From e6bbb8a84c30bb71a5218bb33c56f72b5cb887b3 Mon Sep 17 00:00:00 2001 From: aws-sam-cli-bot <46753707+aws-sam-cli-bot@users.noreply.github.com> Date: Mon, 24 Aug 2026 14:37:31 -0700 Subject: [PATCH 1/4] chore: bump version to 1.113.0 --- samtranslator/__init__.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/samtranslator/__init__.py b/samtranslator/__init__.py index ff02d400a..22c47ece6 100644 --- a/samtranslator/__init__.py +++ b/samtranslator/__init__.py @@ -1 +1 @@ -__version__ = "1.111.0" +__version__ = "1.113.0" From 47ab648a8e3d9e0eaca987705a59a9e9d53332ff Mon Sep 17 00:00:00 2001 From: aws-sam-cli-bot <46753707+aws-sam-cli-bot@users.noreply.github.com> Date: Mon, 24 Aug 2026 15:34:02 -0700 Subject: [PATCH 2/4] fix: add unused-ignore to add_multi_constructor type ignore to fix mypy CI --- samtranslator/yaml_helper.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/samtranslator/yaml_helper.py b/samtranslator/yaml_helper.py index 60f0e4f16..8a20e7fab 100644 --- a/samtranslator/yaml_helper.py +++ b/samtranslator/yaml_helper.py @@ -7,7 +7,7 @@ def yaml_parse(yamlstr): # type: ignore[no-untyped-def] """Parse a yaml string""" - yaml.SafeLoader.add_multi_constructor("!", intrinsics_multi_constructor) # type: ignore[no-untyped-call] + yaml.SafeLoader.add_multi_constructor("!", intrinsics_multi_constructor) # type: ignore[no-untyped-call,unused-ignore] return yaml.safe_load(yamlstr) From ad89eb8352b398ae1a301ac20a98dec664048864 Mon Sep 17 00:00:00 2001 From: Vichy Meas Date: Thu, 8 Oct 2026 15:01:58 -0700 Subject: [PATCH 3/4] feat: add OAuth and IAM auth support for self-managed Kafka --- .cfnlintrc.yaml | 3 + samtranslator/model/eventsources/pull.py | 29 +- .../test_self_managed_kafka_event_source.py | 354 ++++++++++++++++++ ...tion_with_self_managed_kafka_iam_auth.yaml | 26 ++ ...ion_with_self_managed_kafka_iam_oauth.yaml | 28 ++ ...unction_with_self_managed_kafka_oauth.yaml | 38 ++ ...tion_with_self_managed_kafka_iam_auth.json | 117 ++++++ ...ion_with_self_managed_kafka_iam_oauth.json | 121 ++++++ ...unction_with_self_managed_kafka_oauth.json | 153 ++++++++ ...OOT_CA_CERTIFICATE_and_auth_mechanism.json | 2 +- ...tion_with_self_managed_kafka_iam_auth.json | 117 ++++++ ...ion_with_self_managed_kafka_iam_oauth.json | 121 ++++++ ...unction_with_self_managed_kafka_oauth.json | 153 ++++++++ ...OOT_CA_CERTIFICATE_and_auth_mechanism.json | 2 +- ...tion_with_self_managed_kafka_iam_auth.json | 117 ++++++ ...ion_with_self_managed_kafka_iam_oauth.json | 121 ++++++ ...unction_with_self_managed_kafka_oauth.json | 153 ++++++++ ...OOT_CA_CERTIFICATE_and_auth_mechanism.json | 2 +- 18 files changed, 1650 insertions(+), 7 deletions(-) create mode 100644 tests/translator/input/function_with_self_managed_kafka_iam_auth.yaml create mode 100644 tests/translator/input/function_with_self_managed_kafka_iam_oauth.yaml create mode 100644 tests/translator/input/function_with_self_managed_kafka_oauth.yaml create mode 100644 tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_auth.json create mode 100644 tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_oauth.json create mode 100644 tests/translator/output/aws-cn/function_with_self_managed_kafka_oauth.json create mode 100644 tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_auth.json create mode 100644 tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_oauth.json create mode 100644 tests/translator/output/aws-us-gov/function_with_self_managed_kafka_oauth.json create mode 100644 tests/translator/output/function_with_self_managed_kafka_iam_auth.json create mode 100644 tests/translator/output/function_with_self_managed_kafka_iam_oauth.json create mode 100644 tests/translator/output/function_with_self_managed_kafka_oauth.json diff --git a/.cfnlintrc.yaml b/.cfnlintrc.yaml index 72eda88df..e9a256a84 100644 --- a/.cfnlintrc.yaml +++ b/.cfnlintrc.yaml @@ -108,6 +108,9 @@ ignore_templates: - tests/translator/output/**/managed_policies_everything.json # intentionally contains wrong arns - tests/translator/output/**/function_with_metrics_config.json - tests/translator/output/**/function_with_self_managed_kafka_and_schema_registry.json # cfnlint is not updated to recognize the SchemaRegistryConfig property + - tests/translator/output/**/function_with_self_managed_kafka_oauth.json # cfnlint is not updated to recognize OAuth SourceAccessConfigurations types + - tests/translator/output/**/function_with_self_managed_kafka_iam_auth.json # cfnlint is not updated to recognize IAM_AUTH SourceAccessConfigurations type + - tests/translator/output/**/function_with_self_managed_kafka_iam_oauth.json # cfnlint is not updated to recognize IAM_OAUTHBEARER_AUTH SourceAccessConfigurations type - tests/translator/output/**/function_with_msk_with_schema_registry_config.json # cfnlint is not updated to recognize the SchemaRegistryConfig property - tests/translator/output/**/function_with_logging_config.json # cfnlint is not updated to recognize the LoggingConfig property - tests/translator/output/aws-*/*capacity_provider*.json # Ignore Capacity Provider test format in non-aws partitions diff --git a/samtranslator/model/eventsources/pull.py b/samtranslator/model/eventsources/pull.py index dd1158d12..78b41700a 100644 --- a/samtranslator/model/eventsources/pull.py +++ b/samtranslator/model/eventsources/pull.py @@ -664,6 +664,19 @@ class SelfManagedKafka(PullEventSource): "SASL_SCRAM_512_AUTH", "BASIC_AUTH", "CLIENT_CERTIFICATE_TLS_AUTH", + "OAUTHBEARER_AUTH", + "IAM_AUTH", + "IAM_OAUTHBEARER_AUTH", + ] + NON_URI_TYPES = [ + "IAM_AUTH", + "IAM_OAUTHBEARER_AUTH", + ] + OAUTH_METADATA_TYPES = [ + "OAUTHBEARER_SCOPE", + "OAUTHBEARER_AUDIENCE", + "OAUTHBEARER_LOGICAL_CLUSTER", + "OAUTHBEARER_IDENTITY_POOL", ] def get_event_source_arn(self) -> PassThrough | None: @@ -699,6 +712,8 @@ def get_policy_statements( "No SourceAccessConfigurations for self managed kafka event provided.", ) document = self.generate_policy_document(self.SourceAccessConfigurations, intrinsic_resolver) + if not document["PolicyDocument"]["Statement"]: + return None return [document] def generate_policy_document( # type: ignore[no-untyped-def] @@ -711,7 +726,7 @@ def generate_policy_document( # type: ignore[no-untyped-def] statements.append(secret_manager) if authentication_uri_2: - secret_manager = self.get_secret_manager_secret(authentication_uri) # type: ignore[no-untyped-call] + secret_manager = self.get_secret_manager_secret(authentication_uri_2) # type: ignore[no-untyped-call] statements.append(secret_manager) if has_vpc_config: @@ -741,6 +756,7 @@ def get_secret_key(self, source_access_configurations: list[Any]) -> tuple[str | authentication_uri = None has_vpc_subnet = False has_vpc_security_group = False + has_auth_mechanism = False authentication_uri_2 = None if not isinstance(source_access_configurations, list): @@ -759,18 +775,23 @@ def get_secret_key(self, source_access_configurations: list[Any]) -> tuple[str | has_vpc_security_group = True elif config.get("Type") in self.AUTH_MECHANISM: - if authentication_uri: + if has_auth_mechanism: raise InvalidEventException( self.relative_id, "Multiple auth mechanism properties specified in SourceAccessConfigurations for self managed kafka event.", ) - self.validate_uri(config.get("URI"), "auth mechanism") - authentication_uri = config.get("URI") + has_auth_mechanism = True + if config.get("Type") not in self.NON_URI_TYPES: + self.validate_uri(config.get("URI"), "auth mechanism") + authentication_uri = config.get("URI") elif config.get("Type") == "SERVER_ROOT_CA_CERTIFICATE": self.validate_uri(config.get("URI"), "SERVER_ROOT_CA_CERTIFICATE") authentication_uri_2 = config.get("URI") + elif config.get("Type") in self.OAUTH_METADATA_TYPES: + self.validate_uri(config.get("URI"), config.get("Type")) + else: raise InvalidEventException( self.relative_id, diff --git a/tests/model/eventsources/test_self_managed_kafka_event_source.py b/tests/model/eventsources/test_self_managed_kafka_event_source.py index 325e45602..779836c34 100644 --- a/tests/model/eventsources/test_self_managed_kafka_event_source.py +++ b/tests/model/eventsources/test_self_managed_kafka_event_source.py @@ -116,6 +116,360 @@ def test_get_policy_statements_with_only_vpc_config(self): ] self.assertEqual(policy_statements, expected_policy_document) + def