Method: Aws::Transfer::Types::UpdateAgreementRequest#access_role

Defined in:
lib/aws-sdk-transfer/types.rb

#access_roleString

Connectors are used to send files using either the AS2 or SFTP protocol. For the access role, provide the Amazon Resource Name (ARN) of the Identity and Access Management role to use.

**For AS2 connectors**

With AS2, you can send files by calling StartFileTransfer and specifying the file paths in the request parameter, SendFilePaths. We use the file’s parent directory (for example, for ‘–send-file-paths /bucket/dir/file.txt`, parent directory is /bucket/dir/) to temporarily store a processed AS2 message file, store the MDN when we receive them from the partner, and write a final JSON file containing relevant metadata of the transmission. So, the AccessRole needs to provide read and write access to the parent directory of the file location used in the StartFileTransfer request. Additionally, you need to provide read and write access to the parent directory of the files that you intend to send with StartFileTransfer.

If you are using Basic authentication for your AS2 connector, the access role requires the secretsmanager:GetSecretValue permission for the secret. If the secret is encrypted using a customer-managed key instead of the Amazon Web Services managed key in Secrets Manager, then the role also needs the kms:Decrypt permission for that key.

**For SFTP connectors**

Make sure that the access role provides read and write access to the parent directory of the file location that’s used in the StartFileTransfer request. Additionally, make sure that the role provides secretsmanager:GetSecretValue permission to Secrets Manager.

Returns:

  • (String)


6967
6968
6969
6970
6971
6972
6973
6974
6975
6976
6977
6978
6979
6980
6981
# File 'lib/aws-sdk-transfer/types.rb', line 6967

class UpdateAgreementRequest < Struct.new(
  :agreement_id,
  :server_id,
  :description,
  :status,
  :local_profile_id,
  :partner_profile_id,
  :base_directory,
  :access_role,
  :preserve_filename,
  :enforce_message_signing,
  :custom_directories)
  SENSITIVE = []
  include Aws::Structure
end