WorkGroupConfiguration - Amazon Athena


The configuration of the workgroup, which includes the location in Amazon S3 where query and calculation results are stored, the encryption option, if any, used for query and calculation results, whether the Amazon CloudWatch Metrics are enabled for the workgroup and whether workgroup settings override query settings, and the data usage limits for the amount of data scanned per query or per workgroup. The workgroup settings override is specified in EnforceWorkGroupConfiguration (true/false) in the WorkGroupConfiguration. See WorkGroupConfiguration:EnforceWorkGroupConfiguration.



Specifies a user defined JSON string that is passed to the notebook engine.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 128.

Required: No


The upper data usage limit (cutoff) for the amount of bytes a single query in a workgroup is allowed to scan.

Type: Long

Valid Range: Minimum value of 10000000.

Required: No


Specifies the KMS key that is used to encrypt the user's data stores in Athena. This setting does not apply to Athena SQL workgroups.

Type: CustomerContentEncryptionConfiguration object

Required: No


Enforces a minimal level of encryption for the workgroup for query and calculation results that are written to Amazon S3. When enabled, workgroup users can set encryption only to the minimum level set by the administrator or higher when they submit queries.

The EnforceWorkGroupConfiguration setting takes precedence over the EnableMinimumEncryptionConfiguration flag. This means that if EnforceWorkGroupConfiguration is true, the EnableMinimumEncryptionConfiguration flag is ignored, and the workgroup configuration for encryption is used.

Type: Boolean

Required: No


If set to "true", the settings for the workgroup override client-side settings. If set to "false", client-side settings are used. For more information, see Workgroup Settings Override Client-Side Settings.

Type: Boolean

Required: No


The engine version that all queries running on the workgroup use. Queries on the AmazonAthenaPreviewFunctionality workgroup run on the preview engine regardless of this setting.

Type: EngineVersion object

Required: No


The ARN of the execution role used to access user resources for Spark sessions and IAM Identity Center enabled workgroups. This property applies only to Spark enabled workgroups and IAM Identity Center enabled workgroups. The property is required for IAM Identity Center enabled workgroups.

Type: String

Length Constraints: Minimum length of 20. Maximum length of 2048.

Pattern: ^arn:aws[a-z\-]*:iam::\d{12}:role/?[a-zA-Z_0-9+=,.@\-_/]+$

Required: No


Specifies whether the workgroup is IAM Identity Center supported.

Type: IdentityCenterConfiguration object

Required: No


Indicates that the Amazon CloudWatch metrics are enabled for the workgroup.

Type: Boolean

Required: No


Specifies whether Amazon S3 access grants are enabled for query results.

Type: QueryResultsS3AccessGrantsConfiguration object

Required: No


If set to true, allows members assigned to a workgroup to reference Amazon S3 Requester Pays buckets in queries. If set to false, workgroup members cannot query data from Requester Pays buckets, and queries that retrieve data from Requester Pays buckets cause an error. The default is false. For more information about Requester Pays buckets, see Requester Pays Buckets in the Amazon Simple Storage Service Developer Guide.

Type: Boolean

Required: No


The configuration for the workgroup, which includes the location in Amazon S3 where query and calculation results are stored and the encryption option, if any, used for query and calculation results. To run the query, you must specify the query results location using one of the ways: either in the workgroup using this setting, or for individual queries (client-side), using ResultConfiguration:OutputLocation. If none of them is set, Athena issues an error that no output location is provided.

Type: ResultConfiguration object

Required: No

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: