snapshot_copy_grants
Creates, updates, deletes, gets or lists a snapshot_copy_grants resource.
Overview
| Name | snapshot_copy_grants |
| Type | Resource |
| Id | aws.redshift.snapshot_copy_grants |
Fields
The following fields are returned by SELECT queries:
- describe_snapshot_copy_grants
| Name | Datatype | Description |
|---|---|---|
kms_key_id | string | The unique identifier of the encrypted symmetric key in Amazon Web Services KMS to which Amazon Redshift is granted permission. |
snapshot_copy_grant_name | string | The name of the snapshot copy grant. |
tags | string | A list of tag instances. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
describe_snapshot_copy_grants | select | region | SnapshotCopyGrantName, MaxRecords, Marker, TagKeys, TagValues | Returns a list of snapshot copy grants owned by the Amazon Web Services account in the destination region. For more information about managing snapshot copy grants, go to Amazon Redshift Database Encryption in the Amazon Redshift Cluster Management Guide. |
create_snapshot_copy_grant | insert | SnapshotCopyGrantName, region | KmsKeyId, Tags | Creates a snapshot copy grant that permits Amazon Redshift to use an encrypted symmetric key from Key Management Service (KMS) to encrypt copied snapshots in a destination region. For more information about managing snapshot copy grants, go to Amazon Redshift Database Encryption in the Amazon Redshift Cluster Management Guide. |
delete_snapshot_copy_grant | delete | SnapshotCopyGrantName, region | Deletes the specified snapshot copy grant. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
SnapshotCopyGrantName | string | The name of the snapshot copy grant to delete. |
region | string | AWS region (default: us-east-1) |
KmsKeyId | string | The unique identifier of the encrypted symmetric key to which to grant Amazon Redshift permission. If no key is specified, the default key is used. |
Marker | string | An optional parameter that specifies the starting point to return a set of response records. When the results of a DescribeSnapshotCopyGrant request exceed the value specified in MaxRecords, Amazon Web Services returns a value in the Marker field of the response. You can retrieve the next set of response records by providing the returned marker value in the Marker parameter and retrying the request. Constraints: You can specify either the SnapshotCopyGrantName parameter or the Marker parameter, but not both. |
MaxRecords | integer | The maximum number of response records to return in each call. If the number of remaining response records exceeds the specified MaxRecords value, a value is returned in a marker field of the response. You can retrieve the next set of records by retrying the command with the returned marker value. Default: 100 Constraints: minimum 20, maximum 100. |
SnapshotCopyGrantName | string | The name of the snapshot copy grant. |
TagKeys | array | A tag key or keys for which you want to return all matching resources that are associated with the specified key or keys. For example, suppose that you have resources tagged with keys called owner and environment. If you specify both of these tag keys in the request, Amazon Redshift returns a response with all resources that have either or both of these tag keys associated with them. |
TagValues | array | A tag value or values for which you want to return all matching resources that are associated with the specified value or values. For example, suppose that you have resources tagged with values called admin and test. If you specify both of these tag values in the request, Amazon Redshift returns a response with all resources that have either or both of these tag values associated with them. |
Tags | array | A list of tag instances. |
SELECT examples
- describe_snapshot_copy_grants
Returns a list of snapshot copy grants owned by the Amazon Web Services account in the destination region. For more information about managing snapshot copy grants, go to Amazon Redshift Database Encryption in the Amazon Redshift Cluster Management Guide.
SELECT
kms_key_id,
snapshot_copy_grant_name,
tags
FROM aws.redshift.snapshot_copy_grants
WHERE region = '{{ region }}' -- required
AND SnapshotCopyGrantName = '{{ SnapshotCopyGrantName }}'
AND MaxRecords = '{{ MaxRecords }}'
AND Marker = '{{ Marker }}'
AND TagKeys = '{{ TagKeys }}'
AND TagValues = '{{ TagValues }}'
;
INSERT examples
- create_snapshot_copy_grant
- Manifest
Creates a snapshot copy grant that permits Amazon Redshift to use an encrypted symmetric key from Key Management Service (KMS) to encrypt copied snapshots in a destination region. For more information about managing snapshot copy grants, go to Amazon Redshift Database Encryption in the Amazon Redshift Cluster Management Guide.
INSERT INTO aws.redshift.snapshot_copy_grants (
SnapshotCopyGrantName,
region,
KmsKeyId,
Tags
)
SELECT
'{{ SnapshotCopyGrantName }}',
'{{ region }}',
'{{ KmsKeyId }}',
'{{ Tags }}'
RETURNING
kms_key_id,
snapshot_copy_grant_name,
tags
;
# Description fields are for documentation purposes
- name: snapshot_copy_grants
props:
- name: SnapshotCopyGrantName
value: "{{ SnapshotCopyGrantName }}"
description: Required parameter for the snapshot_copy_grants resource.
- name: region
value: "{{ region }}"
description: Required parameter for the snapshot_copy_grants resource.
- name: KmsKeyId
value: "{{ KmsKeyId }}"
description: The unique identifier of the encrypted symmetric key to which to grant Amazon Redshift permission. If no key is specified, the default key is used.
description: The unique identifier of the encrypted symmetric key to which to grant Amazon Redshift permission. If no key is specified, the default key is used.
- name: Tags
value: "{{ Tags }}"
description: A list of tag instances.
description: A list of tag instances.
DELETE examples
- delete_snapshot_copy_grant
Deletes the specified snapshot copy grant.
DELETE FROM aws.redshift.snapshot_copy_grants
WHERE SnapshotCopyGrantName = '{{ SnapshotCopyGrantName }}' --required
AND region = '{{ region }}' --required
;