Skip to main content

key_groups

Creates, updates, deletes or gets a key_group resource or lists key_groups in a region

Overview

Namekey_groups
TypeResource
DescriptionA key group.
A key group contains a list of public keys that you can use with [CloudFront signed URLs and signed cookies](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/PrivateContent.html).
Idawscc.cloudfront.key_groups

Fields

NameDatatypeDescription
idstring
key_group_configobjectThe key group configuration.
last_modified_timestring
regionstringAWS region.

For more information, see AWS::CloudFront::KeyGroup.

Methods

NameResourceAccessible byRequired Params
create_resourcekey_groupsINSERTKeyGroupConfig, region
delete_resourcekey_groupsDELETEIdentifier, region
update_resourcekey_groupsUPDATEIdentifier, PatchDocument, region
list_resourceskey_groups_list_onlySELECTregion
get_resourcekey_groupsSELECTIdentifier, region

SELECT examples

Gets all properties from an individual key_group.

SELECT
region,
id,
key_group_config,
last_modified_time
FROM awscc.cloudfront.key_groups
WHERE
region = 'us-east-1' AND
Identifier = '{{ id }}';

INSERT example

Use the following StackQL query and manifest file to create a new key_group resource, using stack-deploy.

/*+ create */
INSERT INTO awscc.cloudfront.key_groups (
KeyGroupConfig,
region
)
SELECT
'{{ key_group_config }}',
'{{ region }}';

UPDATE example

Use the following StackQL query and manifest file to update a key_group resource, using stack-deploy.

/*+ update */
UPDATE awscc.cloudfront.key_groups
SET PatchDocument = string('{{ {
"KeyGroupConfig": key_group_config
} | generate_patch_document }}')
WHERE
region = '{{ region }}' AND
Identifier = '{{ id }}';

DELETE example

/*+ delete */
DELETE FROM awscc.cloudfront.key_groups
WHERE
Identifier = '{{ id }}' AND
region = 'us-east-1';

Permissions

To operate on the key_groups resource, the following permissions are required:

cloudfront:CreateKeyGroup