Interface TransitEncryption
- All Superinterfaces:
software.amazon.jsii.JsiiSerializable
- All Known Implementing Classes:
TransitEncryption.Jsii$Proxy
Uses AWS Secrets Manager for key management.
The secret must live in the same AWS account and Region as the consuming resource. MediaConnect does not support cross-account or cross-Region secrets.
Trust-policy scope on routers. Router I/O ids are service-generated (unknown at synth
time), and pinning the live ARN would create a CloudFormation dependency cycle — so the
auto-created role pins aws:SourceArn to a wildcarded ARN (arn:...:routerInput:* /
arn:...:routerOutput:*) plus aws:SourceAccount. To pin a tighter trust policy, supply
your own role.
Example:
Stack stack;
IChannel mediaLiveChannel;
Secret transitSecret;
// must hold the same value as the channel's MediaConnectRouterSettings.shared() secret
RouterInput input = RouterInput.Builder.create(stack, "ChannelInput")
.routerInputName("channel-input")
.maximumBitrate(Bitrate.mbps(20))
.routingScope(RoutingScope.REGIONAL)
.tier(RouterInputTier.INPUT_50)
.configuration(RouterInputConfiguration.mediaLiveChannel(MediaLiveChannelConfigurationProps.builder()
.channel(mediaLiveChannel)
.outputName("router-ts")
.pipeline(MediaLivePipeline.PIPELINE_0)
.sourceTransitDecryption(TransitEncryption.builder().secret(transitSecret).build())
.build()))
.build();
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeInterfaceDescriptionstatic final classA builder forTransitEncryptionstatic final classAn implementation forTransitEncryption -
Method Summary
Methods inherited from interface software.amazon.jsii.JsiiSerializable
$jsii$toJson
-
Method Details
-
getSecret
(experimental) Secrets Manager secret containing the transit encryption key. -
getRole
(experimental) IAM role that MediaConnect assumes to access the Secrets Manager secret.If provided, the role is used as-is; you must grant it the necessary permissions yourself.
Default: - a scoped role is auto-created with read access to the secret and a confused-deputy trust condition. See the **Encryption** section of the module README for the generated trust policy.
-
builder
- Returns:
- a
TransitEncryption.BuilderofTransitEncryption
-