View a markdown version of this page

AWS::SageMaker::Workforce OidcConfig - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

This is the new Amazon CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the Amazon CloudFormation User Guide.

AWS::SageMaker::Workforce OidcConfig

Use this parameter to configure your OIDC Identity Provider (IdP).

Syntax

To declare this entity in your Amazon CloudFormation template, use the following syntax:

JSON

{ "AuthenticationRequestExtraParams" : {Key: Value, ...}, "AuthorizationEndpoint" : String, "ClientId" : String, "ClientSecret" : String, "Issuer" : String, "JwksUri" : String, "LogoutEndpoint" : String, "Scope" : String, "TokenEndpoint" : String, "UserInfoEndpoint" : String }

YAML

AuthenticationRequestExtraParams: Key: Value AuthorizationEndpoint: String ClientId: String ClientSecret: String Issuer: String JwksUri: String LogoutEndpoint: String Scope: String TokenEndpoint: String UserInfoEndpoint: String

Properties

AuthenticationRequestExtraParams

A string to string map of identifiers specific to the custom identity provider (IdP) being used.

Required: No

Type: Object of String

Pattern: ^.+$

Maximum: 512

Update requires: No interruption

AuthorizationEndpoint

The OIDC IdP authorization endpoint used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^https://.*$

Maximum: 500

Update requires: No interruption

ClientId

The OIDC IdP client ID used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^[\w+]+$

Maximum: 1024

Update requires: No interruption

ClientSecret

The OIDC IdP client secret used to configure your private workforce.

Required: No

Type: String

Pattern: ^[\w+]+$

Maximum: 1024

Update requires: No interruption

Issuer

The OIDC IdP issuer used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^https://.*$

Maximum: 500

Update requires: No interruption

JwksUri

The OIDC IdP JSON Web Key Set (Jwks) URI used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^https://.*$

Maximum: 500

Update requires: No interruption

LogoutEndpoint

The OIDC IdP logout endpoint used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^https://.*$

Maximum: 500

Update requires: No interruption

Scope

An array of string identifiers used to refer to the specific pieces of user data or claims that the client application wants to access.

Required: No

Type: String

Pattern: ^[\p{L}\p{M}\p{S}\p{N}\p{P}\s]+$

Maximum: 500

Update requires: No interruption

TokenEndpoint

The OIDC IdP token endpoint used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^https://.*$

Maximum: 500

Update requires: No interruption

UserInfoEndpoint

The OIDC IdP user information endpoint used to configure your private workforce.

Required: Yes

Type: String

Pattern: ^https://.*$

Maximum: 500

Update requires: No interruption