test_get_policy_statements_with_oauthbearer_auth(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "OAUTHBEARER_AUTH", "URI": "OAUTH_SECRET_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": ["secretsmanager:GetSecretValue"], + "Effect": "Allow", + "Resource": "OAUTH_SECRET_URI", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + + self.assertEqual(policy_statements, expected_policy_document) + + def test_get_policy_statements_with_oauthbearer_auth_and_vpc(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "OAUTHBEARER_AUTH", "URI": "OAUTH_SECRET_URI"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": ["secretsmanager:GetSecretValue"], + "Effect": "Allow", + "Resource": "OAUTH_SECRET_URI", + }, + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + ], + "Effect": "Allow", + "Resource": "*", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + + self.assertEqual(policy_statements, expected_policy_document) + + def test_get_policy_statements_with_oauthbearer_auth_and_server_root_ca(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "OAUTHBEARER_AUTH", "URI": "OAUTH_SECRET_URI"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + {"Type": "SERVER_ROOT_CA_CERTIFICATE", "URI": "CA_CERT_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": ["secretsmanager:GetSecretValue"], + "Effect": "Allow", + "Resource": "OAUTH_SECRET_URI", + }, + { + "Action": ["secretsmanager:GetSecretValue"], + "Effect": "Allow", + "Resource": "CA_CERT_URI", + }, + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + ], + "Effect": "Allow", + "Resource": "*", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + + self.assertEqual(policy_statements, expected_policy_document) + + def test_get_policy_statements_with_oauth_metadata_types_only(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "OAUTHBEARER_SCOPE", "URI": "scope_value"}, + {"Type": "OAUTHBEARER_AUDIENCE", "URI": "audience_value"}, + {"Type": "OAUTHBEARER_LOGICAL_CLUSTER", "URI": "cluster_value"}, + {"Type": "OAUTHBEARER_IDENTITY_POOL", "URI": "pool_value"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + ], + "Effect": "Allow", + "Resource": "*", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + self.assertEqual(policy_statements, expected_policy_document) + + @parameterized.expand( + [ + ("OAUTHBEARER_SCOPE",), + ("OAUTHBEARER_AUDIENCE",), + ("OAUTHBEARER_LOGICAL_CLUSTER",), + ("OAUTHBEARER_IDENTITY_POOL",), + ] + ) + def test_must_raise_for_missing_uri_on_oauth_metadata_types(self, metadata_type): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": metadata_type, "URI": ""}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.BatchSize = 1 + + with self.assertRaises(InvalidEventException): + self.kafka_event_source.get_policy_statements() + + def test_get_policy_statements_with_iam_auth(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "IAM_AUTH"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + ], + "Effect": "Allow", + "Resource": "*", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + + self.assertEqual(policy_statements, expected_policy_document) + + def test_get_policy_statements_with_iam_auth_no_vpc(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "IAM_AUTH"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + self.assertIsNone(policy_statements) + + def test_get_policy_statements_with_iam_oauthbearer_auth(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "IAM_OAUTHBEARER_AUTH"}, + {"Type": "OAUTHBEARER_AUDIENCE", "URI": "audience_value"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + ], + "Effect": "Allow", + "Resource": "*", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + + self.assertEqual(policy_statements, expected_policy_document) + + def test_get_policy_statements_with_iam_oauthbearer_auth_and_all_metadata(self): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "IAM_OAUTHBEARER_AUTH"}, + {"Type": "OAUTHBEARER_AUDIENCE", "URI": "audience_value"}, + {"Type": "OAUTHBEARER_LOGICAL_CLUSTER", "URI": "cluster_value"}, + {"Type": "OAUTHBEARER_IDENTITY_POOL", "URI": "pool_value"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.BatchSize = 1 + + policy_statements = self.kafka_event_source.get_policy_statements() + expected_policy_document = [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + ], + "Effect": "Allow", + "Resource": "*", + }, + ], + "Version": "2012-10-17", + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy", + } + ] + + self.assertEqual(policy_statements, expected_policy_document) + + @parameterized.expand( + [ + ("SASL_SCRAM_256_AUTH",), + ("SASL_SCRAM_512_AUTH",), + ("BASIC_AUTH",), + ("CLIENT_CERTIFICATE_TLS_AUTH",), + ("IAM_AUTH",), + ("IAM_OAUTHBEARER_AUTH",), + ] + ) + def test_must_raise_for_multiple_auth_mechanisms_with_iam_auth(self, other_auth_type): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "IAM_AUTH"}, + {"Type": other_auth_type, "URI": "OTHER_SECRET_URI"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.BatchSize = 1 + + with self.assertRaises(InvalidEventException): + self.kafka_event_source.get_policy_statements() + + @parameterized.expand( + [ + ("SASL_SCRAM_256_AUTH",), + ("SASL_SCRAM_512_AUTH",), + ("BASIC_AUTH",), + ("CLIENT_CERTIFICATE_TLS_AUTH",), + ] + ) + def test_must_raise_for_multiple_auth_mechanisms_with_oauthbearer(self, other_auth_type): + self.kafka_event_source.SourceAccessConfigurations = [ + {"Type": "OAUTHBEARER_AUTH", "URI": "OAUTH_SECRET_URI"}, + {"Type": other_auth_type, "URI": "OTHER_SECRET_URI"}, + {"Type": "VPC_SUBNET", "URI": "SECRET_URI"}, + {"Type": "VPC_SECURITY_GROUP", "URI": "SECRET_URI"}, + ] + self.kafka_event_source.KafkaBootstrapServers = ["endpoint1", "endpoint2"] + self.kafka_event_source.Enabled = True + self.kafka_event_source.Topics = ["Topics"] + self.kafka_event_source.BatchSize = 1 + + with self.assertRaises(InvalidEventException): + self.kafka_event_source.get_policy_statements() + def test_get_policy_statements_with_secrets_manager_kms_key_id(self): self.kafka_event_source.SourceAccessConfigurations = [ {"Type": "SASL_SCRAM_256_AUTH", "URI": "SECRET_URI"}, diff --git a/tests/translator/input/function_with_self_managed_kafka_iam_auth.yaml b/tests/translator/input/function_with_self_managed_kafka_iam_auth.yaml new file mode 100644 index 000000000..f6dd86b75 --- /dev/null +++ b/tests/translator/input/function_with_self_managed_kafka_iam_auth.yaml @@ -0,0 +1,26 @@ +AWSTemplateFormatVersion: '2010-09-09' +Parameters: {} +Resources: + KafkaFunction: + Type: AWS::Serverless::Function + Properties: + CodeUri: s3://sam-demo-bucket/kafka.zip + Handler: index.kafka_handler + Runtime: python3.9 + Events: + MyKafkaCluster: + Type: SelfManagedKafka + Properties: + KafkaBootstrapServers: + - abc.xyz.com:9092 + - 123.45.67.89:9096 + Topics: + - Topic1 + SourceAccessConfigurations: + - Type: IAM_AUTH + - Type: VPC_SUBNET + URI: subnet:subnet-12345 + - Type: VPC_SECURITY_GROUP + URI: security_group:sg-67890 + ConsumerGroupId: consumergroup1 + StartingPosition: LATEST diff --git a/tests/translator/input/function_with_self_managed_kafka_iam_oauth.yaml b/tests/translator/input/function_with_self_managed_kafka_iam_oauth.yaml new file mode 100644 index 000000000..86508d666 --- /dev/null +++ b/tests/translator/input/function_with_self_managed_kafka_iam_oauth.yaml @@ -0,0 +1,28 @@ +AWSTemplateFormatVersion: '2010-09-09' +Parameters: {} +Resources: + KafkaFunction: + Type: AWS::Serverless::Function + Properties: + CodeUri: s3://sam-demo-bucket/kafka.zip + Handler: index.kafka_handler + Runtime: python3.9 + Events: + MyKafkaCluster: + Type: SelfManagedKafka + Properties: + KafkaBootstrapServers: + - abc.xyz.com:9092 + - 123.45.67.89:9096 + Topics: + - Topic1 + SourceAccessConfigurations: + - Type: IAM_OAUTHBEARER_AUTH + - Type: OAUTHBEARER_AUDIENCE + URI: https://api.example.com + - Type: VPC_SUBNET + URI: subnet:subnet-12345 + - Type: VPC_SECURITY_GROUP + URI: security_group:sg-67890 + ConsumerGroupId: consumergroup1 + StartingPosition: LATEST diff --git a/tests/translator/input/function_with_self_managed_kafka_oauth.yaml b/tests/translator/input/function_with_self_managed_kafka_oauth.yaml new file mode 100644 index 000000000..e4b5fbf28 --- /dev/null +++ b/tests/translator/input/function_with_self_managed_kafka_oauth.yaml @@ -0,0 +1,38 @@ +AWSTemplateFormatVersion: '2010-09-09' +Parameters: {} +Resources: + KafkaFunction: + Type: AWS::Serverless::Function + Properties: + CodeUri: s3://sam-demo-bucket/kafka.zip + Handler: index.kafka_handler + Runtime: python3.9 + Events: + MyKafkaCluster: + Type: SelfManagedKafka + Properties: + KafkaBootstrapServers: + - abc.xyz.com:9092 + - 123.45.67.89:9096 + Topics: + - Topic1 + SourceAccessConfigurations: + - Type: OAUTHBEARER_AUTH + URI: arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c + - Type: OAUTHBEARER_SCOPE + URI: read write + - Type: OAUTHBEARER_AUDIENCE + URI: https://api.example.com + - Type: OAUTHBEARER_LOGICAL_CLUSTER + URI: lkc-12345 + - Type: OAUTHBEARER_IDENTITY_POOL + URI: pool-12345 + - Type: SERVER_ROOT_CA_CERTIFICATE + URI: arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r + - Type: VPC_SUBNET + URI: subnet:subnet-12345 + - Type: VPC_SECURITY_GROUP + URI: security_group:sg-67890 + ConsumerGroupId: consumergroup1 + StartingPosition: AT_TIMESTAMP + StartingPositionTimestamp: 1672560000 diff --git a/tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_auth.json b/tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_auth.json new file mode 100644 index 000000000..be918a558 --- /dev/null +++ b/tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_auth.json @@ -0,0 +1,117 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "IAM_AUTH" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "LATEST", + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws-cn:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_oauth.json b/tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_oauth.json new file mode 100644 index 000000000..b2529cd11 --- /dev/null +++ b/tests/translator/output/aws-cn/function_with_self_managed_kafka_iam_oauth.json @@ -0,0 +1,121 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "IAM_OAUTHBEARER_AUTH" + }, + { + "Type": "OAUTHBEARER_AUDIENCE", + "URI": "https://api.example.com" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "LATEST", + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws-cn:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/aws-cn/function_with_self_managed_kafka_oauth.json b/tests/translator/output/aws-cn/function_with_self_managed_kafka_oauth.json new file mode 100644 index 000000000..2a73135a3 --- /dev/null +++ b/tests/translator/output/aws-cn/function_with_self_managed_kafka_oauth.json @@ -0,0 +1,153 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "OAUTHBEARER_AUTH", + "URI": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c" + }, + { + "Type": "OAUTHBEARER_SCOPE", + "URI": "read write" + }, + { + "Type": "OAUTHBEARER_AUDIENCE", + "URI": "https://api.example.com" + }, + { + "Type": "OAUTHBEARER_LOGICAL_CLUSTER", + "URI": "lkc-12345" + }, + { + "Type": "OAUTHBEARER_IDENTITY_POOL", + "URI": "pool-12345" + }, + { + "Type": "SERVER_ROOT_CA_CERTIFICATE", + "URI": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "AT_TIMESTAMP", + "StartingPositionTimestamp": 1672560000, + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws-cn:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "secretsmanager:GetSecretValue" + ], + "Effect": "Allow", + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c" + }, + { + "Action": [ + "secretsmanager:GetSecretValue" + ], + "Effect": "Allow", + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r" + }, + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/aws-cn/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json b/tests/translator/output/aws-cn/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json index b61743f4f..4155569d1 100644 --- a/tests/translator/output/aws-cn/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json +++ b/tests/translator/output/aws-cn/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json @@ -99,7 +99,7 @@ "secretsmanager:GetSecretValue" ], "Effect": "Allow", - "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-secret-name-1a2b3c" + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:test-root-certificate-abcdef" }, { "Action": [ diff --git a/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_auth.json b/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_auth.json new file mode 100644 index 000000000..f61c15b8b --- /dev/null +++ b/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_auth.json @@ -0,0 +1,117 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "IAM_AUTH" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "LATEST", + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws-us-gov:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_oauth.json b/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_oauth.json new file mode 100644 index 000000000..05884f7fe --- /dev/null +++ b/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_iam_oauth.json @@ -0,0 +1,121 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "IAM_OAUTHBEARER_AUTH" + }, + { + "Type": "OAUTHBEARER_AUDIENCE", + "URI": "https://api.example.com" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "LATEST", + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws-us-gov:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_oauth.json b/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_oauth.json new file mode 100644 index 000000000..60be8903c --- /dev/null +++ b/tests/translator/output/aws-us-gov/function_with_self_managed_kafka_oauth.json @@ -0,0 +1,153 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "OAUTHBEARER_AUTH", + "URI": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c" + }, + { + "Type": "OAUTHBEARER_SCOPE", + "URI": "read write" + }, + { + "Type": "OAUTHBEARER_AUDIENCE", + "URI": "https://api.example.com" + }, + { + "Type": "OAUTHBEARER_LOGICAL_CLUSTER", + "URI": "lkc-12345" + }, + { + "Type": "OAUTHBEARER_IDENTITY_POOL", + "URI": "pool-12345" + }, + { + "Type": "SERVER_ROOT_CA_CERTIFICATE", + "URI": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "AT_TIMESTAMP", + "StartingPositionTimestamp": 1672560000, + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws-us-gov:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "secretsmanager:GetSecretValue" + ], + "Effect": "Allow", + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c" + }, + { + "Action": [ + "secretsmanager:GetSecretValue" + ], + "Effect": "Allow", + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r" + }, + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/aws-us-gov/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json b/tests/translator/output/aws-us-gov/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json index 110f226b1..5efdc82a3 100644 --- a/tests/translator/output/aws-us-gov/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json +++ b/tests/translator/output/aws-us-gov/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json @@ -99,7 +99,7 @@ "secretsmanager:GetSecretValue" ], "Effect": "Allow", - "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-secret-name-1a2b3c" + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:test-root-certificate-abcdef" }, { "Action": [ diff --git a/tests/translator/output/function_with_self_managed_kafka_iam_auth.json b/tests/translator/output/function_with_self_managed_kafka_iam_auth.json new file mode 100644 index 000000000..9face7a17 --- /dev/null +++ b/tests/translator/output/function_with_self_managed_kafka_iam_auth.json @@ -0,0 +1,117 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "IAM_AUTH" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "LATEST", + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/function_with_self_managed_kafka_iam_oauth.json b/tests/translator/output/function_with_self_managed_kafka_iam_oauth.json new file mode 100644 index 000000000..8ceed5e83 --- /dev/null +++ b/tests/translator/output/function_with_self_managed_kafka_iam_oauth.json @@ -0,0 +1,121 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "IAM_OAUTHBEARER_AUTH" + }, + { + "Type": "OAUTHBEARER_AUDIENCE", + "URI": "https://api.example.com" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "LATEST", + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/function_with_self_managed_kafka_oauth.json b/tests/translator/output/function_with_self_managed_kafka_oauth.json new file mode 100644 index 000000000..e9ca07783 --- /dev/null +++ b/tests/translator/output/function_with_self_managed_kafka_oauth.json @@ -0,0 +1,153 @@ +{ + "AWSTemplateFormatVersion": "2010-09-09", + "Parameters": {}, + "Resources": { + "KafkaFunction": { + "Properties": { + "Code": { + "S3Bucket": "sam-demo-bucket", + "S3Key": "kafka.zip" + }, + "Handler": "index.kafka_handler", + "Role": { + "Fn::GetAtt": [ + "KafkaFunctionRole", + "Arn" + ] + }, + "Runtime": "python3.9", + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::Lambda::Function" + }, + "KafkaFunctionMyKafkaCluster": { + "Properties": { + "FunctionName": { + "Ref": "KafkaFunction" + }, + "SelfManagedEventSource": { + "Endpoints": { + "KafkaBootstrapServers": [ + "abc.xyz.com:9092", + "123.45.67.89:9096" + ] + } + }, + "SelfManagedKafkaEventSourceConfig": { + "ConsumerGroupId": "consumergroup1" + }, + "SourceAccessConfigurations": [ + { + "Type": "OAUTHBEARER_AUTH", + "URI": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c" + }, + { + "Type": "OAUTHBEARER_SCOPE", + "URI": "read write" + }, + { + "Type": "OAUTHBEARER_AUDIENCE", + "URI": "https://api.example.com" + }, + { + "Type": "OAUTHBEARER_LOGICAL_CLUSTER", + "URI": "lkc-12345" + }, + { + "Type": "OAUTHBEARER_IDENTITY_POOL", + "URI": "pool-12345" + }, + { + "Type": "SERVER_ROOT_CA_CERTIFICATE", + "URI": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r" + }, + { + "Type": "VPC_SUBNET", + "URI": "subnet:subnet-12345" + }, + { + "Type": "VPC_SECURITY_GROUP", + "URI": "security_group:sg-67890" + } + ], + "StartingPosition": "AT_TIMESTAMP", + "StartingPositionTimestamp": 1672560000, + "Topics": [ + "Topic1" + ] + }, + "Type": "AWS::Lambda::EventSourceMapping" + }, + "KafkaFunctionRole": { + "Properties": { + "AssumeRolePolicyDocument": { + "Statement": [ + { + "Action": [ + "sts:AssumeRole" + ], + "Effect": "Allow", + "Principal": { + "Service": [ + "lambda.amazonaws.com" + ] + } + } + ], + "Version": "2012-10-17" + }, + "ManagedPolicyArns": [ + "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" + ], + "Policies": [ + { + "PolicyDocument": { + "Statement": [ + { + "Action": [ + "secretsmanager:GetSecretValue" + ], + "Effect": "Allow", + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-oauth-secret-1a2b3c" + }, + { + "Action": [ + "secretsmanager:GetSecretValue" + ], + "Effect": "Allow", + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-server-root-ca-cert-7p8q9r" + }, + { + "Action": [ + "ec2:CreateNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DeleteNetworkInterface", + "ec2:DescribeVpcs", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups" + ], + "Effect": "Allow", + "Resource": "*" + } + ], + "Version": "2012-10-17" + }, + "PolicyName": "SelfManagedKafkaExecutionRolePolicy" + } + ], + "Tags": [ + { + "Key": "lambda:createdBy", + "Value": "SAM" + } + ] + }, + "Type": "AWS::IAM::Role" + } + } +} diff --git a/tests/translator/output/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json b/tests/translator/output/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json index 25c998bb4..58061b580 100644 --- a/tests/translator/output/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json +++ b/tests/translator/output/self_managed_kafka_with_SERVER_ROOT_CA_CERTIFICATE_and_auth_mechanism.json @@ -99,7 +99,7 @@ "secretsmanager:GetSecretValue" ], "Effect": "Allow", - "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:my-path/my-secret-name-1a2b3c" + "Resource": "arn:aws:secretsmanager:us-west-2:123456789012:secret:test-root-certificate-abcdef" }, { "Action": [ From 136d6443d2ecda56c126a57b9cd0e10270827c04 Mon Sep 17 00:00:00 2001 From: aws-sam-cli-bot <46753707+aws-sam-cli-bot@users.noreply.github.com> Date: Thu, 8 Oct 2026 15:01:58 -0700 Subject: [PATCH 4/4] chore: bump version to 1.114.0 --- samtranslator/__init__.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/samtranslator/__init__.py b/samtranslator/__init__.py index 22c47ece6..9f97f8dea 100644 --- a/samtranslator/__init__.py +++ b/samtranslator/__init__.py @@ -1 +1 @@ -__version__ = "1.113.0" +__version__ = "1.114.0"