Client) of {ok, <<>>} -> {ok, undefined, {200, ResponseHeaders, Client}}; {ok, Body} -> Result = jsx:decode(Body, [return_maps]), {ok, Result, {200, ResponseHeaders, Client}} end; handle_response({ok, StatusCode, ResponseHeaders, Client}) -> {ok, Body} = hackney:body(Client), Error = jsx:decode(Body, [return_maps]), Exception = maps:get(<<"__type">>, Error, undefined), Reason = maps:get(<<"message">>, Error, undefined), {error, {Exception, Reason}, {StatusCode, ResponseHeaders, Client}}; handle_response({error, Reason}) -> {error, Reason}. get_host(_EndpointPrefix, #{region := <<"local">>}) -> <<"localhost">>; get_host(EndpointPrefix, #{region := Region, endpoint := Endpoint}) -> aws_util:binary_join([EndpointPrefix, <<".">>, Region, <<".">>, Endpoint], <<"">>). get_url(Host, Client) -> Proto = maps:get(proto, Client), Port = maps:get(port, Client), aws_util:binary_join([Proto, <<"://">>, Host, <<":">>, Port, <<"/">>], <<"">>).