CreateDeployment
Creates a deployment. A deployment applies one or more policies to the accounts and resources selected by a scope. Use isPublished to create the deployment in published (ACTIVE) or draft (DRAFT) state. The response includes coverage information and any warnings about the deployment.
Request Syntax
POST /deployments HTTP/1.1
Content-type: application/json
{
"associatedPolicyList": [
{
"policyIdentifier": "string"
}
],
"associatedScopeList": [
{
"scopeIdentifier": "string"
}
],
"clientToken": "string",
"deploymentConfiguration": {
"enableCrossAccountVisibility": boolean
},
"deploymentDescription": "string",
"deploymentName": "string",
"isPublished": boolean,
"tags": {
"string" : "string"
}
}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
- associatedPolicyList
-
The policies associated with the deployment.
Type: Array of PolicyReference objects
Array Members: Minimum number of 1 item. Maximum number of 2 items.
Required: Yes
- associatedScopeList
-
The scope associated with the deployment. A deployment has exactly one scope.
Type: Array of ScopeReference objects
Array Members: Fixed number of 1 item.
Required: Yes
- clientToken
-
A unique, case-sensitive token that you provide to ensure that the operation completes no more than one time. If you retry a request with the same client token and the same parameters, the service returns the result of the original successful request.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[\x21-\x7E]+Required: No
- deploymentConfiguration
-
The configuration settings for the deployment.
Type: DeploymentConfiguration object
Required: Yes
- deploymentDescription
-
A description of the deployment.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 256.
Pattern:
[a-zA-Z0-9 _.:/=+\-@]*Required: No
- deploymentName
-
The name of the deployment.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*Required: Yes
- isPublished
-
Specifies whether to publish the resource. When
true, the resource is saved in published (ACTIVE) state. Whenfalse, it is saved as a draft (DRAFT). Default:true.Type: Boolean
Required: No
-
The tags to add to the resource when it is created.
Type: String to string map
Map Entries: Minimum number of 0 items. Maximum number of 200 items.
Key Length Constraints: Minimum length of 1. Maximum length of 128.
Key Pattern:
([\p{L}\p{Z}\p{N}_.:/=+\-@]*)Value Length Constraints: Minimum length of 0. Maximum length of 256.
Required: No
Response Syntax
HTTP/1.1 201
Content-type: application/json
{
"associatedPolicyList": [
{
"policyArn": "string"
}
],
"associatedScopeList": [
{
"scopeArn": "string"
}
],
"deploymentArn": "string",
"deploymentConfiguration": {
"enableCrossAccountVisibility": boolean
},
"deploymentCoverage": [
{
"firewallType": "string",
"inScopeResourceTypes": [ "string" ],
"policyArns": [ "string" ]
}
],
"deploymentDescription": "string",
"deploymentId": "string",
"deploymentName": "string",
"hasPublishedVersion": boolean,
"isSnapshot": boolean,
"status": "string",
"updatedAt": "string",
"updateToken": "string",
"version": "string",
"warnings": [
{
"code": "string",
"message": "string",
"policyArn": "string"
}
]
}
Response Elements
If the action is successful, the service sends back an HTTP 201 response.
The following data is returned in JSON format by the service.
- associatedPolicyList
-
The policies associated with the deployment.
Type: Array of AssociatedPolicy objects
Array Members: Minimum number of 1 item. Maximum number of 2 items.
- associatedScopeList
-
The scope associated with the deployment. A deployment has exactly one scope.
Type: Array of AssociatedScope objects
Array Members: Fixed number of 1 item.
- deploymentArn
-
The Amazon Resource Name (ARN) of the deployment.
Type: String
Length Constraints: Minimum length of 20. Maximum length of 1010.
Pattern:
arn(:[a-z0-9]+([.-][a-z0-9]+)*){2}(:([a-z0-9]+([.-][a-z0-9]+)*)?){2}:(.+) - deploymentConfiguration
-
The configuration settings for the deployment.
Type: DeploymentConfiguration object
- deploymentCoverage
-
The coverage information for the deployment. For each firewall type, it shows which policies have that firewall type and which in-scope resource types the firewall type protects.
Type: Array of DeploymentCoverageEntry objects
Array Members: Minimum number of 0 items. Maximum number of 10 items.
- deploymentDescription
-
A description of the deployment.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 256.
Pattern:
[a-zA-Z0-9 _.:/=+\-@]* - deploymentId
-
The service-generated id of the deployment.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[a-z0-9]{1,64} - deploymentName
-
The name of the deployment.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]* - hasPublishedVersion
-
Specifies whether a published version of the resource exists.
Type: Boolean
- isSnapshot
-
Specifies whether the resource is a snapshot of a published version.
Type: Boolean
- status
-
The current status of the resource:
DRAFT(unpublished, editable) orACTIVE(published, in use).Type: String
Valid Values:
DRAFT | ACTIVE | DISABLED - updatedAt
-
The time when the resource was last updated.
Type: Timestamp
- updateToken
-
A token used for optimistic concurrency control. Each read and write returns an
updateToken. Provide the most recent value on your next update to detect and prevent conflicting concurrent modifications.Type: String
Length Constraints: Fixed length of 36.
Pattern:
([0-9a-f]{8})-([0-9a-f]{4}-){3}([0-9a-f]{12}) - version
-
The version of the resource.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 10.
Pattern:
[1-9][0-9]* - warnings
-
Warnings about potential issues, such as a policy that has no applicable resources in the deployment's scope.
Type: Array of DeploymentWarningEntry objects
Array Members: Minimum number of 0 items. Maximum number of 100 items.
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
You do not have sufficient permissions to perform this action.
HTTP Status Code: 403
- ConflictException
-
The request conflicts with the current state of the resource. For example, the resource was modified concurrently, or it is in a state that does not allow the requested operation.
- resourceId
-
The ID of the resource that is in conflict with the request.
- resourceType
-
The type of the resource that is in conflict with the request.
HTTP Status Code: 409
- InternalServerException
-
The request processing failed because of an internal error in the service. This is a retryable error.
HTTP Status Code: 500
- ServiceQuotaExceededException
-
The request would exceed a service quota.
- quotaCode
-
The code that identifies the service quota that was exceeded.
- resourceId
-
The ID of the resource associated with the quota that was exceeded.
- resourceType
-
The type of the resource associated with the quota that was exceeded.
- serviceCode
-
The code for the AWS service that owns the quota that was exceeded.
HTTP Status Code: 402
- ServiceUnavailableException
-
The service is temporarily unavailable. This is a retryable error.
- retryAfterSeconds
-
The number of seconds to wait before retrying the request.
HTTP Status Code: 503
- TagPolicyViolationException
-
The request violates a tag policy that is in effect for the account or organization.
HTTP Status Code: 400
- ThrottlingException
-
The request was denied because of request throttling. Reduce your request rate and try again.
- retryAfterSeconds
-
The number of seconds to wait before retrying the request.
HTTP Status Code: 429
- ValidationException
-
The request failed validation. For details, see the
reasonandfieldListmembers of the response.- fieldList
-
The list of request fields that failed validation, if any.
- reason
-
The reason that the request failed validation.
HTTP Status Code: 400
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: